RE: [users@httpd] copy ssl cert from old machine to replacement machine?

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

 




> -----Original Message-----
> From: Sean Brown [mailto:seanmichaelbrown@xxxxxxxxx]
> Sent: Freitag, 4. November 2005 15:36
> To: users@xxxxxxxxxxxxxxxx
> Subject: Re: [users@httpd] copy ssl cert from old machine to 
> replacement
> machine?
> 
> 
> It's my understanding that the SSL Certificate is bound to the IP of
> the site, NOT the DNS name.  

It's the ther way round. The cert contains a field called "CommonName". When the client gets the cert from the server, it compares the CommonName with the URL it just requested. If you request www.amazon.com and get back a cert with CN=www.dodgy-crook.com, you should think twice about putting in your credit card number...

Rgds,
Owen Boyle
Disclaimer: Any disclaimer attached to this message may be ignored. 

> So if you're moving to a new machine AND
> changing the IP address, you may need to get your certificate
> recreated.  If you moving to a new machine, but keeping the IP
> address, you should be able to simply move the files as explained
> elsewhere in the thread.
> 
> 
> Sean
> '
> 
> On 11/4/05, Boyle Owen <Owen.Boyle@xxxxxxx> wrote:
> > Plain text please...
> >
> > The certificate is bound to the website - not the physical 
> machine. The certificate is just a file like any other. You 
> simply have to copy the file containing the certificate to 
> the new machine.
> >
> > If you change the filestructure on the new machine, you 
> need to define the path to the cert and key in the 
> SSLCertificateFile and SSLCertificateKeyFile directives.
> >
> > Rgds,
> > Owen Boyle
> > Disclaimer: Any disclaimer attached to this message may be ignored.
> >
> > -----Original Message-----
> > From: Joe A [mailto:joe.biz@xxxxxxxxx]
> > Sent: Donnerstag, 3. November 2005 19:02
> > To: users@xxxxxxxxxxxxxxxx
> > Subject: [users@httpd] copy ssl cert from old machine to 
> replacement machine?
> >
> >
> > i have a machine that has apache2 and ssl setup on domain.com
> >
> > i want to replace that machine with a new one ... do i have 
> to request a new certificate or is there an easy way to copy 
> the certificate to the new machine that will be replacing the 
> old one as the server for domain.com?
> >
> > Diese E-mail ist eine private und persönliche 
> Kommunikation. Sie hat keinen Bezug zur Börsen- bzw. 
> Geschäftstätigkeit der SWX Gruppe. This e-mail is of a 
> private and personal nature. It is not related to the 
> exchange or business activities of the SWX Group. Le présent 
> e-mail est un message privé et personnel, sans rapport avec 
> l'activité boursière du Groupe SWX.
> >
> >
> > This message is for the named person's use only. It may 
> contain confidential, proprietary or legally privileged 
> information. No confidentiality or privilege is waived or 
> lost by any mistransmission. If you receive this message in 
> error, please notify the sender urgently and then immediately 
> delete the message and any copies of it from your system. 
> Please also immediately destroy any hardcopies of the 
> message. You must not, directly or indirectly, use, disclose, 
> distribute, print, or copy any part of this message if you 
> are not the intended recipient. The sender's company reserves 
> the right to monitor all e-mail communications through their 
> networks. Any views expressed in this message are those of 
> the individual sender, except where the message states 
> otherwise and the sender is authorised to state them to be 
> the views of the sender's company.
> >
> > 
> ---------------------------------------------------------------------
> > The official User-To-User support forum of the Apache HTTP 
> Server Project.
> > See <URL:http://httpd.apache.org/userslist.html> for more info.
> > To unsubscribe, e-mail: users-unsubscribe@xxxxxxxxxxxxxxxx
> >    "   from the digest: users-digest-unsubscribe@xxxxxxxxxxxxxxxx
> > For additional commands, e-mail: users-help@xxxxxxxxxxxxxxxx
> >
> >
> 
> ---------------------------------------------------------------------
> The official User-To-User support forum of the Apache HTTP 
> Server Project.
> See <URL:http://httpd.apache.org/userslist.html> for more info.
> To unsubscribe, e-mail: users-unsubscribe@xxxxxxxxxxxxxxxx
>    "   from the digest: users-digest-unsubscribe@xxxxxxxxxxxxxxxx
> For additional commands, e-mail: users-help@xxxxxxxxxxxxxxxx
> 
> 
Diese E-mail ist eine private und persönliche Kommunikation. Sie hat keinen Bezug zur Börsen- bzw. Geschäftstätigkeit der SWX Gruppe. This e-mail is of a private and personal nature. It is not related to the exchange or business activities of the SWX Group. Le présent e-mail est un message privé et personnel, sans rapport avec l'activité boursière du Groupe SWX.

---------------------------------------------------------------------
The official User-To-User support forum of the Apache HTTP Server Project.
See <URL:http://httpd.apache.org/userslist.html> for more info.
To unsubscribe, e-mail: users-unsubscribe@xxxxxxxxxxxxxxxx
   "   from the digest: users-digest-unsubscribe@xxxxxxxxxxxxxxxx
For additional commands, e-mail: users-help@xxxxxxxxxxxxxxxx



[Index of Archives]     [Open SSH Users]     [Linux ACPI]     [Linux Kernel]     [Linux Laptop]     [Kernel Newbies]     [Security]     [Netfilter]     [Bugtraq]     [Squid]     [Yosemite News]     [MIPS Linux]     [ARM Linux]     [Linux Security]     [Linux RAID]     [Samba]     [Video 4 Linux]     [Device Mapper]

  Powered by Linux