If I get an SSL certificate from one SSL provider and then decide to go with another provider for the same subdomain, do I have to get the first one revoked or simply replace the old with the new?
every 4 or 5 days the lock table permission keeps getting revoked, does anyone have anything that can point me in the general direction of what would cause this? The only thing i can think of is a cpanel layer 2 update has occured a few times during hte periods where the permission is revoked
unfortunately whenever it happens it results in my SQL backup script failing
Have been given a task where I am not familiar at all..
Task I have been given is to 1. implement mod_ssl in apache 2.2.4 2. create ssl cert for mail server 3. create ssl cert for Terminal Server
Now the problem is am unsure when I create these crt files and keys should I enable a pass phrase or not?? Am using openssl and the documentation states if it is a server certificate then maybe better not to have a passphrase..
Initially I thought I dont want the user when they check there mail to have to authenticate their mail account and also the passphrase for the cert and same for the TS users but am unsure of the meaning and usage of the passphrase.
for my online service. Do i spend the money for the special ssl cert that makes the ie7 bar green or a normal ssl cert?
Been thinking about getting an account on resellerclub for $200 and selling a cert to myself. Their other stuff might be helpful too. sounds like a plan?
user of shared SSL and trying to use my hosts shared SSL cert to process the form opened from a menu link. The form opens OK using href=[url] on the test page, but when I submit the form using the action=[url] I get a IE cannot display this webpage error.
The host says: The way you are using our shared SSL is correct. Still there is lot of scripts in the /home/blah-blah/public_html/staging, calling the link [url], which in turn gives error. This means that the scripts do not work on our shared SSL. It seems you need a separate SSL installed for your domain for the scripts to work properly.
Should it matter how many scripts (I assume he means php scripts) there are in the /staging area?
Is there another way to securely send this form to the server for processing? Do I need a cert for this domain to make this work? I've seen threads on this topic in other forums but the discussion level was between experienced developers, not a beginner like me. I would appreciate a do this not that kind of answer if possible.
The key matches the cert, and the cabundle is directly from Verisign.
Has anyone had a similar problem with getting a Verisign or other intermediate cert to work properly? I've reissued the thing twice and so far nothing has changed. It's like the intermediate cert isn't being sent even though it is installed.
When viewing the cert in firefox the Certificate Hierarchy only shows my domain. In internet explorer is shows Verisign Class 3 Public Primary CA -> Verisign Class 3 Secure Server CA -> My domain.
I ordered a RapidSSL (also called QuickSSL) cert from RapdiSSL.com (GeoTrust) to test out an email service. It works on firefox, but not in any version of IE I have on my two computers at home, a PC and a laptop running 6.0sp2 and 7.0 respectively.
When I raised a trouble ticket, Geotrust responded with a ppt attachment that clearly shows the cert working for the domain in IE. I have no reason to doubt them, but I replied with a ppt of my own showing the cert not working and am waiting for their reply.
Is it possible for a cert not to work on a specific browser like this? When I asked my email service provider, they said the following:
Quote:
Hello,
This indicates a problem with the SSL certificate that was installed. Possibly, an intermediate certificate issued by your certificate authority is need to be installed in addition to the one you gave us to enable Internet Explorer to fully trust your certificate and show the secure site.
Note for example that the only difference between going to [url]and [url] is the certificate in use ... the same server and software with the same settings is used in both cases. I recommend going back to Geotrust and ask if there is a Geotrust Intermediate certificate that should be installed in addition to your issued certificate."
The domain is CNAMED to their server so that the app looks as if it is being run off my domain. I don't think there is anything non-standard about this because LuxSci is a topnotch provider and this is how they enable their clients to run private label services.
As many Reseller Hosts offer shared certificates as a feature, and many resellers have small-business clients who make good use of this, is anyone else finding it a major problem where visitors using IE7 get an error message for pages using the shared certifcates?
Quote:
There is a problem with this website's security certificate.
The security certificate presented by this website was not issued by a trusted certificate authority.
Security certificate problems may indicate an attempt to fool you or intercept any data you send to the server.
We recommend that you close this webpage and do not continue to this website....
As a layperson visitor seeing that, I would not even think of using the link they offer to "continue" anyway. It scares customers off. I asked my Host about it and he said that it is beause all the shared SSL's are self-signed certifcates, so they do incur that error.
How are others dealing with it? No other option but to advise the client to get their own certificate?
Are there resellers that do NOT have this problem with their shared certs?
So after the palaver yesterday, I managed to remove everything to a degree enough to reinstall Plesk. I'm still having quite a few issues but at least the websites are up and running again.
One of the more important ones is SSL certificates. Apparently they still exist somewhere, but they're not showing up in Plesk.
I tried doing /usr/local/psa/bin/certificate -l -domain <domain>, however that returns:
I have a valid cert installed for a particular domain on my plesk server. I would like to take that cert info and export it to a valid PKCS12.
I was looking for the actual cert or pem files on the server but couldn't find them. Should i just copy all of the cert information to text files and create a pkcs12 via command line?
Currently i'm running a server with 12 customers on it. They all have their own domainnames and subscriptions. One of them wants to secure his site with SSL and also his mail traffic. Currently he is using the mail.hisdomain.com server for receiving/sending e-mail. I want to install a certificate so that domain is secured. How can i accomplish this?
When i look on the server there is only 1 PEM file for the whole server. If i'm going to install his KEY and CRT in that file than all my clients will use that certifcate right? Can i make it so that only his domain uses thoses certifcates? Plesk is configured to use Postfix with Courier.
We have two in-house servers, one is hosting our public web server. The other one was just purchased to host a mirror of the production server (as a backup). The site is protected by an SSL cert... my question is how do i set up the server(s) so if/when the backup server needs to be switched into produciton, the SSL cert will transition flawlessly?
One year ago a company I work for purchased and used a Code Signing Certificate from Comodo. This type of cert. ables to sign code, so your software executable files display 'company info' when downloaded, and avoid confidence warnings from Vista/XP and so on.
Now it's time to renew this cert (well, just purchase a new one) and surprise, this type of cert. has *raised* the price on every certification company I've looked.
Although I think this is just stealing money from companies, we need it, so I was wondering if you have some good deal to share.
I've seen $179 *a year* at Comodo, $499 *a year* at Verisign (holy cow), and the best deal so far is $563 for *three years* at globalsign.net.
I just setup an intranet wiki running apache2.2 on ubuntu 12.04. The server currently requires two-way certificate authentication (i.e. a server cert AND client certs).In <VirtualHost *:80>, Redirect permanent / https://<intranetSite>
Everything works dandy, except now that I'd like to find a way to bypass the client cert check for localhost so that I can run some maintenance scripts via cron on the server. Or perhaps it's possible to bypass SSL entirely, just for localhost?
I changed the default certificate (I added the certificate and marked as Default in Server->SSL Certificates).Also I assigned the SSL certificate to my domain.
This works fine, but now I'm trying to make the website PCI Compliant and their test shows that if you request the certificate from the ip address (instead of using the domain) it showns the Parallels self signed certificate instead os showing the default certificate i uploaded). I used also ssltools.websecurity.symantec.com tool and it shows the same. How to change the certificate shown for the one I bought?
I had an SSL cert that is about to expire so I purchased a new one, installed it, uninstalled the soon to expire cert. Went into Tools and Settings > IP Addresses, and assigned the new certificate to the IP.
Although I deleted the old certificate, it still shows in a browser as well as when I test the domain at a SSL server testing website. The new certificate shows also in both browser and test website, but it is a secondary certificate after the soon-to-expire cert.
I have a reseller account with 20 or so accounts using WHM. I now have my own dedicated server loaded with WHM. I want to move the accounts to the new server, but WHM asks for the reseller server's root pass which of course I don't have.
I guy I knew transfered 1 account a few weeks ago, with the information I gave him. Unfortunately, I can't get back in touch with him.
How do I move these accounts?
I have my WHM access on my dedicated server. I have my reseller WHM access on my reseller server, but not root access on that server.
i run a vbuletin forum, right now i am on a virtual dedicated
All my ips are stored on the same root ip, i am moving one of my forums from the default IP to a separate IP. I populated the DNS and my webite shows up properly on the new IP, but my forum is comming up as a database error.
Does anyone know what I can do to fix the problem? Or tools I can run? Or is it merely not connecting to the database yet, because of some name server or other issue?