public:radio:2025:yaddnet_ssl_renewal
Differences
This shows you the differences between two versions of the page.
| Next revision | Previous revision | ||
| public:radio:2025:yaddnet_ssl_renewal [15/03/25 06:55 GMT] – created john | public:radio:2025:yaddnet_ssl_renewal [13/10/25 07:00 BST] (current) – [UPDATE ON TWO INTERMEDIATE CERTIFICATES 5/7/25] john | ||
|---|---|---|---|
| Line 2: | Line 2: | ||
| - | ====== | + | ====== |
| ** Renewed SSL certificates for 2025/6 ** | ** Renewed SSL certificates for 2025/6 ** | ||
| + | <note important> | ||
| ===== 15/03/25 : SSL certificates ===== | ===== 15/03/25 : SSL certificates ===== | ||
| Line 13: | Line 14: | ||
| * Download //both// " | * Download //both// " | ||
| * not sure why there are 2 // | * not sure why there are 2 // | ||
| - | * rename one as '' | + | * rename one as '' |
| - | * renmame other as '' | + | * renmame other as '' |
| * Use WinSCP to copy the 3 certificates to the Yaddnet VPS | * Use WinSCP to copy the 3 certificates to the Yaddnet VPS | ||
| * Log on to yaddnet vps via SSH | * Log on to yaddnet vps via SSH | ||
| Line 23: | Line 24: | ||
| * for clarity this gives new files | * for clarity this gives new files | ||
| * ''/ | * ''/ | ||
| - | * ''/ | + | * ''/ |
| - | * ''/ | + | * ''/ |
| + | * copy '' | ||
| * Restart Apache | * Restart Apache | ||
| * '' | * '' | ||
| Line 31: | Line 33: | ||
| * check site security | * check site security | ||
| - | {{: | + | {{: |
| - | * swap '' | + | * swap '' |
| * Restart Apache | * Restart Apache | ||
| * browse to [[https:// | * browse to [[https:// | ||
| Line 39: | Line 41: | ||
| * security also valid | * security also valid | ||
| + | ==== Different intermediate CA.pem certificates ==== | ||
| + | |||
| + | I used openssl to inspect the two different // | ||
| + | |||
| + | < | ||
| + | |||
| + | |||
| + | * for ca.pem.1 | ||
| + | |||
| + | < | ||
| + | Certificate: | ||
| + | Data: | ||
| + | Version: 3 (0x2) | ||
| + | Serial Number: | ||
| + | 39: | ||
| + | Signature Algorithm: sha384WithRSAEncryption | ||
| + | Issuer: C = GB, ST = Greater Manchester, L = Salford, O = Comodo CA Limited, CN = AAA Certificate Services | ||
| + | Validity | ||
| + | Not Before: Mar 12 00:00:00 2019 GMT | ||
| + | Not After : Dec 31 23:59:59 2028 GMT | ||
| + | Subject: C = US, ST = New Jersey, L = Jersey City, O = The USERTRUST Network, CN = USERTrust RSA Certification Authority | ||
| + | |||
| + | </ | ||
| + | |||
| + | * or ca.pem.2 | ||
| + | |||
| + | < | ||
| + | Certificate: | ||
| + | Data: | ||
| + | Version: 3 (0x2) | ||
| + | Serial Number: | ||
| + | 7d: | ||
| + | Signature Algorithm: sha384WithRSAEncryption | ||
| + | Issuer: C = US, ST = New Jersey, L = Jersey City, O = The USERTRUST Network, CN = USERTrust RSA Certification Authority | ||
| + | Validity | ||
| + | Not Before: Nov 2 00:00:00 2018 GMT | ||
| + | Not After : Dec 31 23:59:59 2030 GMT | ||
| + | Subject: C = GB, ST = Greater Manchester, L = Salford, O = Sectigo Limited, CN = Sectigo RSA Domain Validation Secure Server CA | ||
| + | </ | ||
| + | |||
| + | * and for completeness the //old// original ca.pem from prior to the renewal | ||
| + | |||
| + | < | ||
| + | Certificate: | ||
| + | Data: | ||
| + | Version: 3 (0x2) | ||
| + | Serial Number: | ||
| + | 0d: | ||
| + | Signature Algorithm: sha256WithRSAEncryption | ||
| + | Issuer: C = US, O = DigiCert Inc, OU = www.digicert.com, | ||
| + | Validity | ||
| + | Not Before: Nov 27 12:46:40 2017 GMT | ||
| + | Not After : Nov 27 12:46:40 2027 GMT | ||
| + | Subject: C = US, O = DigiCert Inc, OU = www.digicert.com, | ||
| + | </ | ||
| + | |||
| + | It appears that the certificate (ca.pem.2) from " | ||
| + | |||
| + | '' | ||
| + | |||
| + | '' | ||
| + | |||
| + | |||
| + | |||
| + | ===== UPDATE ON TWO INTERMEDIATE CERTIFICATES 5/7/25 ===== | ||
| + | |||
| + | <note important> | ||
| + | </ | ||
| + | |||
| + | |||
| + | What should be done is to join them together into one //ca.pem// file (and in the correct order.... ) | ||
| + | |||
| + | **Don' | ||
| + | |||
| + | Transfer them both with their **// | ||
| + | |||
| + | <code bash> | ||
| + | |||
| + | [root@yaddnet2:/ | ||
| + | |||
| + | [root@yaddnet2:/ | ||
| + | |||
| + | [root@yaddnet2:/ | ||
| + | |||
| + | </ | ||
| + | |||
| + | Check correct SSL operation at [[https:// | ||
| Line 47: | Line 136: | ||
| - | {{tag>}} | + | {{tag>yaddnet radio}} |
public/radio/2025/yaddnet_ssl_renewal.1742021739.txt.gz · Last modified: by john
