First, a question: dear lazyweb, how do I completely disable non-SSL access with lighttpd? I can't seem to find how to have a lighttpd SSL-only configuration. (and only binding port 80 on localhost does not count for an answer)
On to the subject. While it's easy to add SSL to lighttpd and enable PHP (through fastcgi) — and Debian makes it even easier with it's lighty-enable-mod tool — if you only do it once in a blue moon then it's not exactly resident knowledge. So here are the steps to do it, on Debian Etch:
apt-get the lighttpd, php4-cgi or php5-cgi, and openssl packages
lighty-enable-mod fastcgi
- if using php5, update the path to the cgi binary in
/etc/lighttpd/conf-available/10-fastcgi.conf (it's preconfigured for php4)
lighty-enable-mod ssl
- update the path to the SSL certificate in
/etc/lighttpd/conf-available/10-ssl.conf
- restart the lighttpd server
That's all there is to it. Well, strictly speaking there's a step 4a: install a certificate; but that's arguably not a part of the configuration process.
(for reference:
openssl req -new -x509 -keyout /etc/lighttpd/selfcert.pem -out /etc/lighttpd/selfcert.pem -days 365 -nodes will generate a self-signed certificate)
Comments
Sun, 06.04.2008 16:59 CEST
You're right, that not only so me, but many questions in the LPI are not up to date and tha t you probably don't use [...]
Fri, 04.04.2008 13:14 CEST
Sure, it does it's job fine (m ost of the time :). And it's straightforward. Why not us e it?
Thu, 27.03.2008 19:53 CET
You still use LILO?!
Thu, 27.03.2008 00:51 CET
Can't you use UUID-naming?
Tue, 18.03.2008 21:45 CET
If it were the old blog, it /m ight/ have been from some comm ent spam. Then again, I cou ldn't find any reference [...]
Tue, 18.03.2008 21:34 CET
That's highly dependent on you r age. I do know who Racquel Darrian is...
Tue, 18.03.2008 18:16 CET
In my logs I was interested to find that searching for "ladi es pro wrestling" (6 hits from this one) and "jello wr [...]
Tue, 18.03.2008 12:12 CET
You dont have to pretend not k nowing sylvia saint, its gener al education! :-)
Thu, 13.03.2008 16:25 CET
Do both. Trying to regulate /eradicate all sound pollution is just not going to work wel l enough. You just need [...]
Thu, 13.03.2008 14:12 CET
Last time I went out to a live gig I wore earplugs for the f irst time, and enjoyed the mus ic much more because I c [...]