Skip to main content

CHUYỂN SSL SANG LEGACY SSL

 CHUYỂN SSL SANG LEGACY SSL

Một số server hoặc application cũ không hỗ trợ SSL cipher mới, buộc phải "convert" về định dạng legacy. Cách thực hiện là dùng OpenSSL

1. Tải và cài đặt OpenSSL

2. Cấu hình lại file config để load Legacy module

- Mở CMD, 

- Kiểm tra file config OpenSSL: 

openssl version -d

- Kiểm provider:

openssl list -providers


3. Sửa cấu hình file openssl.cnf

- Mở file openssl.cnf (thường ở thư mục Program Files\Common Files)

- Thêm dòng 

legacy = legacy_sect

- Xóa dấu # trước [Default sect]

- Thêm dòng:

[legacy_sect]

activate = 1

4. Kiểm tra lại provider:



5. Chỉnh lại đường dẫn môi trường dll.

Trong 1 số trường hợp OpenSSL bị sai đường dẫn thư viện, cần tìm đường dẫn và chỉnh lại cho chính xác:

setx OPENSSL_MODULES "C:\Program Files\OpenSSL-Win64\bin"


6. Chạy lệnh convert SSL:

openssl pkcs12 -in new.pfx -out temp.pem -provider legacy -nodes

(*) "new.pfx" là file ssl hiện tại, "temp.pem" là file xuất tạm

openssl pkcs12 -export -in temp.pem -out legacy.pfx -legacy

(*) "legacy.pfx" là file đã convert qua legacy


Comments

Popular posts from this blog

[RAID] SWITCH FROM AHCI TO RAID WITH INTEL C600 CONTROLLER

I personally have used other ways to do this. Manipulating some registry settings in combination with a safe boot before booting normally does the trick as well. This works with both SATA SSD and M.2 NVMe drives and it enables relatively fast switching between back and forth between AHCI and RAID. I have described this method below.  I have also tried the same process used to switch from RAD to AHCI and that works as well. Switch to safe boot Reboot into BIOS Change from AHCI to RAID in the BIOS Boot into safe mode Turn off safe mode and reboot normally again Nothing else and that also did the trick, just like with moving from RAID to AHCI.  So the link above and my step by step below is here for completeness. You have options in case one of them doesn’t work! Step by step AHCI to RAID registry method This procedure I describe below works on Windows 10 1803/1809 and has been tested on Dell Latitude E6220 an XPS 13 9360. Editing the registry is...

LỖI KHÔNG TẠO PIN CODE ĐỂ DÙNG HELLO LOGIN

Lỗi  0x801C044D khi khởi tạo PIN code  Nguyên nhân:  Authorization token does not contain device ID Tham khảo:  https://docs.microsoft.com/en-us/windows/security/identity-protection/hello-for-business/hello-errors-during-pin-creation Cách xử lý:  Unjoin the device from Azure AD and rejoin. Làm như sau: Vào Settings > Accounts > Access work or school Disconnect tất cả các tài khoản link với Azure (Cloud) Reboot lại máy

CÀI ĐẶT NGINX PROXY MANAGER TRÊN UBUNTU 22

  CÀI ĐẶT NGINX PROXY MANAGER TRÊN UBUNTU 22 Link: https://azdigi.com/blog/en/linux-server-en/web-server/how-to-install-nginx-proxy-manager-with-docker-compose-on-ubuntu-22-04/ First, you need to create a directory containing the project and create a  docker-compose.yml  file for Nginx Proxy Manager with the following commands in turn:     AZDIGI Tutorial mkdir /home/nginxproxymanager cd /home/nginxproxymanager nano docker-compose.yml Enter the content below and save it. version: '3' services: app: image: 'jc21/nginx-proxy-manager:latest' restart: unless-stopped ports: - '80:80' - '81:81' - '443:443' environment: DB_MYSQL_HOST: "db" DB_MYSQL_PORT: 3306 DB_MYSQL_USER: "npm" DB_MYSQL_PASSWORD: "npm" DB_MYSQL_NAME: "npm" volumes: - ./data:/data - ./letsencrypt:/etc/letsencrypt db: image: 'jc21/mariadb-aria:latest...