EasyManua.ls Logo

EndRun Sonoma D12 - Configure Certificate and Key; Ntp; Network Security Vulnerabilities

EndRun Sonoma D12
172 pages
Print Icon
To Next Page IconTo Next Page
To Next Page IconTo Next Page
To Previous Page IconTo Previous Page
To Previous Page IconTo Previous Page
Loading...
S o n o m a U s e r M a n u a l
48
C H A P T E R F I V E
Configure Certificate and Key
For SSL it is recommended, but not required, that new certicates and keys are generated and
installed on the Apache web server with mod_ssl. The factory congured, self-signed certicate is
located in /etc/httpd/server.crt, and the key in/etc/httpd/server.key. After creating new certicates and
private keys, they will need to be saved in /boot/etc/httpd/server.crt and /boot/etc/httpd/server.key. To
generate a new certicate and key, issue these commands:
cd /boot/etc/httpd
openssl req -new -x509 -nodes -out server.crt -keyout server.key
The two les will be created in the /boot/etc/httpd directory. You must reboot the Sonoma for them
to take effect. An excellent book which describes operation and conguration of the various HTTPS
directives and SSL conguration is:
Professional Apache, Wainwright, Wrox Press, 1999.
NTP
You can congure your NTP clients for secure MD5 authentication. See Chapter 3 - NTP, Unix-like
Platforms: MD5 Authenticated NTP Client Setup or Chapter 3 - NTP, Windows: MD5 Authenti-
cated NTP Client Setup. You can also restrict NTP query access. See Restrict Query Access - NTP
in this chapter.
Network Security
Vulnerabilities
EndRun addresses major network security vulnerabilities that affect Sonoma at the top of this web-
page:
http://www.endruntechnologies.com/fsb.htm
This Application Note describes best practices to secure your time server and mitigate many network
security vulnerabilities:
http://www.endruntechnologies.com/pdf/AppNoteSecurity.pdf

Table of Contents

Related product manuals