PDA

View Full Version : Installing a SSL Certificate on 10.6 Server




fluffels
Jan 19, 2011, 03:47 PM
I've just been migrating services off a G5 Xserve running 10.5 Server, to a Mac Pro running 10.6 Server.

It dawned on me it'd be a good idea to get an actual SSL certificate. Because of the lack of funds available, I've gone for PositiveSSL.

Here are the steps I took to get it:

1. In Server Admin > Certificates I chose Generate CSR

2. I pasted this in to Comodo's page and chose Apache + MOD SSL

3. Took the .crt file emailed to me and chose "replace with signed certificate", dropped it on and clicked "replace certificate" (replacing the old, self signed one).

This all seemed to work fine. HOWEVER, the web service doesn't seem to be playing ball with it at all and because of this I'm scared to propagate it around any other services.

These are the errors I'm receiving: (not that Server Admin notices anything wrong!)

[Wed Jan 19 05:59:58 2011] [error] Init: Pass phrase incorrect
[Wed Jan 19 05:59:58 2011] [error] SSL Library Error: 218710120 error:0D094068:asn1 encoding routines:d2i_ASN1_SET:bad tag
[Wed Jan 19 05:59:58 2011] [error] SSL Library Error: 218529960 error:0D0680A8:asn1 encoding routines:ASN1_CHECK_TLEN:wrong tag
[Wed Jan 19 05:59:58 2011] [error] SSL Library Error: 218595386 error:0D07803A:asn1 encoding routines:ASN1_ITEM_EX_D2I:nested asn1 error
[Wed Jan 19 05:59:58 2011] [error] SSL Library Error: 218734605 error:0D09A00D:asn1 encoding routines:d2i_PrivateKey:ASN1 lib


The pass pharse thing is stumping me (along with the whole situation) - I saw the box in Server Admin 10.5, but it's gone from Snow Leopard. There's no obvious place for it that I've seen.

Is there any easy how-to guide for actually getting this sorted and having SSL up and running (I'm missing something easy, I bet!) - or anyone with a fair idea of what the next step would be?