<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: SSL autentizácia s webovým serverom Apache</title>
	<atom:link href="http://www.jariq.sk/2009/05/25/ssl-autentizacia-s-webovym-serverom-apache/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.jariq.sk/2009/05/25/ssl-autentizacia-s-webovym-serverom-apache/</link>
	<description>O svete, linuxe a mojej ceste nimi..</description>
	<lastBuildDate>Tue, 31 Aug 2010 11:44:47 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.0.1</generator>
	<item>
		<title>By: Lubos Rendek</title>
		<link>http://www.jariq.sk/2009/05/25/ssl-autentizacia-s-webovym-serverom-apache/#comment-155</link>
		<dc:creator>Lubos Rendek</dc:creator>
		<pubDate>Sat, 29 Aug 2009 01:49:03 +0000</pubDate>
		<guid isPermaLink="false">http://www.jariq.sk/?p=265#comment-155</guid>
		<description>AHOJTE,

Znovu dalsi kvalitny clanok od Jaroslava! Dovolujem si iba pridat par poznamok pre configuraciu s apache2 pre linux:

otvorenie portu 443 nieje potrebne ak v subore /etc/apache2/ports.conf je definovana directiva

&lt;IfModule mod_ssl.c&gt;
Listen 443
&lt;/IfModule&gt;

tato directiva automaticky povoli port 443 ak je ssl modul aktivovany. Dalsia moznost je jednoducho iba pridat riadok &quot;Listen 443&quot; do /etc/apache2/ports.conf subora.

Aktivovanie ssl modulu docielime prikazom:
a2enmod ssl  ( vytvorenie symbolickeho ssl.conf linku do /etc/apache2/mods-enabled )

ak mame definovanu directivu IfModule mod_ssl.c v subore /etc/apache2/ports.conf tak tento 
prikaz automaticky zapne aj pocuvanie na porte 443 

restart signal:
apache2ctl graceful

Vytorenie virualneho suboru potrebuje malu zmenu:

 BrowserMatch &quot;.*MSIE.*&quot; 
                nokeepalive ssl-unclean-shutdown 
                downgrade-1.0 force-response-1.0
zmenit na:
BrowserMatch &quot;.*MSIE.*&quot; \
                nokeepalive ssl-unclean-shutdown \
                downgrade-1.0 force-response-1.0</description>
		<content:encoded><![CDATA[<p>AHOJTE,</p>
<p>Znovu dalsi kvalitny clanok od Jaroslava! Dovolujem si iba pridat par poznamok pre configuraciu s apache2 pre linux:</p>
<p>otvorenie portu 443 nieje potrebne ak v subore /etc/apache2/ports.conf je definovana directiva</p>
<p>&lt;IfModule mod_ssl.c&gt;<br />
Listen 443<br />
&lt;/IfModule&gt;</p>
<p>tato directiva automaticky povoli port 443 ak je ssl modul aktivovany. Dalsia moznost je jednoducho iba pridat riadok &#8220;Listen 443&#8243; do /etc/apache2/ports.conf subora.</p>
<p>Aktivovanie ssl modulu docielime prikazom:<br />
a2enmod ssl  ( vytvorenie symbolickeho ssl.conf linku do /etc/apache2/mods-enabled )</p>
<p>ak mame definovanu directivu IfModule mod_ssl.c v subore /etc/apache2/ports.conf tak tento<br />
prikaz automaticky zapne aj pocuvanie na porte 443 </p>
<p>restart signal:<br />
apache2ctl graceful</p>
<p>Vytorenie virualneho suboru potrebuje malu zmenu:</p>
<p> BrowserMatch &#8220;.*MSIE.*&#8221;<br />
                nokeepalive ssl-unclean-shutdown<br />
                downgrade-1.0 force-response-1.0<br />
zmenit na:<br />
BrowserMatch &#8220;.*MSIE.*&#8221; \<br />
                nokeepalive ssl-unclean-shutdown \<br />
                downgrade-1.0 force-response-1.0</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Jaroslav Imrich</title>
		<link>http://www.jariq.sk/2009/05/25/ssl-autentizacia-s-webovym-serverom-apache/#comment-154</link>
		<dc:creator>Jaroslav Imrich</dc:creator>
		<pubDate>Mon, 24 Aug 2009 07:28:19 +0000</pubDate>
		<guid isPermaLink="false">http://www.jariq.sk/?p=265#comment-154</guid>
		<description>Na CRL treba Apache naviest pomocou direktivy &lt;a href=&quot;http://httpd.apache.org/docs/2.2/mod/mod_ssl.html#sslcarevocationfile&quot; rel=&quot;nofollow&quot;&gt;SSLCARevocationFile&lt;/a&gt; alebo &lt;a href=&quot;http://httpd.apache.org/docs/2.2/mod/mod_ssl.html#sslcarevocationpath&quot; rel=&quot;nofollow&quot;&gt;SSLCARevocationPath&lt;/a&gt;. Stahovanie aktualneho CRL na lokalny disk musis zabezpecit sam napriklad skriptom spustanym z cronu.</description>
		<content:encoded><![CDATA[<p>Na CRL treba Apache naviest pomocou direktivy <a href="http://httpd.apache.org/docs/2.2/mod/mod_ssl.html#sslcarevocationfile" rel="nofollow">SSLCARevocationFile</a> alebo <a href="http://httpd.apache.org/docs/2.2/mod/mod_ssl.html#sslcarevocationpath" rel="nofollow">SSLCARevocationPath</a>. Stahovanie aktualneho CRL na lokalny disk musis zabezpecit sam napriklad skriptom spustanym z cronu.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Vlado</title>
		<link>http://www.jariq.sk/2009/05/25/ssl-autentizacia-s-webovym-serverom-apache/#comment-153</link>
		<dc:creator>Vlado</dc:creator>
		<pubDate>Sun, 23 Aug 2009 07:55:22 +0000</pubDate>
		<guid isPermaLink="false">http://www.jariq.sk/?p=265#comment-153</guid>
		<description>Super clanok.
Chcem sa spytat kde mam definovat cestu ku .clr suboru. V mojom pripade ho mam umiestneny na roote servera v priecinku certifikaty.

Dakujem.</description>
		<content:encoded><![CDATA[<p>Super clanok.<br />
Chcem sa spytat kde mam definovat cestu ku .clr suboru. V mojom pripade ho mam umiestneny na roote servera v priecinku certifikaty.</p>
<p>Dakujem.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Jaroslav Imrich</title>
		<link>http://www.jariq.sk/2009/05/25/ssl-autentizacia-s-webovym-serverom-apache/#comment-149</link>
		<dc:creator>Jaroslav Imrich</dc:creator>
		<pubDate>Fri, 29 May 2009 23:43:12 +0000</pubDate>
		<guid isPermaLink="false">http://www.jariq.sk/?p=265#comment-149</guid>
		<description>Ak sa nemylim, tak tebou opisane informacie o identite obsahuju len tzv. &quot;extended validation&quot; certifikaty. Najlahsi (a pravdepodobne aj jediny) sposob ako takyto certifikat ziskat je kupit si ho od niektorej z komercnych autorit. Mohol by si sa sice pokusit vygenerovat certifikat s rovnakymi rozsireniami ako maju EV certifikaty, no do prehliadaca by si nedokazal naimportovat certifikat CA, ktorou si ho vydal. Zoznam EV autorit totiz spravuje vyrobca prehliadaca.</description>
		<content:encoded><![CDATA[<p>Ak sa nemylim, tak tebou opisane informacie o identite obsahuju len tzv. &#8220;extended validation&#8221; certifikaty. Najlahsi (a pravdepodobne aj jediny) sposob ako takyto certifikat ziskat je kupit si ho od niektorej z komercnych autorit. Mohol by si sa sice pokusit vygenerovat certifikat s rovnakymi rozsireniami ako maju EV certifikaty, no do prehliadaca by si nedokazal naimportovat certifikat CA, ktorou si ho vydal. Zoznam EV autorit totiz spravuje vyrobca prehliadaca.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: yoy</title>
		<link>http://www.jariq.sk/2009/05/25/ssl-autentizacia-s-webovym-serverom-apache/#comment-148</link>
		<dc:creator>yoy</dc:creator>
		<pubDate>Wed, 27 May 2009 10:10:56 +0000</pubDate>
		<guid isPermaLink="false">http://www.jariq.sk/?p=265#comment-148</guid>
		<description>Pekny clanok, len sa chcem spytat ako je mozne vygenerovat SSL certifikat, tak aby poskytoval &quot;informacie o identite&quot;.

v adrese prehliadaca sa zobrazi (s informaciami o identite):
http://img242.imageshack.us/img242/948/urlngy.jpg

vo vlastnostiach certifikatu sa zobrazi (bez informacii o identite):
http://img242.imageshack.us/img242/1033/vlastnosti2.jpg</description>
		<content:encoded><![CDATA[<p>Pekny clanok, len sa chcem spytat ako je mozne vygenerovat SSL certifikat, tak aby poskytoval &#8220;informacie o identite&#8221;.</p>
<p>v adrese prehliadaca sa zobrazi (s informaciami o identite):<br />
<a href="http://img242.imageshack.us/img242/948/urlngy.jpg" rel="nofollow">http://img242.imageshack.us/img242/948/urlngy.jpg</a></p>
<p>vo vlastnostiach certifikatu sa zobrazi (bez informacii o identite):<br />
<a href="http://img242.imageshack.us/img242/1033/vlastnosti2.jpg" rel="nofollow">http://img242.imageshack.us/img242/1033/vlastnosti2.jpg</a></p>
]]></content:encoded>
	</item>
</channel>
</rss>
