<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Apache SSL problem in Operating System - HP-UX</title>
    <link>https://community.hpe.com/t5/operating-system-hp-ux/apache-ssl-problem/m-p/3479994#M847223</link>
    <description>Hi,&lt;BR /&gt;&lt;BR /&gt;I think it looks the CA certificate file.&lt;BR /&gt;Try to add SSLCACertificateFile option also.&lt;BR /&gt;&lt;BR /&gt;like:&lt;BR /&gt;&lt;BR /&gt;SSLCertificateFile /tmp/server.crt&lt;BR /&gt;SSLCertificateKeyFile /tmp/myserver.key&lt;BR /&gt;SSLCACertificateFile /tmp/other-bundle.txt&lt;BR /&gt;</description>
    <pubDate>Wed, 09 Feb 2005 04:21:27 GMT</pubDate>
    <dc:creator>VEL_1</dc:creator>
    <dc:date>2005-02-09T04:21:27Z</dc:date>
    <item>
      <title>Apache SSL problem</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/apache-ssl-problem/m-p/3479980#M847209</link>
      <description>I have an web application using SSL. On some servers my application doesn't start and the following error message is logged in the error log file.&lt;BR /&gt;&lt;BR /&gt;Thu Feb  3 03:35:39 2005] [crit] error setting verify locations&lt;BR /&gt;[Thu Feb  3 03:35:39 2005] [crit] error:02001002:system library:fopen:No such file or directory&lt;BR /&gt;[Thu Feb  3 03:35:39 2005] [crit] error:2006D002:BIO routines:BIO_new_file:system lib&lt;BR /&gt;[Thu Feb  3 03:35:39 2005] [crit] error:0B084002:x509 certificate routines:X509_load_cert_crl_file:system lib&lt;BR /&gt;&lt;BR /&gt;Can anyone help me with the problem</description>
      <pubDate>Mon, 07 Feb 2005 09:30:31 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/apache-ssl-problem/m-p/3479980#M847209</guid>
      <dc:creator>Seetha Lakshmi</dc:creator>
      <dc:date>2005-02-07T09:30:31Z</dc:date>
    </item>
    <item>
      <title>Re: Apache SSL problem</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/apache-ssl-problem/m-p/3479981#M847210</link>
      <description>To me it looks like it is problem with few of the libraries on some boxes. Are all libraries present on the boxes where it is a problem??&lt;BR /&gt;&lt;BR /&gt;Anil</description>
      <pubDate>Mon, 07 Feb 2005 09:36:39 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/apache-ssl-problem/m-p/3479981#M847210</guid>
      <dc:creator>RAC_1</dc:creator>
      <dc:date>2005-02-07T09:36:39Z</dc:date>
    </item>
    <item>
      <title>Re: Apache SSL problem</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/apache-ssl-problem/m-p/3479982#M847211</link>
      <description>Can you mention the names of the library files.</description>
      <pubDate>Mon, 07 Feb 2005 09:38:08 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/apache-ssl-problem/m-p/3479982#M847211</guid>
      <dc:creator>Seetha Lakshmi</dc:creator>
      <dc:date>2005-02-07T09:38:08Z</dc:date>
    </item>
    <item>
      <title>Re: Apache SSL problem</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/apache-ssl-problem/m-p/3479983#M847212</link>
      <description>Seetha,&lt;BR /&gt;have you got a SSLCertificateFile or SSLCertificateKeyFile ?&lt;BR /&gt;Where are they located?&lt;BR /&gt;Regards</description>
      <pubDate>Mon, 07 Feb 2005 09:47:15 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/apache-ssl-problem/m-p/3479983#M847212</guid>
      <dc:creator>Peter Godron</dc:creator>
      <dc:date>2005-02-07T09:47:15Z</dc:date>
    </item>
    <item>
      <title>Re: Apache SSL problem</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/apache-ssl-problem/m-p/3479984#M847213</link>
      <description>Yes, they are located under apache/ssl/certs and apache/ssl/private directories.</description>
      <pubDate>Mon, 07 Feb 2005 09:50:20 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/apache-ssl-problem/m-p/3479984#M847213</guid>
      <dc:creator>Seetha Lakshmi</dc:creator>
      <dc:date>2005-02-07T09:50:20Z</dc:date>
    </item>
    <item>
      <title>Re: Apache SSL problem</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/apache-ssl-problem/m-p/3479985#M847214</link>
      <description>Seetha,&lt;BR /&gt;may also be worthwhile to try:&lt;BR /&gt;SSLCACertificatePath may have to be fully qualified &lt;BR /&gt;i.e. same as ServerRoot&lt;BR /&gt;ServerRoot      /etc/httpsd&lt;BR /&gt;SSLCACertificatePath /etc/httpsd/certifs&lt;BR /&gt;Regards&lt;BR /&gt;</description>
      <pubDate>Mon, 07 Feb 2005 09:50:52 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/apache-ssl-problem/m-p/3479985#M847214</guid>
      <dc:creator>Peter Godron</dc:creator>
      <dc:date>2005-02-07T09:50:52Z</dc:date>
    </item>
    <item>
      <title>Re: Apache SSL problem</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/apache-ssl-problem/m-p/3479986#M847215</link>
      <description>Yes i have fully qualified the certificate file and the key file.&lt;BR /&gt;&lt;BR /&gt;SSLCertificateKeyFile apache/ssl/private/$WEB_HOST.key&lt;BR /&gt;SSLCertificateFile apache/ssl/certs/$WEB_HOST.cert&lt;BR /&gt;&lt;BR /&gt;</description>
      <pubDate>Mon, 07 Feb 2005 09:53:36 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/apache-ssl-problem/m-p/3479986#M847215</guid>
      <dc:creator>Seetha Lakshmi</dc:creator>
      <dc:date>2005-02-07T09:53:36Z</dc:date>
    </item>
    <item>
      <title>Re: Apache SSL problem</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/apache-ssl-problem/m-p/3479987#M847216</link>
      <description>Seetha,&lt;BR /&gt;would you not need a "/" before the first entry to make the path absolute?&lt;BR /&gt;</description>
      <pubDate>Mon, 07 Feb 2005 09:54:58 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/apache-ssl-problem/m-p/3479987#M847216</guid>
      <dc:creator>Peter Godron</dc:creator>
      <dc:date>2005-02-07T09:54:58Z</dc:date>
    </item>
    <item>
      <title>Re: Apache SSL problem</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/apache-ssl-problem/m-p/3479988#M847217</link>
      <description>Are these the SSL keys and Certs that came with apache. Those are somewhat fake and useless, using the name localhost.localdomain.&lt;BR /&gt;&lt;BR /&gt;I recently learned (last Friday) how to generate proper ssl certificates and keys. If this is where the problem is I can connect to a machine at another office and get you the script I developed to semi automate the process.&lt;BR /&gt;&lt;BR /&gt;SEP</description>
      <pubDate>Mon, 07 Feb 2005 09:57:41 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/apache-ssl-problem/m-p/3479988#M847217</guid>
      <dc:creator>Steven E. Protter</dc:creator>
      <dc:date>2005-02-07T09:57:41Z</dc:date>
    </item>
    <item>
      <title>Re: Apache SSL problem</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/apache-ssl-problem/m-p/3479989#M847218</link>
      <description>No. actually i have set them as follows.&lt;BR /&gt;&lt;BR /&gt;SSLCertificateKeyFile $WEB_HOME/data/apache/ssl/private/$WEB_HOST.key&lt;BR /&gt;SSLCertificateFile $WEB_HOME/data/apache/ssl/certs/$WEB_HOST.cert&lt;BR /&gt;&lt;BR /&gt;Where the variables WEB_HOME and WEB_HOST are set by the application&lt;BR /&gt;&lt;BR /&gt;</description>
      <pubDate>Mon, 07 Feb 2005 09:58:55 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/apache-ssl-problem/m-p/3479989#M847218</guid>
      <dc:creator>Seetha Lakshmi</dc:creator>
      <dc:date>2005-02-07T09:58:55Z</dc:date>
    </item>
    <item>
      <title>Re: Apache SSL problem</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/apache-ssl-problem/m-p/3479990#M847219</link>
      <description>No the SSL certificate and key were created for the application by us.</description>
      <pubDate>Mon, 07 Feb 2005 09:59:58 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/apache-ssl-problem/m-p/3479990#M847219</guid>
      <dc:creator>Seetha Lakshmi</dc:creator>
      <dc:date>2005-02-07T09:59:58Z</dc:date>
    </item>
    <item>
      <title>Re: Apache SSL problem</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/apache-ssl-problem/m-p/3479991#M847220</link>
      <description>Seetha,&lt;BR /&gt;as my last attempt can you replace the $variables with hardcoded values and try again. My thinking is what happens if $WEB_HOME or $WEB_HOST are incorrect/blank?&lt;BR /&gt;That would explain the no such file message.&lt;BR /&gt;Regards</description>
      <pubDate>Mon, 07 Feb 2005 11:19:17 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/apache-ssl-problem/m-p/3479991#M847220</guid>
      <dc:creator>Peter Godron</dc:creator>
      <dc:date>2005-02-07T11:19:17Z</dc:date>
    </item>
    <item>
      <title>Re: Apache SSL problem</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/apache-ssl-problem/m-p/3479992#M847221</link>
      <description>This situation is impossible because all these environment variables are set in a particular ".ksh" file and it is run each time the application starts. Also the application will not start if these variables are not set.</description>
      <pubDate>Mon, 07 Feb 2005 22:24:48 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/apache-ssl-problem/m-p/3479992#M847221</guid>
      <dc:creator>Seetha Lakshmi</dc:creator>
      <dc:date>2005-02-07T22:24:48Z</dc:date>
    </item>
    <item>
      <title>Re: Apache SSL problem</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/apache-ssl-problem/m-p/3479993#M847222</link>
      <description>I also tried setting the SSLCertificateFile and SSLCertificateKeyFile specifying the absolute path but still i get the same error. Can some one help me with the problem</description>
      <pubDate>Mon, 07 Feb 2005 23:43:28 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/apache-ssl-problem/m-p/3479993#M847222</guid>
      <dc:creator>Seetha Lakshmi</dc:creator>
      <dc:date>2005-02-07T23:43:28Z</dc:date>
    </item>
    <item>
      <title>Re: Apache SSL problem</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/apache-ssl-problem/m-p/3479994#M847223</link>
      <description>Hi,&lt;BR /&gt;&lt;BR /&gt;I think it looks the CA certificate file.&lt;BR /&gt;Try to add SSLCACertificateFile option also.&lt;BR /&gt;&lt;BR /&gt;like:&lt;BR /&gt;&lt;BR /&gt;SSLCertificateFile /tmp/server.crt&lt;BR /&gt;SSLCertificateKeyFile /tmp/myserver.key&lt;BR /&gt;SSLCACertificateFile /tmp/other-bundle.txt&lt;BR /&gt;</description>
      <pubDate>Wed, 09 Feb 2005 04:21:27 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/apache-ssl-problem/m-p/3479994#M847223</guid>
      <dc:creator>VEL_1</dc:creator>
      <dc:date>2005-02-09T04:21:27Z</dc:date>
    </item>
    <item>
      <title>Re: Apache SSL problem</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/apache-ssl-problem/m-p/3479995#M847224</link>
      <description>Here is the steps I did for Apache with SSL:&lt;BR /&gt;&lt;BR /&gt;To build apache with OpenSSL for secure communication, Use following steps.&lt;BR /&gt;&lt;BR /&gt;Steps:&lt;BR /&gt;&lt;BR /&gt;I. Build &lt;BR /&gt;&lt;BR /&gt;a. Untar the Source &amp;amp; configure, gmake and gmake install&lt;BR /&gt;&lt;BR /&gt;#  tar -zxvf httpd-2.0.46.tar.gz&lt;BR /&gt;&lt;BR /&gt;b. Configure the apache with options&lt;BR /&gt;&lt;BR /&gt;# cd  httpd-2.0.46&lt;BR /&gt;# ./configure --prefix=/usr/local/apache --with-ssl=/usr/local/ssl/lib --enable-expires --enable-ssl --enable-rewrite --enable-so --enable-xml --enable-modules=most &lt;BR /&gt;&lt;BR /&gt;b. Compile &amp;amp; install the apache using following commands&lt;BR /&gt;&lt;BR /&gt;# gmake&lt;BR /&gt;# gmake install&lt;BR /&gt;&lt;BR /&gt;II. Create Certificate Authority (CA)&lt;BR /&gt;&lt;BR /&gt;a. To create RSA private key&lt;BR /&gt;&lt;BR /&gt;# /usr/local/ssl/bin/openssl genrsa -des3 -out ca.key 1024&lt;BR /&gt;Generating RSA private key, 1024 bit long modulus&lt;BR /&gt;...++++++&lt;BR /&gt;............++++++&lt;BR /&gt;e is 65537 (0x10001)&lt;BR /&gt;Enter pass phrase for ca.key:&lt;BR /&gt;Verifying - Enter pass phrase for ca.key:&lt;BR /&gt;# &lt;BR /&gt;&lt;BR /&gt;b. To create self-signed CA certificate&lt;BR /&gt;&lt;BR /&gt;# /usr/local/ssl/bin/openssl req -new -x509 -days 365 -key ca.key -out ca.crt&lt;BR /&gt;Enter pass phrase for ca.key:&lt;BR /&gt;You are about to be asked to enter information that will be incorporated&lt;BR /&gt;into your certificate request.&lt;BR /&gt;What you are about to enter is what is called a Distinguished Name or a DN.&lt;BR /&gt;There are quite a few fields but you can leave some blank&lt;BR /&gt;For some fields there will be a default value,&lt;BR /&gt;If you enter '.', the field will be left blank.&lt;BR /&gt;-----&lt;BR /&gt;Country Name (2 letter code) [AU]:IN&lt;BR /&gt;State or Province Name (full name) [Some-State]:TN&lt;BR /&gt;Locality Name (eg, city) []:CBE&lt;BR /&gt;Organization Name (eg, company) [Internet Widgits Pty Ltd]:cisco&lt;BR /&gt;Organizational Unit Name (eg, section) []:OpenSource&lt;BR /&gt;Common Name (eg, YOUR name) []:linuxtest.cisco.com&lt;BR /&gt;Email Address []:opensource@cisco.com&lt;BR /&gt;#&lt;BR /&gt;&lt;BR /&gt;III. Create SSL Certificate&lt;BR /&gt;&lt;BR /&gt;a. To create RSA private key &lt;BR /&gt;&lt;BR /&gt;# /usr/local/ssl/bin/openssl genrsa -des3 -out server.key 1024&lt;BR /&gt;Generating RSA private key, 1024 bit long modulus&lt;BR /&gt;..........++++++&lt;BR /&gt;...............................++++++&lt;BR /&gt;e is 65537 (0x10001)&lt;BR /&gt;Enter pass phrase for server.key:&lt;BR /&gt;Verifying - Enter pass phrase for server.key:&lt;BR /&gt;#&lt;BR /&gt;&lt;BR /&gt;b. Decrypt private key (so that apache can start w/o asking for password) &lt;BR /&gt;&lt;BR /&gt;# mv server.key server.key.secure&lt;BR /&gt;# /usr/local/ssl/bin/openssl rsa -in server.key.secure -out server.key&lt;BR /&gt;Enter pass phrase for server.key.secure:&lt;BR /&gt;writing RSA key&lt;BR /&gt;#&lt;BR /&gt;&lt;BR /&gt;c. To create a Certificate Signing Request (CSR) &lt;BR /&gt;&lt;BR /&gt;# /usr/local/ssl/bin/openssl req -new -days 365 -key server.key -out server.csr&lt;BR /&gt;You are about to be asked to enter information that will be incorporated&lt;BR /&gt;into your certificate request.&lt;BR /&gt;What you are about to enter is what is called a Distinguished Name or a DN.&lt;BR /&gt;There are quite a few fields but you can leave some blank&lt;BR /&gt;For some fields there will be a default value,&lt;BR /&gt;If you enter '.', the field will be left blank.&lt;BR /&gt;-----&lt;BR /&gt;Country Name (2 letter code) [AU]:IN&lt;BR /&gt;State or Province Name (full name) [Some-State]:TN&lt;BR /&gt;Locality Name (eg, city) []:CBE&lt;BR /&gt;Organization Name (eg, company) [Internet Widgits Pty Ltd]:cisco&lt;BR /&gt;Organizational Unit Name (eg, section) []:OpenSource&lt;BR /&gt;Common Name (eg, YOUR name) []:linuxtest.cisco.com&lt;BR /&gt;Email Address []:opensource@cisco.com&lt;BR /&gt;&lt;BR /&gt;Please enter the following 'extra' attributes&lt;BR /&gt;to be sent with your certificate request&lt;BR /&gt;A challenge password []:welcome&lt;BR /&gt;An optional company name []:Senas.net&lt;BR /&gt;#&lt;BR /&gt;&lt;BR /&gt;IV. Sign SSL Certificate&lt;BR /&gt;&lt;BR /&gt;# /usr/local/ssl/bin/openssl x509 -req -days 30 -in server.csr -signkey server.key -out server.crt&lt;BR /&gt;Signature ok&lt;BR /&gt;subject=/C=IN/ST=TN/L=CBE/O=cisco/OU=OpenSource/CN=linuxtest.cisco.com/emailAddress=opensource@cisco.com&lt;BR /&gt;Getting Private key&lt;BR /&gt;#&lt;BR /&gt;&lt;BR /&gt;V. Create directories for SSL certificate &amp;amp; key and copy the certificate &amp;amp; key to corresponding directories&lt;BR /&gt;&lt;BR /&gt;# mkdir /usr/local/apache/conf/ssl.crt &lt;BR /&gt;# mkdir /usr/local/apache/conf/ssl.key&lt;BR /&gt;# cp server.crt ssl.crt&lt;BR /&gt;# cp server.key ssl.key&lt;BR /&gt;&lt;BR /&gt;VI. Apache configuration&lt;BR /&gt;&lt;BR /&gt;In /usr/local/apache/conf/httpd.conf,&lt;BR /&gt;&lt;BR /&gt;ServerName linuxtest.cisco.com&lt;BR /&gt;ServerAdmin sysadmin@linuxtest.cisco.com&lt;BR /&gt;&lt;BR /&gt;VII. Start Apache&lt;BR /&gt;&lt;BR /&gt;# /usr/local/apache/bin/apachectl startssl  // both 80 &amp;amp; 443&lt;BR /&gt;&lt;BR /&gt;To check apache whether it listens on port 80 &amp;amp; 443&lt;BR /&gt;&lt;BR /&gt;a. Use "netstat" command &lt;BR /&gt;&lt;BR /&gt;# netstat -na | grep 80&lt;BR /&gt;tcp        0      0 0.0.0.0:80              0.0.0.0:*               LISTEN&lt;BR /&gt;# netstat -na | grep 443&lt;BR /&gt;tcp        0      0 0.0.0.0:443             0.0.0.0:*               LISTEN&lt;BR /&gt;&lt;BR /&gt;b. Use the following URL's                       &lt;BR /&gt;&lt;BR /&gt;&lt;A href="http://127.0.0.1/" target="_blank"&gt;http://127.0.0.1/&lt;/A&gt;&lt;BR /&gt;&lt;A href="https://127.0.0.1/" target="_blank"&gt;https://127.0.0.1/&lt;/A&gt;&lt;BR /&gt;&lt;BR /&gt;VII. Stop apache&lt;BR /&gt;&lt;BR /&gt;# /usr/local/apache/bin/apachectl stop&lt;BR /&gt;&lt;BR /&gt;To check apache whether it listens on port 80 &amp;amp; 443&lt;BR /&gt;&lt;BR /&gt;#  netstat -na | grep 80&lt;BR /&gt;#  netstat -na | grep 443&lt;BR /&gt;#&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;Note: See the file  /usr/local/apache/conf/ssl.conf for SSL configuration</description>
      <pubDate>Wed, 09 Feb 2005 05:33:03 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/apache-ssl-problem/m-p/3479995#M847224</guid>
      <dc:creator>VEL_1</dc:creator>
      <dc:date>2005-02-09T05:33:03Z</dc:date>
    </item>
    <item>
      <title>Re: Apache SSL problem</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/apache-ssl-problem/m-p/3479996#M847225</link>
      <description>Thanks everyone&lt;BR /&gt;&lt;BR /&gt;The error message was due to absence of CA certificate file. When I set the valid file name for SSLCACertificateFile it worked properly.</description>
      <pubDate>Wed, 09 Feb 2005 05:36:41 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/apache-ssl-problem/m-p/3479996#M847225</guid>
      <dc:creator>Seetha Lakshmi</dc:creator>
      <dc:date>2005-02-09T05:36:41Z</dc:date>
    </item>
  </channel>
</rss>

