problem setting up my cert

problem setting up my cert

am 15.11.2002 01:51:15 von roberto.torres

This is a multi-part message in MIME format.

------=_NextPart_000_0004_01C28C0E.CF384F40
Content-Type: text/plain;
charset="Windows-1252"
Content-Transfer-Encoding: 8bit

Hi everyone!

I´ve just installed Apache Server in my box (Debian 2), I created my
private key with password and I send my (server.CSR) to verisign, later
they send my server.crt, I follow the instructions to set up my server.key
and server.crt. (in my httpd.conf)

When I start apachessl, it ask for PEM pass Phrase, I typed the password but
I doesn´t run https and I got this error /var/log/apache-ssl/error.log

[Thu Nov 14 17:52:10 2002] [crit] (22)Invalid argument: Error reading
private key file /etc/apache/nuevo/server.key:
[Thu Nov 14 17:52:10 2002] [crit] error:0906406D:PEM
routines:DEF_CALLBACK:problems getting password
[Thu Nov 14 17:52:10 2002] [crit] error:0906A068:PEM
routines:PEM_do_header:bad password read

these is what I wrote in httpd.conf
# Point SSLCertificateFile at a PEM encoded certificate.
# If the certificate is encrypted, then you will be prompted for a pass
phrase.
# Note that a kill -1 will prompt again.
# A test certificate can be generated with "make certificate".
#modified by Robert ########################
#SSLCertificateFile /etc/apache-ssl/apache.pem <---this is the original
cert
#SSLCertificateFile /u/ben/apache/apache_1.2.6-ssl/SSLconf/conf/t1.pem
SSLCertificateFile /etc/apache/nuevo/server.crt
SSLCertificateKeyFile /etc/apache/nuevo/server.key

the password is correct, actualy i open server.key with openssl and the PEM
phrase, but when i start the server doesn´t work

Any help is appreciated.
Thanks in advance

Robert

------=_NextPart_000_0004_01C28C0E.CF384F40
Content-Type: text/html;
charset="Windows-1252"
Content-Transfer-Encoding: quoted-printable

xmlns:w=3D"urn:schemas-microsoft-com:office:word" =
xmlns=3D"http://www.w3.org/TR/REC-html40">


charset=3Dwindows-1252">












color=3Dblack
face=3DArial> style=3D'font-size:10.0pt;mso-bidi-font-size:12.0pt;font-fam ily:
Arial'>Hi everyone!



color=3Dblack
face=3DArial> style=3D'font-size:10.0pt;mso-bidi-font-size:12.0pt;font-fam ily:
Arial'> !supportEmptyParas]> 



color=3Dblack
face=3DArial> style=3D'font-size:10.0pt;mso-bidi-font-size:12.0pt;
font-family:Arial;mso-ansi-language:EN-US'>I=B4ve just installed style=3D"mso-spacerun: yes">=A0
Apache Server in my box (Debian =
style=3D"mso-spacerun: yes">=A0
2), I created my private key with =
style=3D"mso-spacerun: yes">=A0password and I send my =
(server.CSR) to verisign,
later they send my server.crt, I follow the instructions to set up my
server.key and server.crt. (in my =
httpd.conf)



color=3Dblack
face=3DArial> style=3D'font-size:10.0pt;mso-bidi-font-size:12.0pt;
font-family:Arial;mso-ansi-language:EN-US'> !supportEmptyParas]> 



color=3Dblack
face=3DArial> style=3D'font-size:10.0pt;mso-bidi-font-size:12.0pt;
font-family:Arial;mso-ansi-language:EN-US'>When I start apachessl, it =
ask for PEM
pass Phrase, I typed the password but I doesn=B4t run https and I got =
this error style=3D"mso-spacerun: yes">=A0
/var/log/apache-ssl/error.log =



color=3Dblack
face=3DArial> style=3D'font-size:10.0pt;mso-bidi-font-size:12.0pt;
font-family:Arial;mso-ansi-language:EN-US'> !supportEmptyParas]> 



color=3Dblack
face=3DArial> style=3D'font-size:10.0pt;mso-bidi-font-size:12.0pt;
font-family:Arial;mso-ansi-language:EN-US'>[Thu Nov 14 17:52:10 2002] =
[crit]
(22)Invalid argument: Error reading private key file
/etc/apache/nuevo/server.key:



color=3Dblack
face=3DArial> style=3D'font-size:10.0pt;mso-bidi-font-size:12.0pt;
font-family:Arial;mso-ansi-language:EN-US'>[Thu Nov 14 17:52:10 2002] =
[crit]
error:0906406D:PEM routines:DEF_CALLBACK:problems getting =
password



color=3Dblack
face=3DArial> style=3D'font-size:10.0pt;mso-bidi-font-size:12.0pt;
font-family:Arial;mso-ansi-language:EN-US'>[Thu Nov 14 17:52:10 2002] =
[crit]
error:0906A068:PEM routines:PEM_do_header:bad password =
read



Roman"> lang=3DEN-US =
style=3D'font-size:12.0pt;color:black;mso-ansi-language:EN-U S'> !supportEmptyParas]> 
color=3Dblack> style=3D'color:black;mso-color-alt:windowtext;
mso-ansi-language:EN-US'>



Roman"> lang=3DEN-US =
style=3D'font-size:12.0pt;color:black;mso-ansi-language:EN-U S'>these
is what I wrote in httpd.conf
lang=3DEN-US
style=3D'color:black;mso-color-alt:windowtext;mso-ansi-langu age:EN-US'> :p>



Roman"> lang=3DEN-US =
style=3D'font-size:12.0pt;color:black;mso-ansi-language:EN-U S'># Point
SSLCertificateFile at a PEM encoded certificate.
color=3Dblack> style=3D'color:black;mso-color-alt:windowtext;
mso-ansi-language:EN-US'>



Roman"> lang=3DEN-US =
style=3D'font-size:12.0pt;color:black;mso-ansi-language:EN-U S'># If
the certificate is encrypted, then you will be prompted for a pass =
phrase.
color=3Dblack> style=3D'color:black;mso-color-alt:windowtext;
mso-ansi-language:EN-US'>



Roman"> lang=3DEN-US =
style=3D'font-size:12.0pt;color:black;mso-ansi-language:EN-U S'># Note
that a kill -1 will prompt again.
lang=3DEN-US =
style=3D'color:black;mso-color-alt:windowtext;mso-ansi-langu age:EN-US'> :p>



Roman"> lang=3DEN-US =
style=3D'font-size:12.0pt;color:black;mso-ansi-language:EN-U S'># A
test certificate can be generated with "make =
certificate".
color=3Dblack> style=3D'color:black;mso-color-alt:windowtext;
mso-ansi-language:EN-US'>



Roman"> lang=3DEN-US =
style=3D'font-size:12.0pt;color:black;mso-ansi-language:EN-U S'>#modified
by Robert  =A0 =
########################
color=3Dblack> style=3D'color:black;mso-color-alt:windowtext;
mso-ansi-language:EN-US'>



Roman"> lang=3DEN-US =
style=3D'font-size:12.0pt;color:black;mso-ansi-language:EN-U S'>#SSLCertif=
icateFile
/etc/apache-ssl/apache.pem=A0 =
color=3Dblack face=3DWingdings> style=3D'font-family:Wingdings;mso-ascii-font-family:
"Times New Roman";mso-hansi-font-family:"Times New Roman";color:black;
mso-char-type:symbol;mso-symbol-font-family:Wingdings'> style=3D'mso-char-type:
symbol;mso-symbol-font-family:Wingdings'>ß
color=3Dblack> style=3D'color:black;mso-ansi-language:EN-US'>-this is
the original cert
style=3D'color:black;mso-color-alt:windowtext;mso-ansi-langu age:EN-US'> :p>



Roman"> style=3D'font-size:12.0pt;color:black'>#SSLCertificateFile
/u/ben/apache/apache_1.2.6-ssl/SSLconf/conf/t1.pem
color=3Dblack> style=3D'color:black;mso-color-alt:windowtext'><=
/p>

Roman"> style=3D'font-size:12.0pt;color:black'>SSLCertificateFile =
/etc/apache/nuevo/server.crt
color=3Dblack> style=3D'color:black;mso-color-alt:windowtext'><=
/p>

Roman"> style=3D'font-size:12.0pt;color:black'>SSLCertificateKeyFile
/etc/apache/nuevo/server.key
style=3D'color:black;mso-color-alt:windowtext'><=
/p>

Roman"> style=3D'font-size:12.0pt;color:black'> !supportEmptyParas]>  color=3Dblack> style=3D'color:black;mso-color-alt:windowtext'><=
/p>

Roman"> lang=3DEN-US =
style=3D'font-size:12.0pt;color:black;mso-ansi-language:EN-U S'>the
password is correct, actualy i open server.key with openssl and the PEM =
phrase,
but when i start the server doesn=B4t work
color=3Dblack> lang=3DEN-US =
style=3D'color:black;mso-color-alt:windowtext;mso-ansi-langu age:EN-US'> :p>



Roman"> lang=3DEN-US =
style=3D'font-size:12.0pt;color:black;mso-ansi-language:EN-U S'> !supportEmptyParas]> 
color=3Dblack> style=3D'color:black;mso-color-alt:windowtext;
mso-ansi-language:EN-US'>



Roman"> lang=3DEN-US =
style=3D'font-size:12.0pt;color:black;mso-ansi-language:EN-U S'>Any
help is appreciated.
style=3D'color:black;mso-color-alt:windowtext;mso-ansi-langu age:EN-US'> :p>



Roman"> lang=3DEN-US =
style=3D'font-size:12.0pt;color:black;mso-ansi-language:EN-U S'>Thanks
in advance
style=3D'color:black;
mso-color-alt:windowtext;mso-ansi-language:EN-US'>
t>



Roman"> lang=3DEN-US =
style=3D'font-size:12.0pt;color:black;mso-ansi-language:EN-U S'> !supportEmptyParas]> 
color=3Dblack> style=3D'color:black;mso-color-alt:windowtext;
mso-ansi-language:EN-US'>



Roman"> lang=3DEN-US =
style=3D'font-size:12.0pt;color:black;mso-ansi-language:EN-U S'>Robert an>
color=3Dblack> style=3D'color:black;mso-color-alt:windowtext;
mso-ansi-language:EN-US'>









------=_NextPart_000_0004_01C28C0E.CF384F40--


____________________________________________________________ __________
Apache Interface to OpenSSL (mod_ssl) www.modssl.org
User Support Mailing List modssl-users@modssl.org
Automated List Manager majordomo@modssl.org