<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>gionn-book &#187; openssl</title>
	<atom:link href="http://blog.scorpionworld.it/tag/openssl/feed" rel="self" type="application/rss+xml" />
	<link>http://blog.scorpionworld.it</link>
	<description>Powered by caffeine</description>
	<lastBuildDate>Sun, 25 Jul 2010 10:32:14 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.0</generator>
<atom:link rel="hub" href="http://pubsubhubbub.appspot.com"/><atom:link rel="hub" href="http://superfeedr.com/hubbub"/>		<item>
		<title>Debian Openssl bug &#8211; predictable random number generator</title>
		<link>http://blog.scorpionworld.it/debian-openssl-bug-predictable-random-number-generator.html?utm_source=rss&amp;utm_medium=rss&amp;utm_campaign=debian-openssl-bug-predictable-random-number-generator</link>
		<comments>http://blog.scorpionworld.it/debian-openssl-bug-predictable-random-number-generator.html#comments</comments>
		<pubDate>Wed, 21 May 2008 18:54:26 +0000</pubDate>
		<dc:creator>gionn</dc:creator>
				<category><![CDATA[Fun]]></category>
		<category><![CDATA[Software]]></category>
		<category><![CDATA[bug]]></category>
		<category><![CDATA[Debian]]></category>
		<category><![CDATA[key]]></category>
		<category><![CDATA[kurt]]></category>
		<category><![CDATA[openssl]]></category>
		<category><![CDATA[rsa]]></category>
		<category><![CDATA[ssh]]></category>
		<category><![CDATA[Ubuntu]]></category>

		<guid isPermaLink="false">http://blog.scorpionworld.it/?p=415</guid>
		<description><![CDATA[Bug simpatici come questo non se ne vedono tanti. Ai posteri lascio il changelog della patch incriminata, qualche vignetta satirica e la collezione completa delle chiavi generabili con il pacchetto buggato: 262144. openssl (0.9.8b-1) unstable; urgency=low &#8230; * Don&#8217;t add &#8230; <a href="http://blog.scorpionworld.it/debian-openssl-bug-predictable-random-number-generator.html">Continue reading <span class="meta-nav">&#8594;</span></a>]]></description>
			<content:encoded><![CDATA[<p>Bug simpatici come <a href="http://www.debian.org/security/2008/dsa-1571">questo</a> non se ne vedono tanti.</p>
<p>Ai posteri lascio il <strong>changelog</strong> della patch incriminata, qualche <strong>vignetta satirica</strong> e la <strong>collezione completa</strong> delle chiavi generabili con il pacchetto buggato: <a href="http://www.mediafire.com/?is5llmey0jg">262144</a>.</p>
<p><span id="more-415"></span></p>
<blockquote><p>openssl (0.9.8b-1) unstable; urgency=low<br />
&#8230;<br />
  * Don&#8217;t add uninitialised data to the random number generator.  This stop<br />
    valgrind from giving error messages in unrelated code.<br />
    (Closes: #363516)<br />
&#8230;<br />
 &#8212; Kurt Roeckx <kurt@roeckx.be>  Thu,  4 May 2006 20:40:03 +0200</p>
<p>openssl (0.9.8c-1) unstable; urgency=low<br />
&#8230;<br />
  * Move the modified rand/md_rand.c file to the right place,<br />
    really fixing #363516.<br />
&#8230;<br />
 &#8212; Kurt Roeckx <kurt@roeckx.be>  Sun, 17 Sep 2006 14:47:59 +0000</p>
<p>openssl (0.9.8g-9) unstable; urgency=high<br />
&#8230;<br />
  [ Kurt Roeckx ]<br />
  * ssleay_rand_add() really needs to call MD_Update() for buf.<br />
 &#8212; Kurt Roeckx <kurt@roeckx.be>  Wed, 07 May 2008 20:32:12 +0200</p></blockquote>
<p><a href="http://www.flickr.com/photos/scorpionworld/2511276373/" title="dilbert9 di ~scorp, su Flickr"><img src="http://farm4.static.flickr.com/3039/2511276373_096cfeb1c1.jpg" width="500" height="283" alt="dilbert9" /></a></p>
<p><a href="http://www.flickr.com/photos/scorpionworld/2511276377/" title="random4 di ~scorp, su Flickr"><img src="http://farm4.static.flickr.com/3065/2511276377_371e6b67e4.jpg" width="500" height="293" alt="random4" /></a></p>
<p><a href="http://www.flickr.com/photos/scorpionworld/2511276379/" title="xkcd_security_holes di ~scorp, su Flickr"><img src="http://farm4.static.flickr.com/3004/2511276379_ac82e9f481.jpg" width="468" height="500" alt="xkcd_security_holes" /></a></p>
<p>E scusate il tempismo :D</p>
]]></content:encoded>
			<wfw:commentRss>http://blog.scorpionworld.it/debian-openssl-bug-predictable-random-number-generator.html/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Apache2 e ssl (https)</title>
		<link>http://blog.scorpionworld.it/apache2-e-ssl-https.html?utm_source=rss&amp;utm_medium=rss&amp;utm_campaign=apache2-e-ssl-https</link>
		<comments>http://blog.scorpionworld.it/apache2-e-ssl-https.html#comments</comments>
		<pubDate>Fri, 12 Oct 2007 11:39:02 +0000</pubDate>
		<dc:creator>gionn</dc:creator>
				<category><![CDATA[Software]]></category>
		<category><![CDATA[Apache]]></category>
		<category><![CDATA[apache2]]></category>
		<category><![CDATA[apache2-ssl-certificate]]></category>
		<category><![CDATA[Debian]]></category>
		<category><![CDATA[https]]></category>
		<category><![CDATA[openssl]]></category>
		<category><![CDATA[pem]]></category>
		<category><![CDATA[ssl]]></category>
		<category><![CDATA[Ubuntu]]></category>

		<guid isPermaLink="false">http://blog.scorpionworld.it/2007/10/12/apache2-e-ssl-https/</guid>
		<description><![CDATA[Non so bene per quale oscuro motivo abbiano segato dai pacchetti binari deb di Debian (e quindi di conseguenza anche da Ubuntu) il tool automatico per la creazione di un certificato PKCS#10 (apache2-ssl-certificate) da usare con mod_ssl di Apache2. Tocca &#8230; <a href="http://blog.scorpionworld.it/apache2-e-ssl-https.html">Continue reading <span class="meta-nav">&#8594;</span></a>]]></description>
			<content:encoded><![CDATA[<p><a href="http://www.flickr.com/photos/laursifer/12533024/"><img src="http://farm1.static.flickr.com/10/12533024_c51a66bf03_m.jpg" alt="apache" class="alignleft" /></a>Non so bene per quale oscuro motivo abbiano segato dai pacchetti binari deb di Debian (e quindi di conseguenza anche da Ubuntu) il tool automatico per la creazione di un certificato PKCS#10 (apache2-ssl-certificate) da usare con mod_ssl di Apache2. Tocca quindi crearsi da soli un certificato self-signed da poter sfruttare utilizzando direttamente openssl.<br />
<span id="more-366"></span><br />
Et voilà :</p>
<pre><code>sudo su
mkdir /etc/apache2/ssl
openssl req -new -x509 -days 365 -nodes -out /etc/apache2/ssl/apache.pem -keyout etc/apache2/ssl/apache.pem</code></pre>
<p>Inserire i dati seguenti a piacere o a fantasia, ma quando viene richiesto il nome inserite il dominio a cui il sito sarà  raggiungibile (tipo www.google.it, ma penso prenda anche l&#8217;indirizzo IP) da cui il vostro sito web è raggiungibile (in codesta maniera eviterete un ulteriore warning dal browser quando i client si collegano).</p>
<p><strong>Update</strong>: meglio tardi che mai.</p>
<pre><code>sudo apt-get install ssl-cert
sudo make-ssl-cert /usr/share/ssl-cert/ssleay.cnf /etc/apache2/ssl/apache.pem</code></pre>
<p>Ora abilitiamo il modulo ssl di Apache2:<br />
<code>a2enmod ssl</code><br />
Aggiungiamo la porta 443 in listening:<br />
<code>nano -w /etc/apache2/ports.conf</code></p>
<pre><code>Listen 80
Listen 443</code></pre>
<p>Ora non resta altro che configurare su quali siti abilitare l&#8217;accesso con SSL, aggiungendo un postfisso al nome del virtualhost e aggiungendo due righe in fondo:</p>
<p>Da:</p>
<pre><code>&lt;VirtualHost 69.36.11.189&gt;
DocumentRoot "/home/fusion-mu/public_html"
ServerName www.sitofacile.org
ServerAlias *.sitofacile.org
Options +FollowSymLinks
&lt;/VirtualHost&gt;</code></pre>
<p>A:</p>
<pre><code>&lt;VirtualHost 69.36.11.189:443&gt;
DocumentRoot "/home/fusion-mu/public_html"
ServerName www.sitofacile.org
Options +FollowSymLinks
SSLEngine on
SSLCertificateFile /etc/apache2/ssl/apache.pem
&lt;/VirtualHost&gt;</code></pre>
<p><a href="http://articles.slicehost.com/2007/9/19/debian-etch-apache-ssl-and-vhosts">[Articolo originale che ha fatto risparmiare un sacco di bestemmie]</a></p>
]]></content:encoded>
			<wfw:commentRss>http://blog.scorpionworld.it/apache2-e-ssl-https.html/feed</wfw:commentRss>
		<slash:comments>2</slash:comments>
		</item>
	</channel>
</rss>
