← Back to Apache Course | Chapter 3: Modules | Lesson 2 of 5

mod_ssl का उपयोग

mod_ssl वह Apache module है जो HTTPS support जोड़ता है -- TLS certificates इस्तेमाल करके browser और server के बीच traffic encrypt करना। इसके बिना, Apache सिर्फ plain, unencrypted HTTP serve कर सकता है।

mod_ssl Enable करना

Ubuntu/Debian पर: sudo a2enmod ssl उसके बाद एक reload। RHEL-family systems पर, mod_ssl package install करना (sudo yum install mod_ssl) इसे install और enable दोनों करता है, और आमतौर पर एक starter /etc/httpd/conf.d/ssl.conf drop करता है।

मुख्य Directives

एक <VirtualHost *:443> block के अंदर, तीन directives असली काम करते हैं: SSLEngine On उस virtual host के लिए TLS on करता है, SSLCertificateFile site के certificate की ओर point करता है, और SSLCertificateKeyFile इसकी private key की ओर point करता है। कई CAs trust की chain browsers verify कर सकें इसके लिए SSLCertificateChainFile (या एक combined bundle) भी माँगते हैं।

एक Certificate लेना

इनमें से कुछ भी काम करने से पहले आपको एक असली TLS certificate चाहिए। free certbot tool के जरिए Let's Encrypt standard modern choice है और certbot --apache से आपका Apache VirtualHost automatically edit भी कर सकता है। local testing के लिए एक self-signed certificate काम करता है लेकिन browser warning दिखाएगा, क्योंकि कोई public certificate authority इसकी vouch नहीं करती।

HTTP को HTTPS पर Redirect करना

same domain के लिए एक अलग <VirtualHost *:80> block आमतौर पर सिर्फ उन visitors को redirect करने के लिए exist करता है जो plain http:// address type करते हैं https:// पर, आमतौर पर mod_rewrite से (पिछले lesson में दिखाया गया) या एक plain Redirect permanent / https://example.com/।

Note: certificate paths को अपने renewal tool के साथ sync रखें -- Let's Encrypt certificates हर 90 दिन में expire होते हैं, और certbot renew (आमतौर पर एक cron job या systemd timer से automatically चलता है) को बाद में नया certificate लागू होने के लिए actually Apache reload करना होता है।

उदाहरण: An HTTPS VirtualHost with mod_ssl

apacheconf
<VirtualHost *:443>
    ServerName example.com
    DocumentRoot /var/www/example.com/public

    SSLEngine On
    SSLCertificateFile /etc/ssl/certs/example.com.crt
    SSLCertificateKeyFile /etc/ssl/private/example.com.key
    SSLCertificateChainFile /etc/ssl/certs/example.com-chain.crt
</VirtualHost>

<VirtualHost *:80>
    ServerName example.com
    Redirect permanent / https://example.com/
</VirtualHost>
{# Flagged by hand after confirming a runner can't handle this example (a shell command / go.mod file stored as a TopicExample, a language feature the configured runner version doesn't support, or output that blows a runner's sandbox limit) -- see TopicExample.norun. Never render the run button for these, regardless of language, since it would just fail at execute_code (or worse, hang the Judge0 queue on a submission that can never finish cleanly). #}

⚠️ This example can't run in the browser editor. Try it in your own local environment instead.

{# common_mistakes/chapter_summary/browser_support: on Hindi pages the view already swaps in the hi_ translation fields (or blanks these out if untranslated), so this renders correctly for both languages without a lang_code check here. #}
आम गलतियां
  1. SSLCertificateFile को सिर्फ domain certificate पर point करना और SSLCertificateChainFile/intermediate bundle skip करना, जो कुछ browsers में काम करता है लेकिन दूसरों में validation fail करता है।
  2. अलग port 80 VirtualHost भूल जाना, ताकि जो visitors https:// के बिना bare domain type करें उन्हें कभी secure version पर redirect ही न मिले।
  3. एक Let's Encrypt certificate को expire होने देना क्योंकि renewal job renew करने के बाद actually Apache को कभी reload नहीं करता, पुरानी (अब invalid) certificate file को इस्तेमाल में छोड़ते हुए।
🔒

Chapter Quiz — Complete all 5 topics to unlock

0/5 topics done

Complete these topics first:

Login to run this code

C/C++/Java/PHP execution requires a free account. Your code is saved — you'll land right back in the editor after logging in.