Tag: SSL
-
WordPress: Site not Secure despite SSL Certificate
I’ve recently migrated all my sites to use SSL (I know, it’s long overdue) and despite the SSL-Certificates being valid and working, Chrome and Firefox would show my sites as “not secure”. (No padlock icon.) After some digging, I discovered that WordPress really doesn’t play very nicely with SSL. Lots of themes, plugins, etc will […]
-
Easy-RSA: “failed to update database”
Attempted to create a new certificate using the EasyRSA suite and got the following error: “failed to update database” Unfortunately the script is pretty laconic, but some quick testing showed this was due to trying to re-use the default display name: Name [EasyRSA]: Picked a different name and the script committed my certificate correctly.
-
Easy-RSA Jabber SSL Certificate Problems
I’m currently setting up a new server and ran into something odd. Connecting to ejabberd with Pidgin, the later would reject the SSL certificate outright. At first I thought I had messed up the hostnames, or used an outdated Hash algorithm or whatever. The errors I saw in the debug window were: (22:17:42) nss: ERROR […]
-
Disable SSLv3 in Postfix, Dovecot
Postfix: Disabling certain versions of SSL works like this in Postfix: In your /etc/postfix/main.cf add or modify the following config parameter like so: smtpd_tls_protocols=!SSLv2,!SSLv3 If you are using mandatory TLS you’ll want to set this instead: smtpd_tls_mandatory_protocols=!SSLv2,!SSLv3 These should be fairly self-explanatory, but for further detail read the Postfix configuration parameters documentation. Do not forget […]
-
Test your SSL setup
Qualys offers a great tool that will check your server for SSL config issues, such as weak ciphers and outdated protocol versions.
-
Can I safely send a Certificate Request (CSR) by Email?
Yes. The CSR is your public key, which will be verified and signed by the certificate authority (CA) and returned to you afterward. It is this signed version you will then use in your application. It is useless without the private key, so even if someone makes a copy of it, they won’t be able […]
-
Apache: How To Redirect http to https
If you want to direct traffic from your http so that it gets encrypted, this is really easy to do in Apache: Step one: Set up your https vhost: <IfModule mod_ssl.c><VirtualHost 10.1.1.1:443>DocumentRoot /var/www# other server options go here as needed# – logging for exampleSSLEngine onSSLCertificateFile /etc/ssl/certs/example.certSSLCertificateKeyFile /etc/ssl/private/example.key# Add other SSL specific options as needed</pre></VirtualHost></IfModule> Step […]
-
Apache: ssl_error_rx_record_too_long Error
Got the error ssl_error_rx_record_too_long in Apache. Was confused at first, but then realized I had not configured SSL properly – Firefox was attempting to parse http as https. So I set out to configure SSL and lo and behold, this solved the issue.
-
Enabling SSL in Apache2 on Ubuntu
I’m using my server for various admin interfaces and so want to SSL encrypt all traffic to the web server. This is easy enough to add to the default vhosts. First, we need an SSL certificate. Create it by running: openssl req -new -x509 -days 3650 -nodes -out /etc/ssl/certs/apacheserver.pem -keyout /etc/ssl/private/apacheserver.pem This generates a self-signed […]