← Back to Apache Course | Chapter 4: Security | Lesson 2 of 4

SSL/TLS का Setup

HTTPS को असल में end-to-end काम करवाने का मतलब सिर्फ mod_ssl directives से ज़्यादा है -- मतलब है एक असली certificate लेना, इसे renewed रखना, और TLS को खुद securely configure करना।

"SSL" बनाम TLS

"SSL" वह नाम है जिसे सब आदत से अब भी इस्तेमाल करते हैं, लेकिन आज असल में जो protocol इस्तेमाल होता है वह TLS है -- SSL का modern successor। Apache का module historical कारणों से अभी भी mod_ssl कहलाता है, और इसके directives (SSLEngine, SSLProtocol) पुराना नाम रखते हैं भले ही वे TLS configure करते हों।

Certbot से Certificate लेना

एक free, trusted certificate पाने का standard तरीका Let's Encrypt (certbot tool के जरिए) है। sudo certbot --apache -d example.com -d www.example.com एक certificate लेता है, matching VirtualHost को automatically edit करके SSL directives add करता है, और HTTP से HTTPS पर एक redirect set up करता है -- SSLCertificateFile हाथ से edit करने से कहीं कम manual।

Automatic Renewal

Let's Encrypt certificates design से सिर्फ 90 दिन चलते हैं, इसलिए certbot एक systemd timer (या cron job) install करता है जो automatically certbot renew चलाता है। sudo certbot renew --dry-run से यह check करना अभी भी worth है कि renewal actually काम करता है, क्योंकि एक चुपचाप टूटा हुआ renewal job मतलब certificate महीनों बाद बिना किसी warning के expire हो जाता है।

Note: setup के तुरंत बाद certbot renew --dry-run चलाएं, और periodically दोबारा भी -- यह live certificate को छुए बिना renewal process simulate करता है, ताकि आप confirm कर सकें कि यह काम करता है इससे पहले कि actually इसकी ज़रूरत पड़े।

Weak Protocols और Ciphers को Restrict करना

SSLProtocol और SSLCipherSuite control करते हैं कि Apache कौन से TLS versions और encryption algorithms accept करेगा। modern practice पुराने, insecure protocol versions को explicitly disable करने की है: SSLProtocol all -SSLv3 -TLSv1 -TLSv1.1 सिर्फ TLS 1.2 और 1.3 को available छोड़ता है, क्योंकि पुराने versions में known weaknesses हैं।

उदाहरण: Restricting to modern TLS versions

apacheconf
<VirtualHost *:443>
    ServerName example.com
    SSLEngine On
    SSLCertificateFile /etc/letsencrypt/live/example.com/fullchain.pem
    SSLCertificateKeyFile /etc/letsencrypt/live/example.com/privkey.pem

    SSLProtocol all -SSLv3 -TLSv1 -TLSv1.1
</VirtualHost>
{# Flagged by hand after confirming a runner can't handle this example (a shell command / go.mod file stored as a TopicExample, a language feature the configured runner version doesn't support, or output that blows a runner's sandbox limit) -- see TopicExample.norun. Never render the run button for these, regardless of language, since it would just fail at execute_code (or worse, hang the Judge0 queue on a submission that can never finish cleanly). #}

⚠️ This example can't run in the browser editor. Try it in your own local environment instead.

{# common_mistakes/chapter_summary/browser_support: on Hindi pages the view already swaps in the hi_ translation fields (or blanks these out if untranslated), so this renders correctly for both languages without a lang_code check here. #}
आम गलतियां
  1. एक बार certificate set up करना और यह कभी verify न करना कि auto-renewal actually काम करता है, फिर महीनों बाद इसके चुपचाप expire होने पर site down हो जाना।
  2. SSLProtocol explicitly set न करके पुराने TLS versions (SSLv3, TLS 1.0/1.1) enabled छोड़ना, जिसे कुछ security scanners और compliance checks flag करते हैं।
  3. certificate के domain name को VirtualHost के ServerName से confuse करना -- एक certificate सिर्फ उन exact domains के लिए valid होता है जिनके लिए यह issue हुआ था।
🔒

Chapter Quiz — Complete all 4 topics to unlock

0/4 topics done

Complete these topics first:

Login to run this code

C/C++/Java/PHP execution requires a free account. Your code is saved — you'll land right back in the editor after logging in.