Index: openacs-4/packages/acs-core-docs/www/install-ssl.adp =================================================================== RCS file: /usr/local/cvsroot/openacs-4/packages/acs-core-docs/www/install-ssl.adp,v diff -u -r1.4 -r1.4.2.1 --- openacs-4/packages/acs-core-docs/www/install-ssl.adp 25 Apr 2018 08:38:27 -0000 1.4 +++ openacs-4/packages/acs-core-docs/www/install-ssl.adp 2 Mar 2019 19:30:05 -0000 1.4.2.1 @@ -1,5 +1,5 @@ -{/doc/acs-core-docs {ACS Core Documentation}} {Installing SSL Support for an OpenACS service} +{/doc/acs-core-docs/ {ACS Core Documentation}} {Installing SSL Support for an OpenACS service} Installing SSL Support for an OpenACS service
  • -

    Prepare a certificate directory for the service.

    [$OPENACS_SERVICE_NAME etc]$ mkdir /var/lib/aolserver/$OPENACS_SERVICE_NAME/etc/certs
    -[$OPENACS_SERVICE_NAME etc]$ chmod 700 /var/lib/aolserver/$OPENACS_SERVICE_NAME/etc/certs
    +

    +Prepare a +certificate directory for the service.

    [$OPENACS_SERVICE_NAME etc]$ mkdir /var/lib/aolserver/$OPENACS_SERVICE_NAME/etc/certs
    +[$OPENACS_SERVICE_NAME etc]$ chmod 700 /var/lib/aolserver/$OPENACS_SERVICE_NAME/etc/certs
     [$OPENACS_SERVICE_NAME etc]$ 
    -mkdir /var/lib/aolserver/$OPENACS_SERVICE_NAME/etc/certs
    -chmod 700 /var/lib/aolserver/$OPENACS_SERVICE_NAME/etc/certs
    +mkdir /var/lib/aolserver/$OPENACS_SERVICE_NAME/etc/certs
    +chmod 700 /var/lib/aolserver/$OPENACS_SERVICE_NAME/etc/certs
     
  • It takes two files to support an SSL connection. The certificate @@ -38,7 +40,7 @@ section, we'll generate an unsigned certificate which will work in most browsers, albeit with pop-up messages.

    Use an OpenSSL perl script to generate a certificate and key.

    Debian users: use /usr/lib/ssl/misc/CA.pl instead of -/usr/share/ssl/CA

    Mac OS X users: use perl /System/Library/OpenSSL/misc/CA.pl +/usr/share/ssl/CA

    macOS users: use perl /System/Library/OpenSSL/misc/CA.pl -newcert instead of /usr/share/ssl/CA

     [$OPENACS_SERVICE_NAME $OPENACS_SERVICE_NAME]$ cd /var/lib/aolserver/$OPENACS_SERVICE_NAME/etc/certs
     [$OPENACS_SERVICE_NAME certs]$ perl /usr/share/ssl/misc/CA -newcert