Umm, are you a moving target ? I could have sworn it was Apache SSL you
were doing before ..... :-)
Hey Steve do you have a firewall or gateway in the middle here ? or a
filtering proxy or something ? if yes make sure https is allowed
through......
I am not sure that the vers you show below would be built against a late
version of OpenSSL, did you check the SRPMs ?
I can only say if all above is irrelavant, get the zedz Apache SSL , do a
standard RPM install as root, it should work straight away.....
Check List: Install, check for httpsd process, then connect to
https://box.ip , should see default RH page (dont gen own certs till past
here)
Good Luck !
*********** REPLY SEPARATOR ***********
On 25/01/00 at 16:01 Steve Frampton wrote:
>-----BEGIN PGP SIGNED MESSAGE-----
>Hash: SHA1
>
>Hullo:
>
>Well, in another attempt to get Apache with SSL support, I installed the
>following files:
>
>openssl-0.9.4-3.i386.rpm
>openssl-devel-0.9.4-3.i386.rpm
>apache-mod_ssl-1.3.6.2.3.0-0.i386.rpm
>apache-mod_ssl-devel-1.3.6.2.3.0-0.i386.rpm
>
>I then created a set of test certificates, and edited the /etc/httpd/conf
>httpd.conf file to point to them. I then started Apache with
>/etc/rc.i/init.d/httpd start
>
>I am able to successfully view standard unencrypted pages, but when I
>attempt to do an https://localhost, Netscape complains with:
>
>SSL has received an error from the server indicating an incorrect Message
>Authentication Code. This could indicate a network error, a bad server
>implementation, or a security violation.
>
>My /var/log/error_log contains the following:
>
>[Tue Jan 25 15:47:47 2000] [error] mod_ssl: SSL handshake failed
>(client 205.100.100.213, server localhost:443) (OpenSSL library
>error follows)
>[Tue Jan 25 15:47:47 2000] [error] OpenSSL: error:0407106B:rsa
>routines:RSA_padding_check_PKCS1_type_2:block type is not 02
>[Tue Jan 25 15:47:47 2000] [error] OpenSSL: error:04065072:rsa
>routines:RSA_EAY_PRIVATE_DECRYPT:padding check failed
>[Tue Jan 25 15:47:47 2000] [error] OpenSSL: error:1408F071:SSL
>routines:SSL3_GET_RECORD:bad mac decode
>
>Ideas?
Regards
Greg Wright
IT Consultant Sydney Australia
--
*** Please trim any replies ***
*** Please turn off HTML in your email ***
*** Please don't use the list for test messages ***
*** Why not read the archives? http://moongroup.com/redhat.phtml ***
--
To unsubscribe: mail [EMAIL PROTECTED] with "unsubscribe"
as the Subject.