Koozali.org: home of the SME Server

CA Cert SSL certificate expired, apache not running, HELP!

Offline gixmo

  • ***
  • 63
  • +0/-0
    • http://www.gixmo.nl
CA Cert SSL certificate expired, apache not running, HELP!
« on: September 19, 2007, 11:41:52 AM »
I've just received a mail from cacert.org that my server certificate will soon expire.
I've renewed on their site my certificate and pasted the new code into the {mydomain}.crt file.
Now it seems i can't open any web page (secure and not) on my server anymore :-?

After a reboot i see these errors in my messages l:
Quote
Sep 19 11:48:10 gixmo esmith::event[2783]: ERROR in /etc/e-smith/templates//home/e-smith/ssl.pem/20key: Program fragment delivered error <<Coul                             d not open key file: No such file or directory at /etc/e-smith/templates//home/e-smith/ssl.pem/20key line 16.>> at template line 1
Sep 19 11:48:10 gixmo esmith::event[2783]: ERROR in /etc/e-smith/templates//home/e-smith/ssl.pem/40crt: Program fragment delivered error <<Coul                             d not open crt file: No such file or directory at /etc/e-smith/templates//home/e-smith/ssl.pem/40crt line 15.>> at template line 1
Sep 19 11:48:10 gixmo esmith::event[2783]: ERROR: Template processing failed for //home/e-smith/ssl.pem/gixmo.gixmo.nl.pem: 2 fragments generat                             ed errors
Sep 19 11:48:23 gixmo esmith::event[2783]: ERROR in /etc/e-smith/templates//home/e-smith/ssl.pem/20key: Program fragment delivered error <<Coul                             d not open key file: No such file or directory at /etc/e-smith/templates//home/e-smith/ssl.pem/20key line 16.>> at template line 1
Sep 19 11:48:24 gixmo esmith::event[2783]: ERROR in /etc/e-smith/templates//home/e-smith/ssl.pem/40crt: Program fragment delivered error <<Coul                             d not open crt file: No such file or directory at /etc/e-smith/templates//home/e-smith/ssl.pem/40crt line 15.>> at template line 1
Sep 19 11:48:24 gixmo esmith::event[2783]: ERROR: Template processing failed for //var/service/qpsmtpd/ssl/cert.pem: 2 fragments generated erro                             rs
Sep 19 11:53:47 gixmo 10fix_privilege_tables: ERROR
Sep 19 11:53:47 gixmo 10fix_privilege_tables: ERROR
Sep 19 11:53:47 gixmo 10fix_privilege_tables: ERROR 1060 (42S21) at line 29: Duplicate column name 'Grant_priv'
Sep 19 11:53:47 gixmo 10fix_privilege_tables: ERROR 1060 (42S21) at line 30: Duplicate column name 'Grant_priv'
Sep 19 11:53:47 gixmo 10fix_privilege_tables: ERROR 1060 (42S21) at line 41: Duplicate column name 'ssl_type'
Sep 19 11:53:55 gixmo 10fix_privilege_tables: ERROR 1060 (42S21) at line 70: Duplicate column name 'Routine_type'
Sep 19 11:53:55 gixmo 10fix_privilege_tables: ERROR 1054 (42S22) at line 94: Unknown column 'Type' in 'columns_priv'
Sep 19 11:53:55 gixmo 10fix_privilege_tables: ERROR 1060 (42S21) at line 100: Duplicate column name 'type'
Sep 19 11:53:55 gixmo 10fix_privilege_tables: ERROR 1060 (42S21) at line 110: Duplicate column name 'Show_db_priv'
Sep 19 11:53:55 gixmo 10fix_privilege_tables: ERROR 1060 (42S21) at line 127: Duplicate column name 'max_questions'
Sep 19 11:53:55 gixmo 10fix_privilege_tables: ERROR 1060 (42S21) at line 137: Duplicate column name 'Create_tmp_table_priv'
Sep 19 11:53:55 gixmo 10fix_privilege_tables: ERROR 1060 (42S21) at line 140: Duplicate column name 'Create_tmp_table_priv'
Sep 19 11:53:56 gixmo 10fix_privilege_tables: ERROR 1061 (42000) at line 145: Duplicate key name 'Grantor'
Sep 19 11:53:59 gixmo 10fix_privilege_tables: ERROR 1060 (42S21) at line 252: Duplicate column name 'Create_view_priv'
Sep 19 11:53:59 gixmo 10fix_privilege_tables: ERROR 1060 (42S21) at line 253: Duplicate column name 'Create_view_priv'
Sep 19 11:53:59 gixmo 10fix_privilege_tables: ERROR 1060 (42S21) at line 254: Duplicate column name 'Create_view_priv'
Sep 19 11:53:59 gixmo 10fix_privilege_tables: ERROR 1060 (42S21) at line 259: Duplicate column name 'Show_view_priv'
Sep 19 11:53:59 gixmo 10fix_privilege_tables: ERROR 1060 (42S21) at line 260: Duplicate column name 'Show_view_priv'
Sep 19 11:53:59 gixmo 10fix_privilege_tables: ERROR 1060 (42S21) at line 261: Duplicate column name 'Show_view_priv'
Sep 19 11:53:59 gixmo 10fix_privilege_tables: ERROR 1060 (42S21) at line 282: Duplicate column name 'Create_routine_priv'
Sep 19 11:54:00 gixmo 10fix_privilege_tables: ERROR 1060 (42S21) at line 283: Duplicate column name 'Create_routine_priv'
Sep 19 11:54:00 gixmo 10fix_privilege_tables: ERROR 1060 (42S21) at line 284: Duplicate column name 'Create_routine_priv'
Sep 19 11:54:00 gixmo 10fix_privilege_tables: ERROR 1060 (42S21) at line 289: Duplicate column name 'Alter_routine_priv'
Sep 19 11:54:00 gixmo 10fix_privilege_tables: ERROR 1060 (42S21) at line 290: Duplicate column name 'Alter_routine_priv'
Sep 19 11:54:00 gixmo 10fix_privilege_tables: ERROR 1060 (42S21) at line 291: Duplicate column name 'Alter_routine_priv'
Sep 19 11:54:00 gixmo 10fix_privilege_tables: ERROR 1060 (42S21) at line 293: Duplicate column name 'Execute_priv'
Sep 19 11:54:00 gixmo 10fix_privilege_tables: ERROR 1060 (42S21) at line 294: Duplicate column name 'Execute_priv'
Sep 19 11:54:00 gixmo 10fix_privilege_tables: ERROR 1060 (42S21) at line 306: Duplicate column name 'max_user_connections'
Sep 19 11:54:00 gixmo 10fix_privilege_tables: ERROR 1060 (42S21) at line 315: Duplicate column name 'Create_user_priv'


and when i restart apache with "httpd -k restart"i get this error message:

Quote
SSLCertificateFile: file '/home/e-smith/ssl.crt/{domain}.crt' does not exist or is empty

i that dir i have a file gixmo.nl.crt

Where did i go wrong?
« Last Edit: September 19, 2007, 03:01:59 PM by gixmo »

Offline byte

  • *
  • 2,183
  • +2/-0
--[byte]--

Have you filled in a Bug Report over @ http://bugs.contribs.org ? Please don't wait to be told this way you help us to help you/others - Thanks!

Offline gixmo

  • ***
  • 63
  • +0/-0
    • http://www.gixmo.nl
Re: CA Cert SSL certificate expired, apache not running, HELP!
« Reply #2 on: September 19, 2007, 03:30:40 PM »
When i initially installed the certificate. Now i want to update it, so some steps can't be done anymore

Offline gixmo

  • ***
  • 63
  • +0/-0
    • http://www.gixmo.nl
Re: CA Cert SSL certificate expired, apache not running, HELP!
« Reply #3 on: September 19, 2007, 04:17:49 PM »
I have read the wiki at http://wiki.contribs.org/Custom_CA_Certificate again and now did the following :

First i renewed my certifcate at CA cert.
The new certificate i got from CAcert.org i pasted in to /home/e-smith/ssl.crt/{my_domain}.crt

then the last 2 steps of the wiki :

Quote
   
* Configure SME database

config setprop modSSL crt /home/e-smith/ssl.crt/{my_domain}.crt
config setprop modSSL key /home/e-smith/ssl.key/{my_domain}.key

    * and apply the changes


signal-event console-save


after a restart of httpd with :

httpd -k restart

everything works fine now.

I think the first time i tried this i din't copy and paste right. Sorry  :oops: