LinuxQuestions.org
Help answer threads with 0 replies.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Security
User Name
Password
Linux - Security This forum is for all security related questions.
Questions, tips, system compromises, firewalls, etc. are all included here.

Notices


Reply
  Search this Thread
Old 01-27-2005, 07:53 AM   #1
dominant
Member
 
Registered: Jan 2004
Posts: 409

Rep: Reputation: 30
creating a secure certificate


Hello guys

I want to create a certificate for an Apache with SSL enabled.

I know that this can be done using the openssl program but i don't know what excactly options or switches should i use to create it.

Could you help me a little ?
 
Old 01-27-2005, 09:45 AM   #2
Hangdog42
LQ Veteran
 
Registered: Feb 2003
Location: Maryland
Distribution: Slackware
Posts: 7,803
Blog Entries: 1

Rep: Reputation: 422Reputation: 422Reputation: 422Reputation: 422Reputation: 422
At the bottom of this tutorial are links to a good FAQ about making your own certificates.
 
Old 01-28-2005, 03:53 AM   #3
[GOD]Anck
Member
 
Registered: Dec 2003
Location: The Netherlands
Distribution: Slackware
Posts: 171

Rep: Reputation: 35
Do keep in mind that the commands from the bottom of that FAQ will result in a self-signed certificate. This is probably what you want initially as it allows you to test SSL functionality, but it is not 100% secure since you issued it to yourself, effectively. For a production environment you'd want to get a certificate from a certificate authority such as Thawte or VeriSign.

Last edited by [GOD]Anck; 01-28-2005 at 07:39 AM.
 
Old 01-28-2005, 04:58 AM   #4
dominant
Member
 
Registered: Jan 2004
Posts: 409

Original Poster
Rep: Reputation: 30
What i have to win if i pay for a certificate?
Longer private key (difficult to crack it?) ?
 
Old 01-28-2005, 07:32 AM   #5
Hangdog42
LQ Veteran
 
Registered: Feb 2003
Location: Maryland
Distribution: Slackware
Posts: 7,803
Blog Entries: 1

Rep: Reputation: 422Reputation: 422Reputation: 422Reputation: 422Reputation: 422
I don't think the certificate is any different from one you can make yourself. What you are really paying for is a third party endorsement that you are who you say you are.
 
Old 01-28-2005, 07:37 AM   #6
[GOD]Anck
Member
 
Registered: Dec 2003
Location: The Netherlands
Distribution: Slackware
Posts: 171

Rep: Reputation: 35
The difference would be in how much people trust your site rather than in how hard it is to crack. With self-signed certificates, basically what you are doing is saying "hey look at me, i'm trustworthy!" and since pretty much anyone can do this it doesn't pack as much of a punch as when your certificate is signed by a global certificate authority. Wether it's worth the money depends on how important the customer's trust is, obviously.
 
Old 01-28-2005, 09:32 AM   #7
dominant
Member
 
Registered: Jan 2004
Posts: 409

Original Poster
Rep: Reputation: 30
I see.

Could i make a public key of 2048 bits ? (i supposed that it could be cracked much harder, couln't it)
 
Old 01-28-2005, 09:44 AM   #8
[GOD]Anck
Member
 
Registered: Dec 2003
Location: The Netherlands
Distribution: Slackware
Posts: 171

Rep: Reputation: 35
Yes, you could specify the number of bits along with the algorithm to use. So if you're following the FAQ, replace "rsa" with "rsa:2048", that should do it. How much more secure that really is compared to the already pretty secure 1024 bit default I couldn't tell you.
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
creating a secure ftp-based backup account? evank Linux - Security 3 11-30-2005 12:44 AM
creating a secure ftp server with chrooting MisterESauce Linux - Networking 6 04-07-2005 11:22 AM
Creating Secure SMB Connections scottpioso Linux - Networking 17 12-03-2003 08:07 AM
Creating a personal digital certificate seven212 General 1 09-14-2003 04:13 AM
Creating an email certificate using SSL? jmnovak Linux - Software 0 04-29-2003 09:22 PM

LinuxQuestions.org > Forums > Linux Forums > Linux - Security

All times are GMT -5. The time now is 03:42 PM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration