Beste,
Ik kreeg vandaag in het logboek van mijn server het volgende:
Toch wil ik mijn SSL certificaten gaan vervangen echter weet ik niet of de persoon dan weer kan toeslaan.
OpenSSL versie: OpenSSL 1.0.1e-fips 11 Feb 2013
OS: CentOS
Ik kreeg vandaag in het logboek van mijn server het volgende:
In het logboek van apache kwam ik het volgende tegen:2014-04-18 10:22:05 TLS client disconnected cleanly (rejected our certificate?): 1 Time(s)
2014-04-18 10:22:05 TLS error on connection from 5ed2115b.cm-7-3a.dynamic.ziggo.nl [94.210.17.91] (SSL_accept): error:1406B0CB:SSL routines:GET_CLIENT_MASTER_KEY:peer error no cipher: 1 Time(s)
2014-04-18 12:08:32 TLS client disconnected cleanly (rejected our certificate?): 1 Time(s)
2014-04-18 12:08:32 TLS error on connection from 5ed2115b.cm-7-3a.dynamic.ziggo.nl (openssl.client.net) [94.210.17.91] (SSL_accept): error:1406B0CB:SSL routines:GET_CLIENT_MASTER_KEY:peer error no cipher: 1 Time(s)
Voorzover als ik in deze logboeken kan zien is er niets gelekt omtrent de "masterkey", is er nog een ander log behalve auth.log, access.log en error.log waar de ssl requests worden opgeslagen?[Sat Apr 19 00:11:02.016534 2014] [ssl:warn] [pid 28555] AH02292: Init: Name-based SSL virtual hosts only work for clients with TLS server name indication support (RFC 4366)
[Sat Apr 19 00:11:02.016602 2014] [suexec:notice] [pid 28555] AH01232: suEXEC mechanism enabled (wrapper: /usr/sbin/suexec)
[Sat Apr 19 00:11:02.058611 2014] [so:warn] [pid 28555] AH01574: module php5_module is already loaded, skipping
[Sat Apr 19 00:11:02.086443 2014] [auth_digest:notice] [pid 28556] AH01757: generating secret for digest authentication ...
[Sat Apr 19 00:11:03.007518 2014] [ssl:warn] [pid 28556] AH01909: RSA certificate configured for localhost:443 does NOT include an ID which matches the server name
[Sat Apr 19 00:11:03.007961 2014] [ssl:warn] [pid 28556] AH01909: RSA certificate configured for localhost:443 does NOT include an ID which matches the server name
[Sat Apr 19 00:11:03.008157 2014] [ssl:warn] [pid 28556] AH02292: Init: Name-based SSL virtual hosts only work for clients with TLS server name indication support (RFC 4366)
[Sat Apr 19 00:11:03.008200 2014] [lbmethod_heartbeat:notice] [pid 28556] AH02282: No slotmem from mod_heartmonitor
[Sat Apr 19 00:11:03.031306 2014] [mpm_prefork:notice] [pid 28556] AH00163: Apache/2.4.7 (Unix) OpenSSL/1.0.1e-fips configured -- resuming normal operations
[Sat Apr 19 00:11:03.031431 2014] [core:notice] [pid 28556] AH00094: Command line: '/usr/sbin/httpd -D SSL'
Toch wil ik mijn SSL certificaten gaan vervangen echter weet ik niet of de persoon dan weer kan toeslaan.
OpenSSL versie: OpenSSL 1.0.1e-fips 11 Feb 2013
OS: CentOS
[ Voor 0% gewijzigd door Schuurdeur op 19-04-2014 10:44 . Reden: Typo ]