在运行Sentora的Ubuntu 14.04 DigitalOcean Droplet安装EV SSL遇问题
Hey there, let’s tackle this Comodo EV SSL installation on your Sentora-managed Apache 2.4.3 server. Since Apache 2.4.8 introduced changes to SSL chain configuration (replacing SSLCertificateChainFile with SSLCACertificateFile), the standard tutorial won’t work directly for your older version. Here’s the adjusted step-by-step process tailored to your setup:
1. Prepare Your Certificate Files
First, make sure you have all the files from Comodo:
- Your domain’s primary SSL certificate (e.g.,
yourdomain.crt) - Comodo’s intermediate certificates (usually
COMODORSADomainValidationSecureServerCA.crtandCOMODORSAAddTrustCA.crt) - The private key file you generated when creating the CSR (e.g.,
yourdomain.key)
Upload these files to your server:
- Store the certificate files in
/etc/ssl/certs/(set permissions to644withchmod 644 /etc/ssl/certs/*.crt) - Store the private key in
/etc/ssl/private/(lock down permissions to600withchmod 600 /etc/ssl/private/yourdomain.keyto keep it secure)
Next, create a combined chain file for Apache 2.4.3—this is critical for proper EV certificate validation:
cat /etc/ssl/certs/COMODORSADomainValidationSecureServerCA.crt /etc/ssl/certs/COMODORSAAddTrustCA.crt > /etc/ssl/certs/yourdomain_chain.crt
2. Locate and Edit Your Sentora Virtual Host Config
Sentora stores Apache virtual host files in /etc/sentora/configs/apache/. Find the config file for your domain (it’ll look like vhost_yourdomain_com.conf). Open it with your favorite editor (e.g., nano):
nano /etc/sentora/configs/apache/vhost_yourdomain_com.conf
Add the SSL Virtual Host Block
Add a new <VirtualHost *:443> block below your existing port 80 block. Make sure to replace placeholders with your actual domain and file paths:
<VirtualHost *:443> ServerName yourdomain.com ServerAlias www.yourdomain.com DocumentRoot /var/sentora/hostdata/your_username/public_html/yourdomain_com # Match your Sentora document root # SSL Configuration (critical for Apache 2.4.3) SSLEngine on SSLCertificateFile /etc/ssl/certs/yourdomain.crt SSLCertificateKeyFile /etc/ssl/private/yourdomain.key # Use SSLCertificateChainFile (not SSLCACertificateFile—this is the pre-2.4.8 difference!) SSLCertificateChainFile /etc/ssl/certs/yourdomain_chain.crt # Copy over existing logging/PHP config from your port 80 block to keep consistency ErrorLog ${APACHE_LOG_DIR}/yourdomain-ssl-error.log CustomLog ${APACHE_LOG_DIR}/yourdomain-ssl-access.log combined # Add any other Sentora-specific directives from your port 80 block here </VirtualHost>
Redirect HTTP to HTTPS
Update your existing port 80 <VirtualHost *:80> block to redirect all HTTP traffic to HTTPS:
<VirtualHost *:80> ServerName yourdomain.com ServerAlias www.yourdomain.com DocumentRoot /var/sentora/hostdata/your_username/public_html/yourdomain_com # Add redirect rules RewriteEngine On RewriteCond %{HTTPS} !=on RewriteRule ^/?(.*) https://%{SERVER_NAME}/$1 [R=301,L] # Keep your existing logging and other directives here </VirtualHost>
3. Validate and Restart Apache
Before restarting, check for configuration errors—this saves you from downtime:
apache2ctl configtest
If you see Syntax OK, restart Apache to apply changes:
service apache2 restart
4. Verify the EV SSL Installation
- Visit your site via
https://yourdomain.com—you should see the green address bar (EV SSL’s signature) showing your organization’s name. - Double-check the certificate chain is complete by viewing the certificate details in your browser, or using an SSL testing tool to confirm no chain issues.
Key Notes to Avoid Headaches
- Match Private Key and Certificate: Ensure your private key matches the certificate by running these commands—both outputs should be identical:
openssl x509 -noout -modulus -in /etc/ssl/certs/yourdomain.crt | openssl md5 openssl rsa -noout -modulus -in /etc/ssl/private/yourdomain.key | openssl md5 - Sentora Config Overrides: If you edit virtual host settings via the Sentora panel later, it may overwrite your manual SSL config. To prevent this, add your SSL directives in Sentora’s Apache Config module under the custom section instead.
内容的提问来源于stack exchange,提问作者NipBoss

