Rebooting web server w/o having to type certificate passphrase?

Rebooting web server w/o having to type certificate passphrase?

Secure Home | Search | About
 General Computer Security    Post an article   get this group's latest topics as an RSS feed add this group's latest topics to your My MSN content add this group's latest topics to your My Yahoo content add this group's latest topics to your Google content
Subject Author Date
Rebooting web server w/o having to type certificate passphrase? Ramon F Herrera 06-11-2007
Posted by Ramon F Herrera on June 11, 2007, 1:43 am
If you were  Registered and logged in, you could reply and use other advanced thread options

Every time I add a cert to a web server (to support https://) I have
to be around and type the passphrase at reboot time.

I have tried two kinds of certs:

(1) cd /usr/share/ssl/certs; make testcert

and

(2) make server.pem

In case (2) the resultant cert is RSA and it doesn't need a password.
I have to extract the 2 components manually from the .pem file and
save them in separate files server.crt and server.key

In case (1) the resultant cert is DSA and needs a password.

It seems that (1) is more secure, but it requires the password to be
typed.

Is there a way to prevent the interactive password typing?

Comments?

TIA,

-Ramon


Posted by Ramon F Herrera on June 11, 2007, 2:18 am
If you were  Registered and logged in, you could reply and use other advanced thread options
> Every time I add a cert to a web server (to support https://) I have
> to be around and type the passphrase at reboot time.
>
> I have tried two kinds of certs:
>
> (1) cd /usr/share/ssl/certs; make testcert
>
> and
>
> (2) make server.pem
>
> In case (2) the resultant cert is RSA and it doesn't need a password.
> I have to extract the 2 components manually from the .pem file and
> save them in separate files server.crt and server.key
>
> In case (1) the resultant cert is DSA and needs a password.
>
> It seems that (1) is more secure, but it requires the password to be
> typed.
>
> Is there a way to prevent the interactive password typing?
>
> Comments?
>
> TIA,
>
> -Ramon

Correction: it seems like in both cases (1) and (2) the key is RSA.

-RFH



Similar ThreadsPosted
Re: Rebooting web server w/o having to type certificate passphrase? June 11, 2007, 2:58 am
Re: Rebooting web server w/o having to type certificate passphrase? June 15, 2007, 1:02 pm
Re: Rebooting web server w/o having to type certificate passphrase? June 24, 2007, 5:28 am
Sign e-mail with server certificate February 22, 2005, 4:17 pm
SSL security with server certificate compromised December 22, 2006, 7:06 am
Symbols vs letters as passphrase? October 5, 2005, 12:19 pm
Howto setup a certificate authority and create a signed certificate using openssl on Debian sarge March 16, 2005, 10:39 am
Re: Some kind of dictionary type attack? January 9, 2008, 6:22 am
Sending CMS SignedData via http - which Content-Type?? March 22, 2005, 8:44 am
ICMP Type 8 Echo Request packet security concerns October 11, 2005, 5:39 am

The site map in XML format XML site map

Contact Us | Privacy Policy