【发布时间】:2018-11-22 22:35:21
【问题描述】:
我正在为 SSL 执行以下步骤:
openssl req -new -newkey rsa:2048 -nodes -keyout domain.key -out domain.crt
这很好用。
openssl req -text -noout -verify -in domain.crt
效果很好。
openssl rsa -in domain.key -check
> RSA key ok writing RSA key
> -----BEGIN RSA PRIVATE KEY-----
>
>
> .....
>
>
> -----END RSA PRIVATE KEY-----
将.key 和.crt 文件移动到/etc/apache2/ssl
打开/etc/apache2/sites-available/default-ssl.conf
添加
SSLEngine on
SSLCertificateFile /etc/apache2/ssl/domain.crt
SSLCertificateKeyFile /etc/apache2/ssl/domain.key
接下来是
sudo a2enmod ssl
sudo service apache2 restart
错误是::
[Wed Jun 13 10:48:03.690496 2018] [ssl:emerg] [pid 2536] AH02562: Failed to configure certificate 172.31.25.100:443:0 (with chain), check /etc/apache2/ssl/domain.crt
[Wed Jun 13 10:48:03.690538 2018] [ssl:emerg] [pid 2536] SSL Library Error: error:0906D06C:PEM routines:PEM_read_bio:no start line (Expecting: TRUSTED CERTIFICATE) -- Bad file contents or format - or even just a forgotten SSLCertificateKeyFile?
[Wed Jun 13 10:48:03.690548 2018] [ssl:emerg] [pid 2536] SSL Library Error: error:140DC009:SSL routines:SSL_CTX_use_certificate_chain_file:PEM lib
AH00016: Configuration Failed
【问题讨论】:
-
您尚未签署证书。 CSR 不是证书。离题。
标签: apache ssl openssl ssl-certificate