Digi-Sign, The Certificate Corporation
Published on Digi-Sign, The Certificate Corporation (http://www2.digi-sign.com)

Home > Installing Apache Mod SSL

By Digi-Sign
Created Feb 18 2008 - 16:07

Installing Apache Mod SSL

Step-by-Step Instructions


  • Step one: Copy your certificate to file
  • You will receive an email from Digi-Sign with the certificate in the email (yourdomainname.cer or yourdomainname.crt). When viewed in a text editor, your certificate will look something like:

      -----BEGIN CERTIFICATE-----
      MIAGCSqGSIb3DQEHAqCAMIACAQExADALBgkqhkiG9w0BBwGggDCCAmowggHXAhAF
      UbM77e50M63v1Z2A/5O5MA0GCSqGSIb3DQEOBAUAMF8xCzAJBgNVBAYTAlVTMSAw
      (.......)
      E+cFEpf0WForA+eRP6XraWw8rTN8102zGrcJgg4P6XVS4l39+l5aCEGGbauLP5W6
      K99c42ku3QrlX2+KeDi+xBG2cEIsdSiXeQS/16S36ITclu4AADEAAAAAAAAA
      -----END CERTIFICATE-----



    Copy your Certificate into the directory that you will be using to hold your certificates. In this example we will use /etc/ssl/crt/. Both the public and private key files will already be in this directory. The private key used in the example will be labelled private.key and the public key will be yourdomainname.cer.

    It is recommended that you make the directory that contains the private key file only readable by root.

  • Step two: Install the Intermediate Certificates
  • You will need to install the chain certificates (intermediates) in order for browsers to trust your certificate. As well as your SSL certificate (yourdomainname.cer) two other certificates, named UTN-USERFirst-Hardware.crt and Digi-SignCADigi-SSLXp.crt or Digi-SignCADigi-SSLXs.crt, are also attached to the email from Digi-Sign.

    Apache users will not require these certificates. Instead you can install the intermediate certificates using a 'bundle' method. You can download the correct Apache bundled CA file for your SSL server certificate here [1].

    In the Virtual Host settings for your site, in the httpd.conf file, you will need to complete the following:

      1. Copy this ca-bundle file to the same directory as httpd.conf (this contains all of the CA certificates in the chain).

      2. Add the following line to SSL section of the httpd.conf (assuming /etc/httpd/conf is the directory to where you have copied the bundlecafilename.pem file). If the line already exists amend it to read the following:

    SSLCACertificateFile /etc/httpd/conf/ca-bundle/bundlecafilename.txt

    If you are using a different location and certificate file names you will need to change the path and filename to reflect your server.

    The SSL section of the updated httpd config file should now read similar to this example (depending on your naming and directories used):

    • SSLCertificateFile /etc/ssl/crt/yourdomainname.cer.
    • SSLCertificateKeyFile /etc/ssl/crt/private.key.
    • SSLCACertificateFile /etc/httpd/conf/ca-bundle/bundlecafilename.pem.
    • Save your httpd.conf file and restart Apache.
  • Install SSL

Source URL: http://www2.digi-sign.com/support/digi-ssl/install-certificate/apache-mod-ssl

Links:
[1] http://www.digi-sign.com/support/digi-ssl/install%20certificate/index