LinuxSir.cn,穿越时空的Linuxsir!

 找回密码
 注册
搜索
热搜: shell linux mysql
12
返回列表 发新帖
楼主: cxfcxf

一堆SSL的疑问。。。

[复制链接]
发表于 2005-10-24 05:11:44 | 显示全部楼层
Post by zaiwen
First, about apachessl start, I did some tests and yongjian is correct: you don't need to use apachectl startssl to start the SSL http server.  When you start httpd, it will start the SSL portion of it too.

However, I am still very confused with the key and cert files.

cxfxcf says, "i think it's not need to transfer a key to client site; i have tested it with outlook".

If you don't need to transfer a key or cert to client site, how could the key and certificate be verified?  When you connect from the client to the server? (maybe silly questions

I tested both imaps and https from windows clients.  

跳出ssl提醒框。。2个选项都是不安全, except date.  

But after I viewed the certificate and installed it into the window's store, I don't get ssl提醒框 any more....

Yongjian, could you please explain the whole logic of ssl key and certificate files about imaps and https for us?  I will check this posting anxiously....waiting for you.....

Sorry I am not an expert on SSL, so I did some research. Looks like you don't necessary need to manually install the cert locally but you certain can do that if you want. The client and server will do some handshakes to negotiate what method they will use to communicate during the session and it includes choosing the cipher algorithm and verify the cert. If it is successfully, the client will store the cert. Manually install can be done such as this: open your browser and do https://your.mail.server:993/
Reference:
1. http://wiki.dovecot.org/moin.cgi/ChainedSSLCertificates
2. http://en.wikipedia.org/wiki/Secure_Sockets_Layer
3. http://www.knowplace.org/imaps.html
4. http://www.seifried.org/security ... imap_pop_linux.html
回复 支持 反对

使用道具 举报

发表于 2005-10-24 06:29:37 | 显示全部楼层
Thank you so much, yongjian!!!!  After reading all the links you provide, I now have a much more clear picture of SSL for https and imaps.

I did more tests again with both imaps and https from windows clients to linux server.

跳出ssl提醒框。only the first one 选项是不安全, which i think is normal...that's why we need to install the certificate.  After i chose to install the certificate into the window's store, it works fine.

I don't have another linux client to test connection to the linux server.  Will do it tomorrow....is it the same as from windows client?  Just open browser on linux and do https://your.mail.server:993/?  If yes, that's good....i always thought from linux client you need to manually transfer the certificate file to client and copy it somewhere yourself....

Will let you know tomorrow after I do the test......
Feel much relieved now....will enjoy my sunday dinner more
回复 支持 反对

使用道具 举报

 楼主| 发表于 2005-10-24 09:49:23 | 显示全部楼层
and...how to set a key and crt 's data??
i can not find that section in dovecot-openssl.cnf
set up all and i get a feedback from IE
证书的时间已经过期或还没生效
回复 支持 反对

使用道具 举报

您需要登录后才可以回帖 登录 | 注册

本版积分规则

快速回复 返回顶部 返回列表