× The internal search function is temporarily non-functional. The current search engine is no longer viable and we are researching alternatives.
As a stop gap measure, we are using Google's custom search engine service.
If you know of an easy to use, open source, search engine ... please contact support@midrange.com.



Is there really a space in the IP address for the port 443 listen directive?

If you add the following lines, I would expect https://10.20.30.40/ to take you to the same place http://10.20.30.40/ does.

<VirtualHost 10.20.30.40:443>
  SSLEngine On
  SSLAppName QIBM_HTTP_SERVER_MYINSTANCE
</VirtualHost>

In my case, I used *:443 because I'm only planning on running off one IP therefore only one cert.

When I was installing an SSL cert, I arrived at that solution via the directions in the iSeries Information Center for accessing the web administration server securely. In that example, they used ports 2001 http and 2010 for https.

Thanks,
Alfred

Joe Pluta wrote:

Alfredo Delgado said:

I believe the problem is likely to be in the httpd.conf. Once SSL is working
correctly it shouldn't matter what host name you use to make the secure
connection since the negotiation will be occurring via IP. It's up to the
web browser to warn the user that they may not be where they might be
expecting to be.

Can you share more of the httpd.conf?
---------

"myinstance" is the instance name
"10.20.30.40" is the IP address of the iSeries
I've also got a location set up for validation; this is the context used to
get to WebSphere

I can get to http://10.20.30.40 and http://10.20.30.40:443, but not to
https://10.20.30.40.

Some of the lines are broken by email formatting; hopefully it's clear which
ones.

LoadModule ibm_ssl_module /QSYS.LIB/QHTTPSVR.LIB/QZSRVSSL.SRVPGM
WebSpherePluginConfig
/QIBM/UserData/WebASE/ASE5/MYINSTANCE/config/cells/plugin-cfg.xml
LoadModule ibm_app_server_http_module
/QSYS.LIB/QHTTPSVR.LIB/QSVTIHSAH.SRVPGM
# HTTP server (powered by Apache) configuration
DocumentRoot /www/myinstance/htdocs
ServerRoot /www/myinstance
Options -ExecCGI -FollowSymLinks -SymLinksIfOwnerMatch -Includes
-IncludesNoExec -Indexes -MultiViews
Listen 10.20.30.40:80
Listen 10. 20.30.40:443
TimeOut 600
LogLevel Debug
LogFormat "%h %l %u %t \"%r\" %>s %b \"%{Referer}i\" \"%{User-Agent}i\""
combined
LogFormat "%{Cookie}n \"%r\" %t" cookie
LogFormat "%{User-agent}i" agent
LogFormat "%{Referer}i -> %U" referer
LogFormat "%h %l %u %t \"%r\" %>s %b" common
CustomLog logs/access_log combined
SetEnvIf "User-Agent" "Mozilla/2" nokeepalive
SetEnvIf "User-Agent" "JDK/1\.0" force-response-1.0
SetEnvIf "User-Agent" "Java/1\.0" force-response-1.0
SetEnvIf "User-Agent" "RealPlayer 4\.0" force-response-1.0
SetEnvIf "User-Agent" "MSIE 4\.0b2;" nokeepalive
SetEnvIf "User-Agent" "MSIE 4\.0b2;" force-response-1.0
SSLEngine Optional
# SSLEngine On
SSLAppName QIBM_HTTP_SERVER_MYINSTANCE
SSLCacheEnable
SSLVersion TLSV1_SSLV3
SetEnv HTTPS_PORT 443
<Directory />
  Order Deny,Allow
  Deny From all
</Directory>
<Directory /www/myinstance/htdocs>
  Order Allow,Deny
  Allow From all
</Directory>
<Location /WSApp>
  PasswdFile WSAPPLIB/WSAPPVLDL
  AuthType Basic
  AuthName WSApp
  Require valid-user
</Location>




As an Amazon Associate we earn from qualifying purchases.

This thread ...

Follow-Ups:
Replies:

Follow On AppleNews
Return to Archive home page | Return to MIDRANGE.COM home page

This mailing list archive is Copyright 1997-2024 by midrange.com and David Gibbs as a compilation work. Use of the archive is restricted to research of a business or technical nature. Any other uses are prohibited. Full details are available on our policy page. If you have questions about this, please contact [javascript protected email address].

Operating expenses for this site are earned using the Amazon Associate program and Google Adsense.