[prev in list] [next in list] [prev in thread] [next in thread] 

List:       packetfence-users
Subject:    Re: [PacketFence-users] Problem with Certificates
From:       Hubert Kupper via PacketFence-users <packetfence-users () lists ! sourceforge ! net>
Date:       2018-01-26 13:02:50
Message-ID: D0591286-942B-43A8-9653-E8B050970767 () uni-landau ! de
[Download RAW message or body]

Hi, I was to fast with my question. I changed the ca chain file frpm .crt (as in \
ssl-certificates.conf) to the .pem format. Now it works fine.

Thank you for the help.

Best Regards,
Hubert

> Am 25.01.2018 um 14:40 schrieb Hubert Kupper via PacketFence-users \
> <packetfence-users@lists.sourceforge.net>: 
> Hello Fabrice,
> 
> thanks. I did: cat server.crt server.key > server.pem. Now packetfence starts and \
> the registration page pop up. How can I add the ca chain? 
> Best regards,
> Hubert
> 
> > Am 25.01.2018 um 03:22 schrieb Durand fabrice via PacketFence-users:
> > Hello Hubert,
> > 
> > Haproxy terminate the ssl connection , so the certificate must be use by haproxy.
> > 
> > Take a look there \
> > https://github.com/inverse-inc/packetfence/blob/devel/Makefile#L78 to see how to \
> > do it. 
> > Regards
> > 
> > Fabrice
> > 
> > 
> > 
> > > Le 2018-01-23 à 00:26, Hubert Kupper via PacketFence-users a écrit :
> > > Hello,
> > > 
> > > we have the following problem:
> > > We want to replace the packetfence certs with certs from our PKI provider \
> > > because the security warnings confuse some of our users. We copied the certs to \
> > > /conf/ssl, checked /conf/httpd.conf.d/ssl-certificates.conf and the hostname in \
> > > pf.conf. All seems to be ok. After restarting packetfence the registration page \
> > > for the users doesn't pop up. Packetfence.log shows no entries. When we use the \
> > > original certs from packetfence, the registration page pop up and all things \
> > > are fine. Did we forget a step when changing the certs? 
> > > Regards,
> > > Hubert
> > > 
> > > ------------------------------------------------------------------------------ 
> > > Check out the vibrant tech community on one of the world's most
> > > engaging tech sites, Slashdot.org! http://sdm.link/slashdot
> > > _______________________________________________
> > > PacketFence-users mailing list
> > > PacketFence-users@lists.sourceforge.net
> > > https://lists.sourceforge.net/lists/listinfo/packetfence-users
> > 
> 
> 
> ------------------------------------------------------------------------------
> Check out the vibrant tech community on one of the world's most
> engaging tech sites, Slashdot.org! http://sdm.link/slashdot
> _______________________________________________
> PacketFence-users mailing list
> PacketFence-users@lists.sourceforge.net
> https://lists.sourceforge.net/lists/listinfo/packetfence-users


------------------------------------------------------------------------------
Check out the vibrant tech community on one of the world's most
engaging tech sites, Slashdot.org! http://sdm.link/slashdot
_______________________________________________
PacketFence-users mailing list
PacketFence-users@lists.sourceforge.net
https://lists.sourceforge.net/lists/listinfo/packetfence-users


[prev in list] [next in list] [prev in thread] [next in thread] 

Configure | About | News | Add a list | Sponsored by KoreLogic