<?xml version="1.0" encoding="utf-8"?>
<rss version="2.0">
  <channel>
    <title>viaVerio :: Digital Certificates : Installing A Custom Certificate</title>
	<copyright>Copyright (c) 2007 Verio Inc. All rights reserved.</copyright>
    <link>http://www.viaverio.com/index.cfm?page_id=573</link>
    <description>Digital Certificates : Installing A Custom Certificate</description>
    <language>en-us</language>
    <lastBuildDate>Tue, 06 Nov 2007 15:46:57 GMT</lastBuildDate>
	<managingEditor>sales@verio.net</managingEditor>
	<webMaster>sales@verio.net</webMaster>
	<ttl>5</ttl>	
    <image>
      <title>viaVerio :: Digital Certificates : Installing A Custom Certificate</title>
	  <width>149</width>
	  <height>70</height>
	  <link>http://www.viaverio.com</link>
      <url>http://www.viaverio.com/images2/nav/viaverio_logo.gif</url>
    </image>
	<item>
	  <title>Digital Certificates : Installing A Custom Certificate</title>
	  <link>http://www.viaverio.com/rss/page_573.rss</link>
	  <guid isPermaLink="true">http://www.viaverio.com/rss/page_573.rss</guid>
	  <pubDate>Wed, 13 Oct 2004 12:00:00 GMT</pubDate>
	  <description>
	    <![CDATA[ &lt;h1&gt;Installing your Custom Digital Certificate&lt;/h1&gt;&lt;br&gt;&lt;br&gt;&lt;p&gt;Once you have a &lt;a href=&quot;/index.cfm?page_id=567&quot;&gt;obtained a signed digital certificate&lt;/a&gt;, you need&lt;br&gt;	to install it and set up SSL to use your certificate and private key instead of the default.&lt;/p&gt;&lt;br&gt;	&lt;br&gt;	&lt;table width=&quot;80%&quot; border=&quot;0&quot; cellspacing=&quot;2&quot; cellpadding=&quot;5&quot; align=&quot;center&quot;&gt;&lt;br&gt;		&lt;tr&gt;&lt;br&gt;			&lt;td class=&quot;note&quot;&gt;&lt;br&gt;			&lt;br&gt;&lt;p&gt;&lt;b&gt;NOTE:&lt;/b&gt; If you have not already ordered &lt;a href=&quot;/index.cfm?page_id=229&quot;&gt;SSL&lt;/a&gt; for your Virtual Private&lt;br&gt;				Server, you will need to do that before continuing with the steps outlined below.&lt;/p&gt;&lt;br&gt;			&lt;/td&gt;&lt;br&gt;		&lt;/tr&gt;&lt;br&gt;	&lt;/table&gt;&lt;br&gt;	&lt;br&gt;&lt;br&gt;&lt;p&gt;When you got your certificate, you most likely saved it to a file on your local computer.  You will need to copy the file onto&lt;br&gt;	your Virtual Private Server via &lt;a href=&quot;/index.cfm?page_id=237&quot;&gt;FTP&lt;/a&gt;.  Be sure to copy the file using &lt;i&gt;ASCII&lt;/i&gt;&lt;br&gt;	format to avoid corrupting the file.  Save the file in the &lt;i&gt;~/etc/&lt;/i&gt; directory with the name &lt;i&gt;ssl.cert&lt;/i&gt;.&lt;/p&gt;&lt;br&gt;	&lt;br&gt;&lt;br&gt;&lt;p&gt;Once the certificate is on your server, get the Private Key, which you generated at the same time as you generated the CSR,&lt;br&gt;	and copy it to the &lt;i&gt;~/etc/&lt;/i&gt; directory with the name &lt;i&gt;ssl.pk&lt;/i&gt;.  Make sure to keep a copy of the Private Key in a&lt;br&gt;	different location as well so if you make a mistake you don&apos;t lose your Private Key.  You may want to create a directory on &lt;br&gt;	your Virtual Private Server and store a copy of both your Private Key and the Certificate until you are certain that the new&lt;br&gt;	certificate is working properly.&lt;/p&gt;&lt;br&gt;	&lt;br&gt;&lt;br&gt;&lt;p&gt;With both files in place, connect to your Virtual Private Server via &lt;a href=&quot;/index.cfm?page_id=426&quot;&gt;SSH or&lt;br&gt;	Telnet&lt;/a&gt; and run the following command.&lt;/p&gt;&lt;br&gt;	&lt;br&gt;&lt;blockquote&gt;&lt;br&gt;		&lt;pre&gt;% openssl rsa -in ssl.pk -out ssl.pk&lt;/pre&gt;&lt;br&gt;&lt;/blockquote&gt;&lt;br&gt;	&lt;br&gt;&lt;br&gt;&lt;p&gt;This command removes the default encryption on your key, and makes it useable by the Apache Web Server.  With the key&lt;br&gt;	decrypted, run &lt;i&gt;restart_apache&lt;/i&gt; to restart the Web server using your new certificate.  You can tell if your Private Key has&lt;br&gt;	been decrypted or not by looking at the file.  When your key was generated, the first few lines should have looked similar to &lt;br&gt;	the following.&lt;/p&gt;&lt;br&gt;	&lt;br&gt;&lt;blockquote&gt;&lt;br&gt;		&lt;pre&gt;-----BEGIN RSA PRIVATE KEY-----&lt;br&gt;Proc-Type: 4,ENCRYPTED&lt;br&gt;DEK-Info: DES-EDE3-CBC,BCC23A5E16582F3D&lt;br&gt;&lt;br&gt;hfWyPkea3gnVCHCZJ/zgQpCH9RZF7WjYXGYohdbfkJY0ETLwXaqjvnNHQlLomwIt&lt;/pre&gt;&lt;br&gt;&lt;/blockquote&gt;&lt;br&gt;	&lt;br&gt;&lt;br&gt;&lt;p&gt;After decrypting your key, the key should have changed to look similar to the following.&lt;/p&gt;&lt;br&gt;	&lt;br&gt;&lt;blockquote&gt;&lt;br&gt;		&lt;pre&gt;-----BEGIN RSA PRIVATE KEY-----&lt;br&gt;MIICXQIBAAKBgQCot9aa9R38QevFSWqU718VFxqEDcY4gJfdZ6sBy282jdgCVcwU&lt;br&gt;q92tQ5V3amQanoSIWxI/O9GYm5kJSo3b2qGib2sqLiHZFav/bRjL5IDFOMwcSTyp&lt;br&gt;O0I9otCK72/rrxMl+Gt8b5saEiIdmGO4ar9AM2DYYQCFKYR62mDZ7mRa6wIDAQAB&lt;br&gt;AoGBAJWy0CqblGhvgSeCdZwCK+ZFopRKuHcHujeLtRKZk2rfPisMP1CUEdObJLJY&lt;br&gt;5ssrnUJzM+SBSf5TCN1Slj3dZg2NRBq+68L1dR+3voEWv2ebPhzicjw81l0xuVoX&lt;br&gt;HbXhM052Bmhp8XWZd3VdKXyQuTQeh17F4R2o39r9vP88pGnRAkEA4OxTu4p6gAxF&lt;br&gt;l4JwiqFeswdoq/jEj9KkKGy/wM4psGQqUrzWzgKmN+R1NpSRWcyohpSOsU8yFcHb&lt;br&gt;bydNYvYj0wJBAMAHgQENrGx+3XEzcCx3uY8vv1gvcNFou0RKKcoaHyf8n028AJAf&lt;br&gt;ZAM/7h+cFcJVYEeb8n54ED4979c+gr3ttYkCQD444okVLAJUYsQhL6UKMzpvqEM6&lt;br&gt;1JW8/fC49OsPnXTQoOy2lO30yarYppxsyTEAbvacDkV61S4zrNK5Gq1vzkUCQF45&lt;br&gt;0GVR7k92mPZZBSvsu5K1HTEKZlN7Dpjdw0+2LZ+TaB/epnAR1yN5FUFRd6PZ/Npm&lt;br&gt;fUDtbRr9jViTBdhocfECQQDfxT3bUNjvJUeWQieQg2ooj7yzbjMD5MjA+9z+qh1V&lt;br&gt;Cb+4kQSEWrP7EdJk4cOHOH+ZYjinf77x8v2PbnaKE5Dc&lt;br&gt;-----END RSA PRIVATE KEY-----&lt;/pre&gt;&lt;br&gt;&lt;/blockquote&gt;&lt;br&gt;	&lt;br&gt;&lt;br&gt;&lt;p&gt;Check to make sure the new certificate is working by connecting to the domain your certificate is set up to use via HTTPS. &lt;br&gt;	For example, if your domain name were &lt;i&gt;www.my-domain.name&lt;/i&gt;, you would type the following into your browser&apos;s location&lt;br&gt;	bar.&lt;/p&gt;&lt;br&gt;	&lt;br&gt;&lt;blockquote&gt;&lt;br&gt;		&lt;pre&gt;https://&lt;i&gt;www.my-domain.name&lt;/i&gt;&lt;/pre&gt;&lt;br&gt;&lt;/blockquote&gt;&lt;br&gt;	&lt;br&gt;&lt;br&gt;&lt;p&gt;If the page loads without any errors, find the &lt;i&gt;lock&lt;/i&gt; icon on your browser and click on it (depending on your browser,&lt;br&gt;	you may need to double-click).  This will bring up the certificate information, or a window that lets you &lt;i&gt;view certificate&lt;br&gt;	information&lt;/i&gt;.  Check to see that the certificate is using the correct domain name and has the correct information.&lt;/p&gt;&lt;br&gt;	&lt;br&gt;&lt;br&gt;&lt;p&gt;If you get an error trying to view the page, see the &lt;br&gt;	&lt;a href=&quot;/index.cfm?page_id=584&quot;&gt;Troubleshooting Certificate Installation Problems&lt;/a&gt; page to&lt;br&gt;	help you get the certificate working.&lt;/p&gt;]]>
	  </description>
	  <author>Content V1</author>
	</item>
  </channel>
</rss> 
