1,234
edits
Changes
→Lab completion
# Again acting as the '''CA''': export the certificate and key (i.e. the public key and the private key) as .pem files. The extension .pem doesn't imply what the contents are, it's just a format that is typically used to store keys. You want to export the key without a passphrase, unless you want to type in a password every time your server reboots:<br />[[File:TinyCAExportCert.png]]<br /><br />[[File:TinyCAExportKey.png]]
# That key pair (private + public key) is what you'll need to use to set up your servers. These specific ones you generated here aren't particularly useful because they're for the server yourusername.ops, and you don't have a server with that hostname. But the process is identical for every keypair you'll need to generate in this lab.
= PART 2: ENCRYPTION FOR APACHE(HTTPS) =
In one of the labs we've set up the Apache web server on lin1. In another lab we've set up simple authentication for our simple webpage, and we intercepted the username and password that was sent from a web browser to the web server.
In this lab we're going to upgrade the same web server to serve pages using encrypted HTTPS instead of the plain-text HTTP.
* Use the steps in the previous section to create a certificate and key for lin1.yourusername.ops.
* By default Apache on CentOS doesn't come with the SSL modules installed, so you'll have to install mod_ssl using yum.
* After installing that package you'll have a new configuration file on your system: <code>/etc/httpd/conf.d/ssl.conf</code>
* Edit that file and look for two lines: <code>SSLCertificateFile</code> and <code>SSLCertificateKeyFile</code>. Those are the two files that you generated. Make sure the filenames are correct.
* In the same file, uncomment the <code>ServerName</code> setting and set it to lin1.yourusername.ops
* Copy the two files to lin1 into the appropriate directories.
* Restart Apache and check in /var/log/httpd/ssl_error_log that there are no errors related to your changes.
* Use nmap on lin1 and on c7host to confirm that the port used for HTTPS is open.
* If all of the above worked, use Firefox on c7host to go to https://lin1.yourusername.ops. You should see a security warning. Do not click through it, we'll fix it in another way.
= Lab completion =