Security and Cryptography
 
Forums: » Register « |  User CP |  Games |  Calendar |  Members |  FAQs |  Sitemap |  Support | 
User Name:
Password:
Remember me
Go Back   Dev Shed ForumsSystem AdministrationSecurity and Cryptography

Reply
Add This Thread To:
  Del.icio.us   Digg   Google   Spurl   Blink   Furl   Simpy   Y! MyWeb 
Thread Tools Search this Thread Rate Thread Display Modes
 
Unread Dev Shed Forums Sponsor:
  #1  
Old November 17th, 2005, 10:20 PM
lothario lothario is offline
Contributing User
Dev Shed Newbie (0 - 499 posts)
 
Join Date: Sep 2003
Posts: 133 lothario User rank is Sergeant (500 - 2000 Reputation Level)lothario User rank is Sergeant (500 - 2000 Reputation Level)lothario User rank is Sergeant (500 - 2000 Reputation Level)lothario User rank is Sergeant (500 - 2000 Reputation Level)lothario User rank is Sergeant (500 - 2000 Reputation Level) 
Time spent in forums: 1 Day 1 h 24 m 9 sec
Reputation Power: 23
Expired Certificate

I have an old Red Hat 9 system.
I use it as a file server.

As a web server (Apache) it works too.

But when I try to access it with https, I get these 2 (expected) warnings:

1. The security certificate has expired.
2. The name on the security certificate is invalid or does not match the name of the site.

Yes, I have changed the name of the host.

How do I update the certificate to take care of these?
It is for personal use only so I assume I can update the certificate myself.

Reply With Quote
  #2  
Old November 19th, 2005, 10:45 AM
CyBerHigh CyBerHigh is offline
Contributing User
Dev Shed Newbie (0 - 499 posts)
 
Join Date: Jun 2004
Posts: 448 CyBerHigh User rank is Sergeant (500 - 2000 Reputation Level)CyBerHigh User rank is Sergeant (500 - 2000 Reputation Level)CyBerHigh User rank is Sergeant (500 - 2000 Reputation Level)CyBerHigh User rank is Sergeant (500 - 2000 Reputation Level)CyBerHigh User rank is Sergeant (500 - 2000 Reputation Level) 
Time spent in forums: 4 Days 9 h 20 m 35 sec
Reputation Power: 20
Send a message via AIM to CyBerHigh
you must buy your own ssl certificate. Last time I checked they are around 70 to 700 US dollars. It depends on what it is going to be used for and the support of the certificate. If you want it to work with your subdomains than it gets really expensive.

Your data is still being encryptied with ssl it just isn't certified, so thats the error that you are reseving.

But there is no way to get it for free, as far as i know. Someone may know more about it but I havn't ever heard of a way.
__________________
My Site:
http://www.coryhardman.com

Reply With Quote
  #3  
Old November 21st, 2005, 01:53 AM
viewport viewport is offline
Registered User
Dev Shed Newbie (0 - 499 posts)
 
Join Date: Nov 2005
Posts: 2 viewport User rank is Just a Lowly Private (1 - 20 Reputation Level) 
Time spent in forums: 29 m 37 sec
Reputation Power: 0
Self-generated and self-signed SSL Certs

Quote:
Originally Posted by lothario
Yes, I have changed the name of the host.

How do I update the certificate to take care of these?
It is for personal use only so I assume I can update the certificate myself.


Self-generate your own SSL cert. Do you have OpenSSL installed on your redhat?

3 steps:

1. Generate your own private key
2. Generate a CSR (certificate-signing request).
3. Sign your own cert with own private key.

Meaning, you process your own CSR.

All you have to do is tell your friends and family (folks who surf your website) about the fingerprint of your key. Tell them over phone, if you don't want some tom-****-harry calling them to impersonate you. Tell them to check that the fingerprint (showing on their browsers) is correct, and tell them to add your cert to their "trusted list". Beyond that, they won't get a warning like "warning, cert not trusted by any CAs that you trust, blah blah".

The idea behind a CA-signed cert is that a CA has TALKED to you and (somehow) VERIFIED you are who you claim to be (eg Neo, running domain matrix.com). All web browsers will have a list of well-known CAs. These browsers trust those well-known CAs. And through a "web of trust" (a single child link in this case), those browsers also automatically trust any certs "signed by" (vouched for by) those CAs.

Jonathon

Reply With Quote
Reply

Viewing: Dev Shed ForumsSystem AdministrationSecurity and Cryptography > Expired Certificate


Thread Tools  Search this Thread 
Search this Thread:

Advanced Search
Display Modes  Rate This Thread 
Rate This Thread:


Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
View Your Warnings | New Posts | Latest News | Latest Threads | Shoutbox
Forum Jump


Forums: » Register « |  User CP |  Games |  Calendar |  Members |  FAQs |  Sitemap |  Support | 
  
 





© 2003-2008 by Developer Shed. All rights reserved. DS Cluster 6 hosted by Hostway
Stay green...Green IT