13.配置安全 web 服务
试题概述
为站点 https://server0.example.com 配置 TLS 加密:
一个已签名证书从 http://classroom/pub/example-ca.crt 获取
此证书的密钥从 http://classroom/pub/tls/certs/server0.crt 获取
此证书的签名授权信息从 http://classroom/pub/tls/private/server0.key 获取
解题参考
yum -y install mod_ssl
cd /etc/pki/tls/certs/
wget http://classroom/pub/example-ca.crt
wget http://classroom/pub/tls/certs/server0.crt
cd ../private/
wget http://classroom/pub/tls/private/server0.key
chmod 600 server0.key
vim /etc/httpd/conf.d/ssl.conf
SSLCertificateFile /etc/pki/tls/certs/server0.crt #修改第100行 SSLCertificateKeyFile /etc/pki/tls/private/server0.key#修改第107行 SSLCertificateChainFile /etc/pki/tls/certs/example-ca.crt#修改第116行,并去掉注释
systemctl restart httpd
firefox #浏览器需要手动添加根证书
共有 0 条评论