Ê×Ò³ | Óʼþ×ÊѶ | ¼¼Êõ½Ì³Ì | ½â¾ö·½°¸ | ²úÆ·ÆÀ²â | ÓʼþÈ˲Š| Óʼþ²©¿Í | ÓʼþϵͳÂÛ̳ | Èí¼þÏÂÔØ | ÓʼþÖÜ¿¯ | ÈȵãרÌâ | ¹¤¾ß
ÍøÂç¼¼Êõ | ²Ù×÷ϵͳ | Óʼþϵͳ | ¿Í»§¶Ë | µç×ÓÓÊÏä | ·´À¬»øÓʼþ | Óʼþ°²È« | ÓʼþÓªÏú | ÒÆ¶¯µçÓÊ | ÓʼþÈí¼þÏÂÔØ | µç×ÓÊéÏÂÔØ

²Ù×÷ϵͳ

Vista | Windows 9X | Windows Server | Linux&Uinx | FreeBSD | ÆäËü²Ù×÷ϵͳ |
Ê×Ò³ > ²Ù×÷ϵͳ > Windows Server > Windows2000 Ï APACHE+OpenSSL+MOD_SSL µÄ°²×°ÊÖ²á > ÕýÎÄ

Windows2000 Ï APACHE+OpenSSL+MOD_SSL µÄ°²×°ÊÖ²á

³ö´¦£º5DMail.NETÊÕ¼¯ ×÷ÕߣºRainbow ʱ¼ä£º2006-1-13 8:27:00
/********************************************************************************************************************
ÉùÃ÷£º±¾ÎĵµÓÃÓÚѧϰÓëÑо¿¿ÉÒÔ×ÔÓÉ×ªÔØ£¬ÎÞÂÛÒÔºÎÖÖÐÎʽ·¢²¼¶¼±ØÐë±£ÁôÍêÕûµÄ°æÈ¨ÉùÃ÷£¬ÉÌÒµÓÃ;²»µÃ×ªÔØ.±¾ÈËÄÜÁ¦ÓÐÏÞ£¬ÈçÓÐÎÊÌâ»¶Ó­½»Á÷ÓëÖ¸Õý¡£
ÍøÕ¾£ºhttp://www.infosecurity.org.cn
ÂÛ̳£ºhttp://www.infosecurity.org.cn/forum/forum.html
Óʼþ£ºrainbow_zrh@sina.com webmaster@infosecurity.org.cn
*********************************************************************************************************************/
Ò»¡¢OpenSSLµÄ°²×° 2
    1.1¡¢ÏÂÔØOpenSSL  2
    1.2¡¢ÏÂÔØperl£º   2
    1.3¡¢±àÒë 2
    1.4¡¢°²×°£º 2
¶þ¡¢ApacheÓëmod_sslµÄ°²×° 3
   2.1¡¢ËùÐè×ÊÔ´ 3
     2.1.1¡¢ÏÂÔØawk.exe 3
     2.1.2¡¢APACHEÏÂÔØ 3
     2.1.3¡¢mod_sslµÄÏÂÔØ 3
   2.2¡¢ÅäÖÃMOD_SSL 3
   2.3¡¢±àÒëapache 3
   2.4¡¢°²×°apache 3
Èý¡¢ÅäÖÃÖ¤Êé 4
   3.1¡¢Éú³É×ÔÇ©ÃûµÄÖ¤Êé 4
   3.2¡¢ÅäÖÃhttpd.conf 4
   3.3¡¢²âÊÔ 6
ËÄ¡¢ÅäÖÿͻ§¶ËÈÏÖ¤ 6
   4.1 Éú³É¿Í»§Ö¤ÊéÇëÇó 6
   4.2 ¿Í»§Ö¤ÊéµÄÉú³É 6
   4.3 Éú³ÉPKCS#12¸ñʽµÄÖ¤Êé 6
   4.4¡¢½«Éú³ÉµÄzrh.p12µ¼ÈëIE 6
   4.5¡¢ÅäÖÃhttpd.confÒªÇó¿Í»§¶ËÈÏÖ¤ 7
   4.6¡¢²âÊÔ--Ò»´ÎÕæÊµµÄÑÝʾ¹ý³Ì 7
²Î¿¼ÎÄÏ× 11

----------------------------------------------------------------------------------------------------------------------
Ò»¡¢OpenSSLµÄ°²×°
 1.1¡¢ÏÂÔØOpenSSL¡¡
µ½OpenSSLµÄ¹Ù·½Ö÷Ò³(http://www.openssl.org)È¥ÏÂÔØ¡£
 1.2¡¢ÏÂÔØperl£º
http://aspn.activestate.com/ASPN/Downloads/ActivePerl/Download?OS=Windows&version=5.6.1&build=629\&download=/ActivePerl/Windows/5.6/ActivePerl-5.6.1.629-MSWin32-x86-multi-thread.msi
 1.3¡¢±àÒë
ÉèÖúû·¾³±äÁ¿
c:\> cd d:\program files\Microsoft visual studio\vc98\bin
c:\> d:
c:\> VCVARS32.BAT
ÉèÖúÃperlËùÔÚ·¾¶ÈçD:\Perl\bin\;
cd openssl-0.9.6g
perl Configure VC-WIN32
ms\do_ms
nmake /f ms\ntdll.mak
 1.4¡¢°²×°£º

copy out32dll\libeay32.dll c:\windows\system 
copy out32dll\ssleay32.dll c:\windows\system 
md c:\openssl 
md c:\openssl\bin
md c:\openssl\lib
md c:\openssl\include
md c:\openssl\include\openssl
copy /b inc32\openssl\* c:\openssl\include\openssl
copy /b out32dll\ssleay32.lib c:\openssl\lib
copy /b out32dll\libeay32.lib c:\openssl\lib
copy /b out32dll\ssleay32.dll c:\openssl\bin
copy /b out32dll\libeay32.dll c:\openssl\bin
copy /b out32dll\openssl.exe c:\openssl\bin


¶þ¡¢ApacheÓëmod_sslµÄ°²×°¡¡
 2.1¡¢ËùÐè×ÊÔ´
  2.1.1¡¢ÏÂÔØawk.exe
µ½http://cm.bell-labs.com/cm/cs/awkbook/index.htmlÏÂÔØawk95.exe,Áí´æÎªawk.exe,
ÉèÖú÷¾¶(¿½µ½ÄãµÄ±àÒëĿ¼»òÕßSystem32ÏÂ,»òÆäËüÄÜÕÒµ½µÄµØ·½)£¬ÒÔ±ãVC++¿ÉÒÔÕÒµ½¡£
  2.1.2¡¢APACHEÏÂÔØ¡¡
http://www.apache.orgÏÂÔØ£¬²¢½âѹµ½F:\apache\1_3_28
  2.1.3¡¢mod_sslµÄÏÂÔØ
http://www.modssl.orgÏÂÔØ£¬²¢½âѹµ½F:\apache\mod_ssl-2.8.15-1.3.28

 2.2¡¢ÅäÖÃMOD_SSL
cd F:\apache\mod_ssl-2.8.15-1.3.28
configure.bat --with-apache=f:\apache\1_3_28 --with-ssl=f:\opensslpro\openssl_0.9.6eh
×¢Òâ ÕâÒ»²½²»Òª½«mod_sslµÄÔ´´úÂëºÍapacheµÄÔ´´úÂë·ÅÔÚÒ»¸öĿ¼ÏÂ,Ŀ¼Ҳ¾¡Á¿²»Òª´ø¿Õ¸ñ¡£

 2.3¡¢±àÒëapache
cd F:\apache\1_3_28\src
nmake /f Makefile.win _apacher
 2.4¡¢°²×°apache
nmake /f Makefile.win installr INSTDIR=f:\apache\1328
f:\apache\1328ÊÇApacheµÄ°²×°Ä¿Â¼£¬¿ÉÒÔ¸ù¾Ý×Ô¼ºµÄÐèÒª½øÐÐÐ޸ġ£
Èý¡¢ÅäÖÃÖ¤Êé
 3.1¡¢Éú³É×ÔÇ©ÃûµÄÖ¤Êé

cd F:\apache\1328\conf 
mkdir ssl
cd ssl
copy F:\OpenSSLPro\openssl-engine-0.9.6h\apps\openssl.cnf .
cd %APACHE_HOME%\conf\ssl
openssl req -config openssl.cnf -new -out ces-s.csr
openssl rsa -in privkey.pem -out ces-s.key
openssl x509 -in ces-s.csr -out ces-s.cert -req -signkey ces-s.key -days 365
del *.rnd(ÕâÒ»²½Ã»ÓÐ)


 3.2¡¢ÅäÖÃhttpd.conf
ÔÚ194ÐмÓÈëÄ£¿é¼ÓÔØÖ¸Áî
<IfDefine SSL>
LoadModule ssl_module modules/mod_ssl.so
</IfDefine>
ÔÚ246ÐмÓÈëAddModuleÖ¸ÁîÓëLoadModule¶ÔÓ¦
<IfDefine SSL>
AddModule mod_ssl.c
</IfDefine>

278ÐмÓÈëÒªÕìÌýµÄ¶Ë¿Ú
<IfDefine SSL>
Listen 80
Listen 443
</IfDefine>
×îºó1035×óÓÒ¼ÓÈë:ÐéÄâÖ÷»ú¼°¹«Ô¿ºÍ˽ԿµÄ·¾¶¡£

<IfDefine SSL>
AddType application/x-x509-ca-cert .crt
AddType application/x-pkcs7-crl .crl
</IfDefine>

<IfModule mod_ssl.c> 
SSLPassPhraseDialog builtin 
SSLSessionCache dbm:logs/ssl_scache
SSLSessionCacheTimeout 300
SSLMutex sem
SSLRandomSeed startup builtin
SSLRandomSeed connect builtin
SSLLog logs/ssl_engine_log
SSLLogLevel info

</IfModule>

<IfDefine SSL>

<VirtualHost _default_:443>

DocumentRoot "F:\apache\1328\htdocs"
ServerName 127.0.0.1
ServerAdmin you@your.address
ErrorLog logs/error_log
TransferLog logs/access_log

SSLEngine on
SSLCipherSuite ALL:!ADH:!EXPORT56:RC4+RSA:+HIGH:+MEDIUM:+LOW:+SSLv2:+EXP:+eNULL
SSLCertificateFile F:\apache\1328\conf\ssl\ces-s.cert
SSLCertificateKeyFile F:\apache\1328\conf\ssl\ces-s.key

<Files ~ "\.(cgi|shtml|phtml|php3?)$">
SSLOptions +StdEnvVars
</Files>
<Directory "F:\apache\1328\cgi-bin">
SSLOptions +StdEnvVars
</Directory>

SetEnvIf User-Agent ".*MSIE.*" nokeepalive ssl-unclean-shutdown downgrade-1.0 force-response-1.0

CustomLog logs/ssl_request_log "%t %h %{SSL_PROTOCOL}x %{SSL_CIPHER}x \"%r\" %b"
</VirtualHost> 

</IfDefine>



3.3¡¢²âÊÔ
Æô¶¯ÃüÁîÌáʾ·û´°¿Ú
cd f:\apache\1328
apache ¨CD SSL
ËÄ¡¢ÅäÖÿͻ§¶ËÈÏÖ¤
ËùÓеÄÃÜÂ붼ĬÈÏΪ12345678
 4.1 Éú³É¿Í»§Ö¤ÊéÇëÇó
Ö¤ÊéÇëÇóµÄÃû×ÖΪzrh.csr,˽ԿÎļþÃûΪzrhkey.pem¡£
CD f:\apache\1328\conf\ssl
F:\apache\1328\conf\ssl>openssl req -config openssl.cnf -new -out zrh.csr -keyout zrhkey.pem
È»ºóÊäÈë¸öÈËÐÅÏ¢
 4.2 ¿Í»§Ö¤ÊéµÄÉú³É
ÊäÈëÖ¤ÊéÇëÇóµÄÃû×ÖΪzrh.csr£¬Éú³ÉµÄÖ¤ÊéµÄÃû×ÖΪzrh.pem¡£
CAÖ¤ÊéµÄÖ¤ÊéÃû×ÖΪces-s.cert£¬Ë½Ô¿ÎļþÃûΪces-s.key
F:\apache\1328\conf\ssl>openssl x509 -req -in zrh.csr -out zrh.pem -CA ces-s.cert -CAkey ces-s.key -CAcreateserial -days 365 -outform PEM
µ½ÏÖÔÚΪֹÄã¾ÍÒѾ­ÓÐÁËÒ»¸ö¾­CAÇ©¹ýÃûµÄÖ¤Êézrh.pemºÍÒ»¸ö˽Կzrhkey.pem
 4.3 Éú³ÉPKCS#12¸ñʽµÄÖ¤Êé
ΪÁËÔÚIEÖиüºÃµÄʹÓá£
F:\apache\1328\conf\ssl>openssl pkcs12 -export -in zrh.pem -out zrh.p12 -inkey zrhkey.pem -name "Zhang RongHua Cert"
ÕâÒ»²½½«Éú¹«Ô¿Ö¤ÊéºÍ˽´ò°üÔÚÒ»ÆðµÄzrh.p12Óû§Ö¤Êé¡£
 4.4¡¢½«Éú³ÉµÄzrh.p12µ¼ÈëIE
Ë«»÷zrh.p12°´Ìáʾ½øÐÐ,¼´¿É¡£Èç¹ûûÓбØÒª²»ÒªÑ¡Ôñǿ˽Կ±£»¤,ÒòΪÿһ´ÎʹÓÃ˽ԿµÄʱºò¶¼ÊÇÈÃÄãÈ·ÈÏÒ»´Î¡£
µ¼ÈëÊÜÐÅÈεĸùÖ¤Êéces-s.cert¡£
 4.5¡¢ÅäÖÃhttpd.confÒªÇó¿Í»§¶ËÈÏÖ¤
<VirtualHost _default_:443>¡­¡­</VirtualHost>Öмä¼ÓÈëÒÔÏÂÅäÖÃ
# enable client certificate requirement

SSLVerifyClient require
SSLVerifyDepth 1
SSLCACertificatePath conf\ssl
SSLCACertificateFile conf\ssl\ces-s.cert(Ϊ·þÎñÆ÷Ö¤Êé/CAÖ¤ÊéËùÔÚµÄĿ¼)

 4.6¡¢²âÊÔ--Ò»´ÎÕæÊµµÄÑÝʾ¹ý³Ì
Ò»´ÎÕæÊµµÄÑÝʾ¹ý³Ì¡£
´òhttps://127.0.0.1
µãÈ·¶¨°´Å¥
µãÈ·¶¨°´Å¥
Ñ¡ÔñÒ»ÕÅÖ¤Ê飬ȻºóµãÈ·¶¨°´Å¥
µãÏêϸÐÅÏ¢
µãÈ·¶¨°´Å¥
µã²é¿´Ö¤Êé°´Å¥£¬¿ÉÒÔ¿´Ö¤ÊéµÄÏêϸÐÅÏ¢
µãÈ·¶¨°´Å¥
Ò»´Î·ÃÎʾͳɹ¦ÁË¡£
(µã»÷ÕâÀïÏÂÔØÑÝʾͼƬ)
²Î¿¼ÎÄÏ×
 1¡¢Lajos Moczar mod_ssl°²×°ËµÃ÷
 2¡¢http://www.galatea.com/dist/configure.pl.txt
 3¡¢apacheµÄ°²×°Îĵµ
 4¡¢Rainbow(²»¾­Àú·çÓê,Ôõô¼û²Êºç) ApacheµÄ±àÒë¼°°²×°¹ý³Ì.doc
 5¡¢OpenSSLµÄ°²×°ÎĵµINSTALL.W32  

Ïà¹ØÎÄÕ ÈÈÃÅÎÄÕÂ
  • ÔÚWindows2000ϵͳÖÐÔ¤·ÀPing¹¥»÷
  • Windows2000ÏÂDNSºÍ»î¶¯Ä¿Â¼¹ØÏµÇ³Îö
  • Windows2000¸ß¼¶·þÎñÆ÷°æÊµÏÖ·þÎñÆ÷Ⱥ¼¯
  • ÇáËÉʵÏÖWindows2000ÓëWinXPµÄË«Òýµ¼
  • Windows2000ÖеļÓÃÜÎļþϵͳ
  • ¿ìËÙÔËÐÐWindows2000/XP¹ÜÀíÄ£¿é
  • Windows2000ÏÂʵÏÖ¶¯Ì¬DNSµÄ°²È«¿¼ÂÇ
  • ¡°http 500ÄÚ²¿·þÎñÆ÷´íÎ󡱵Ľâ¾ö·½·¨
  • ÀûÓÃWindows 2000 ServerµÄRRASʵÏÖVPN·þÎñÆ÷
  • Ó÷ï»ËÍòÄÜÆô¶¯Å̽â¾ö±¾µØ/Óò¹ÜÀíÔ±ÃÜÂ붪ʧ
  • Win2003 ServerÆóÒµ°æ°²×°ÅäÖÃ
  • Active directory ÔÖÄѻָ´
  • Windows 2000/03ÓòºÍ»î¶¯Ä¿Â¼
  • ÈçºÎÔÚvmware4ÉÏ´´½¨windows 2003Ⱥ¼¯
  • MSIÎļþÖÆ×÷È«¹ý³Ì
  • Win2000ÃüÁîÈ«¼¯(Ò»)
  • Windows 2000/AD¼¼ÇÉ
  • ´ËϵͳµÄ±¾µØ²ßÂÔ²»ÔÊÐíÄú²ÉÓý»»¥Ê½µÇ¼½â¾ö·½·¨
  • Win2000·ÓɵݲװÓëÉèÖÃʵÏÖ²»Í¬Íø¶Î»¥Í¨
  • ×ÔÓÉ¹ã¸æÇø
    ¡¡
     
    ×îÐÂÈí¼þÏÂÔØ
  • ORF Enterprise Edition 4.2 Õýʽ°æ
  • WinWebMail 3.7.7.3 ±ê×¼°æ
  • WinWebMail 3.7.7.3 ÆóÒµ°æ
  • BMailì÷ÓÊ
  • Merak Email Server for Windows 9.3.1..
  • Merak Email Server for Linux 9.3.1 ¼..
  • Merak Email Server 9.3.1 For Windwos..
  • AXIGEN Mail Server 6.1.1 for Windows
  • AXIGEN Mail Server 6.1.0 for Linux
  • ADModify.NETÏÂÔØ
  • symantec10.1»ù±¾°²×°¼°ÅäÖÃÊÓÆµ½Ì³Ì
  • Backup Exec System RecoveryÖ®±¸·ÝÊÓÆ..
  • ½ñÈÕÓʼþ¼¼ÊõÎÄÕÂ
  • ÃÀ´óѧÉúÇÖÈëÅåÁÖÖݳ¤¸öÈËÓʼþÕË»§±»´þ²¶
  • ˼¿ÆIronPort·¢²¼Ðµç×ÓÓʼþ°²È«É豸
  • Éî¸û"Èí¼þ+·þÎñ" ΢Èí300³ÇÊÐѲչî£ÓÊ
  • ´ÓºÚ¿Í³£Óù¥»÷Êֶο´WEBÓ¦Ó÷À»¤
  • ÏûÏ¢ÈËʿ͸¶ÑÅ»¢ÓëAOLºÏ²¢Ï¸½Ú½«ÓÚ±¾Ô..
  • ¹È¸èÌṩµÄµç×ÓÓʼþ´æµµÊ±¼äÑÓ³¤ÎªÊ®Äê
  • ÑÅ»¢½«ÔÚÓÊÏä·þÎñÖÐÕûºÏаæÔÚÏßÈÕÀú
  • 9ÔÂÀ¬»øÓʼþ×ÜÁ¿¼õÉÙ ÓëISPµ¹±ÕÓйØ
  • À¬»øÓʼþ·¢Õ¹µÄËÄ´óÇ÷ÊÆ
  • º«¹úÒéÔ±³ÆÖйúºÚ¿Íð³äÇàÍß̨·¢ËͲ¡¶¾..
  • VistaÄÑ³ÉÆøºò Windows XPÊÙÃü±»ÑÓ³¤
  • ÈüÃÅÌú¿ËÉý¼¶DLP²úÆ·¼°·´À¬»øÓʼþÍø¹Ø
  • ×îÐÂרÌâ
  • Sendmail ÓʼþϵͳÅäÖÃ
  • ×齨Exchange 2003Óʼþϵͳ
  • Windows Server 2008 רÌâ
  • ORF ·´À¬»øÓʼþϵͳ
  • Exchange Server 2007 רÌâ
  • ISA Server 2006 ½Ì³ÌרÌâ
  • Windows Vista ¼¼ÊõרÌâ
  • ¡°ºÚÝ®¡±£¨BlackBerry£©×¨Ìâ
  • ÒÆ¶¯µç×ÓÓʼþרÌâ
  • Apache James רÌâ
  • IMail Server ²Ù×÷Ö¸ÄÏ
  • ISA Server 2004 ʹÓÃרÌâ
  • ·ÖÀർº½
    ÓʼþÐÂÎÅ×ÊѶ:
    ITÒµ½ç | Óʼþ·þÎñÆ÷ | ÓʼþȤÎÅ | ÒÆ¶¯µçÓÊ
    µç×ÓÓÊÏä | ·´À¬»øÓʼþ|Óʼþ¿Í»§¶Ë|ÍøÂ簲ȫ
    ÐÐÒµÊý¾Ý | ÓʼþÈËÎï | ÍøÕ¾¹«¸æ | ÐÐÒµ·¨¹æ
    ÍøÂç¼¼Êõ:
    ÓʼþÔ­Àí | ÍøÂçЭÒé | ÍøÂç¹ÜÀí | ´«Êä½éÖÊ
    Ïß·½ÓÈë | ·ÓÉ½Ó¿Ú | Óʼþ´æ´¢ | »ªÎª3Com
    CISCO¼¼Êõ | ÍøÂçÓë·þÎñÆ÷Ó²¼þ
    ²Ù×÷ϵͳ:
    Windows 9X | Linux&Uinx | Windows NT
    Windows Vista | FreeBSD | ÆäËü²Ù×÷ϵͳ
    Óʼþ·þÎñÆ÷:
    ³ÌÐòÓ뿪·¢ | Exchange | Qmail | Postfix
    Sendmail | MDaemon | Domino | Foxmail
    KerioMail | JavaMail | Winwebmail |James
    Merak&VisNetic | CMailServer | WinMail
    ½ðµÑÓʼþϵͳ | ÆäËü |
    ·´À¬»øÓʼþ:
    ×ÛÊö| ¿Í»§¶Ë·´À¬»øÓʼþ|·þÎñÆ÷¶Ë·´À¬»øÓʼþ
    Óʼþ¿Í»§¶ËÈí¼þ:
    Outlook | Foxmail | DreamMail| KooMail
    The bat | À×Äñ | Eudora |Becky! |Pegasus
    IncrediMail |ÆäËü
    µç×ÓÓÊÏä: ¸öÈËÓÊÏä | ÆóÒµÓÊÏä |Gmail
    ÒÆ¶¯µç×ÓÓʼþ:·þÎñÆ÷ | ¿Í»§¶Ë | ¼¼ÊõÇ°ÑØ
    ÓʼþÍøÂ簲ȫ:
    Èí¼þ©¶´ | °²È«ÖªÊ¶ | ²¡¶¾¹«¸æ |·À»ðǽ
    ¹¥·À¼¼Êõ | ²¡¶¾²éɱ| ISA | Êý×ÖÇ©Ãû
    ÓʼþÓªÏú:
    EmailÓªÏú | ÍøÂçÓªÏú | ÓªÏú¼¼ÇÉ |ÓªÏú°¸Àý
    ÓʼþÈ˲Å:ÕÐÆ¸ | Ö°³¡ | Åàѵ | Ö¸ÄÏ | Ö°³¡
    ½â¾ö·½°¸:
    Óʼþϵͳ|·´À¬»øÓʼþ |°²È« |ÒÆ¶¯µçÓÊ |Õбê
    ²úÆ·ÆÀ²â:
    Óʼþϵͳ |·´À¬»øÓʼþ |ÓÊÏä |°²È« |¿Í»§¶Ë
    ¹ã¸æÁªÏµ | ºÏ×÷ÁªÏµ | ¹ØÓÚÎÒÃÇ | ÁªÏµÎÒÃÇ | ·±ówÖÐÎÄ
    °æÈ¨ËùÓУºÓʼþ¼¼Êõ×ÊÑ¶Íø©2003-2007 www.5dmail.net, All Rights Reserved
    www.5Dmail.net Web Team   ÔÁICP±¸05009143ºÅ