#1  
Old 26th March 2012, 03:19
xicoloco xicoloco is offline
Junior Member
 
Join Date: Mar 2012
Location: Brazil
Posts: 15
Thanks: 0
Thanked 3 Times in 3 Posts
Default Apache + SSL problems

ok its the 3 rd time i get this i reinstall linux + ispconfig from scratch 3 times to see if this happen again and it does.

Well everything is fine i but when i trying out the certificate buttons on website SSL creation in some point apache stop working ...

my questions are :

there is a sequence to use the ISP interface to create the certificates without messing with him ?
i can recover the instalation so i not have to reinstall the linux itself ?



well i have tryed something i saw somewhere in forum without sucess :

root@tarik01:~# a2dissite petrolube.com.br.vhost
Site petrolube.com.br.vhost already disabled

i have disable all domains and apache stills not start ... well any clues ?
Reply With Quote
Sponsored Links
  #2  
Old 26th March 2012, 09:33
till till is offline
Super Moderator
 
Join Date: Apr 2005
Location: Lüneburg, Germany
Posts: 36,421
Thanks: 834
Thanked 5,501 Times in 4,330 Posts
Default

Quote:
there is a sequence to use the ISP interface to create the certificates without messing with him ?
1) Select a IP address in the website settings.
2) Enable the ssl checkbox in the site settings.
3) Enter the details of the ssl cert, select create certificate as action.

The most likely resaon for your problem is a broken ssl certificate. This can happen if you enter chars in the ssl fields that cant be interpreted by openssl when the ssl cert is created.

Quote:
i have disable all domains and apache stills not start ... well any clues ?
Post the errors that you get on the shell and in the apache error and ssl log when you restart apache.

There is no need to reinstall Linux or reinstall ispconfig. Reinstalling ispconfig when you created already some items like websites etc can mess up your setup, so its not recommended to do that.
__________________
Till Brehm
--
Get ISPConfig support and the ISPConfig 3 manual from ispconfig.org.
Reply With Quote
  #3  
Old 26th March 2012, 14:29
xicoloco xicoloco is offline
Junior Member
 
Join Date: Mar 2012
Location: Brazil
Posts: 15
Thanks: 0
Thanked 3 Times in 3 Posts
Default

when starting apache:

root@tarik01:~# /etc/init.d/apache2 restart
Restarting web server: apache2Action 'start' failed.
The Apache error log may have more information.
failed!
root@tarik01:~#

th eapace log is :

Code:
[Sun Mar 25 18:22:33 2012] [error] [client 201.94.206.149] client denied by server configuration: /etc/apache2/htd
ocs
[Sun Mar 25 18:22:33 2012] [error] [client 201.94.206.149] client denied by server configuration: /etc/apache2/htd
ocs
[Sun Mar 25 18:22:33 2012] [error] [client 201.94.206.149] client denied by server configuration: /etc/apache2/htd
ocs
[Sun Mar 25 18:22:58 2012] [error] [client 201.94.206.149] client denied by server configuration: /etc/apache2/htd
ocs
[Sun Mar 25 18:22:58 2012] [error] [client 201.94.206.149] client denied by server configuration: /etc/apache2/htd
ocs
[Sun Mar 25 18:22:59 2012] [error] [client 201.94.206.149] client denied by server configuration: /etc/apache2/htd
ocs
[Sun Mar 25 18:22:59 2012] [error] [client 201.94.206.149] client denied by server configuration: /etc/apache2/htd
ocs
[Sun Mar 25 18:23:02 2012] [notice] caught SIGTERM, shutting down
[Sun Mar 25 18:23:03 2012] [warn] RSA server certificate is a CA certificate (BasicConstraints: CA == TRUE !?)
[Sun Mar 25 18:23:03 2012] [warn] RSA server certificate CommonName (CN) `xicoloco' does NOT match server name!?
[Sun Mar 25 18:23:03 2012] [notice] suEXEC mechanism enabled (wrapper: /usr/lib/apache2/suexec)
[Sun Mar 25 18:23:03 2012] [notice] Digest: generating secret for digest authentication ...
[Sun Mar 25 18:23:03 2012] [notice] Digest: done
[Sun Mar 25 18:23:03 2012] [warn] RSA server certificate is a CA certificate (BasicConstraints: CA == TRUE !?)
[Sun Mar 25 18:23:03 2012] [warn] RSA server certificate CommonName (CN) `xicoloco' does NOT match server name!?
[Sun Mar 25 18:23:03 2012] [notice] Apache/2.2.16 (Debian) DAV/2 mod_fcgid/2.3.6 PHP/5.3.3-7+squeeze8 with Suhosin
-Patch mod_ruby/1.2.6 Ruby/1.8.7(2010-08-16) mod_ssl/2.2.16 OpenSSL/0.9.8o configured -- resuming normal operation
s
[Sun Mar 25 18:23:07 2012] [notice] caught SIGTERM, shutting down
Let me ask i cant use self signed SSL to all virtual servers ? they mess up ?

If i have only 5 ips in rackspace for each server, there is a diferent solution to have more then one certificate in one IP ?

i am reinstalling anyway because this is one of my tests ... i will try now the cluster confg, sorry i feel very newby right now i left computers and linux back in 1999 is hard to get in shape again ...

Last edited by xicoloco; 26th March 2012 at 15:13.
Reply With Quote
  #4  
Old 29th March 2012, 14:53
xicoloco xicoloco is offline
Junior Member
 
Join Date: Mar 2012
Location: Brazil
Posts: 15
Thanks: 0
Thanked 3 Times in 3 Posts
Default

well today that happens again ....

Code:
[Thu Mar 29 06:42:15 2012] [error] [client 189.58.110.185] client denied by server configuration: /etc/apache2/htdocs
[Thu Mar 29 06:42:15 2012] [error] [client 189.58.110.185] client denied by server configuration: /etc/apache2/htdocs
[Thu Mar 29 06:42:17 2012] [error] [client 189.58.110.185] client denied by server configuration: /etc/apache2/htdocs
[Thu Mar 29 06:42:17 2012] [error] [client 189.58.110.185] client denied by server configuration: /etc/apache2/htdocs
[Thu Mar 29 06:42:18 2012] [error] [client 189.58.110.185] client denied by server configuration: /etc/apache2/htdocs
[Thu Mar 29 06:42:18 2012] [error] [client 189.58.110.185] client denied by server configuration: /etc/apache2/htdocs
[Thu Mar 29 06:42:19 2012] [error] [client 189.58.110.185] client denied by server configuration: /etc/apache2/htdocs
[Thu Mar 29 06:42:19 2012] [error] [client 189.58.110.185] client denied by server configuration: /etc/apache2/htdocs
[Thu Mar 29 06:42:34 2012] [error] [client 189.58.110.185] client denied by server configuration: /etc/apache2/htdocs
[Thu Mar 29 06:42:34 2012] [error] [client 189.58.110.185] client denied by server configuration: /etc/apache2/htdocs
[Thu Mar 29 06:42:54 2012] [error] [client 189.58.110.185] client denied by server configuration: /etc/apache2/htdocs
[Thu Mar 29 06:42:54 2012] [error] [client 189.58.110.185] client denied by server configuration: /etc/apache2/htdocs
[Thu Mar 29 06:43:02 2012] [notice] caught SIGTERM, shutting down
[Thu Mar 29 06:43:03 2012] [warn] RSA server certificate is a CA certificate (BasicConstraints: CA == TRUE !?)
[Thu Mar 29 06:43:03 2012] [warn] RSA server certificate CommonName (CN) `xicoloco' does NOT match server name!?
[Thu Mar 29 06:43:03 2012] [notice] suEXEC mechanism enabled (wrapper: /usr/lib/apache2/suexec)
[Thu Mar 29 06:43:03 2012] [notice] Digest: generating secret for digest authentication ...
[Thu Mar 29 06:43:03 2012] [notice] Digest: done
[Thu Mar 29 06:43:03 2012] [warn] RSA server certificate is a CA certificate (BasicConstraints: CA == TRUE !?)
[Thu Mar 29 06:43:03 2012] [warn] RSA server certificate CommonName (CN) `xicoloco' does NOT match server name!?
[Thu Mar 29 06:43:03 2012] [notice] Apache/2.2.16 (Debian) DAV/2 mod_fcgid/2.3.6 PHP/5.3.3-7+squeeze8 with Suhosin-Patch mod_ruby/1.2.6 Ruby/1.8.7(2010-08-16) mod_ssl/2.2.16 OpenSSL/0.9.8o configured -- resuming normal operations
[Thu Mar 29 06:43:06 2012] [notice] caught SIGTERM, shutting down
[Thu Mar 29 06:43:07 2012] [warn] RSA server certificate is a CA certificate (BasicConstraints: CA == TRUE !?)
[Thu Mar 29 06:43:07 2012] [warn] RSA server certificate CommonName (CN) `xicoloco' does NOT match server name!?
[Thu Mar 29 06:43:07 2012] [notice] suEXEC mechanism enabled (wrapper: /usr/lib/apache2/suexec)
[Thu Mar 29 06:43:07 2012] [notice] Digest: generating secret for digest authentication ...
[Thu Mar 29 06:43:07 2012] [notice] Digest: done
[Thu Mar 29 06:43:07 2012] [warn] RSA server certificate is a CA certificate (BasicConstraints: CA == TRUE !?)
[Thu Mar 29 06:43:07 2012] [warn] RSA server certificate CommonName (CN) `xicoloco' does NOT match server name!?
[Thu Mar 29 06:43:07 2012] [notice] Apache/2.2.16 (Debian) DAV/2 mod_fcgid/2.3.6 PHP/5.3.3-7+squeeze8 with Suhosin-Patch mod_ruby/1.2.6 Ruby/1.8.7(2010-08-16) mod_ssl/2.2.16 OpenSSL/0.9.8o configured -- resuming normal operations
[Thu Mar 29 06:43:09 2012] [error] [client 189.58.110.185] client denied by server configuration: /etc/apache2/htdocs
[Thu Mar 29 06:43:09 2012] [error] [client 189.58.110.185] client denied by server configuration: /etc/apache2/htdocs
[Thu Mar 29 06:43:10 2012] [notice] caught SIGTERM, shutting down
[Thu Mar 29 06:50:11 2012] [error] Server should be SSL-aware but has no certificate configured [Hint: SSLCertificateFile] ((null):0)
root@tarik01:~#
omg what fuk i doing wrong ????
Reply With Quote
  #5  
Old 30th March 2012, 11:13
falko falko is offline
Super Moderator
 
Join Date: Apr 2005
Location: Lüneburg, Germany
Posts: 41,701
Thanks: 1,900
Thanked 2,745 Times in 2,578 Posts
Default

Quote:
[Thu Mar 29 06:50:11 2012] [error] Server should be SSL-aware but has no certificate configured [Hint: SSLCertificateFile] ((null):0)
What's the output of
Code:
cd /etc/apache2
grep -Ri SSLCertificateFile *
?
__________________
Falko
--
Download the ISPConfig 3 Manual! | Check out the ISPConfig 3 Billing Module!

FB: http://www.facebook.com/howtoforge

nginx-Webhosting: Timme Hosting | Follow me on:
Reply With Quote
  #6  
Old 2nd April 2012, 00:14
xicoloco xicoloco is offline
Junior Member
 
Join Date: Mar 2012
Location: Brazil
Posts: 15
Thanks: 0
Thanked 3 Times in 3 Posts
Default

root@tarik01:/etc/apache2# grep -Ri SSLCertificateFile *
sites-available/ispconfig.vhost: SSLCertificateFile /usr/local/ispconfig/interface/ssl/ispserver.crt
sites-available/default-ssl: # SSLCertificateFile directive is needed.
sites-available/default-ssl: SSLCertificateFile /etc/ssl/certs/ssl-cert-snakeoil.pem
sites-available/default-ssl: # the referenced file can be the same as SSLCertificateFile
sites-enabled/000-ispconfig.vhost: SSLCertificateFile /usr/local/ispconfig/interface/ssl/ispserver.crt
root@tarik01:/etc/apache2#
Reply With Quote
Reply

Bookmarks

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off

Forum Jump

Similar Threads
Thread Thread Starter Forum Replies Last Post
Fixing 404 Not Found Errors on Apache on Centos 5 x86_64 Dedi LinuxOnMyMac HOWTO-Related Questions 11 16th October 2010 05:29
How To Get SSL On My Apache Server? carlosinfl Server Operation 9 8th October 2010 13:57
SSL and default apache page Issues korbynn Installation/Configuration 5 6th October 2010 15:55
CENTOS 5 Ping Problem gAnDo Server Operation 11 28th March 2008 21:58
Disable SSL on the ISPConfig Apache server lespaul49 Installation/Configuration 1 24th July 2007 15:15


All times are GMT +2. The time now is 03:21.


Powered by vBulletin® Version 3.8.7
Copyright ©2000 - 2014, vBulletin Solutions, Inc.