[lug] self-signed apache certs

B Giles bldrbear at hotmail.com
Sun Aug 10 21:07:37 MDT 2003


What are your file permissions?  What user are you running the script as?

>I'm trying to fix a broken private (in house only) web server ssl. It died 
>because the cert expired. This is from KRUD 7.3. I tried to self-sign based 
>on:
>   http://www.modssl.org/docs/2.8/ssl_faq.html#ToC27
>
>I created
>   ca.crt
>   ca.key
>   server.crt
>   server.csr
>   server.key
>
>Some other files are generated as well.
>
>This is running on a machine without any server source code, and lacks 
>sign.sh, so I used sign.sh from another RH 7.3 (KRUD 7.3) install. It looks 
>like sign.sh is working, then it dies at the end:
>
>unable to load CA private key
>22903:error:06065064:digital envelope routines:EVP_DecryptFinal:bad 
>decrypt:evp_enc.c:277:
>22903:error:0906A065:PEM routines:PEM_do_header:bad decrypt:pem_lib.c:451:
>CA verifying: server.crt <-> CA cert
>server.crt: unable to load certificate file
>22904:error:0906D06C:PEM routines:PEM_read_bio:no start 
>line:pem_lib.c:662:Expecting: CERTIFICATE

_________________________________________________________________
MSN 8 with e-mail virus protection service: 2 months FREE*  
http://join.msn.com/?page=features/virus




More information about the LUG mailing list