How to verify SSL cert from command line
When I need to verify an SSL certificate and the corresponding CA intermediate certs a good tool is openssl like this:
|
1 |
openssl verify -CAfile cabundle.crt www.domain.com.crt |
When I need to verify an SSL certificate and the corresponding CA intermediate certs a good tool is openssl like this:
|
1 |
openssl verify -CAfile cabundle.crt www.domain.com.crt |
Here’s a single command to generate a new key and CSR:
|
1 |
openssl req -nodes -newkey rsa:2048 -keyout mydomain.key -out mydomain.csr |
Need to redirect from acme.com to www.acme.com with nginx? No problem … just add a virtual host declaration for the non-www that redirects like this:
|
1 2 3 4 5 6 |
server { listen 80; server_name acme.com; rewrite ^/(.*) http://www.acme.com/$1 permanent; } |
or if you want to add to an existing vhost:
|
1 2 3 |
if ( $host != 'www.domain.com' ) { rewrite ^/(.*)$ http://www.domain.com/$1 permanent; } |
Here’s a good rule set for forcing use of a preferred url:
|
1 2 3 |
RewriteCond %{HTTP_HOST} !^desired\.domain\.name(:.*)?$ [NC] RewriteCond %{HTTP_HOST} !^$ RewriteRule ^/?(.*) http://desired.domain.name/$1 [L,R=301] |
This version of the canonical rewrite expands on the original found here: http://httpd.apache.org/docs/2.2/rewrite/rewrite_guide.html#canonicalhost by adding: redirects domains with suffixes (not just prefixes) back to the canonical host; and allows Host request headers to contain port specifiers (which is allowed by RFC2616 section 14.24) as suggested here: http://colby.id.au/node/99 and by using a 301 redirect as recommended by Google here: http://www.google.com/support/webmasters/bin/answer.py?answer=44231&hl=en
Problem was that uploaded files were being assigned permissions of 0600 which is “-rw——-“. The webserver was then unable to service the files. The “0600” permissions corresponds to a umask of “066”. Instead I wanted “022” which would yield “-rw-rw-r–” or “0664”. On Ubuntu, edit /etc/apache2/envvars and add this line to the end of the file:
|
1 |
umask 022 |
On Red Hat/CentOS do this:
|
1 |
echo "umask 002" >> /etc/sysconfig/httpd |
Now restart Apache and the new umask will be in effect.
Reliable Penguin provides managed web hosting, systems administration, website and server migrations, and expert consulting.
Submit the form—or for immediate service call 866-649-7984.