IBM HTTP Server https configuration

本文档详细介绍了如何配置IBM HTTP Server以支持HTTPS,包括生成密钥库、证书,启用SSL并在httpd.conf中强制从HTTP重定向到HTTPS。遵循这些步骤可以确保服务器的安全通信。

摘要生成于 C知道 ,由 DeepSeek-R1 满血版支持, 前往体验 >

1. Generate kdb

gskcmd -keydb -create -db ihskey -pw pwd -type pkcs12 -expire 365 -stash


2. Generate Certificate

gskcmd -cert -create -db ihskey -pw pwd -size 1024 -dn CN=localhost,O=IBM,OU=IBM HTTP Server,C=CN -label ihskey -default_cert yes - expire 365


3. Enable SSL in httpd.conf

# Example SSL configuration which supports SSLv3 and TLSv1
# To enable this support:
#   1) Create a key database with ikeyman
#   2) Update the KeyFile directive below to point to that key database
#   3) Uncomment the directives up through the end of the example
#
LoadModule ibm_ssl_module modules/mod_ibm_ssl.so
Listen 443
<VirtualHost *:443>
SSLEnable
SSLServerCert ihskey
SSLClientAuth None
</VirtualHost>
SSLDisable
KeyFile /opt/ibm/HTTPServer/bin/ihskey.p12
# End of example SSL configuration


4. Force 80 to 443

update httpd.conf

uncomment LoadModule rewrite_module modules/mod_rewrite.so and add

RewriteEngine on
RewriteCond %{SERVER_PORT} =80
RewriteRule ^(.*) https://%{SERVER_NAME}%{REQUEST_URI} [R,L]


Ref:

Creating a new key database using the command-line interface

http://www-01.ibm.com/support/knowledgecenter/SSEQTJ_8.5.5/com.ibm.websphere.ihs.doc/ihs/tihs_createkeydb390.html?lang=en

Creating a self-signed certificate
http://www-01.ibm.com/support/knowledgecenter/SSEQTJ_8.5.5/com.ibm.websphere.ihs.doc/ihs/tihs_selfsigned.html?lang=en


Rewriting HTTP (port 80) requests to HTTPS (port 443)
http://www-01.ibm.com/support/docview.wss?rs=177&context=SSEQTJ&uid=swg21114864


评论
添加红包

请填写红包祝福语或标题

红包个数最小为10个

红包金额最低5元

当前余额3.43前往充值 >
需支付:10.00
成就一亿技术人!
领取后你会自动成为博主和红包主的粉丝 规则
hope_wisdom
发出的红包
实付
使用余额支付
点击重新获取
扫码支付
钱包余额 0

抵扣说明:

1.余额是钱包充值的虚拟货币,按照1:1的比例进行支付金额的抵扣。
2.余额无法直接购买下载,可以购买VIP、付费专栏及课程。

余额充值