S o n o m a U s e r M a n u a l
48
C H A P T E R F I V E
Configure Certificate and Key
For SSL it is recommended, but not required, that new certificates and keys are generated and
installed on the Apache web server with mod_ssl. The factory configured, self-signed certificate is
located in
/etc/httpd/server.crt
, and the key in
/etc/httpd/server.key
. After creating new certificates and
private keys, they will need to be saved in
/boot/etc/httpd/server.crt
and
/boot/etc/httpd/server.key
. To
generate a new certificate and key, issue these commands:
cd /boot/etc/httpd
openssl req -new -x509 -nodes -out server.crt -keyout server.key
The two files will be created in the
/boot/etc/httpd
directory. You must reboot the Sonoma for them
to take effect. An excellent book which describes operation and configuration of the various HTTPS
directives and SSL configuration is:
Professional Apache
, Wainwright, Wrox Press, 1999.
NTP
You can configure your NTP clients for secure MD5 authentication. See
Chapter 3 - NTP, Unix-like
Platforms: MD5 Authenticated NTP Client Setup
or
Chapter 3 - NTP, Windows: MD5 Authenti-
cated NTP Client Setup
. You can also restrict NTP query access. See
Restrict Query Access - NTP
in this chapter.
Network Security
Vulnerabilities
EndRun addresses major network security vulnerabilities that affect Sonoma at the top of this web-
page:
http://www.endruntechnologies.com/fsb.htm
This Application Note describes best practices to secure your time server and mitigate many network
security vulnerabilities:
Summary of Contents for Sonoma N12
Page 2: ......
Page 16: ...S o n o m a U s e r M a n u a l This page intentionally left blank...
Page 20: ...S o n o m a U s e r M a n u a l 4 C H A P T E R O N E This page intentionally left blank...
Page 32: ...S o n o m a U s e r M a n u a l 16 C H A P T E R T W O This page intentionally left blank...
Page 48: ...S o n o m a U s e r M a n u a l 32 C H A P T E R T H R E E This page intentionally left blank...
Page 70: ...S o n o m a U s e r M a n u a l 54 C H A P T E R S I X This page intentionally left blank...
Page 82: ...S o n o m a U s e r M a n u a l 66 C H A P T E R S E V E N This page intentionally left blank...
Page 122: ...S o n o m a U s e r M a n u a l 106 A P P E N D I X A This page intentionally left blank...
Page 156: ...S o n o m a U s e r M a n u a l 140 A P P E N D I X E...
Page 158: ...S o n o m a U s e r M a n u a l 142 A P P E N D I X F This page intentionally left blank...
Page 168: ...S o n o m a U s e r M a n u a l 152 A P P E N D I X H...
Page 169: ...153 S o n o m a U s e r M a n u a l S P E C I F I C AT I O N S...
Page 170: ...S o n o m a U s e r M a n u a l 154 A P P E N D I X H This page intentionally left blank...
Page 173: ......