
23rd July 2010, 11:49
|
|
Moderator
|
|
Join Date: Jul 2006
Posts: 1,016
Thanks: 7
Thanked 56 Times in 51 Posts
|
|
SSL Host - Intermediate Cert
Hi folks,
does anybody know, if ISPConfig 2 supports providing an intermediate certificate?
I'd say currently not out of the box, only by changing the apache conf's generation template, as an additional config entry is needed to point to the intermediate file.
thanks in advance.
Ben
|

24th July 2010, 12:26
|
|
Super Moderator
|
|
Join Date: Apr 2005
Location: Lüneburg, Germany
Posts: 41,665
Thanks: 1,896
Thanked 2,592 Times in 2,443 Posts
|
|
Quote:
Originally Posted by Ben
I'd say currently not out of the box, only by changing the apache conf's generation template, as an additional config entry is needed to point to the intermediate file.
|
That's right, you must modify the Apache configuration manually.
|

24th July 2010, 15:31
|
|
Moderator
|
|
Join Date: Jul 2006
Posts: 1,016
Thanks: 7
Thanked 56 Times in 51 Posts
|
|
Hi Falko,
the apache config or the template for the config?
Last would be kind of bad as it must be changed each update of ispcfg and does only work for the assumption of using only one ssl cert on the whole host (which is at least no problem for me  )
Does it make sense to add another textbox in the ssl config interface, as many of the CAs tend to intermediate CA certs.
|

25th July 2010, 13:53
|
|
Super Moderator
|
|
Join Date: Apr 2005
Location: Lüneburg, Germany
Posts: 41,665
Thanks: 1,896
Thanked 2,592 Times in 2,443 Posts
|
|
I'm not sure - but maybe you can include the intermediate certificate in the main Apache configuration? In that case you don't have to modify the template. (BTW, you could place the customized template in /root/ispconfig/isp/conf/customized_templates, and it will not be overwritten in case of an update.)
|

28th July 2010, 22:46
|
|
Moderator
|
|
Join Date: Jul 2006
Posts: 1,016
Thanks: 7
Thanked 56 Times in 51 Posts
|
|
good idea, but except "{SSL}" there is nothing in the vhost master template?!
EDIT: Ok it did work more or less. I added the Intermediate CA line below {SSL} with the result having this line in each vhost block instead of just in the ssl block. Luckily apache does not complain about this. Is there a better way to customize the ssl block directly?
Last edited by Ben; 28th July 2010 at 22:58.
|

29th July 2010, 10:37
|
|
Super Moderator
|
|
Join Date: Apr 2005
Location: Lüneburg, Germany
Posts: 31,888
Thanks: 693
Thanked 4,188 Times in 3,205 Posts
|
|
Quote:
|
Is there a better way to customize the ssl block directly?
|
The only other way might be to edit the function in config.lib.php file that creates the ssl block. If I remember correctly, it is named make_vhost. But then you might have to patch the file after every ispconfig update, so this solution is not ideal too.
|

29th July 2010, 11:26
|
|
Moderator
|
|
Join Date: Jul 2006
Posts: 1,016
Thanks: 7
Thanked 56 Times in 51 Posts
|
|
As I have to patch one line regarding the safe mode and the open_basedir paths I think about patching only one line for an include to the additional config. But thanks for the info.
|

14th February 2011, 11:53
|
|
Senior Member
|
|
Join Date: Oct 2005
Posts: 192
Thanks: 9
Thanked 1 Time in 1 Post
|
|
a possible fix?
I have a few sites that use SSL and I needed to add an intermediate certificate as certificates are renewed.
So putting an intermediate certificate reference into the vhosts file was never going to be a solution.
I have simply put the line
SSLCACertificateFile /home/www/cabundle.crt
into apache2.conf
and it seems to be working OK.
|

28th February 2011, 11:44
|
|
Senior Member
|
|
Join Date: Oct 2005
Posts: 192
Thanks: 9
Thanked 1 Time in 1 Post
|
|
Quote:
Originally Posted by hairydog2
and it seems to be working OK.
|
Two weeks later and it is still working just fine, so it seems like this is a good fix!
|
| Thread Tools |
|
|
| Display Modes |
Linear Mode
|
Posting Rules
|
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts
HTML code is Off
|
|
|
All times are GMT +2. The time now is 07:32.
|
|
Recent comments
1 day 5 hours ago
1 day 10 hours ago
1 day 11 hours ago
1 day 12 hours ago
1 day 14 hours ago
1 day 18 hours ago
1 day 19 hours ago
1 day 21 hours ago
2 days 10 hours ago
2 days 12 hours ago