public:radio:2025:yaddnet_ssl_renewal
Differences
This shows you the differences between two versions of the page.
| Both sides previous revisionPrevious revisionNext revision | Previous revision | ||
| public:radio:2025:yaddnet_ssl_renewal [15/03/25 07:21 GMT] – [Different intermediate CA.pem certificates] john | public:radio:2025:yaddnet_ssl_renewal [Unknown date] (current) – removed - external edit (Unknown date) 127.0.0.1 | ||
|---|---|---|---|
| Line 1: | Line 1: | ||
| - | < | ||
| - | |||
| - | |||
| - | ====== Yaddnet VPS SSL Renewal ====== | ||
| - | |||
| - | ** Renewed SSL certificates for 2025/6 ** | ||
| - | |||
| - | ===== 15/03/25 : SSL certificates ===== | ||
| - | |||
| - | |||
| - | * Renewed SSL certificates available for download on Fasthosts account | ||
| - | * Download " | ||
| - | * Download //both// " | ||
| - | * not sure why there are 2 // | ||
| - | * rename one as '' | ||
| - | * renmame other as '' | ||
| - | * Use WinSCP to copy the 3 certificates to the Yaddnet VPS | ||
| - | * Log on to yaddnet vps via SSH | ||
| - | * copy existing certificates in ''/ | ||
| - | * '' | ||
| - | * '' | ||
| - | * copy new certificates from '' | ||
| - | * for clarity this gives new files | ||
| - | * ''/ | ||
| - | * ''/ | ||
| - | * ''/ | ||
| - | * copy '' | ||
| - | * Restart Apache | ||
| - | * '' | ||
| - | * browse to [[https:// | ||
| - | * site loads correctly | ||
| - | * check site security | ||
| - | |||
| - | {{: | ||
| - | |||
| - | * swap '' | ||
| - | * Restart Apache | ||
| - | * browse to [[https:// | ||
| - | * site loads correctly | ||
| - | * security also valid | ||
| - | |||
| - | ==== Different intermediate CA.pem certificates ==== | ||
| - | |||
| - | I used openssl to inspect the two different // | ||
| - | |||
| - | < | ||
| - | |||
| - | |||
| - | * for ca.pem.1 | ||
| - | |||
| - | < | ||
| - | Certificate: | ||
| - | Data: | ||
| - | Version: 3 (0x2) | ||
| - | Serial Number: | ||
| - | 39: | ||
| - | Signature Algorithm: sha384WithRSAEncryption | ||
| - | Issuer: C = GB, ST = Greater Manchester, L = Salford, O = Comodo CA Limited, CN = AAA Certificate Services | ||
| - | Validity | ||
| - | Not Before: Mar 12 00:00:00 2019 GMT | ||
| - | Not After : Dec 31 23:59:59 2028 GMT | ||
| - | Subject: C = US, ST = New Jersey, L = Jersey City, O = The USERTRUST Network, CN = USERTrust RSA Certification Authority | ||
| - | |||
| - | </ | ||
| - | |||
| - | * or ca.pem.2 | ||
| - | |||
| - | < | ||
| - | Certificate: | ||
| - | Data: | ||
| - | Version: 3 (0x2) | ||
| - | Serial Number: | ||
| - | 7d: | ||
| - | Signature Algorithm: sha384WithRSAEncryption | ||
| - | Issuer: C = US, ST = New Jersey, L = Jersey City, O = The USERTRUST Network, CN = USERTrust RSA Certification Authority | ||
| - | Validity | ||
| - | Not Before: Nov 2 00:00:00 2018 GMT | ||
| - | Not After : Dec 31 23:59:59 2030 GMT | ||
| - | Subject: C = GB, ST = Greater Manchester, L = Salford, O = Sectigo Limited, CN = Sectigo RSA Domain Validation Secure Server CA | ||
| - | </ | ||
| - | |||
| - | * and for completeness the //old// original ca.pem from prior to the renewal | ||
| - | |||
| - | < | ||
| - | Certificate: | ||
| - | Data: | ||
| - | Version: 3 (0x2) | ||
| - | Serial Number: | ||
| - | 0d: | ||
| - | Signature Algorithm: sha256WithRSAEncryption | ||
| - | Issuer: C = US, O = DigiCert Inc, OU = www.digicert.com, | ||
| - | Validity | ||
| - | Not Before: Nov 27 12:46:40 2017 GMT | ||
| - | Not After : Nov 27 12:46:40 2027 GMT | ||
| - | Subject: C = US, O = DigiCert Inc, OU = www.digicert.com, | ||
| - | </ | ||
| - | |||
| - | It appears that the certificate (ca.pem.2) from " | ||
| - | |||
| - | '' | ||
| - | |||
| - | '' | ||
| - | |||
| - | |||
| - | --- //John Pumford-Green 15/03/25 06:36 GMT// | ||
| - | |||
| - | |||
| - | ===== Further Information ===== | ||
| - | |||
| - | |||
| - | {{tag>}} | ||
| - | |||
public/radio/2025/yaddnet_ssl_renewal.1742023315.txt.gz · Last modified: (external edit)
