LinuxQuestions.org
Help answer threads with 0 replies.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Server
User Name
Password
Linux - Server This forum is for the discussion of Linux Software used in a server related context.

Notices


Reply
  Search this Thread
Old 02-17-2010, 11:51 PM   #1
sleepyz
LQ Newbie
 
Registered: Jul 2008
Location: US
Distribution: Linux version 2.6.29.1-desktop586-4mnb (herton@n2.mandriva.com) (gcc version 4.3.2 (GCC) )
Posts: 20

Rep: Reputation: 0
Can SSL Certificates be the same


I have a Server with Webmin, Usermin and Sendmail using pop3s. I have created a seft signed certificate using webmin. Exported it and imported it to the trusted root certification authorities on my client. This fixes the warning message from internet explorer when attempting making a ssl connection to webmin. When attempting to use usermin or retrieving mail I get that warning that this site's certificate is self signed. I look at the certificate and its not the same as the one I created with webmin. My question is. Is possible to have the same certificate be used by each?
 
Old 02-18-2010, 04:03 AM   #2
acid_kewpie
Moderator
 
Registered: Jun 2001
Location: UK
Distribution: Gentoo, RHEL, Fedora, Centos
Posts: 43,417

Rep: Reputation: 1985Reputation: 1985Reputation: 1985Reputation: 1985Reputation: 1985Reputation: 1985Reputation: 1985Reputation: 1985Reputation: 1985Reputation: 1985Reputation: 1985
Yeah, that's fine, it's the hostname that needs to match the certificate, so using over pop3s, https etc, it doesn't make any difference, as long as the cert is a proper server certificate like yours certainly appears to be.
 
Old 02-19-2010, 12:05 AM   #3
sleepyz
LQ Newbie
 
Registered: Jul 2008
Location: US
Distribution: Linux version 2.6.29.1-desktop586-4mnb (herton@n2.mandriva.com) (gcc version 4.3.2 (GCC) )
Posts: 20

Original Poster
Rep: Reputation: 0
Thanks for you response and you're right about the hostname because I noticed that using www.hostname.com works and hostname.com doesn't. I guest I should have created the cert with a wildcard (ie *.hostname.com) but that's another matter I'll look into.

I also discovered that webmin uses the cert located in /etc/webmin/miniserv.pem and usemin uses a cert located in /etc/usermin/miniserv.pem
I initialy re-configured usermin to use the webmin cert but changed it back and copied /etc/webmin/miniserv.pem to /etc/usermin/miniserv.pem to keep the default usermin ssl configuration.

So I have one cert on my client and my client can now connect and access webmin and usermin with out any warnings about certificates. But I still get the warning when using Outlook to check mail on my sendmail server using pop3s .. So the million dollar question is where does pop3s daemon look for its certificate?
 
Old 02-19-2010, 03:45 AM   #4
acid_kewpie
Moderator
 
Registered: Jun 2001
Location: UK
Distribution: Gentoo, RHEL, Fedora, Centos
Posts: 43,417

Rep: Reputation: 1985Reputation: 1985Reputation: 1985Reputation: 1985Reputation: 1985Reputation: 1985Reputation: 1985Reputation: 1985Reputation: 1985Reputation: 1985Reputation: 1985
Depends what pop3 service it is. dovecot? courier? cyrus? wu?
 
Old 02-19-2010, 09:31 AM   #5
sleepyz
LQ Newbie
 
Registered: Jul 2008
Location: US
Distribution: Linux version 2.6.29.1-desktop586-4mnb (herton@n2.mandriva.com) (gcc version 4.3.2 (GCC) )
Posts: 20

Original Poster
Rep: Reputation: 0
Im using wu I believe. I installed imap.rpm from University of Washington which includes pop3s along with other mail protocols

Last edited by sleepyz; 02-19-2010 at 09:33 AM.
 
Old 02-19-2010, 09:34 AM   #6
acid_kewpie
Moderator
 
Registered: Jun 2001
Location: UK
Distribution: Gentoo, RHEL, Fedora, Centos
Posts: 43,417

Rep: Reputation: 1985Reputation: 1985Reputation: 1985Reputation: 1985Reputation: 1985Reputation: 1985Reputation: 1985Reputation: 1985Reputation: 1985Reputation: 1985Reputation: 1985
Hmm, well wu has a pretty poor reputation, and I'm not familiar with it's config any more. I'd recommend dovecot personally, which also has a very clear config file to point to the certificate and CA certs.
 
Old 02-19-2010, 10:52 AM   #7
sleepyz
LQ Newbie
 
Registered: Jul 2008
Location: US
Distribution: Linux version 2.6.29.1-desktop586-4mnb (herton@n2.mandriva.com) (gcc version 4.3.2 (GCC) )
Posts: 20

Original Poster
Rep: Reputation: 0
Thanks, I believe I figured it out. The certiticate is stored in /etc/ssl/imap folder. Because this server is mail.hostname.com and not www.hostname.com as you mentioned before about hostnames; I created another cert by using openssl reg -new -x509 -nodes -out ipop3sd.pem -keyout ipop3sd.pem -days 3650

Thanks for you help again
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
SSL Certificates irvinew31 SUSE / openSUSE 2 10-03-2006 10:27 AM
SSL Certificates SBN Linux - Security 1 09-30-2006 03:29 AM
SSL Certificates ashiers Linux - Security 2 06-30-2006 08:39 AM
ssl certificates champ Linux - Security 2 04-05-2003 09:47 AM
ssl certificates Syncrm Linux - General 7 02-26-2003 10:01 AM

LinuxQuestions.org > Forums > Linux Forums > Linux - Server

All times are GMT -5. The time now is 07:08 AM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration