mod_ssl
套件。
[root@kvm5 ~]# yum install -y mod_ssl
mod_ssl
提供的設定檔 /etc/httpd/conf.d/ssl.conf,取消 SSLCertificateChainFile 註解。如果指定的憑證檔檔名想要改成比較好識別的方式,也可一併修改。
[root@kvm5 ~]# vim /etc/httpd/conf.d/ssl.conf [root@kvm5 ~]# egrep '^SSL(Certi|Engine)' /etc/httpd/conf.d/ssl.conf SSLEngine on SSLCertificateFile /etc/pki/tls/certs/localhost.crt SSLCertificateKeyFile /etc/pki/tls/private/localhost.key SSLCertificateChainFile /etc/pki/tls/certs/server-chain.crt
[root@kvm5 ~]# wget http://dywang.csie.cyut.edu.tw/materials/kvm5.crt \ -O /etc/pki/tls/certs/localhost.crt [root@kvm5 ~]# wget http://dywang.csie.cyut.edu.tw/materials/kvm5.key \ -O /etc/pki/tls/private/localhost.key [root@kvm5 ~]# wget http://dywang.csie.cyut.edu.tw/materials/kvm5.pem \ -O /etc/pki/tls/certs/server-chain.crt
[root@kvm5 ~]# systemctl restart httpd.service
[root@kvm5 ~]# curl --cacert /etc/pki/tls/certs/server-chain.crt https://kvm5.deyu.wang/ web test
[root@kvm7 ~]# wget http://dywang.csie.cyut.edu.tw/materials/kvm5.pem
[root@kvm7 ~]# curl --cacert kvm5.pem https://kvm5.deyu.wang web test
Trust this CA to identify websites
。
Edit → Preferences Advanced → Certificates tab View Certificates (Authorities) → Import button
Settings → Show advanced settings... HTTPS/SSL → Manage Certificates... Authorities → Import button