LiteSpeed Technologies
Download Download     Blog Blog     Wiki Wiki     Forum Forum     Store     Contact Contact    

Go Back   LiteSpeed Support Forums > LiteSpeed Web Server > Bug Reports > can not reset SSL Private Key & Certificate for Virtual Host

Reply
 
Thread Tools Display Modes
  #1  
Old 07-19-2011, 05:57 AM
andreas andreas is offline
Senior Member
 
Join Date: Aug 2006
Posts: 91
Default can not reset SSL Private Key & Certificate for Virtual Host

*value must be set
Reply With Quote
  #2  
Old 07-19-2011, 10:31 AM
webizen webizen is offline
LiteSpeed Staff
 
Join Date: Oct 2010
Posts: 2,339
you can manually empty the fields in config xml for the time being. admin cp will be updated to allow reset in a bit.
Reply With Quote
  #3  
Old 07-20-2011, 11:19 AM
webizen webizen is offline
LiteSpeed Staff
 
Join Date: Oct 2010
Posts: 2,339
the latest 4.1.2 allows the reset.
Reply With Quote
  #4  
Old 08-01-2011, 01:11 PM
netjess netjess is offline
Member
 
Join Date: Mar 2011
Posts: 34
Default /etc/ssl/private/server.key

I have a new install running on Ubuntu 10.10.
I accepted defaults during install.

When I try to set up my first SSL listener it sees the cert file but on the key file it returns "*file /etc/ssl/private/server.key does not exist. Please create manually".

In the server log it has the error:
0#_AdminVHost] [STDERR] PHP Warning: is_file() [<a href='function.is-file'>function.is-file</a>]: Stat failed for /etc/ssl/private/server.key (errno=13 - Permission denied) in /usr/local/lsws/admin/html.4.1.2/classes/ConfValidation.php on line 627

I have not been able to figure out what/who access is getting denied.
I compared permissions to the file to another server we have running and they look the same. I even added lsadm user to the root group (not sure that is a good idea).

sudo ls -l /etc/ssl/private/server.key
-rwxrwxr-- 1 root root 963 2011-07-28 16:49 /etc/ssl/private/server.key

any thoughts?
Reply With Quote
  #5  
Old 08-01-2011, 01:40 PM
netjess netjess is offline
Member
 
Join Date: Mar 2011
Posts: 34
Well, I did a "chown -R lsadm:lsadm /etc/ssl/private" and that let me apply the key.

But now I am getting:
"[SSL] Config SSL Context with Certificate File: /etc/ssl/certs/server.crt and Key File:/etc/ssl/private/server.key get SSL error: error:0906406D:PEM routines:PEM_def_callback: problems getting password"

and

"[config:server:listener:SSL] failed to start SSL listener on address 192.168.1.238:443!"
Reply With Quote
  #6  
Old 08-01-2011, 02:03 PM
mistwang mistwang is offline
LiteSpeed Staff
 
Join Date: May 2003
Location: New Jersey
Posts: 7,590
You can make /etc/ssl/private/ world readable temporarily, after save the configuration, then lock down the permission.
This issue will be addressed in next release 4.1.3 .
Reply With Quote
  #7  
Old 08-01-2011, 02:03 PM
mistwang mistwang is offline
LiteSpeed Staff
 
Join Date: May 2003
Location: New Jersey
Posts: 7,590
Quote:
Originally Posted by netjess View Post
Well, I did a "chown -R lsadm:lsadm /etc/ssl/private" and that let me apply the key.

But now I am getting:
"[SSL] Config SSL Context with Certificate File: /etc/ssl/certs/server.crt and Key File:/etc/ssl/private/server.key get SSL error: error:0906406D:PEM routines:PEM_def_callback: problems getting password"

and

"[config:server:listener:SSL] failed to start SSL listener on address 192.168.1.238:443!"
You have to remove the passcode of the private key.
Reply With Quote
  #8  
Old 08-01-2011, 02:25 PM
netjess netjess is offline
Member
 
Join Date: Mar 2011
Posts: 34
Yeah, I have seen posts to that extent.
Looking at https://help.ubuntu.com/10.04/server...-security.html

- got it, guess I just have to read a bit closer.

Thanks for the assist.
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off

Forum Jump


All times are GMT -7. The time now is 07:20 PM.



- Archive - Top
© Copyright 2003-2011 LiteSpeed Technologies, Inc. All rights reserved. Privacy Policy.