IdentifiantMot de passe
Loading...
Mot de passe oublié ?Je m'inscris ! (gratuit)
Navigation

Inscrivez-vous gratuitement
pour pouvoir participer, suivre les réponses en temps réel, voter pour les messages, poser vos propres questions et recevoir la newsletter

Apache Discussion :

Probleme OpenSSL avec Apache


Sujet :

Apache

  1. #1
    Membre à l'essai
    Profil pro
    Inscrit en
    Juin 2007
    Messages
    36
    Détails du profil
    Informations personnelles :
    Localisation : France

    Informations forums :
    Inscription : Juin 2007
    Messages : 36
    Points : 23
    Points
    23
    Par défaut Probleme OpenSSL avec Apache
    Bonjour à tous,

    Je dois dans le cadre d'un projet, signer automatiquement un pdf (qui s'affiche dans une page web) à l'aide d'un certificat client. Bon j'arrive sans problemes à afficher un pdf dans le navigateur et je souhaite me servir d'openssl pour gérer les certificats.

    Je dispose d'easyphp 2.0
    avec Apache 2.2.3
    sous winXP

    Je me suis servi du tuto de votre site pour installer donc openSSL et générer une clé privée et un certificat.( Le tuto semble d'ailleurs incomplet mais j'y suis arrivé...)

    Je modifie le fichier httpd.conf pour activer le SSL sur apache. Je décommente ensuite la ligne pour charger le module SSL et j'ouvre le port 443..juskici tout va bien... (mais l'important....)
    mais le serveur Apache s'arrete brutalement et ne redémarre plus lorsque je décommente la ligne : SSL Engine ON

    Voici le ptit bout du fichier qui gère le SSL :

    Code : Sélectionner tout - Visualiser dans une fenêtre à part
    1
    2
    3
    4
    5
    6
    7
    8
    9
    10
    11
    12
    13
    SSLMutex default
    SSLRandomSeed startup builtin
    SSLSessionCache none
    <VirtualHost _default_:443>
     
    DocumentRoot "C:/PROGRA~1/EASYPH~1.0B1/www"
    ServerName localhost:443
    ErrorLog C:/PROGRA~1/EASYPH~1.0B1/apache/logs/error_log
    TransferLog C:/PROGRA~1/EASYPH~1.0B1/apache/logs/access_log
        SSLEngine On
        SSLCertificateFile conf/ssl/projet.cert
        SSLCertificateKeyFile conf/ssl/projet.key
    </VirtualHost>
    J'aimerais votre aide pour faire marcher OpenSSL avec Apache et voir enfin s'afficher https://127.0.0.1

    J'attends votre réponse

    merci d'avance

  2. #2
    Rédacteur
    Avatar de _Mac_
    Profil pro
    Inscrit en
    Août 2005
    Messages
    9 601
    Détails du profil
    Informations personnelles :
    Localisation : France

    Informations forums :
    Inscription : Août 2005
    Messages : 9 601
    Points : 12 977
    Points
    12 977
    Par défaut
    Que disent les fichiers de log d'Apache ? Erreur 500 = aller voir dans error_log

  3. #3
    Membre à l'essai
    Profil pro
    Inscrit en
    Juin 2007
    Messages
    36
    Détails du profil
    Informations personnelles :
    Localisation : France

    Informations forums :
    Inscription : Juin 2007
    Messages : 36
    Points : 23
    Points
    23
    Par défaut
    Oui effectivement c important :

    [Tue May 13 20:27:31 2008] [notice] Parent: Received shutdown signal -- Shutting down the server.
    [Tue May 13 20:27:31 2008] [notice] Child 1916: Exit event signaled. Child process is ending.
    [Tue May 13 20:27:32 2008] [notice] Child 1916: Released the start mutex
    [Tue May 13 20:27:33 2008] [notice] Child 1916: Waiting for 250 worker threads to exit.
    [Tue May 13 20:27:33 2008] [notice] Child 1916: All worker threads have exited.
    [Tue May 13 20:27:33 2008] [notice] Child 1916: Child process is exiting
    [Tue May 13 20:27:33 2008] [notice] Parent: Child process exited successfully.
    [Tue May 13 20:27:35 2008] [warn] Init: (localhost:443) You configured HTTP(80) on the standard HTTPS(443) port!
    [Tue May 13 20:27:36 2008] [warn] Init: (localhost:443) You configured HTTP(80) on the standard HTTPS(443) port!
    [Tue May 13 20:27:36 2008] [notice] Apache/2.2.3 (Win32) mod_ssl/2.2.3 OpenSSL/0.9.8g PHP/5.2.0 configured -- resuming normal operations
    [Tue May 13 20:27:36 2008] [notice] Server built: Jul 27 2006 16:49:49
    [Tue May 13 20:27:36 2008] [notice] Parent: Created child process 2776
    [Tue May 13 20:27:36 2008] [warn] Init: (localhost:443) You configured HTTP(80) on the standard HTTPS(443) port!
    [Tue May 13 20:27:36 2008] [warn] Init: (localhost:443) You configured HTTP(80) on the standard HTTPS(443) port!
    [Tue May 13 20:27:36 2008] [notice] Child 2776: Child process is running
    [Tue May 13 20:27:36 2008] [notice] Child 2776: Acquired the start mutex.
    [Tue May 13 20:27:36 2008] [notice] Child 2776: Starting 250 worker threads.
    [Tue May 13 20:27:36 2008] [notice] Child 2776: Starting thread to listen on port 443.
    [Tue May 13 20:27:36 2008] [notice] Child 2776: Starting thread to listen on port 80.
    [Tue May 13 20:27:52 2008] [notice] Parent: Received shutdown signal -- Shutting down the server.
    [Tue May 13 20:27:52 2008] [notice] Child 2776: Exit event signaled. Child process is ending.
    [Tue May 13 20:27:53 2008] [notice] Child 2776: Released the start mutex
    [Tue May 13 20:27:54 2008] [notice] Child 2776: Waiting for 250 worker threads to exit.
    [Tue May 13 20:27:54 2008] [notice] Child 2776: All worker threads have exited.
    [Tue May 13 20:27:54 2008] [notice] Child 2776: Child process is exiting
    [Tue May 13 20:27:54 2008] [notice] Parent: Child process exited successfully.


    Voila.

    Merci de t'interesser à mon probleme en tout cas. J'ai vraiment besoin d'aide.

  4. #4
    Rédacteur
    Avatar de _Mac_
    Profil pro
    Inscrit en
    Août 2005
    Messages
    9 601
    Détails du profil
    Informations personnelles :
    Localisation : France

    Informations forums :
    Inscription : Août 2005
    Messages : 9 601
    Points : 12 977
    Points
    12 977
    Par défaut
    Tu peux donner ta conf Apache complète ? Il manque peut-être une directive NameVirtualHost, et la directive ServerName n'est pas correcte : ça doit être ServerName localhost + définir Port 443.

  5. #5
    Membre à l'essai
    Profil pro
    Inscrit en
    Juin 2007
    Messages
    36
    Détails du profil
    Informations personnelles :
    Localisation : France

    Informations forums :
    Inscription : Juin 2007
    Messages : 36
    Points : 23
    Points
    23
    Par défaut
    ok voici httpd.conf (presque) en entier :

    Code : Sélectionner tout - Visualiser dans une fenêtre à part
    1
    2
    3
    4
    5
    6
    7
    8
    9
    10
    11
    12
    13
    14
    15
    16
    17
    18
    19
    20
    21
    22
    23
    24
    25
    26
    27
    28
    29
    30
    31
    32
    33
    34
    35
    36
    37
    38
    39
    40
    41
    42
    43
    44
    45
    46
    47
    48
    49
    50
    51
    52
    53
    54
    55
    56
    57
    58
    59
    60
    61
    62
    63
    64
    65
    66
    67
    68
    69
    70
    71
    72
    73
    74
    75
    76
    77
    78
    79
    80
    81
    82
    83
    84
    85
    86
    87
    88
    89
    90
    91
    92
    93
    94
    95
    96
    97
    98
    99
    100
    101
    102
    103
    104
    105
    106
    107
    108
    109
    110
    111
    112
    113
    114
    115
    116
    117
    118
    119
    120
    121
    122
    123
    124
    125
    126
    127
    128
    129
    130
    131
    132
    133
    134
    135
    136
    137
    138
    139
    140
    141
    142
    143
    144
    145
    146
    147
    148
    149
    150
    151
    152
    153
    154
    155
    156
    157
    158
    159
    160
    161
    162
    163
    164
    165
    166
    167
    168
    169
    170
    171
    172
    173
    174
    175
    176
    177
    178
    179
    180
    181
    182
    183
    184
    185
    186
    187
    188
    189
    190
    191
    192
    193
    194
    195
    196
    197
    198
    199
    200
    201
    202
    203
    204
    205
    206
    207
    208
    209
    210
    211
    212
    213
    214
    215
    216
    217
    218
    219
    220
    221
    222
    223
    224
    225
    226
    227
    228
    229
    230
    231
    232
    233
    234
    235
    236
    237
    238
    239
    240
    241
    242
    243
    244
    245
    246
    247
    248
    249
    250
    251
    252
    253
    254
    255
    256
    257
    258
    259
    260
    261
    262
    263
    264
    265
    266
    267
    268
    269
    270
    271
    272
    273
    274
    275
    276
    277
    278
    279
    280
    281
    282
    283
    284
    285
    286
    287
    288
    289
    290
    291
    292
    293
    294
    295
    296
    297
    298
    299
    300
    301
    302
    303
    304
    305
    306
    307
    308
    309
    310
    311
    312
    313
    314
    315
    316
    317
    318
    319
    320
    321
    322
    323
    324
    325
    326
    327
    328
    329
    330
    331
    332
    333
    334
    335
    336
    337
    338
    339
    340
    341
    342
    343
    344
    345
    346
    347
    348
    349
    350
    351
    352
    353
    354
    355
    356
    357
    358
    359
    360
    361
    362
    363
    364
    365
    366
    367
    368
    369
    370
    371
    372
    373
    374
    375
    376
    377
    378
    379
    380
    381
    382
    383
    384
    385
    386
    387
    388
    389
    390
    391
    392
    393
    394
    395
    396
    397
    398
    399
    400
    401
    402
    403
    404
    405
    406
    407
    408
    409
    410
    411
    412
    413
    414
    415
    416
    417
    418
    419
    420
    421
    422
    423
    424
    425
    426
    427
    428
    429
    430
    431
    432
    433
    434
    435
    436
    437
    438
    439
    440
    441
    442
    443
    444
    445
    446
    447
    448
    449
    450
    451
    452
    453
    454
    455
    456
    457
    458
    459
    460
    461
    462
    463
    464
    465
    466
    467
    468
    469
    470
    471
    472
    473
    474
    475
    476
    477
    478
    479
    480
    481
    482
    483
    484
    485
    486
    487
    488
    489
    490
    491
    492
    493
    494
    495
    496
    497
    498
    499
    500
    501
    502
    503
    504
    505
    506
    507
    508
    509
    510
    511
    512
    513
    514
    515
    516
    517
    518
    519
    520
    521
    522
    523
    524
    525
    526
    527
    528
    529
    530
    531
    532
    533
    534
    535
    536
    537
    538
    539
    540
    541
    542
    543
    544
    545
    546
    547
    548
    549
    550
    551
    552
    553
    554
    555
    556
    557
    558
    559
    560
    561
    562
    563
    564
    565
    566
    567
    568
    569
    570
    571
    572
    573
    574
    575
    576
    577
    578
    579
    580
    581
    582
    583
    584
    585
    586
    587
    588
    589
    590
    591
    592
    593
    594
    595
    596
    597
    598
    599
    600
    601
    602
    603
    604
    605
    606
    607
    608
    609
    610
    611
    612
    613
    614
    615
    616
    617
    618
    619
    620
    621
    622
    623
    624
    625
    626
    627
    628
    629
    630
    631
    632
    633
    634
    635
    636
    637
    638
    639
    640
    641
    642
    643
    644
    645
    646
    647
    648
    649
    650
    651
    652
    653
    654
    655
    #------------------------ IMPORTANT ! ----------------------
    # ThreadsPerChild: constant number of worker threads in the server process
    # MaxRequestsPerChild: maximum  number of requests a server process serves
    ThreadsPerChild 250
    MaxRequestsPerChild  0
     
    ServerRoot "C:/PROGRA~1/EASYPH~1.0B1/apache"
     
    #Listen 12.34.56.78:80
    Listen 127.0.0.1:80
     
     
    LoadModule actions_module modules/mod_actions.so
    LoadModule alias_module modules/mod_alias.so
    LoadModule asis_module modules/mod_asis.so
    LoadModule auth_basic_module modules/mod_auth_basic.so
    #LoadModule auth_digest_module modules/mod_auth_digest.so
    #LoadModule authn_anon_module modules/mod_authn_anon.so
    #LoadModule authn_dbm_module modules/mod_authn_dbm.so
    LoadModule authn_default_module modules/mod_authn_default.so
    LoadModule authn_file_module modules/mod_authn_file.so
    #LoadModule authz_dbm_module modules/mod_authz_dbm.so
    LoadModule authz_default_module modules/mod_authz_default.so
    LoadModule authz_groupfile_module modules/mod_authz_groupfile.so
    LoadModule authz_host_module modules/mod_authz_host.so
    LoadModule authz_user_module modules/mod_authz_user.so
    LoadModule autoindex_module modules/mod_autoindex.so
    #LoadModule cern_meta_module modules/mod_cern_meta.so
    LoadModule cgi_module modules/mod_cgi.so
    #LoadModule dav_module modules/mod_dav.so
    #LoadModule dav_fs_module modules/mod_dav_fs.so
    #LoadModule deflate_module modules/mod_deflate.so
    LoadModule dir_module modules/mod_dir.so
    LoadModule env_module modules/mod_env.so
    #LoadModule expires_module modules/mod_expires.so
    #LoadModule file_cache_module modules/mod_file_cache.so
    #LoadModule headers_module modules/mod_headers.so
    LoadModule imagemap_module modules/mod_imagemap.so
    LoadModule include_module modules/mod_include.so
    #LoadModule info_module modules/mod_info.so
    LoadModule isapi_module modules/mod_isapi.so
    LoadModule log_config_module modules/mod_log_config.so
    LoadModule mime_module modules/mod_mime.so
    #LoadModule mime_magic_module modules/mod_mime_magic.so
    #LoadModule proxy_module modules/mod_proxy.so
    #LoadModule proxy_ajp_module modules/mod_proxy_ajp.so
    #LoadModule proxy_balancer_module modules/mod_proxy_balancer.so
    #LoadModule proxy_connect_module modules/mod_proxy_connect.so
    #LoadModule proxy_http_module modules/mod_proxy_http.so
    #LoadModule proxy_ftp_module modules/mod_proxy_ftp.so
    LoadModule negotiation_module modules/mod_negotiation.so
    #LoadModule rewrite_module modules/mod_rewrite.so
    LoadModule setenvif_module modules/mod_setenvif.so
    #LoadModule speling_module modules/mod_speling.so
    #LoadModule status_module modules/mod_status.so
    #LoadModule unique_id_module modules/mod_unique_id.so
    LoadModule userdir_module modules/mod_userdir.so
    #LoadModule usertrack_module modules/mod_usertrack.so
    #LoadModule vhost_alias_module modules/mod_vhost_alias.so
    LoadModule ssl_module modules/mod_ssl.so
     
    LoadModule php5_module "C:/PROGRA~1/EASYPH~1.0B1/php5/php5apache2_2.dll"
    PHPIniDir "C:/PROGRA~1/EASYPH~1.0B1/apache"
    SetEnv TMP "C:/PROGRA~1/EASYPH~1.0B1/tmp"
     
     
     
     
     
    ServerAdmin admin@localhost
     
     
    #
    ServerName localhost
     
     
    DocumentRoot "C:/PROGRA~1/EASYPH~1.0B1/www"
     
    #
    #
    <Directory />
        Options FollowSymLinks
        AllowOverride None
        Order deny,allow
        Deny from all
        Satisfy all
    </Directory>
     
     
     
    #
    # This should be changed to whatever you set DocumentRoot to.
    #
    <Directory "C:/PROGRA~1/EASYPH~1.0B1/www">
        #
        # Possible values for the Options directive are "None", "All",
        # or any combination of:
        #   Indexes Includes FollowSymLinks SymLinksifOwnerMatch ExecCGI MultiViews
        #
        # Note that "MultiViews" must be named *explicitly* --- "Options All"
        # doesn't give it to you.
        #
        # The Options directive is both complicated and important.  Please see
        # http://httpd.apache.org/docs/2.2/mod/core.html#options
        # for more information.
        #
        Options Indexes FollowSymLinks
     
        #
        # AllowOverride controls what directives may be placed in .htaccess files.
        # It can be "All", "None", or any combination of the keywords:
        #   Options FileInfo AuthConfig Limit
        #
        AllowOverride None
     
        #
        # Controls who can get stuff from this server.
        #
        Order allow,deny
        Allow from all
     
    </Directory>
     
    <IfModule dir_module>
        DirectoryIndex index.html index.shtml index.wml index.pwml index.php index.php3 index.php4 index.php5
    </IfModule>
     
     
    <FilesMatch "^\.ht">
        Order allow,deny
        Deny from all
    </FilesMatch>
     
     
    ErrorLog logs/error.log
     
     
    LogLevel warn
     
    <IfModule log_config_module>
     
        LogFormat "%h %l %u %t \"%r\" %>s %b \"%{Referer}i\" \"%{User-Agent}i\"" combined
        LogFormat "%h %l %u %t \"%r\" %>s %b" common
     
        <IfModule logio_module>
          # You need to enable mod_logio.c to use %I and %O
          LogFormat "%h %l %u %t \"%r\" %>s %b \"%{Referer}i\" \"%{User-Agent}i\" %I %O" combinedio
        </IfModule>
     
        CustomLog logs/access.log common
     
        #
        # If you prefer a logfile with access, agent, and referer information
        # (Combined Logfile Format) you can use the following directive.
        #
        #CustomLog logs/access.log combined
    </IfModule>
     
    <IfModule alias_module>
     
     
     
    	Alias /images_easyphp "C:/PROGRA~1/EASYPH~1.0B1/home/images_easyphp"
    	Alias /home/mysql "C:/PROGRA~1/EASYPH~1.0B1/phpmyadmin"
    	Alias /home/sqlite "C:/PROGRA~1/EASYPH~1.0B1/sqlitemanager"
    	Alias /home "C:/PROGRA~1/EASYPH~1.0B1/home"
     
     
    	<Directory "C:/PROGRA~1/EASYPH~1.0B1/home/images_easyphp">
            Options Indexes MultiViews
            AllowOverride None
            Order allow,deny
            Allow from all
        </Directory>
     
    	<Directory "C:/PROGRA~1/EASYPH~1.0B1/phpmyadmin">
            Options FollowSymLinks Indexes
            AllowOverride None
            Order deny,allow
            allow from 127.0.0.1
            deny from all
        </Directory>
     
    	<Directory "C:/PROGRA~1/EASYPH~1.0B1/sqlitemanager">
            Options FollowSymLinks Indexes
            AllowOverride None
            Order deny,allow
            allow from 127.0.0.1
            deny from all
        </Directory>	
     
    	<Directory "C:/PROGRA~1/EASYPH~1.0B1/home">
            Options FollowSymLinks Indexes
            AllowOverride None
            Order deny,allow
            allow from 127.0.0.1
            deny from all
        </Directory>
     
     
        ScriptAlias /cgi-bin/ "C:/PROGRA~1/EASYPH~1.0B1/cgi-bin/"
     
    </IfModule>
     
     
    <Directory "C:/PROGRA~1/EASYPH~1.0B1/cgi-bin">
        AllowOverride None
        Options None
        Order allow,deny
        Allow from all
    </Directory>
     
     
    DefaultType text/plain
     
    <IfModule mime_module>
        #
        # TypesConfig points to the file containing the list of mappings from
        # filename extension to MIME-type.
        #
        TypesConfig conf/mime.types
     
    	AddType application/x-compress .Z
    	AddType application/x-gzip .gz .tgz
    	AddType application/x-tar .tgz
    	AddType image/x-icon .ico
    	AddType application/vnd.wap.wmlc .wmlc
    	AddType application/x-httpd-php .phtml .pwml .php5 .php4 .php3 .php2 .php .inc
    	AddType text/vnd.wap.wml .wml
    	AddType text/vnd.wap.wmlscript .wmls
    	AddType text/vnd.wap.wmlscriptc .wmlsc
    	AddType image/vnd.wap.wbmp .wbmp
     
     
    </IfModule>
     
     
     
    # ============================================================================
    # Fancy directory listings
    #
    # Directives controlling the display of server-generated directory listings.
    #
    # Required modules: mod_autoindex, mod_alias
    #
    # To see the listing of a directory, the Options directive for the
    # directory must include "Indexes", and the directory must not contain
    # a file matching those listed in the DirectoryIndex directive.
    #
     
    #
    # IndexOptions: Controls the appearance of server-generated directory
    # listings.
    #
    #IndexOptions FancyIndexing HTMLTable VersionSort
    IndexOptions FancyIndexing SuppressHTMLPreamble FoldersFirst NameWidth=*
     
    # We include the /icons/ alias for FancyIndexed directory listings.  If
    # you do not use FancyIndexing, you may comment this out.
    #
    Alias /icons/ "C:/PROGRA~1/EASYPH~1.0B1/apache/icons/"
     
    <Directory "C:/PROGRA~1/EASYPH~1.0B1/apache/icons">
        Options Indexes MultiViews
        AllowOverride None
        Order allow,deny
        Allow from all
    </Directory>
     
    #
    # AddIcon* directives tell the server which icon to show for different
    # files or filename extensions.  These are only displayed for
    # FancyIndexed directories.
    #
    AddIconByEncoding (CMP,/icons/compressed.gif) x-compress x-gzip
     
    AddIconByType (TXT,/icons/text.gif) text/*
    AddIconByType (IMG,/icons/image2.gif) image/*
    AddIconByType (SND,/icons/sound2.gif) audio/*
    AddIconByType (VID,/icons/movie.gif) video/*
     
    AddIcon /icons/binary.gif .bin .exe
    AddIcon /icons/binhex.gif .hqx
    AddIcon /icons/tar.gif .tar
    AddIcon /icons/world2.gif .wrl .wrl.gz .vrml .vrm .iv
    AddIcon /icons/compressed.gif .Z .z .tgz .gz .zip
    AddIcon /icons/a.gif .ps .ai .eps
    AddIcon /icons/layout.gif .html .shtml .htm .pdf
    AddIcon /icons/text.gif .txt
    AddIcon /icons/c.gif .c
    AddIcon /icons/p.gif .pl .py
    AddIcon /icons/f.gif .for
    AddIcon /icons/dvi.gif .dvi
    AddIcon /icons/uuencoded.gif .uu
    AddIcon /icons/script.gif .conf .sh .shar .csh .ksh .tcl
    AddIcon /icons/tex.gif .tex
    AddIcon /icons/bomb.gif core
     
    AddIcon /icons/back.gif ..
    AddIcon /icons/hand.right.gif README
    AddIcon /icons/folder.gif ^^DIRECTORY^^
    AddIcon /icons/blank.gif ^^BLANKICON^^
     
    #
    # DefaultIcon is which icon to show for files which do not have an icon
    # explicitly set.
    #
    DefaultIcon /icons/unknown.gif
     
    #
    # AddDescription allows you to place a short description after a file in
    # server-generated indexes.  These are only displayed for FancyIndexed
    # directories.
    # Format: AddDescription "description" filename
    #
    AddDescription "GZIP compressed document" .gz
    AddDescription "tar archive" .tar
    AddDescription "GZIP compressed tar archive" .tgz
    AddDescription "ZIP archive" .zip
    AddDescription "CAB archive" .cab
    AddDescription "Win32 Executable" .exe
     
    #
    # ReadmeName is the name of the README file the server will look for by
    # default, and append to directory listings.
    #
    # HeaderName is the name of a file which should be prepended to
    # directory indexes. 
    ReadmeName /icons/FancyIndexing/readme.html
    HeaderName /icons/FancyIndexing/header.html
     
    #
    # IndexIgnore is a set of filenames which directory indexing should ignore
    # and not include in the listing.  Shell-style wildcarding is permitted.
    #
    IndexIgnore .??* *~ *# HEADER* README* RCS CVS *,v *,t
    # ============================================================================
     
     
    # ============================================================================
    # Local access to the Apache HTTP Server Manual
    #
    # Provide access to the documentation on your server as
    #  http://yourserver.localhost/manual/
    # The documentation is always available at
    #  http://httpd.apache.org/docs/2.2/
    #
    # Required modules: mod_alias, mod_setenvif, mod_negotiation
    #
     
    AliasMatch ^/manual(?:/(?:de|en|es|fr|ja|ko|pt-br|ru))?(/.*)?$ "C:/PROGRA~1/EASYPH~1.0B1/apache/manual$1"
     
    <Directory "C:/PROGRA~1/EASYPH~1.0B1/apache/manual">
        Options Indexes
        AllowOverride None
        Order allow,deny
        Allow from all
     
        <Files *.html>
            SetHandler type-map
        </Files>
     
        SetEnvIf Request_URI ^/manual/(de|en|es|fr|ja|ko|pt-br|ru)/ prefer-language=$1
        RedirectMatch 301 ^/manual(?:/(de|en|es|fr|ja|ko|pt-br|ru)){2,}(/.*)?$ /manual/$1$2
     
        LanguagePriority en de es fr ja ko pt-br ru 
        ForceLanguagePriority Prefer Fallback
    </Directory>
     
     
    DAV-upload admin
    redirect-carefully
     
    these 
    # # directives see <URL:http://httpd.apache.org/docs/2.2/mod/mod_ssl.html>
    # # 
    # # Do NOT simply read the instructions in here without understanding
    # # what they do.  They're here only as hints or reminders.  If you are unsure
    # # consult the online docs. You have been warned.  
    # #
    # 
    # #SSLRandomSeed startup file:/dev/random  512
    # #SSLRandomSeed startup file:/dev/urandom 512
    # #SSLRandomSeed connect file:/dev/random  512
    # #SSLRandomSeed connect file:/dev/urandom 512
    # 
    # 
    # #
    # # When we also provide SSL we have to listen to the 
    # # standard HTTP port (see above) and to the HTTPS port
    # #
    # # Note: Configurations that use IPv6 but not IPv4-mapped addresses need two
    # #       Listen directives: "Listen [::]:443" and "Listen 0.0.0.0:443"
    # #
    Listen 443
     
     
     
     
     
     
     
    ##########################CODE DE DEVELOPPEZ.COM
    SSLMutex default
    SSLRandomSeed startup builtin
    SSLSessionCache none
    <VirtualHost _default_:443>
     
    DocumentRoot "C:/PROGRA~1/EASYPH~1.0B1/www"
    ServerName localhost:443
    ErrorLog C:/PROGRA~1/EASYPH~1.0B1/apache/logs/error_log
    TransferLog C:/PROGRA~1/EASYPH~1.0B1/apache/logs/access_log
        SSLEngine On
        SSLCertificateFile conf/ssl/projet.cert
        SSLCertificateKeyFile conf/ssl/projet.key
    </VirtualHost>
    ##########################FIN CODE DE DEVELOPPEZ.COM
     
     
     
     
     
     
     
    # 
    # ##
    # ##  SSL Global Context
    # ##
    # ##  All SSL configuration in this context applies both to
    # ##  the main server and all SSL-enabled virtual hosts.
    # ##
    # 
    # #
    # #   Some MIME-types for downloading Certificates and CRLs
    # #
    # AddType application/x-x509-ca-cert .crt
    # AddType application/x-pkcs7-crl    .crl
    # 
    # #   Pass Phrase Dialog:
    # #   Configure the pass phrase gathering process.
    # #   The filtering dialog program (`builtin' is a internal
    # #   terminal dialog) has to provide the pass phrase on stdout.
    # SSLPassPhraseDialog  builtin
    # 
    # #   Inter-Process Session Cache:
    # #   Configure the SSL Session Cache: First the mechanism 
    # #   to use and second the expiring timeout (in seconds).
    # #SSLSessionCache         dbm:C:/PROGRA~1/EASYPH~1.0B1/apache/logs/ssl_scache
    # SSLSessionCache        shmcb:C:/PROGRA~1/EASYPH~1.0B1/apache/logs/ssl_scache(512000)
    # SSLSessionCacheTimeout  300
    # 
    # #   Semaphore:
    # #   Configure the path to the mutual exclusion semaphore the
    # #   SSL engine uses internally for inter-process synchronization. 
    # SSLMutex default
    # 
    # ##
    # ## SSL Virtual Host Context
    # ##
    # 
    # <VirtualHost _default_:443>
    # 
    # #   General setup for the virtual host
    # DocumentRoot "C:/PROGRA~1/EASYPH~1.0B1/www"
    # ServerName localhost:443
    # ServerAdmin contact@localhost
    # ErrorLog C:/PROGRA~1/EASYPH~1.0B1/apache/logs/error_log
    # TransferLog C:/PROGRA~1/EASYPH~1.0B1/apache/logs/access_log
    # 
    # #   SSL Engine Switch:
    # #   Enable/Disable SSL for this virtual host.
    # SSLEngine on
    # 
    # #   SSL Cipher Suite:
    # #   List the ciphers that the client is permitted to negotiate.
    # #   See the mod_ssl documentation for a complete list.
    # SSLCipherSuite ALL:!ADH:!EXPORT56:RC4+RSA:+HIGH:+MEDIUM:+LOW:+SSLv2:+EXP:+eNULL
    # 
    # #   Server Certificate:
    # #   Point SSLCertificateFile at a PEM encoded certificate.  If
    # #   the certificate is encrypted, then you will be prompted for a
    # #   pass phrase.  Note that a kill -HUP will prompt again.  Keep
    # #   in mind that if you have both an RSA and a DSA certificate you
    # #   can configure both in parallel (to also allow the use of DSA
    # #   ciphers, etc.)
    # SSLCertificateFile C:/PROGRA~1/EASYPH~1.0B1/apache/conf/server.crt
    # #SSLCertificateFile C:/PROGRA~1/EASYPH~1.0B1/apache/conf/server-dsa.crt
    # 
    # #   Server Private Key:
    # #   If the key is not combined with the certificate, use this
    # #   directive to point at the key file.  Keep in mind that if
    # #   you've both a RSA and a DSA private key you can configure
    # #   both in parallel (to also allow the use of DSA ciphers, etc.)
    # SSLCertificateKeyFile C:/PROGRA~1/EASYPH~1.0B1/apache/conf/server.key
    # #SSLCertificateKeyFile C:/PROGRA~1/EASYPH~1.0B1/apache/conf/server-dsa.key
    # 
    # #   Server Certificate Chain:
    # #   Point SSLCertificateChainFile at a file containing the
    # #   concatenation of PEM encoded CA certificates which form the
    # #   certificate chain for the server certificate. Alternatively
    # #   the referenced file can be the same as SSLCertificateFile
    # #   when the CA certificates are directly appended to the server
    # #   certificate for convinience.
    # #SSLCertificateChainFile C:/PROGRA~1/EASYPH~1.0B1/apache/conf/server-ca.crt
    # 
    # #   Certificate Authority (CA):
    # #   Set the CA certificate verification path where to find CA
    # #   certificates for client authentication or alternatively one
    # #   huge file containing all of them (file must be PEM encoded)
    # #   Note: Inside SSLCACertificatePath you need hash symlinks
    # #         to point to the certificate files. Use the provided
    # #         Makefile to update the hash symlinks after changes.
    # #SSLCACertificatePath C:/PROGRA~1/EASYPH~1.0B1/apache/conf/ssl.crt
    # #SSLCACertificateFile C:/PROGRA~1/EASYPH~1.0B1/apache/conf/ssl.crt/ca-bundle.crt
    # 
    # #   Certificate Revocation Lists (CRL):
    # #   Set the CA revocation path where to find CA CRLs for client
    # #   authentication or alternatively one huge file containing all
    # #   of them (file must be PEM encoded)
    # #   Note: Inside SSLCARevocationPath you need hash symlinks
    # #         to point to the certificate files. Use the provided
    # #         Makefile to update the hash symlinks after changes.
    # #SSLCARevocationPath C:/PROGRA~1/EASYPH~1.0B1/apache/conf/ssl.crl
    # #SSLCARevocationFile C:/PROGRA~1/EASYPH~1.0B1/apache/conf/ssl.crl/ca-bundle.crl
    # 
    # #   Client Authentication (Type):
    # #   Client certificate verification type and depth.  Types are
    # #   none, optional, require and optional_no_ca.  Depth is a
    # #   number which specifies how deeply to verify the certificate
    # #   issuer chain before deciding the certificate is not valid.
    # #SSLVerifyClient require
    # #SSLVerifyDepth  10
    # 
    # #   Access Control:
    # #   With SSLRequire you can do per-directory access control based
    # #   on arbitrary complex boolean expressions containing server
    # #   variable checks and other lookup directives.  The syntax is a
    # #   mixture between C and Perl.  See the mod_ssl documentation
    # #   for more details.
    # #<Location />
    # #SSLRequire (    %{SSL_CIPHER} !~ m/^(EXP|NULL)/ \
    # #            and %{SSL_CLIENT_S_DN_O} eq "Snake Oil, Ltd." \
    # #            and %{SSL_CLIENT_S_DN_OU} in {"Staff", "CA", "Dev"} \
    # #            and %{TIME_WDAY} >= 1 and %{TIME_WDAY} <= 5 \
    # #            and %{TIME_HOUR} >= 8 and %{TIME_HOUR} <= 20       ) \
    # #           or %{REMOTE_ADDR} =~ m/^192\.76\.162\.[0-9]+$/
    # #</Location>
    # 
    # #   SSL Engine Options:
    # #   Set various options for the SSL engine.
    # #   o FakeBasicAuth:
    # #     Translate the client X.509 into a Basic Authorisation.  This means that
    # #     the standard Auth/DBMAuth methods can be used for access control.  The
    # #     user name is the `one line' version of the client's X.509 certificate.
    # #     Note that no password is obtained from the user. Every entry in the user
    # #     file needs this password: `xxj31ZMTZzkVA'.
    # #   o ExportCertData:
    # #     This exports two additional environment variables: SSL_CLIENT_CERT and
    # #     SSL_SERVER_CERT. These contain the PEM-encoded certificates of the
    # #     server (always existing) and the client (only existing when client
    # #     authentication is used). This can be used to import the certificates
    # #     into CGI scripts.
    # #   o StdEnvVars:
    # #     This exports the standard SSL/TLS related `SSL_*' environment variables.
    # #     Per default this exportation is switched off for performance reasons,
    # #     because the extraction step is an expensive operation and is usually
    # #     useless for serving static content. So one usually enables the
    # #     exportation for CGI and SSI requests only.
    # #   o StrictRequire:
    # #     This denies access when "SSLRequireSSL" or "SSLRequire" applied even
    # #     under a "Satisfy any" situation, i.e. when it applies access is denied
    # #     and no other module can change it.
    # #   o OptRenegotiate:
    # #     This enables optimized SSL connection renegotiation handling when SSL
    # #     directives are used in per-directory context. 
    # #SSLOptions +FakeBasicAuth +ExportCertData +StrictRequire
    # <FilesMatch "\.(cgi|shtml|phtml|php)$">
    #     SSLOptions +StdEnvVars
    # </FilesMatch>
    # <Directory "C:/PROGRA~1/EASYPH~1.0B1/cgi-bin">
    #     SSLOptions +StdEnvVars
    # </Directory>
    # 
    # #   SSL Protocol Adjustments:
    # #   The safe and default but still SSL/TLS standard compliant shutdown
    # #   approach is that mod_ssl sends the close notify alert but doesn't wait for
    # #   the close notify alert from client. When you need a different shutdown
    # #   approach you can use one of the following variables:
    # #   o ssl-unclean-shutdown:
    # #     This forces an unclean shutdown when the connection is closed, i.e. no
    # #     SSL close notify alert is send or allowed to received.  This violates
    # #     the SSL/TLS standard but is needed for some brain-dead browsers. Use
    # #     this when you receive I/O errors because of the standard approach where
    # #     mod_ssl sends the close notify alert.
    # #   o ssl-accurate-shutdown:
    # #     This forces an accurate shutdown when the connection is closed, i.e. a
    # #     SSL close notify alert is send and mod_ssl waits for the close notify
    # #     alert of the client. This is 100% SSL/TLS standard compliant, but in
    # #     practice often causes hanging connections with brain-dead browsers. Use
    # #     this only for browsers where you know that their SSL implementation
    # #     works correctly. 
    # #   Notice: Most problems of broken clients are also related to the HTTP
    # #   keep-alive facility, so you usually additionally want to disable
    # #   keep-alive for those clients, too. Use variable "nokeepalive" for this.
    # #   Similarly, one has to force some clients to use HTTP/1.0 to workaround
    # #   their broken HTTP/1.1 implementation. Use variables "downgrade-1.0" and
    # #   "force-response-1.0" for this.
    # BrowserMatch ".*MSIE.*" \
    #          nokeepalive ssl-unclean-shutdown \
    #          downgrade-1.0 force-response-1.0
    # 
    # #   Per-Server Logging:
    # #   The home of a custom SSL log file. Use this when you want a
    # #   compact non-error SSL logfile on a virtual host basis.
    # CustomLog C:/PROGRA~1/EASYPH~1.0B1/apache/logs/ssl_request_log \
    #           "%t %h %{SSL_PROTOCOL}x %{SSL_CIPHER}x \"%r\" %b"
    # 
    # </VirtualHost>  
    # ============================================================================
     
     
    # Supplemental configuration
    #
    # The configuration files in the conf/extra/ directory can be 
    # included to add extra features or to modify the default configuration of 
    # the server, or you may simply copy their contents here and change as 
    # necessary.
     
    # Server-pool management (MPM specific)
    #Include conf/extra/httpd-mpm.conf
     
    # Language settings
    #Include conf/extra/httpd-languages.conf
     
    # User home directories
    #Include conf/extra/httpd-userdir.conf
     
    # Real-time info on requests and configuration
    #Include conf/extra/httpd-info.conf
     
    # Virtual hosts
    #Include conf/extra/httpd-vhosts.conf
     
    # Various default settings
    #Include conf/extra/httpd-default.conf
     
    #
    # Note: The following must must be present to support
    #       starting without SSL on platforms with no /dev/random equivalent
    #       but a statically compiled-in mod_ssl.
    #
    <IfModule ssl_module>
    SSLRandomSeed startup builtin
    SSLRandomSeed connect builtin
    </IfModule>

  6. #6
    Membre à l'essai
    Profil pro
    Inscrit en
    Juin 2007
    Messages
    36
    Détails du profil
    Informations personnelles :
    Localisation : France

    Informations forums :
    Inscription : Juin 2007
    Messages : 36
    Points : 23
    Points
    23
    Par défaut
    ServerName localhost:443 c'est pas bon ?

  7. #7
    Membre à l'essai
    Profil pro
    Inscrit en
    Juin 2007
    Messages
    36
    Détails du profil
    Informations personnelles :
    Localisation : France

    Informations forums :
    Inscription : Juin 2007
    Messages : 36
    Points : 23
    Points
    23
    Par défaut
    j'ai également un autre log peut etre plus precis :

    Code : Sélectionner tout - Visualiser dans une fenêtre à part
    1
    2
    3
    4
    5
    6
    7
    8
    9
    10
    11
    12
    13
    14
    [Tue May 13 22:06:57 2008] [info] Loading certificate & private key of SSL-aware server
    [Tue May 13 22:06:57 2008] [debug] ssl_engine_pphrase.c(469): unencrypted RSA private key - pass phrase not required
    [Tue May 13 22:06:57 2008] [info] Configuring server for SSL protocol
    [Tue May 13 22:06:57 2008] [debug] ssl_engine_init.c(405): Creating new SSL context (protocols: SSLv2, SSLv3, TLSv1)
    [Tue May 13 22:06:57 2008] [debug] ssl_engine_init.c(729): Configuring RSA server certificate
    [Tue May 13 22:06:57 2008] [warn] RSA server certificate CommonName (CN) `projet' does NOT match server name!?
    [Tue May 13 22:06:57 2008] [debug] ssl_engine_init.c(768): Configuring RSA server private key
    [Tue May 13 22:06:57 2008] [info] Loading certificate & private key of SSL-aware server
    [Tue May 13 22:06:57 2008] [debug] ssl_engine_pphrase.c(469): unencrypted RSA private key - pass phrase not required
    [Tue May 13 22:06:58 2008] [info] Configuring server for SSL protocol
    [Tue May 13 22:06:58 2008] [debug] ssl_engine_init.c(405): Creating new SSL context (protocols: SSLv2, SSLv3, TLSv1)
    [Tue May 13 22:06:58 2008] [debug] ssl_engine_init.c(729): Configuring RSA server certificate
    [Tue May 13 22:06:58 2008] [warn] RSA server certificate CommonName (CN) `projet' does NOT match server name!?
    [Tue May 13 22:06:58 2008] [debug] ssl_engine_init.c(768): Configuring RSA server private key

  8. #8
    Rédacteur
    Avatar de _Mac_
    Profil pro
    Inscrit en
    Août 2005
    Messages
    9 601
    Détails du profil
    Informations personnelles :
    Localisation : France

    Informations forums :
    Inscription : Août 2005
    Messages : 9 601
    Points : 12 977
    Points
    12 977
    Par défaut
    Citation Envoyé par Antho13 Voir le message
    ServerName localhost:443 c'est pas bon ?
    A ton avis, si je dis que ce n'est pas correct ?
    Code : Sélectionner tout - Visualiser dans une fenêtre à part
    1
    2
    ServerName localhost
    Port 443
    Sinon, y a une trace intéressante dans ta dernière log :
    [Tue May 13 22:06:58 2008] [warn] RSA server certificate CommonName (CN) `projet' does NOT match server name!?
    Mais je ne sais pas si c'est suffisant pour faire planter Apache.

  9. #9
    Membre à l'essai
    Profil pro
    Inscrit en
    Juin 2007
    Messages
    36
    Détails du profil
    Informations personnelles :
    Localisation : France

    Informations forums :
    Inscription : Juin 2007
    Messages : 36
    Points : 23
    Points
    23
    Par défaut
    Préciser le numéro du port me retourne une erreur de syntaxe au moment du lancement d'apache.

    le code de base pour le servername est bien celui que je t'ai envoyé dans mon précédent message.

    Je n'arrive toujours pas à le faire fonctionner. je désespère

  10. #10
    Membre à l'essai
    Profil pro
    Inscrit en
    Juin 2007
    Messages
    36
    Détails du profil
    Informations personnelles :
    Localisation : France

    Informations forums :
    Inscription : Juin 2007
    Messages : 36
    Points : 23
    Points
    23
    Par défaut
    J'ai réussi à enlever l'erreur du Nom de domaine (en mettant localhost lors de la création du certificat).

    Je n'arrive pas à résoudre cette erreur par contre:

    Code : Sélectionner tout - Visualiser dans une fenêtre à part
    1
    2
    3
    4
    5
    6
    7
    8
    9
    10
    11
    12
    13
    14
    15
    16
    [Wed May 14 22:09:37 2008] [info] Loading certificate & private key of SSL-aware server
    [Wed May 14 22:09:37 2008] [debug] ssl_engine_pphrase.c(469): unencrypted RSA private key - pass phrase not required
    [Wed May 14 22:09:37 2008] [info] Configuring server for SSL protocol
    [Wed May 14 22:09:37 2008] [debug] ssl_engine_init.c(405): Creating new SSL context (protocols: SSLv2, SSLv3, TLSv1)
    [Wed May 14 22:09:37 2008] [debug] ssl_engine_init.c(729): Configuring RSA server certificate
    [Wed May 14 22:09:37 2008] [debug] ssl_engine_init.c(768): Configuring RSA server private key
    [Wed May 14 22:09:38 2008] [info] Loading certificate & private key of SSL-aware server
    [Wed May 14 22:09:38 2008] [debug] ssl_engine_pphrase.c(469): unencrypted RSA private key - pass phrase not required
    [Wed May 14 22:09:38 2008] [info] Configuring server for SSL protocol
    [Wed May 14 22:09:38 2008] [debug] ssl_engine_init.c(405): Creating new SSL context (protocols: SSLv2, SSLv3, TLSv1)
    [Wed May 14 22:09:38 2008] [debug] ssl_engine_init.c(729): Configuring RSA server certificate
    [Wed May 14 22:09:38 2008] [debug] ssl_engine_init.c(768): Configuring RSA server private key
    [Wed May 14 22:09:38 2008] [error] Unable to import RSA server private key
    [Wed May 14 22:09:38 2008] [error] SSL Library Error: 218529960 error:0D0680A8:asn1 encoding routines:ASN1_CHECK_TLEN:wrong tag
    [Wed May 14 22:09:38 2008] [error] SSL Library Error: 218595386 error:0D07803A:asn1 encoding routines:ASN1_ITEM_EX_D2I:nested asn1 error
    [Wed May 14 22:09:38 2008] [error] SSL Library Error: 218734605 error:0D09A00D:asn1 encoding routines:d2i_PrivateKey:ASN1 lib

    pass phrase not required ? peut être ça vient de là ? mais elle est exigée lors de la création de la clé. help svp

  11. #11
    Rédacteur
    Avatar de _Mac_
    Profil pro
    Inscrit en
    Août 2005
    Messages
    9 601
    Détails du profil
    Informations personnelles :
    Localisation : France

    Informations forums :
    Inscription : Août 2005
    Messages : 9 601
    Points : 12 977
    Points
    12 977
    Par défaut
    Je ne suis pas sûr que ce soit ça le problème. Je comprends la phrase comme disant que le fichier dans lequel se trouve la clé privée peut être ouvert sans mot de passe, mais je peux me tromper. Je pense que dans l'absolu on peut négliger ce message car c'est juste un avertissement de debug.

    En revanche, ce qui est plus gênant, ce sont les 3 derniers messages error. Fais une recherche sur Google avec le premier message : y a un truc intéressant qui dit qu'il ne faut pas confondre le certificat request (csr) et le certificat (crt). Donc si tu as indiqué à Apache le csr à la place du crt, tu as ce genre de message.

  12. #12
    Membre à l'essai
    Profil pro
    Inscrit en
    Juin 2007
    Messages
    36
    Détails du profil
    Informations personnelles :
    Localisation : France

    Informations forums :
    Inscription : Juin 2007
    Messages : 36
    Points : 23
    Points
    23
    Par défaut
    bon jm'en suis sorti en reprenant tout à zero avec wamp2.

    easy php présente apparemment de gros problemes avec ce genre d'operations...

    ça fonctionne maitnenant

    merci de ton aide

+ Répondre à la discussion
Cette discussion est résolue.

Discussions similaires

  1. probleme mod_jk avec apache
    Par fmorin dans le forum Apache
    Réponses: 1
    Dernier message: 10/10/2011, 10h47
  2. probleme avec apache sous webdev
    Par tirisus dans le forum WebDev
    Réponses: 2
    Dernier message: 28/09/2006, 08h13
  3. probleme d afichage avec apache sous linux .
    Par johnnyaque dans le forum Apache
    Réponses: 1
    Dernier message: 05/09/2006, 21h36
  4. Problème de droits avec Apache
    Par sebeni dans le forum Réseau
    Réponses: 3
    Dernier message: 05/04/2006, 11h05
  5. Réponses: 15
    Dernier message: 15/11/2005, 18h33

Partager

Partager
  • Envoyer la discussion sur Viadeo
  • Envoyer la discussion sur Twitter
  • Envoyer la discussion sur Google
  • Envoyer la discussion sur Facebook
  • Envoyer la discussion sur Digg
  • Envoyer la discussion sur Delicious
  • Envoyer la discussion sur MySpace
  • Envoyer la discussion sur Yahoo