Re: SSL Denying connections [was: A Little SSL Help Please] [*SP* 54%] [*SP* 52%]

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

 





rbragg wrote:

Check all your logs and try to find out more info that way.
What exacly is the error? also triple check firewall rules.
should be in /var/log/messages, /var/log/httpd/error_log, ssl_error_log,... ssl_access_log...


Rick


I checked that a bazillion times but maybie I am missing something so I will post a couple of chunks here:

MESSAGES:

Oct 5 04:02:08 srv01 syslogd 1.4.1: restart.
Oct 5 04:06:57 srv01 kernel: (scsi0:A:0:0): Locking max tag count at 64
Oct 5 12:58:43 srv01 httpd: httpd shutdown succeeded
Oct 5 12:58:43 srv01 httpd: Apache/2.0.40 mod_ssl/2.0.40 (Pass Phrase Dialog)
Oct 5 12:58:43 srv01 httpd: Some of your private key files are encrypted for security reasons. Oct 5 12:58:43 srv01 httpd: In order to read them you have to provide us with the pass phrases.
Oct 5 12:58:43 srv01 httpd:
Oct 5 12:58:43 srv01 httpd: Server www2.cydock.com:443 (RSA)
Oct 5 12:58:43 srv01 httpd: Enter pass phrase:
Oct 5 12:58:45 srv01 httpd:
Oct 5 12:58:45 srv01 httpd: Ok: Pass Phrase Dialog successful.
Oct 5 12:58:50 srv01 httpd: httpd startup succeeded
Oct 5 13:01:16 srv01 httpd: httpd shutdown succeeded
Oct 5 13:01:50 srv01 httpd: Apache/2.0.40 mod_ssl/2.0.40 (Pass Phrase Dialog)
Oct 5 13:01:50 srv01 httpd: Some of your private key files are encrypted for security reasons.
Oct 5 13:01:50 srv01 httpd: In order to read them you have to provide us with the pass phrases.
Oct 5 13:01:50 srv01 httpd:
Oct 5 13:01:50 srv01 httpd: Server www2.cydock.com:443 (RSA)
Oct 5 13:01:50 srv01 httpd: Enter pass phrase:
Oct 5 13:01:52 srv01 httpd:
Oct 5 13:01:52 srv01 httpd: Ok: Pass Phrase Dialog successful.
Oct 5 13:01:54 srv01 httpd: httpd startup succeeded
Oct 5 13:27:24 srv01 httpd: httpd shutdown succeeded
Oct 5 13:27:25 srv01 httpd: Apache/2.0.40 mod_ssl/2.0.40 (Pass Phrase Dialog)
Oct 5 13:27:25 srv01 httpd: Some of your private key files are encrypted for security reasons.
Oct 5 13:27:25 srv01 httpd: In order to read them you have to provide us with the pass phrases.
Oct 5 13:27:25 srv01 httpd:
Oct 5 13:27:25 srv01 httpd: Server new.host.name:443 (RSA)
Oct 5 13:27:25 srv01 httpd: Enter pass phrase: Oct 5 13:27:27 srv01 httpd: Apache:mod_ssl:Error: Pass phrase empty (needs to be at least 1 character).
Oct 5 13:27:27 srv01 httpd: Enter pass phrase:
Oct 5 13:27:35 srv01 httpd:
Oct 5 13:27:35 srv01 httpd: Ok: Pass Phrase Dialog successful.
Oct 5 13:27:38 srv01 httpd: httpd startup succeeded


SSL_ERROR_LOG

[Sun Oct 05 04:02:10 2003] [warn] RSA server certificate is a CA certificate (BasicConstraints: CA == TRUE !?)
[Sun Oct 05 04:02:10 2003] [warn] RSA server certificate CommonName (CN) `srv01.cydock.com' does NOT match server name!?





Andre Cameron wrote:



Andre Cameron wrote:



rbragg wrote:

I think it is a DNS or a local hosts file issue.

Rick





Could be DNS, the domain resolves to the public IP, not the private one. Soooo should I put bind on the box and run an internal DNS server as well as the external one or is there a way arround it?




Ok so it is NOT DNS, Just setup bind, setup zones, restarted services did a dig to confirm proper configuration and still does not allow connections from off the box. Any other ideas?

Andre



Andre Cameron wrote:

I am at a loss here, from the server through lynx I can do:

https://localhost
https://127.0.0.1

from lynx I can NOT do https://192.168.1.100, from my other PC I can not do https://192.168.1.100 but I CAN do http://192.168.1.100.

I never installed the Linux firewall because I use the router, which is not part of the problem here because I am using all private IPS insidde the LAN.
So just for the fun of it I telneted from 192.168.1.101 to 192.168.1.100 on port 443, I connected. So its not getting blocked, it is working locally, and I have no freaking idea where else to look.


Andre

Andre Cameron wrote:

Hello,

Sorry but I am new to Apache 2.x and need to get SSL installed and working, the RH binaries used to have Apache preconfigured with SSL so it was a no brainer. Can anyone give me a hand or point me to an online doc? Everything I find makes me recompile everything which I would really rather not do.

Oh and one side thing, how can I remove RPMS by wild card like *gnome*?

aNc

















--
Shrike-list mailing list
Shrike-list@xxxxxxxxxx
https://www.redhat.com/mailman/listinfo/shrike-list

[Index of Archives]     [Fedora Users]     [Centos Users]     [Kernel Development]     [Red Hat Install]     [Red Hat Watch]     [Red Hat Development]     [Red Hat Phoebe Beta]     [Yosemite Forum]     [Fedora Discussion]     [Gimp]     [Stuff]     [Yosemite News]

  Powered by Linux