From users-return-120045-apmail-httpd-users-archive=httpd.apache.org@httpd.apache.org Thu Nov 12 10:59:43 2020 Return-Path: X-Original-To: apmail-httpd-users-archive@www.apache.org Delivered-To: apmail-httpd-users-archive@www.apache.org Received: from mxout1-ec2-va.apache.org (mxout1-ec2-va.apache.org [3.227.148.255]) by minotaur.apache.org (Postfix) with ESMTP id 4FD471A20A for ; Thu, 12 Nov 2020 10:59:43 +0000 (UTC) Received: from mail.apache.org (mailroute1-lw-us.apache.org [207.244.88.153]) by mxout1-ec2-va.apache.org (ASF Mail Server at mxout1-ec2-va.apache.org) with SMTP id 0954A49DD3 for ; Thu, 12 Nov 2020 10:59:43 +0000 (UTC) Received: (qmail 68132 invoked by uid 500); 12 Nov 2020 10:59:36 -0000 Delivered-To: apmail-httpd-users-archive@httpd.apache.org Received: (qmail 68096 invoked by uid 500); 12 Nov 2020 10:59:36 -0000 Mailing-List: contact users-help@httpd.apache.org; run by ezmlm Precedence: bulk Reply-To: users@httpd.apache.org list-help: list-unsubscribe: List-Post: List-Id: Delivered-To: mailing list users@httpd.apache.org Received: (qmail 68086 invoked by uid 99); 12 Nov 2020 10:59:35 -0000 Received: from spamproc1-he-fi.apache.org (HELO spamproc1-he-fi.apache.org) (95.217.134.168) by apache.org (qpsmtpd/0.29) with ESMTP; Thu, 12 Nov 2020 10:59:35 +0000 Received: from localhost (localhost [127.0.0.1]) by spamproc1-he-fi.apache.org (ASF Mail Server at spamproc1-he-fi.apache.org) with ESMTP id F3268BFD6E for ; Thu, 12 Nov 2020 10:59:34 +0000 (UTC) X-Virus-Scanned: Debian amavisd-new at spamproc1-he-fi.apache.org X-Spam-Flag: NO X-Spam-Score: 2.363 X-Spam-Level: ** X-Spam-Status: No, score=2.363 tagged_above=-999 required=6.31 tests=[DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, FREEMAIL_ENVFROM_END_DIGIT=0.25, KAM_ASCII_DIVIDERS=0.8, KAM_MXURI=1.5, RCVD_IN_MSPIKE_H3=0.001, RCVD_IN_MSPIKE_WL=0.001, SPF_PASS=-0.001, T_FILL_THIS_FORM_SHORT=0.01, URIBL_BLOCKED=0.001, WEIRD_PORT=0.001] autolearn=disabled Authentication-Results: spamproc1-he-fi.apache.org (amavisd-new); dkim=pass (2048-bit key) header.d=gmail.com Received: from mx1-ec2-va.apache.org ([116.203.227.195]) by localhost (spamproc1-he-fi.apache.org [95.217.134.168]) (amavisd-new, port 10024) with ESMTP id xHlPbW-G_1Tf for ; Thu, 12 Nov 2020 10:59:33 +0000 (UTC) Received-SPF: Pass (mailfrom) identity=mailfrom; client-ip=209.85.218.41; helo=mail-ej1-f41.google.com; envelope-from=teoenming.nov2020@gmail.com; receiver= Received: from mail-ej1-f41.google.com (mail-ej1-f41.google.com [209.85.218.41]) by mx1-ec2-va.apache.org (ASF Mail Server at mx1-ec2-va.apache.org) with ESMTPS id A1CEFBC634 for ; Thu, 12 Nov 2020 10:59:32 +0000 (UTC) Received: by mail-ej1-f41.google.com with SMTP id o9so7093117ejg.1 for ; Thu, 12 Nov 2020 02:59:32 -0800 (PST) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20161025; h=mime-version:from:date:message-id:subject:to:cc; bh=1/GkmQ6+qLm6C1dI6NmbCn0bwmcPrW5r1Ie3XFuHT4A=; b=Hhokf2t1aiT/DkWSBvnDaFOHlPuOUd4TIAnKEeky2v5CRhLN4Hi2SoPIC36CkIp2HN DcjkutYuNGybN902TUZgJon89tCrdZUnlG3U0uA5wbD88X81E2F6QwE8UjhlLtiSkbvV 4Bb/ob7so2z0Oc0Iu99GZac3GbYV7KIDmlzG0NpZ+aWBw+6lLTV5XWm16+LBMwzlyO7B vVG4rGGU7sQ+Bf79ZHpxxRSVO0X3ZQWtKkbVn+Eo2yGx6R1u4tr13pYAr6NnW7OjjuAk Im1k949FhBItwgp+I8uwXOXIQHV644Faao4x/kPv40TMs2c/SW9l+tPrOzJDnOxcXthc hgAA== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20161025; h=x-gm-message-state:mime-version:from:date:message-id:subject:to:cc; bh=1/GkmQ6+qLm6C1dI6NmbCn0bwmcPrW5r1Ie3XFuHT4A=; b=fpBVEU7z3Xb8gB3rOeC7B25TFTE9ADsqNzfoIGsNExzSH+M2KiBpO44wRKuuvySHkU 75J4BuHBe3XIbveWhzOxyFHCGRW2mNP2QQ+PW4heQwje2BkNGNYp2inYDFTM/vHIt3QE wRsXXlzlW4NwEXyFfl4kVjVx7xLhQM7vzeytj5ACelHekxJIxWitYK6RRjHxE7W6/MMp ZJkTyxmFFwOJxoUpTqIS/cxGQFzaGhLZCESrytWsiaumF4nA0jfT4wff0KOrX5GeIuXZ 4n9iOsJmBJboMKtjcVwdEw9G6HZYmrUHY9TPM+udELLIvwxNO4dIoQQ9EEq+uRVSXYp9 gPSg== X-Gm-Message-State: AOAM532TWGW9IeL1+L0VjJmlonRfNjw2Ex5YApD0enz+FB60gSZeW4Rc 5oaN3moZ12VRe9KG4nNPbujkWRCw4m9XYtGfDQsASbRAW6vkAPZ97v0= X-Google-Smtp-Source: ABdhPJysSSi573jvmf3AuTHZWlxApjCoUbKJ1vEo4coVAw89JlMBjLYEfdeqmEDG+tysTguNfDj6fnYUQ/amlUSNFmc= X-Received: by 2002:a17:906:4748:: with SMTP id j8mr28247984ejs.22.1605178766043; Thu, 12 Nov 2020 02:59:26 -0800 (PST) MIME-Version: 1.0 From: Turritopsis Dohrnii Teo En Ming Date: Thu, 12 Nov 2020 19:00:03 +0800 Message-ID: To: users@httpd.apache.org Cc: ceo@teo-en-ming-corp.com Content-Type: text/plain; charset="UTF-8" Subject: [users@httpd] Guide on Renewing SSL Certificate for Apache, Postfix and Dovecot on CentOS 6.8 Linux Guide on Renewing SSL Certificate for Apache, Postfix and Dovecot on CentOS 6.8 Linux ===================================================================================== Author: Mr. Turritopsis Dohrnii Teo En Ming (TARGETED INDIVIDUAL) Country: Singapore Date: 12 November 2020 Thursday Singapore Time Type of Publication: Plain Text Document Version: 20201112.01 Generating Certificate Signing Request (CSR) Using OpenSSL command on Linux =========================================================================== Reference Guide: Generating CSR on Apache + OpenSSL/ModSSL/Nginx + Heroku Link: https://www.namecheap.com/support/knowledgebase/article.aspx/9446/14/generating-csr-on-apache--opensslmodsslnginx--heroku/#4 # cd /root # which openssl # openssl req -new -newkey rsa:2048 -nodes -keyout teo-en-ming-corp.key -out teo-en-ming-corp.csr Generating a 2048 bit RSA private key ...............................................................................................................................................................................+++ ........................................................................+++ writing new private key to 'teo-en-ming-corp.key' ----- You are about to be asked to enter information that will be incorporated into your certificate request. What you are about to enter is what is called a Distinguished Name or a DN. There are quite a few fields but you can leave some blank For some fields there will be a default value, If you enter '.', the field will be left blank. ----- Country Name (2 letter code) [XX]:SG State or Province Name (full name) []:Singapore Locality Name (eg, city) [Default City]:Singapore Organization Name (eg, company) [Default Company Ltd]:Teo En Ming Corporation Organizational Unit Name (eg, section) []:IT Department Common Name (eg, your name or your server's hostname) []:*.teo-en-ming-corp.com.sg (USE WILDCARD!!!) Email Address []:ceo@teo-en-ming-corp.com Please enter the following 'extra' attributes to be sent with your certificate request A challenge password []: An optional company name []: # mkdir teo-en-ming # mv teo-en-ming-corp.csr teo-en-ming-corp.key teo-en-ming/ # cd teo-en-ming [root@mail.teo-en-ming-corp.com.sg teo-en-ming]# ls -al total 16 drwxr-xr-x 2 root root 4096 Nov 11 11:43 . dr-xr-x---. 14 root root 4096 Nov 11 11:43 .. -rw-r--r-- 1 root root 1119 Nov 11 11:42 teo-en-ming-corp.csr -rw-r--r-- 1 root root 1708 Nov 11 11:42 teo-en-ming-corp.key # cat teo-en-ming-corp.csr (Display Certificate Signing Request) -----BEGIN CERTIFICATE REQUEST----- -----END CERTIFICATE REQUEST----- # cat teo-en-ming-corp.key (Display Private/Secret Key) -----BEGIN PRIVATE KEY----- -----END PRIVATE KEY----- Result from AlphaSSL Portal ============================ Congratulations! Your order has been placed successfully. Your order number is : You'll need to copy the following Domain Verification Code and place it in a text file called "gsdv.txt" which you'll then need to put in one of the approved locations Meta Tag : http://teo-en-ming-corp.com.sg/.well-known/pki-validation/gsdv.txt https://teo-en-ming-corp.com.sg/.well-known/pki-validation/gsdv.txt To complete the URL Verification, close the browser. Open the SSL Configuration Link in new browser and click on "Complete Url Verification". End of Result from AlphaSSL Portal ================================== Domain Verification for SSL Certificate ======================================= # cd /home/teo-en-ming-corp/public_html # mkdir .well-known # cd .well-known # mkdir pki-validation # cd pki-validation/ Edit gsdv.txt. # nano gsdv.txt Begin Email from AlphaSSL ========================= Email Subject: : Your SSL Certificate for *.teo-en-ming-corp.com.sg has been issued ------------------------------------------------------------------------------- Please note that this email is automatically sent from a noreply mailbox. To contact AlphaSSL please use the Contact Details at the footer of this email. ------------------------------------------------------------------------------- Dear Turritopsis Dohrnii Teo En Ming, Your AlphaSSL Certificate has now been issued and is ready to be installed. Your SSL Certificate can be found at the bottom of this email. CERTIFICATE DETAILS -------------------------------------------------- Order Number: Common Name: *.teo-en-ming-corp.com.sg INSTALLING YOUR CERTIFICATE ---------------------------------------------------- Your SSL Certificate and Intermediate Certificate must be installed on your server. Please note that as of March 31st 2014, SHA-256 will become the default hashing algorithm used unless SHA-1 was selected during the ordering process. You can find guides on installing your certificate with the Support Center online at: http://www.alphassl.com/support QUICK INSTALLATION GUIDE ---------------------------------------------------- 1) Using a text editor, copy the SSL Certificate text from the bottom of this email (including the -----BEGIN CERTIFICATE----- and -----END CERTIFICATE----- lines) and save it to a file such as yourdomain.txt 2) Retrieve the Intermediate Certificate (selecting SHA-1 or SHA-256 as appropriate) from the Support Center at: https://www.alphassl.com/support/install-root-certificate.html 3) Using a text editor, copy the Intermediate Certificate text (including the ----BEGIN CERTIFICATE----- and -----END CERTIFICATE----- lines) and save it to a file such as intermediate_domain_ca.txt 4) Copy these .txt files to your server and then rename them with .crt extensions 5) Install the Intermediate and SSL Certificates 6) Restart your server 7) To test for installation errors please use our SSL Configuration Checker located at https://sslcheck.globalsign.com/en_US 8) Install your Site Seal with the instructions show at: http://www.alphassl.com/support/ssl-site-seal.html 9) We suggest you back-up your SSL Certificate and Private Key pair and keep it safe, all IIS users can use the Export Wizard We hope that your application process was quick and easy and you have enjoyed the AlphaSSL experience. Thank you for choosing AlphaSSL, if you have any questions or issues please do not hesitate to contact us. CONTACT US -------------------------------------------------- For Sales, Technical Support & Account Queries: W: http://www.alphassl.com/support E: support@alphassl.com T: US Toll Free: 877 SSLALPHA (+1 877 775 2574) | Fax: 720 528 8160 T: EU: +44 1622 766 700 | Fax: +44 1622 662 255 --------------------------------------------------- LOW COST. TRUSTED BY ALL BROWSERS. SSL MADE EASY. --------------------------------------------------- YOUR SSL CERTIFICATE -------------------------------------------------- (Formatted for the majority of web server software including IIS and Apache based servers): -----BEGIN CERTIFICATE----- -----END CERTIFICATE----- End of Email from AlphaSSL =========================== # cd /root/teo-en-ming # nano teo-en-ming-corp.crt (Saving the SSL Certificate/Public Key) -----BEGIN CERTIFICATE----- -----END CERTIFICATE----- # nano intermediate_domain_ca.crt (Saving the intermediate CA certificate) -----BEGIN CERTIFICATE----- -----END CERTIFICATE----- Installing SSL Certificate on Postfix SMTP Server ================================================= Backup the Postfix configuration files first before you modify anything. # cd /etc/postfix # cp main.cf main.teoenming # cp master.cf master.teoenming Reference Guide: Installing and configuring SSL on Postfix/Dovecot mail server Link: https://www.namecheap.com/support/knowledgebase/article.aspx/9795/69/installing-and-configuring-ssl-on-postfixdovecot-mail-server Copy the public and private key over from /root/teo-en-ming to /etc/postfix. # cd /root/teo-en-ming/ # cp * /etc/postfix # cd /etc/postfix Edit the Postfix configuration file. # nano main.cf smtpd_tls_cert_file = /etc/postfix/teo-en-ming-corp.crt smtpd_tls_key_file = /etc/postfix/teo-en-ming-corp.key smtpd_tls_CAfile = /etc/postfix/intermedia_domain_ca.crt ***Please note that the previous IT support company did not enable SSL/TLS for SMTP Server.*** Restart the Postfix SMTP Server. # service postfix restart Installing SSL Certificate on Dovecot IMAP and POP3 Incoming Mail Server ========================================================================= Backup the auxiliary Dovecot configuration file first before you modify anything. # cd /etc/dovecot/conf.d # cp 10-ssl.conf 10-ssl.teoenming Begin Redundant/Useless Section =============================== Please do not follow the instructions in this section. # cd /etc/pki/dovecot/certs # cp /root/teo-en-ming/teo-en-ming-corp.crt . # cd /etc/pki/dovecot/private/ # cp /root/teo-en-ming/teo-en-ming-corp.key . # cd /etc/dovecot/conf.d Edit 10-ssl.conf. # nano 10-ssl.conf ssl_cert = You can also configure SSL Certificate using Webmin. I will publish a guide on this in the future. Also, 16 screenshots will be published in the future. End of Guide ============ -----BEGIN EMAIL SIGNATURE----- The Gospel for all Targeted Individuals (TIs): [The New York Times] Microwave Weapons Are Prime Suspect in Ills of U.S. Embassy Workers Link: https://www.nytimes.com/2018/09/01/science/sonic-attack-cuba-microwave.html ******************************************************************************************** Singaporean Targeted Individual Mr. Turritopsis Dohrnii Teo En Ming's Academic Qualifications as at 14 Feb 2019 and refugee seeking attempts at the United Nations Refugee Agency Bangkok (21 Mar 2017), in Taiwan (5 Aug 2019) and Australia (25 Dec 2019 to 9 Jan 2020): [1] https://tdtemcerts.wordpress.com/ [2] https://tdtemcerts.blogspot.sg/ [3] https://www.scribd.com/user/270125049/Teo-En-Ming -----END EMAIL SIGNATURE----- --------------------------------------------------------------------- To unsubscribe, e-mail: users-unsubscribe@httpd.apache.org For additional commands, e-mail: users-help@httpd.apache.org