1

Let's say you have a web app and you distribute an embedded Apache HTTPD with that web app. It's difficult to manage customers that want to run SSL. The best way appears to be to let the customer manage installing SSL certificates on the embedded Apache -- or to recommend the customer use a front-end SSL accelerator card or pizza box.

Are there better ways of doing this?

2 Answers 2

1

You've pretty much covered it. SSL requires the user install valid certs. The best you can do is give them good instructions on how to do so.

1

One option I've seen on embedded systems that's potentially easier to configure than using Apache's built-in support for SSL is stunnel.

It handles all of the SSL layer, and then communicates with the local web server over the loopback interface.

If the only reason to run Apache is to get SSL support, this can provide a way of running an alternate HTTP server with a smaller footprint.

1
  • Currently, we use Apache HTTPD for multiple purposes, but I'll keep stunnel in mind in case it fits a future use. Thanks. Commented May 4, 2009 at 22:57

You must log in to answer this question.

Start asking to get answers

Find the answer to your question by asking.

Ask question

Explore related questions

See similar questions with these tags.