Solved

replace the test cert with a commercial one (mod_ssl)

Posted on 2004-08-10
3
319 Views
Last Modified: 2010-03-04
hi folks,

i've installed a test cert for SSL on Apache 2.0.45 for Windows 2k, by creating a key, creating a CSR and then installing a temporary test cert. i've used mod_ssl 2.0.48. i followed the steps outlined in:
http://www.devx.com/opensource/Article/20085
and i now have 2 mydomain.crt files, 2 mydomain.key files and one mydomain.csr files, in the \ssl and \bin directories.

now i want to change the test cert for SSL to a commercial cert (Entrust).

do i just remove the existing .csr, .crt and .key files (should i also roll back changes in the httpd.conf, openssl.conf etc.), do i just create new key & csr files ignoring the existing setup, or can anybody point me in the right direction to go about replacing my test cert setup with the commercial one?
0
Comment
Question by:gdoherty
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
3 Comments
 
LVL 1

Accepted Solution

by:
justywong earned 150 total points
ID: 11770612
For Unix/Linux version,

assume your $APACHE_HOME = /usr/local/apache2

you can just copy the new cert & key files (name different from old cert and key)  to
  $APACHE_HOME/conf/ssl.key & ssl.crt

and modify the $APACHE_HOME/conf/ssl.conf to point to your new key & cert file.
e.g.
(old key & cert):
SSLCertificateKeyFile /usr/local/apache2/conf/ssl.key/test_server.key
SSLCertificateFile /usr/local/apache2/conf/ssl.crt/test_server.crt
(new key & cert):
SSLCertificateKeyFile /usr/local/apache2/conf/ssl.key/prod_server.key
SSLCertificateFile /usr/local/apache2/conf/ssl.crt/prod_server.crt

remember to backup your ssl.conf before making change. you can just recover the ssl.conf in case you need to rollback.
0
 

Author Comment

by:gdoherty
ID: 11771110
many thanks - wouldn't have thought of that, but it makes sense.

that said, i'm using windows 2k - can anyody out there let me know is there anything else that i need to do on w2k/apache/mod_ssl before justywong gets the points?

thanks,
0
 
LVL 51

Assisted Solution

by:ahoffmann
ahoffmann earned 100 total points
ID: 11771727
> do i just remove the existing .csr, .crt and .key files
yes
> (should i also roll back changes in the httpd.conf, openssl.conf etc.)
not necessary

to do it save and have a working backup, you may install your certs/keys in e new directory, and then change httpd.conf (see previous suggestion), but IMHO that's more error-prone than replaceing 2 files
0

Featured Post

Easy, flexible multimedia distribution & control

Coming soon!  Ideal for large-scale A/V applications, ATEN's VM3200 Modular Matrix Switch is an all-in-one solution that simplifies video wall integration. Easily customize display layouts to see what you want, how you want it in 4k.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Hi, in this article I'm going to teach you how to run your own site, and how to let people in (without IP). I'll talk about and explain each step... :) By the way, everything in this Tutorial is completely free and legal. This article is for …
Introduction This article is intended for those who are new to PHP error handling (https://www.experts-exchange.com/articles/11769/And-by-the-way-I-am-New-to-PHP.html).  It addresses one of the most common problems that plague beginning PHP develop…
In a recent question (https://www.experts-exchange.com/questions/29004105/Run-AutoHotkey-script-directly-from-Notepad.html) here at Experts Exchange, a member asked how to run an AutoHotkey script (.AHK) directly from Notepad++ (aka NPP). This video…
Attackers love to prey on accounts that have privileges. Reducing privileged accounts and protecting privileged accounts therefore is paramount. Users, groups, and service accounts need to be protected to help protect the entire Active Directory …

749 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question