How to Create a SSL Certificate on Apache for Ubuntu 16.04 LTS

About SSL Certificates

A SSL certificate is a way to encrypt a site's information and create a more secure connection. Additionally, the certificate can show the virtual private server's identification information to site visitors. Certificate Authorities can issue SSL certificates that verify the server's details while a self-signed certificate has no 3rd party corroboration.

Set Up

The steps in this tutorial require the user to have root privileges on the VPS. You can see how to set that up here in steps 3 and 4.

Additionally, you need to have apache already installed and running on your virtual server. If this is not the case, you can download it with this command:

$ sudo apt-get install apache2

Step One—Activate the SSL Module

The next step is to enable SSL on the droplet.

sudo a2enmod ssl

Follow up by restarting Apache.

$ sudo service apache2 restart

Step Two—Create a New Directory

When we request a new certificate, we can specify how long the certificate should remain valid by changing the 365 to the number of days we prefer. As it stands this certificate will expire after one year.

sudo openssl req -x509 -nodes -days 365 -newkey rsa:2048 -keyout /etc/apache2/ssl/apache.key -out /etc/apache2/ssl/apache.crt

With this command, we will be both creating the self-signed SSL certificate and the server key that protects it, and placing both of them into the new directory.

This command will prompt terminal to display a lists of fields that need to be filled in.

The most important line is "Common Name". Enter your official domain name here or, if you don't have one yet, your site's IP address.

Generating a 2048 bit RSA private key
...........................................................................+++
.........................................+++
writing new private key to '/etc/apache2/ssl/apache.key'
-----
You are about to be asked to enter information that will be incorporated
into your certificate request.
What you are about to enter is what is called a Distinguished Name or a DN.
There are quite a few fields but you can leave some blank
For some fields there will be a default value,
If you enter '.', the field will be left blank.
-----
Country Name (2 letter code) [AU]:CN
State or Province Name (full name) [Some-State]:Shaanxi
Locality Name (eg, city) []:Xi'an
Organization Name (eg, company) [Internet Widgits Pty Ltd]:Xidian University
Organizational Unit Name (eg, section) []:SEC
Common Name (e.g. server FQDN or YOUR name) []:ce.xidian.edu.cn                 
Email Address []:example@xidian.edu.cn

Step Four—Set Up the Certificate

Now we have all of the required components of the finished certificate.The next thing to do is to set up the virtual hosts to display the new certificate. Open up the SSL config file:

$ sudo vim /etc/apache2/sites-available/default-ssl.conf

Within the section that begins with <VirtualHost default:443>, quickly make the following changes. Add a line with your server name right below the Server Admin email:

ServerName example.com:443

Replace example.com with your DNS approved domain name or server IP address (it should be the same as the common name on the certificate). Find the following three lines, and make sure that they match the extensions below:

SSLEngine on
SSLCertificateFile /etc/apache2/ssl/apache.crt
SSLCertificateKeyFile /etc/apache2/ssl/apache.key

Save and Exit out of the file.

Step Five—Activate the New Virtual Host

Before the website that will come on the 443 port can be activated, we need to enable that Virtual Host:

$ sudo a2ensite default-ssl

You are all set. Restarting your Apache server will reload it with all of your changes in place.

$ sudo service apache2 reload

In your browser, type https://youraddress, and you will be able to see the new certificate.

See More

Once you have setup your SSL certificate on the site, you can Install an FTP server if you haven't done so yet.

[References]How To Create a SSL Certificate on Apache for Ubuntu 12.04

最后編輯于
?著作權(quán)歸作者所有,轉(zhuǎn)載或內(nèi)容合作請(qǐng)聯(lián)系作者
  • 序言:七十年代末华临,一起剝皮案震驚了整個(gè)濱河市疾层,隨后出現(xiàn)的幾起案子滩援,更是在濱河造成了極大的恐慌登渣,老刑警劉巖兼耀,帶你破解...
    沈念sama閱讀 217,277評(píng)論 6 503
  • 序言:濱河連續(xù)發(fā)生了三起死亡事件钉嘹,死亡現(xiàn)場(chǎng)離奇詭異石蔗,居然都是意外死亡娃属,警方通過(guò)查閱死者的電腦和手機(jī),發(fā)現(xiàn)死者居然都...
    沈念sama閱讀 92,689評(píng)論 3 393
  • 文/潘曉璐 我一進(jìn)店門衬横,熙熙樓的掌柜王于貴愁眉苦臉地迎上來(lái)裹粤,“玉大人,你說(shuō)我怎么就攤上這事∫K撸” “怎么了拇泣?”我有些...
    開封第一講書人閱讀 163,624評(píng)論 0 353
  • 文/不壞的土叔 我叫張陵,是天一觀的道長(zhǎng)矮锈。 經(jīng)常有香客問我霉翔,道長(zhǎng),這世上最難降的妖魔是什么苞笨? 我笑而不...
    開封第一講書人閱讀 58,356評(píng)論 1 293
  • 正文 為了忘掉前任债朵,我火速辦了婚禮,結(jié)果婚禮上瀑凝,老公的妹妹穿的比我還像新娘序芦。我一直安慰自己,他們只是感情好粤咪,可當(dāng)我...
    茶點(diǎn)故事閱讀 67,402評(píng)論 6 392
  • 文/花漫 我一把揭開白布谚中。 她就那樣靜靜地躺著,像睡著了一般寥枝。 火紅的嫁衣襯著肌膚如雪宪塔。 梳的紋絲不亂的頭發(fā)上,一...
    開封第一講書人閱讀 51,292評(píng)論 1 301
  • 那天囊拜,我揣著相機(jī)與錄音某筐,去河邊找鬼。 笑死冠跷,一個(gè)胖子當(dāng)著我的面吹牛南誊,可吹牛的內(nèi)容都是我干的。 我是一名探鬼主播蜜托,決...
    沈念sama閱讀 40,135評(píng)論 3 418
  • 文/蒼蘭香墨 我猛地睜開眼弟疆,長(zhǎng)吁一口氣:“原來(lái)是場(chǎng)噩夢(mèng)啊……” “哼!你這毒婦竟也來(lái)了盗冷?” 一聲冷哼從身側(cè)響起怠苔,我...
    開封第一講書人閱讀 38,992評(píng)論 0 275
  • 序言:老撾萬(wàn)榮一對(duì)情侶失蹤,失蹤者是張志新(化名)和其女友劉穎仪糖,沒想到半個(gè)月后柑司,有當(dāng)?shù)厝嗽跇淞掷锇l(fā)現(xiàn)了一具尸體,經(jīng)...
    沈念sama閱讀 45,429評(píng)論 1 314
  • 正文 獨(dú)居荒郊野嶺守林人離奇死亡锅劝,尸身上長(zhǎng)有42處帶血的膿包…… 初始之章·張勛 以下內(nèi)容為張勛視角 年9月15日...
    茶點(diǎn)故事閱讀 37,636評(píng)論 3 334
  • 正文 我和宋清朗相戀三年攒驰,在試婚紗的時(shí)候發(fā)現(xiàn)自己被綠了。 大學(xué)時(shí)的朋友給我發(fā)了我未婚夫和他白月光在一起吃飯的照片故爵。...
    茶點(diǎn)故事閱讀 39,785評(píng)論 1 348
  • 序言:一個(gè)原本活蹦亂跳的男人離奇死亡玻粪,死狀恐怖,靈堂內(nèi)的尸體忽然破棺而出,到底是詐尸還是另有隱情劲室,我是刑警寧澤伦仍,帶...
    沈念sama閱讀 35,492評(píng)論 5 345
  • 正文 年R本政府宣布,位于F島的核電站很洋,受9級(jí)特大地震影響充蓝,放射性物質(zhì)發(fā)生泄漏。R本人自食惡果不足惜喉磁,卻給世界環(huán)境...
    茶點(diǎn)故事閱讀 41,092評(píng)論 3 328
  • 文/蒙蒙 一谓苟、第九天 我趴在偏房一處隱蔽的房頂上張望。 院中可真熱鬧协怒,春花似錦涝焙、人聲如沸。這莊子的主人今日做“春日...
    開封第一講書人閱讀 31,723評(píng)論 0 22
  • 文/蒼蘭香墨 我抬頭看了看天上的太陽(yáng)。三九已至芭商,卻和暖如春,著一層夾襖步出監(jiān)牢的瞬間搀缠,已是汗流浹背铛楣。 一陣腳步聲響...
    開封第一講書人閱讀 32,858評(píng)論 1 269
  • 我被黑心中介騙來(lái)泰國(guó)打工, 沒想到剛下飛機(jī)就差點(diǎn)兒被人妖公主榨干…… 1. 我叫王不留艺普,地道東北人簸州。 一個(gè)月前我還...
    沈念sama閱讀 47,891評(píng)論 2 370
  • 正文 我出身青樓,卻偏偏與公主長(zhǎng)得像歧譬,于是被迫代替她去往敵國(guó)和親岸浑。 傳聞我的和親對(duì)象是個(gè)殘疾皇子,可洞房花燭夜當(dāng)晚...
    茶點(diǎn)故事閱讀 44,713評(píng)論 2 354

推薦閱讀更多精彩內(nèi)容