IBM HTTP Server https configuration

来源:互联网 发布:江苏网络推广公司排名 编辑:程序博客网 时间:2024/05/16 06:40

1. Generate kdb

gskcmd -keydb -create -db ihskey -pw pwd -type pkcs12 -expire 365 -stash

2. Generate Certificate

gskcmd -cert -create -db ihskey -pw pwd -size 1024 -dn CN=localhost,O=IBM,OU=IBM HTTP Server,C=CN -label ihskey -default_cert yes - expire 365

3. Enable SSL in httpd.conf

# Example SSL configuration which supports SSLv3 and TLSv1
# To enable this support:
#   1) Create a key database with ikeyman
#   2) Update the KeyFile directive below to point to that key database
#   3) Uncomment the directives up through the end of the example
LoadModule ibm_ssl_module modules/
Listen 443
<VirtualHost *:443>
SSLServerCert ihskey
SSLClientAuth None
KeyFile /opt/ibm/HTTPServer/bin/ihskey.p12
# End of example SSL configuration

4. Force 80 to 443

update httpd.conf

uncomment LoadModule rewrite_module modules/ and add

RewriteEngine on
RewriteCond %{SERVER_PORT} =80
RewriteRule ^(.*) https://%{SERVER_NAME}%{REQUEST_URI} [R,L]


Creating a new key database using the command-line interface

Creating a self-signed certificate

Rewriting HTTP (port 80) requests to HTTPS (port 443)

0 0