Milí majitelé routerů Turris,
toto fórum bylo 9. 12. 2016 zmrazeno a nahrazeno naším novým Turris fórem. Ještě chvíli bude dostupné k prohlížení, ale již zde není možné přispívat. Více informací naleznete v oznámení o uzavření fóra.
Dear Turris routers users,
this forum has been frozen on Dec 9th, 2016 and replaced by our new Turris forum. It will be read-only accessible for some time after. For more information, read the announcement about closing the forum.
# cat privatekey.pem certificate.pem >/etc/lighttpd-startssl.pem
# wget http://www.startssl.com/certs/sub.class1.server.ca.pem
# mv sub.class1.server.ca.pem /etc/ssl/certs/
/etc/lighttpd/conf.d/ssl-enable.conf
:
ssl.pemfile = "/etc/lighttpd-startssl.pem"
ssl.ca-file = "/etc/ssl/certs/sub.class1.server.ca.pem"
# openssl s_client -connect <adresa turrisu>:443
$HTTP["host"] =~ "druhadomena\.example\.cz$" {
ssl.pemfile = "/etc/lighttpd-druhadomena.pem"
}
2014-09-14 16:31:37: (network.c.747) SSL: Private key does not match the certificate public key, reason: error:0906D066:lib(9):func(109):reason(102) /etc/lighttpd-startssl_xyz.pem
$ openssl x509 -noout -text -in certifikat.pem
$ openssl rsa -noout -text -in private.pem
. Modulus zde uvedený musí být totožný s modulem certifikátu.Subject: C=CZ, CN=turris.<doména>.cz/emailAddress=webmaster@<doména>.cz
root@turris:~# hexdump -C /etc/lighttpd-startssl.pem
00000000 2d 2d 2d 2d 2d 42 45 47 49 4e 20 50 52 49 56 41 |-----BEGIN PRIVA|
00000010 54 45 20 4b 45 59 2d 2d 2d 2d 2d 0a 4d 49 49 45 |TE KEY-----.MIIE|
…
00000690 3d 0a 2d 2d 2d 2d 2d 45 4e 44 20 50 52 49 56 41 |=.-----END PRIVA|
000006a0 54 45 20 4b 45 59 2d 2d 2d 2d 2d 0a 2d 2d 2d 2d |TE KEY-----.----|
000006b0 2d 42 45 47 49 4e 20 43 45 52 54 49 46 49 43 41 |-BEGIN CERTIFICA|
000006c0 54 45 2d 2d 2d 2d 2d 0a 4d 49 49 47 33 44 43 43 |TE-----.MIIG3DCC|
…
00001010 55 6a 53 44 6c 69 55 3d 0a 2d 2d 2d 2d 2d 45 4e |UjSDliU=.-----EN|
00001020 44 20 43 45 52 54 49 46 49 43 41 54 45 2d 2d 2d |D CERTIFICATE---|
00001030 2d 2d 0a |--.|
root@turris:/tmp/klic# hexdump -C turris.<doména>.cz.key
00000000 2d 2d 2d 2d 2d 42 45 47 49 4e 20 52 53 41 20 50 |-----BEGIN RSA P|
00000010 52 49 56 41 54 45 20 4b 45 59 2d 2d 2d 2d 2d 0a |RIVATE KEY-----.|
...
00000670 0a 2d 2d 2d 2d 2d 45 4e 44 20 52 53 41 20 50 52 |.-----END RSA PR|
00000680 49 56 41 54 45 20 4b 45 59 2d 2d 2d 2d 0a 2d 2d |IVATE KEY----.--|
00000690 2d 2d 2d 2d 42 45 47 49 4e 20 43 45 52 54 49 46 |----BEGIN CERTIF|
000006a0 49 43 41 54 45 2d 2d 2d 2d 2d 0a 4d 49 49 47 4e |ICATE-----.MIIGN|
...
00000f10 76 41 75 65 2b 57 55 3d 0a 2d 2d 2d 2d 2d 45 4e |vAue+WU=.-----EN|
00000f20 44 20 43 45 52 54 49 46 49 43 41 54 45 2d 2d 2d |D CERTIFICATE---|
00000f30 2d 2d 0a |--.|
00000f33
-----BEGIN CERTIFICATE-----
-----END RSA PRIVATE KEY----
00000000 2d 2d 2d 2d 2d 42 45 47 49 4e 20 50 52 49 56 41 |-----BEGIN PRIVA|
00000010 54 45 20 4b 45 59 2d 2d 2d 2d 2d 0a 4d 49 49 45 |TE KEY-----.MIIE|
...
00000690 3d 0a 2d 2d 2d 2d 2d 45 4e 44 20 50 52 49 56 41 |=.-----END PRIVA|
000006a0 54 45 20 4b 45 59 2d 2d 2d 2d 2d 0a 2d 2d 2d 2d |TE KEY-----.----|
000006b0 2d 2d 42 45 47 49 4e 20 43 45 52 54 49 46 49 43 |--BEGIN CERTIFIC|
000006c0 41 54 45 2d 2d 2d 2d 2d 0a 4d 49 49 47 4e 44 43 |ATE-----.MIIGNDC|
...
00000f30 75 65 2b 57 55 3d 0a 2d 2d 2d 2d 2d 45 4e 44 20 |ue+WU=.-----END |
00000f40 43 45 52 54 49 46 49 43 41 54 45 2d 2d 2d 2d 2d |CERTIFICATE-----|
00000f50 0a |.|
Powered by mwForum 2.29.3 © 1999-2013 Markus Wichitill