Minggu, 23 September 2007

Config Apache2 With SSL on Linux Debian Etch

pastikan kamu sudah masuk dalam full permission di root
# sudo

pertama yang harus dilakukan adalah menginstall apache
# apt-get install apache2

install openssl :
# apt-get install openssl ssl-cert

Jika tidak mempunyai sertifikat SSL, maka diharuskan membuat sertifikat sendiri.
pada linux debian varian selain etch dapat menjalankan perintah
# apache2-ssl-certificate
pada debian etch, jalankan perintah :
# make-ssl-cert

untuk membentuk sertifikat ssl jalankan perintah dan jawab pertanyaannya :
# openssl req $@ -new -x509 -days 365 -nodes -out /etc/apache2/apache.pem -keyout /etc/apache2/apache.pem

Generating a 1024 bit RSA private key
....................................++++++
.....................++++++
writing new private key to '/etc/apache2/apache.pem'
-----
You are about to be asked to enter information that will be incorporated
into your certificate request.
What you are about to enter is what is called a Distinguished Name or a DN.
There are quite a few fields but you can leave some blank
For some fields there will be a default value,
If you enter '.', the field will be left blank.
-----
Country Name (2 letter code) [AU]:ID
State or Province Name (full name) [Some-State]:DKI Jakarta
Locality Name (eg, city) []:Jakarta
Organization Name (eg, company) [Internet Widgits Pty Ltd]:PT Indo Pratama Cyber net
Organizational Unit Name (eg, section) []:Network Operation Center
Common Name (eg, YOUR name) []:Indra Budiman
Email Address []:noc2@ipnet.net.id

setting permisions pada apache.pem yang telah terbentuk
#chmod 600 /etc/apache2/apache.pem

setelah sertifikat terbentuk,tambahkan port 443
# vi /etc/apache2/ports.conf
isi :
Listen 80
Listen 443

enable support SSL pada Apache2 webserver
# a2enmod ssl
Module ssl installed; run /etc/init.d/apache2 force-reload to enable

tambahkan didalam konfigurasi site :
NameVirtualHost *:443
<>
....
SSLEngine on
SSLCertificateFile /etc/apache2/apache.pem

...
< /VirtualHost >

Restart apache
# /etc/init.d/apache2 restart

Tidak ada komentar: