data:image/s3,"s3://crabby-images/a8098/a8098aaaecfdfaf5441cbe09b17bc2b90089e948" alt="Cray Urika-GX Administration Manual Download Page 69"
Provide the CA with everything returned by the above, including the following lines:
-----BEGIN CERTIFICATE REQUEST----- and -----END CERTIFICATE REQUEST-----
After receiving the signed certificate, copy the certificate into a new file called
certfile.crt
. The
certificate received will contain a lot of random text. Paste that into the new file, which can be modified
using any editor, such as vi.
vi certfile.crt
Paste everything, including the following lines:
-----BEGIN CERTIFICATE----- and -----END CERTIFICATE-----
Save the file and close the editor. Proceed to step 6.
●
Use a Microsoft Windows CA - If Microsoft Windows CA is to be used to sign the certificate request,
follow the steps in
https://support.nagios.com/kb/article.php?id=597
certfile.crt
file and
then proceed to the step 6.
●
Self sign the certificate - Self-sign the certificate by executing the following command:
#
openssl x509 -req -days 365 -in certrequest.csr -signkey keyfile.key -out
certfile.crt
This should produce output saying that the signature was OK and that it retrieved the private key. Self-
signing will result in '
connection not secure
' warnings, as expected. Add an exception for this
certificate.
6. Copy the certificate files to the correct location and set permissions
#
cp certfile.crt /etc/pki/tls/certs/
#
cp keyfile.key /etc/pki/tls/private/
#
chmod go-rwx /etc/pki/tls/certs/certfile.crt
#
chmod go-rwx /etc/pki/tls/private/keyfile.key
The SSL file might already exist in
/etc/apache2/2.2/conf.d/ssl.conf
. If this is the case, ignore the
following commands:
# cp /etc/apache2/2.2/samples-conf.d/ssl.conf /etc/apache2/2.2/conf.d/
# chmod +w /etc/apache2/2.2/conf.d/ssl.conf
7. Update the Apache configuration.
a. Open the
/etc/httpd/conf.d/ssl.conf
file.
#
vi /etc/httpd/conf.d/ssl.conf
b. Locate these lines.
SSLCertificateFile /etc/pki/tls/certs/certfile.crt
c. Modify the preceding lines to:
SSLCertificateKeyFile /etc/pki/tls/private/keyfile.key
d. Save the file.
System Monitoring
S3016
69