5imobi 发表于 2018-11-26 11:24:55

apache+openssl

1.下载apache和openssl  网址:http://www.apache.org
  http://www.openssl.org
  2.解压
  #tar zxvf httpd-2.0.54.tar.gz
  #tar zxvf openssl-0.9.7g.tar.gz
  3.编译安装openssl,这个软件主要是用来生成证书:
  #cd openssl-0.9.7g
  #./config
  #make
  #make test
  #make install
  把openssl放进内核目录下,使其在任何目录下都能运行。
  #cd /usr/local/bin
  #ln -s /usr/local/ssl/bin/openssl openssl
  4.编译安装apache
  #cd /opt/httpd-2.0.54
  #./configure --prefix="/opt/apache2" --enable-so --enable-ssl --with-ssl="/usr/local/ssl/bin"
  #make
  #make install
  5.安装完毕,生成证书:
  在/opt/apache2/conf下建立一个ssl.key目录
  #cd ../apache2/
  #cd conf/
  #mkdir ssl.key
  然后在该目录下生成证书:
  #cd ssl.key/
  生成服务器私钥:
  #openssl genrsa -des3 -out server.key 1024
  Generating RSA private key, 1024 bit long modulus
  .......................++++++
  .................................................++++++
  e is 65537 (0x10001)
  Enter pass phrase for server.key:
  Verifying - Enter pass phrase for server.key:
  生成服务器证书请求,并按要求填些相关证书信息:
  #openssl req -new -key server.key -out server.csr
  Enter pass phrase for server.key:
  You are about to be asked to enter information that will be incorporated
  into your certificate request.
  What you are about to enter is what is called a Distinguished Name or a DN.
  There are quite a few fields but you can leave some blank
  For some fields there will be a default value,
  If you enter '.', the field will be left blank.
  -----
  Country Name (2 letter code) :
  State or Province Name (full name) :
  Locality Name (eg, city) []:tyl
  Organization Name (eg, company) :tz
  Organizational Unit Name (eg, section) []:tz
  Common Name (eg, YOUR name) []:tyl
  Email Address []:tangyl@ruyi.com
  Please enter the following 'extra' attributes
  to be sent with your certificate request
  A challenge password []:
  An optional company name []:
  签证:
  # openssl x509 -req -days 700 -in server.csr -signkey server.key -out server.cert
  Signature ok
  subject=/C=AU/ST=Some-State/L=tyl/O=tz/OU=tz/CN=tyl/emailAddress=tangyl@ruyi.com
  Getting Private key
  Enter pass phrase for server.key:
  为了安全,然后我们把这些文件的权限都设为400
  chmod 400 server.key
  chmod 400 server.cert

页: [1]
查看完整版本: apache+openssl