SSL Chained Certificates for Debian Etch

Discussion in 'Suggest HOWTO' started by steve1084, Jun 20, 2007.

  1. steve1084

    steve1084 New Member

    Hi Till and Falko

    I have a Debian etch perfect server with suphp and ispconfig (because of you it works great Many thanks) But I'm finding it a bit tricky learning how to setup and install the chained root certificates. ie how to make the request, file locations, etc etc. Information is quite scattered.

    There is one howto for Federa system but nothing for debian.

    Site certificates are easy thanks to ispconfig its just getting the chained certificate for the root setup that seems to befuddle many people. Maybe this could be a future feature of ispconfig to install trusted ( etc) root chained certificates using ispconfig.

    But for the time being is it possible to have a howto for setting up the chained certificates from on a debian etch with ispconfig and suphp.

    Many Thanks

    Ps I didnt get mpm-itk to work, had many errors. dont have time for further follow up. Maybe this could also be a future howto project as there is almost no useful information out there for beginners to use.
  2. falko

    falko Super Moderator ISPConfig Developer

  3. steve1084

    steve1084 New Member

    Hi FalKo

    Thanks for the reply. sorry to be such a noob Im slowly getting there.

    I have several more questions. There seems to be no reference to ssl in my apache2.conf file. ssl for individual sites is handled by the Vhosts_ispconfig.conf file.

    I take it root server certificates were not created during my install of debian etch or ispconfig, is this correct and if not where will I find the server.crt file. there is no server.crt file in the /etc/ssl/certs folder

    Certificates were only created for postfix and then for ispconfig itself, is this correct.

    In order to create the certificate request server.crt etc is it enough to use [ openssl req -new -nodes -keyout myserver.key -out server.csr ] as per,1 using this then to creat certificate request for

    and then make reference in my apache2.conf to the created files etc as per is this correct, will this over-ride the individual site certificates

    Many thanks:)
  4. falko

    falko Super Moderator ISPConfig Developer


    You can use ISPConfig to create the CSR:
  5. steve1084

    steve1084 New Member

    do I use the same chained certificate for the root as I do for the site?

    Hi Falko

    Forgive me I'm a little confused but this link is only for the site certificates and not suitable for producing the chained root certificate request which is not setup as a website in ispconfig but is what I thought I needed a certificate for.

    or do I use the same chained certificate for the root as I do for the site?:confused:

  6. falko

    falko Super Moderator ISPConfig Developer

    No, but I read from your previous post that you want to generate the CSR for the site on the shell, too. This can be done by ISPConfig instead.
  7. steve1084

    steve1084 New Member

    Hi Falko

    The one site that I found that has a howto on chained root certificate's is in a combination of english and german I think?

    Unfortunately I don't understand german

    Maybe this could make the basis for a proper easy to follow falko howto as you guys seem to know the best way to write a howto thats understandable by everyone, beginner and expert.

    I can get a standard ssl for site with easy but cant get the chain to work properly yet, still trying.

    Anyway thanks:)
  8. falko

    falko Super Moderator ISPConfig Developer

    I have it on my To-Do list already. :)

Share This Page