First, a question: dear lazyweb, how do I completely disable non-SSL access with lighttpd? I can't seem to find how to have a lighttpd SSL-only configuration. (and only binding port 80 on localhost does not count for an answer)
On to the subject. While it's easy to add SSL to lighttpd and enable PHP (through fastcgi) — and Debian makes it even easier with it's lighty-enable-mod tool — if you only do it once in a blue moon then it's not exactly resident knowledge. So here are the steps to do it, on Debian Etch:
apt-get the lighttpd, php4-cgi or php5-cgi, and openssl packages
lighty-enable-mod fastcgi
- if using php5, update the path to the cgi binary in
/etc/lighttpd/conf-available/10-fastcgi.conf (it's preconfigured for php4)
lighty-enable-mod ssl
- update the path to the SSL certificate in
/etc/lighttpd/conf-available/10-ssl.conf
- restart the lighttpd server
That's all there is to it. Well, strictly speaking there's a step 4a: install a certificate; but that's arguably not a part of the configuration process.
(for reference:
openssl req -new -x509 -keyout /etc/lighttpd/selfcert.pem -out /etc/lighttpd/selfcert.pem -days 365 -nodes will generate a self-signed certificate)
Comments
Thu, 31.12.2009 14:15 CET
They had a fox the other day, too. Funny, indeed.
Thu, 31.12.2009 03:07 CET
A better example, from a genui ne Windows ad campaign, as I s aw personally at Heathrow late this year: http://blogs [...]
Sat, 12.12.2009 18:40 CET
and you are happy with the lap top? you don't want to resell ? :) can't find anything as cheap on kapaza or ebay [...]
Sat, 12.12.2009 18:18 CET
It came with the 5500mAh batte ry.
Sat, 12.12.2009 12:39 CET
this laptop was sold out in 2 days time now they sell a dua l core atom of packard bell fo r 285euro
Thu, 10.12.2009 21:08 CET
Which type of battery does it contain? 4400mah small6 5500 mah standard or 6600mah Big
Sat, 05.12.2009 16:57 CET
The Celeron is probably has be tter performance anyway, but w orse battery life. The Atom is really neutered. I'd [...]
Wed, 28.10.2009 20:41 CET
The lack of checking for a cla shing UUID/name when defining networks is a clear bug in lib virt. We wrote some test [...]
Fri, 16.10.2009 01:45 CEST
This is sunlight shining throu gh the cracks in the Transform atorhus building of WesterGasF abriek in Amsterdam, isn't it?
Tue, 13.10.2009 18:23 CEST
What the beep is this? Damn beautiful picture though.