Тёмный

Installation SSL Certificate on Ubuntu/Linuxmint/Debian to Secure Apache 

LinuxHelp
Подписаться 32 тыс.
Просмотров 119 тыс.
50% 1

This video covers the method to install Certificate on Ubuntu/Linuxmint/Debian to Secure Apache. SSL is a web protocol that is used to send trafic between server and client in a secured manner.
For more explanation on this video: www.linuxhelp.com/installatio...

Опубликовано:

 

3 сен 2018

Поделиться:

Ссылка:

Скачать:

Готовим ссылку...

Добавить в:

Мой плейлист
Посмотреть позже
Комментарии : 66   
@michaelrandall6954
@michaelrandall6954 4 года назад
It was a little difficult to understand with the accent, but the content was spot on and it worked for me. Thanks
@josealva
@josealva 23 дня назад
Thank you. This was helpful.
@linuxhelp5096
@linuxhelp5096 20 дней назад
You're Welcome :-) For more topics subscribe to our channel, ru-vid.com/show-UCvTQ6WM-MSvCFVNCEtI6HPg
@johnivie9866
@johnivie9866 3 года назад
Awesome video!! This solved my problem!
@linuxhelp5096
@linuxhelp5096 3 года назад
Thanks for the feedback :-) For more topics subscribe to our channel, ru-vid.com/show-UCvTQ6WM-MSvCFVNCEtI6HPg
@n3r4zzurr0_
@n3r4zzurr0_ 3 года назад
The x509 parameter indicates that this will be a self-signed certificate. Certificate Authorities do not verify self-signed certificates.
@BeeTrillion
@BeeTrillion 15 часов назад
Excellency.... :)
@1brodex415
@1brodex415 2 месяца назад
Thanks bro, this was much needed for me.
@linuxhelp5096
@linuxhelp5096 2 месяца назад
Glad to help you :-) For more topics subscribe to our channel, ru-vid.com/show-UCvTQ6WM-MSvCFVNCEtI6HPg
@kyozho3912
@kyozho3912 3 года назад
hi thank you, its working fine
@stanislavsmetanin1307
@stanislavsmetanin1307 2 года назад
Right on point, no blah blah ... 👌
@linuxhelp5096
@linuxhelp5096 2 года назад
Thanks for the feedback :-) For more topics subscribe to our channel, ru-vid.com/show-UCvTQ6WM-MSvCFVNCEtI6HPg
@gvnsvn-
@gvnsvn- 4 месяца назад
Great video, very helpful. Thanks!
@linuxhelp5096
@linuxhelp5096 4 месяца назад
Thanks for the feedback :-) For more topics subscribe to our channel, ru-vid.com/show-UCvTQ6WM-MSvCFVNCEtI6HPg
@yashjha7152
@yashjha7152 3 года назад
Thankyou man❤
@jodidascontrasenas
@jodidascontrasenas 2 года назад
Thanks a lot. You help me!
@linuxhelp5096
@linuxhelp5096 2 года назад
Glad to helped! Thanks for the feedback :-) For more topics subscribe to our channel, ru-vid.com/show-UCvTQ6WM-MSvCFVNCEtI6HPg
@thisisnico007
@thisisnico007 3 месяца назад
Worked!
@Ashok-np5ml
@Ashok-np5ml 4 года назад
The https connection still not "secured" in your video. but you mentioned "Secure apache" in title.
@maciekwagner1
@maciekwagner1 3 года назад
@Robert Smith bullshit, this is self-signed certificate This is why it is not accepted by the browser. You can use let's encrypt if you need free SSL cert. Anyway it worked for me.
@DevOpsSupport
@DevOpsSupport 23 дня назад
Hi i installed jenkins http that i converted into https ssl certificates so but that is not integrating to tuleap qhat can i do its asking sha 256 hostname not verified
@linuxhelp5096
@linuxhelp5096 20 дней назад
It sounds like you're encountering an issue with Jenkins not integrating properly with Tuleap due to SSL certificate verification problems, specifically mentioning SHA-256 and hostname verification. Here are some steps you can take to troubleshoot and resolve this issue: 1. Verify SSL Certificate Installation Make sure that your SSL certificate (which you converted to HTTPS) is correctly installed on your Jenkins server. Ensure the following: The certificate chain is properly configured. The certificate is signed by a trusted CA (Certificate Authority). The private key matches the certificate. There are no intermediate certificates missing. 2. Check Jenkins Configuration Ensure that Jenkins is configured to use HTTPS properly: Open your Jenkins configuration file (typically located at /etc/default/jenkins or /etc/sysconfig/jenkins on Linux systems). Verify that JENKINS_HTTPS_KEYSTORE and JENKINS_HTTPS_KEYSTORE_PASSWORD (or similar) are correctly set to point to your SSL keystore and password. 3. Update Java Keystore (if necessary) If you've updated or replaced your SSL certificate, ensure that Java (which Jenkins runs on) is using the updated certificate: Convert your SSL certificate to a Java keystore format if needed: openssl pkcs12 -export -in your_domain.crt -inkey your_private.key -out jenkins.p12 -name jenkins keytool -importkeystore -srckeystore jenkins.p12 -srcstoretype PKCS12 -destkeystore jenkins.jks -deststoretype JKS Restart Jenkins after updating the keystore. 4. Tuleap Configuration Verify Tuleap's configuration to ensure it can communicate securely with Jenkins: Check Tuleap's configuration for Jenkins integration settings. Ensure Tuleap is configured to trust the SSL certificate presented by Jenkins. 5. Debug SSL/TLS Handshake If the hostname verification is failing, it could be due to mismatched DNS names or the certificate's Subject Alternative Name (SAN) not including the Jenkins server's hostname. Use OpenSSL to debug the SSL/TLS handshake: openssl s_client -connect your_jenkins_server:443 Look for any errors or warnings related to the certificate validation. 6. Verify DNS Configuration Ensure that the DNS name used to access Jenkins matches the Common Name (CN) or SAN of the SSL certificate. 7. Jenkins Plugin Updates Ensure that both Jenkins and any relevant plugins (especially those related to SSL/TLS or integration with Tuleap) are updated to the latest versions. Older versions may have bugs or compatibility issues. 8. Debugging Logs Check the Jenkins and Tuleap logs for any specific error messages related to SSL/TLS handshake failures or certificate validation issues. This can provide more insight into what's going wrong.
@goestomars6542
@goestomars6542 3 года назад
Hey, please... and I highly recommend this... make subtitles for your videos, not to be rude but we really cant understand you because of your very strong accent . self-made subtitles would really help your Chanel... you seem to make decent tutorials but nobody can understand what you are saying.
@dipaalaknur3725
@dipaalaknur3725 Год назад
Thank you 🤗
@linuxhelp5096
@linuxhelp5096 Год назад
Welcome :) For more topics Subscribe to our Channel, ru-vid.com/show-UCvTQ6WM-MSvCFVNCEtI6HPg
@shabirkarni2765
@shabirkarni2765 Год назад
If I want to install the SSL for elasticsearch, then in this case can I will be need to add the SSL crt , key etc entries in elasticsearch.yml file or not ? If yes then can you recommend me any other configuration link ? Please update on priority :) Waiting just for your response !!!
@linuxhelp5096
@linuxhelp5096 Год назад
Yes, when setting up SSL/TLS for Elasticsearch, you will need to configure the SSL certificate and private key in the elasticsearch.yml file. Here are the general steps to enable SSL for Elasticsearch: Obtain an SSL certificate and private key from a trusted certificate authority (CA) or generate a self-signed certificate for testing purposes. Make sure you have the certificate file (crt), private key file (key), and any intermediate certificate files if applicable. Copy the certificate files to a directory on your Elasticsearch server. For example, you can create a directory called certs within your Elasticsearch configuration directory and place the certificate and key files there. Open the elasticsearch.yml file in a text editor. This file is typically located in the config directory of your Elasticsearch installation. Locate the section for SSL/TLS settings in the elasticsearch.yml file. If the section does not exist, you can add it at the bottom of the file. It should look similar to the following: # SSL/TLS Settings xpack.security.http.ssl.enabled: true xpack.security.http.ssl.key: /path/to/certs/key.pem xpack.security.http.ssl.certificate: /path/to/certs/cert.pem xpack.security.http.ssl.certificate_authorities: ["/path/to/certs/ca.pem"] Replace /path/to/certs/key.pem, /path/to/certs/cert.pem, and /path/to/certs/ca.pem with the actual paths to your SSL certificate and key files. Save the elasticsearch.yml file and exit the text editor. Restart Elasticsearch to apply the SSL configuration changes. Please note that the specific configuration may vary depending on your Elasticsearch version and setup. It is recommended to refer to the official Elasticsearch documentation or the documentation provided by your Elasticsearch distribution for detailed and up-to-date instructions on configuring SSL/TLS. Here are some useful links to the official Elasticsearch documentation on setting up SSL/TLS: Encrypting Communications www.elastic.co/guide/en/elasticsearch/reference/current/configuring-tls.html Securing Elasticsearch www.elastic.co/guide/en/elasticsearch/reference/current/securing-elasticsearch.html These resources should provide you with more comprehensive information and examples on configuring SSL/TLS for Elasticsearch.
@rnswetasingh
@rnswetasingh 4 года назад
sir can u help me with the error "URLError: "
@bossysmaxx3327
@bossysmaxx3327 5 месяцев назад
The x509 parameter indicates that this will be a self-signed certificate. Certificate Authorities do not verify self-signed certificates.
@raymondyeo4969
@raymondyeo4969 2 года назад
Hi Sir Great Video. Can you create a video to show how to upload Diffie Hellman SSL certificate into Apache on Ubuntu Server ?
@linuxhelp5096
@linuxhelp5096 2 года назад
In your apache configuration after installation cert you can go to the location /etc/ssl/cert and then run the below command for: sudo openssl dhparam -out /etc/ssl/certs/dhparam.pem 2048 We will create a tutorial for that ASAP For more topics subscribe to our channel, ru-vid.com/show-UCvTQ6WM-MSvCFVNCEtI6HPg
@mohebmoheb5645
@mohebmoheb5645 2 года назад
Please read below error: AH00526: Syntax error on line 3 of /etc/apache2/sites-enabled/mine-ssl.conf: SSLCertificateFile: file '/etc/ssl/certs/my.crt' does not exist or is empty Action 'configtest' failed.
@linuxhelp5096
@linuxhelp5096 2 года назад
* First of all, make sure all your commands would be run with Sudo. * Sometimes it was caused because SELinux turned on and this file was inaccessible for apache user. For more topics subscribe to our channel, ru-vid.com/show-UCvTQ6WM-MSvCFVNCEtI6HPg
@chandra-gc4hc
@chandra-gc4hc 2 года назад
Bro how to check list of certificates available in library and how to check expiry date of all certificates with name?
@linuxhelp5096
@linuxhelp5096 2 года назад
* Most distros put their certificates soft-link in system-wide location at /etc/ssl/certs. * Key files go into /etc/ssl/private * System-provided actual files are located at /usr/share/ca-certificates * Custom certificates go into /usr/local/share/ca-certificates For more topics subscribe to our channel, ru-vid.com/show-UCvTQ6WM-MSvCFVNCEtI6HPg
@cameronyoung4148
@cameronyoung4148 Год назад
Couldn't understand the accent. Is it possible to enable subtitles
@linuxhelp5096
@linuxhelp5096 Год назад
Yes we will enable. For more topics subscribe to our channel, ru-vid.com/show-UCvTQ6WM-MSvCFVNCEtI6HPg
@slotcantikbarbar2483
@slotcantikbarbar2483 2 года назад
mkdir /var/www/mine answer cannot create directory
@linuxhelp5096
@linuxhelp5096 2 года назад
If you want to create directory inside parent directory you can use mkdir -p For more topics subscribe to our channel, ru-vid.com/show-UCvTQ6WM-MSvCFVNCEtI6HPg
@wangaigitahi6308
@wangaigitahi6308 10 месяцев назад
@@linuxhelp5096 you can add sudo to elevate the command
@dococentral3778
@dococentral3778 4 года назад
may i ask what language is he speaking in?
@suqmadiqjojoj358
@suqmadiqjojoj358 4 года назад
english
@idontcarey8882
@idontcarey8882 4 года назад
Indianglish
@n3r4zzurr0_
@n3r4zzurr0_ 3 года назад
SOUTH Indian English
@leenevin8451
@leenevin8451 3 года назад
Inglish
@bilalch3472
@bilalch3472 Год назад
Robot language
@leenevin8451
@leenevin8451 3 года назад
Last command didn’t work for me
@linuxhelp5096
@linuxhelp5096 3 года назад
To reflex the changes what have you made in configuration you have to restart the service by using anyone of the command: sudo /etc/init.d/apache2 restart sudo service apache2 restart sudo service apache2 reload For more topics subscribe to our channel, ru-vid.com/show-UCvTQ6WM-MSvCFVNCEtI6HPg
@unknownrider0410
@unknownrider0410 3 года назад
I just heard hear(HARE)wehaveto
@aminekhalifa9969
@aminekhalifa9969 4 года назад
Indianglish
@tiendamueblesonline9347
@tiendamueblesonline9347 5 лет назад
this procedure is dangerous not apply in your machine
@naturevibezz
@naturevibezz 5 лет назад
exactly
@idontcarey8882
@idontcarey8882 4 года назад
Is it safe enough for a local "test" network that is getting a lot of SSL errors on its internal mail server page
@adairjimenez6041
@adairjimenez6041 10 месяцев назад
why is dangerous?
@97javaid
@97javaid 4 года назад
what the .... is this
@sirlico
@sirlico Год назад
Brooo if you know you speak hindi just put it on comment
@jamalbenali9605
@jamalbenali9605 7 месяцев назад
indian
@anonymousgame-beats3591
@anonymousgame-beats3591 Год назад
Help AH00526: Syntax error on line 2 of /etc/apache2/sites-enabled/owncloud.conf: Invalid command 'SSLEngine', perhaps misspelled or defined by a module not included in the server configuration Action 'configtest' failed. The Apache error log may have more information.
@linuxhelp5096
@linuxhelp5096 Год назад
If your output does not give specific information about the error location in Apache’s configuration files, you will need to examine journalctl output from the systemd logs. sudo journalctl -u apache2.service --since today --no-pager If you have an AH00526 error in your Apache configuration, look through the journalctl command. the AH00526 error. Since this error is a general error related to an invalid setting or a typo in a configuration file In this case it is a directive called SSLCertificateFile, which will only be valid if the ssl module is enabled. sudo a2enmod ssl sudo systemctl restart apache2.service apachectl configtest command is useful for catching syntax errors before reloading apache with a new configuration. show for error message removing the directive will resolve the issue. sudo apachectl configtest Ref Link : ru-vid.com/video/%D0%B2%D0%B8%D0%B4%D0%B5%D0%BE-CRiwgzzlwO4.html For more topics subscribe to our channel, ru-vid.com/show-UCvTQ6WM-MSvCFVNCEtI6HPg
@aaronbraithwaite6710
@aaronbraithwaite6710 2 года назад
When I type mkdir /var/www/mine, I get mkdir: cannot create directory '/var/www/mine': No such file or directory exists
@linuxhelp5096
@linuxhelp5096 2 года назад
You can try with mkdir -p /path-to-directory/directory-name For more topics subscribe to our channel, ru-vid.com/show-UCvTQ6WM-MSvCFVNCEtI6HPg
@dabtican4953
@dabtican4953 2 года назад
@@linuxhelp5096 so would that be mkrdir -p /var/www/mine ?
@shrikantdalmia7838
@shrikantdalmia7838 3 года назад
openssl req -x509 -nodes -days 365 -newkey rsa:2048 -keyout /etc/ssl/ssl/private/my.key -out /etc/ssl/certs/my.crt Thank me later
@sohambanerjee4110
@sohambanerjee4110 4 месяца назад
openssl req -x509 -nodes -days 90 -newkey rsa:2048 -keyout /etc/ssl/ssl/private/house.key -out /etc/ssl/certs/my.crt
Далее
Install SSL/TLS for Apache on Ubuntu
29:44
Просмотров 49 тыс.
50 YouTubers Fight For $1,000,000
41:27
Просмотров 75 млн
OpenSSL Certification Authority (CA) on Ubuntu Server
16:07
Create Your Own SSL Certificate Authority (on Linux)
5:34
HTTPS, SSL, TLS & Certificate Authority Explained
43:29
Installing a Basic SSL/TLS Certificate in nginx
10:14
Apache Web Server and HTTPS on Linux
46:38
Просмотров 62 тыс.
Create https localhost (ssl) on ubuntu 16.04
14:14
Просмотров 66 тыс.
Installing XenServer
9:05
Просмотров 5 тыс.
Web Server Concepts and Examples
19:40
Просмотров 233 тыс.
50 YouTubers Fight For $1,000,000
41:27
Просмотров 75 млн