[mdk-re] mod_ssl howto ;)

Peter V. Saveliev =?iso-8859-1?q?peet_=CE=C1_infosite=2Eru?=
Ср Мар 13 00:32:00 MSK 2002


Hello!

При попытке включить в vhosts такую конфигурацию:
8<-------------------------------------------------------------------------------------
<VirtualHost 195.19.253.86:443>

ServerName mail.peet.spb.ru
DocumentRoot    /home/peet/personal/www-server/mail

SSLEngine on
SSLCipherSuite ALL:!ADH:RC4+RSA:+HIGH:+MEDIUM:+LOW:+SSLv2:+EXP:+eNULL
SSLCertificateFile     /home/peet/personal/www-server/mail/ssl/server.crt
SSLCertificateKeyFile  /home/peet/personal/www-server/mail/ssl/server.key
SetEnvIf User-Agent ".*MSIE.*" nokeepalive ssl-unclean-shutdown

</VirtualHost>
8<-------------------------------------------------------------------------------------

# server.crt и server.key сделаны по документации из /usr/share/doc/mod_ssl*

Получаю в /var/log/messages после service httpd restart:
8<-------------------------------------------------------------------------------------
Mar 13 00:33:07 peet httpd: httpd shutdown succeeded
Mar 13 00:33:08 peet httpd: [Wed Mar 13 00:33:08 2002] [warn] module mod_php4.c is already added, skipping
Mar 13 00:33:08 peet httpd: [Wed Mar 13 00:33:08 2002] [warn] module mod_ssl.c is already added, skipping
Mar 13 00:33:08 peet httpd: Syntax OK
Mar 13 00:33:08 peet httpd: Checking configuration sanity for httpd:  succeeded
Mar 13 00:33:09 peet httpd: [Wed Mar 13 00:33:09 2002] [warn] module mod_php4.c is already added, skipping
Mar 13 00:33:09 peet httpd: [Wed Mar 13 00:33:09 2002] [warn] module mod_ssl.c is already added, skipping
Mar 13 00:33:09 peet httpd: Apache/1.3.23 mod_ssl/2.8.7 (Pass Phrase Dialog)
Mar 13 00:33:09 peet httpd: Some of your private key files are encrypted for security reasons.
Mar 13 00:33:09 peet httpd: In order to read them you have to provide us with the pass phrases.
Mar 13 00:33:09 peet httpd: Server mail.peet.spb.ru:443 (RSA)
Mar 13 00:33:09 peet httpd: Enter pass phrase:
8<-------------------------------------------------------------------------------------

Это прикол? ;)) Есть вопрос и посерьезнее: а как же тогда стартовать? 
apachectl заканчивается тем же. При этом, прошу заметить, в top:

8<-------------------------------------------------------------------------------------
  PID USER     PRI  NI  SIZE  RSS SHARE STAT %CPU %MEM   TIME COMMAND
17832 root       0   0   572  572   468 R    97,4  0,4   0:07 initlog
17859 peet      19   0  1184 1184   924 R     0,9  0,9   0:00 top
    5 root      20   0     0    0     0 SW    0,3  0,0   0:01 kupdated
    1 root      20   0   480  432   412 S     0,0  0,3   0:03 init
    2 root      20   0     0    0     0 SW    0,0  0,0   0:00 keventd
8<-------------------------------------------------------------------------------------

Заранее спасибо,
Петр.




Подробная информация о списке рассылки community