S o n o m a U s e r M a n u a l
48
C H A P T E R F I V E
Configure Certificate and Key
For SSL it is recommended, but not required, that new certificates and keys are generated and
installed on the Apache web server with mod_ssl. The factory configured, self-signed certificate is
located in
/etc/httpd/server.crt
, and the key in
/etc/httpd/server.key
. After creating new certificates and
private keys, they will need to be saved in
/boot/etc/httpd/server.crt
and
/boot/etc/httpd/server.key
. To
generate a new certificate and key, issue these commands:
cd /boot/etc/httpd
openssl req -new -x509 -nodes -out server.crt -keyout server.key
The two files will be created in the
/boot/etc/httpd
directory. You must reboot the Sonoma for them
to take effect. An excellent book which describes operation and configuration of the various HTTPS
directives and SSL configuration is:
Professional Apache
, Wainwright, Wrox Press, 1999.
NTP
You can configure your NTP clients for secure MD5 authentication. See
Chapter 3 - NTP, Unix-like
Platforms: MD5 Authenticated NTP Client Setup
or
Chapter 3 - NTP, Windows: MD5 Authenti-
cated NTP Client Setup
. You can also restrict NTP query access. See
Restrict Query Access - NTP
in this chapter.
Network Security
Vulnerabilities
EndRun addresses major network security vulnerabilities that affect Sonoma at the top of this web-
page:
http://www.endruntechnologies.com/fsb.htm
This Application Note describes best practices to secure your time server and mitigate many network
security vulnerabilities:
Содержание Sonoma D12
Страница 2: ......
Страница 20: ...S o n o m a U s e r M a n u a l 4 C H A P T E R O N E This page intentionally left blank...
Страница 32: ...S o n o m a U s e r M a n u a l 16 C H A P T E R T W O This page intentionally left blank...
Страница 48: ...S o n o m a U s e r M a n u a l 32 C H A P T E R T H R E E This page intentionally left blank...
Страница 70: ...S o n o m a U s e r M a n u a l 54 C H A P T E R S I X This page intentionally left blank...
Страница 82: ...S o n o m a U s e r M a n u a l 66 C H A P T E R S E V E N This page intentionally left blank...
Страница 104: ...S o n o m a U s e r M a n u a l 88 C H A P T E R N I N E This page intentionally left blank...
Страница 128: ...S o n o m a U s e r M a n u a l 112 A P P E N D I X A This page intentionally left blank...
Страница 138: ...S o n o m a U s e r M a n u a l 122 A P P E N D I X B This page intentionally left blank...
Страница 154: ...S o n o m a U s e r M a n u a l 138 A P P E N D I X E FIGURE 1B CDMA ANTENNA MOUNTING GUIDELINES WITH PREAMPLIFIER...
Страница 160: ...S o n o m a U s e r M a n u a l 144 A P P E N D I X G This page intentionally left blank...
Страница 166: ...S o n o m a U s e r M a n u a l 150 A P P E N D I X H...
Страница 167: ...151 S o n o m a U s e r M a n u a l S P E C I F I C AT I O N S...
Страница 168: ...S o n o m a U s e r M a n u a l 152 A P P E N D I X H This page intentionally left blank...
Страница 170: ...S o n o m a U s e r M a n u a l 154 S P E C I A L M O D I F I C AT I O N S This page intentionally left blank...
Страница 171: ......