SSL/TLS का Setup
mod_ssl directives से ज़्यादा है -- मतलब है एक असली certificate लेना, इसे renewed रखना, और TLS को खुद securely configure करना।In this page:
"SSL" बनाम TLS
"SSL" वह नाम है जिसे सब आदत से अब भी इस्तेमाल करते हैं, लेकिन आज असल में जो protocol इस्तेमाल होता है वह TLS है -- SSL का modern successor। Apache का module historical कारणों से अभी भी mod_ssl कहलाता है, और इसके directives (SSLEngine, SSLProtocol) पुराना नाम रखते हैं भले ही वे TLS configure करते हों।
Certbot से Certificate लेना
एक free, trusted certificate पाने का standard तरीका Let's Encrypt (certbot tool के जरिए) है। sudo certbot --apache -d example.com -d www.example.com एक certificate लेता है, matching VirtualHost को automatically edit करके SSL directives add करता है, और HTTP से HTTPS पर एक redirect set up करता है -- SSLCertificateFile हाथ से edit करने से कहीं कम manual।
Automatic Renewal
Let's Encrypt certificates design से सिर्फ 90 दिन चलते हैं, इसलिए certbot एक systemd timer (या cron job) install करता है जो automatically certbot renew चलाता है। sudo certbot renew --dry-run से यह check करना अभी भी worth है कि renewal actually काम करता है, क्योंकि एक चुपचाप टूटा हुआ renewal job मतलब certificate महीनों बाद बिना किसी warning के expire हो जाता है।
certbot renew --dry-run चलाएं, और periodically दोबारा भी -- यह live certificate को छुए बिना renewal process simulate करता है, ताकि आप confirm कर सकें कि यह काम करता है इससे पहले कि actually इसकी ज़रूरत पड़े।Weak Protocols और Ciphers को Restrict करना
SSLProtocol और SSLCipherSuite control करते हैं कि Apache कौन से TLS versions और encryption algorithms accept करेगा। modern practice पुराने, insecure protocol versions को explicitly disable करने की है: SSLProtocol all -SSLv3 -TLSv1 -TLSv1.1 सिर्फ TLS 1.2 और 1.3 को available छोड़ता है, क्योंकि पुराने versions में known weaknesses हैं।
उदाहरण: Restricting to modern TLS versions
<VirtualHost *:443>
ServerName example.com
SSLEngine On
SSLCertificateFile /etc/letsencrypt/live/example.com/fullchain.pem
SSLCertificateKeyFile /etc/letsencrypt/live/example.com/privkey.pem
SSLProtocol all -SSLv3 -TLSv1 -TLSv1.1
</VirtualHost>
{# Flagged by hand after confirming a runner can't handle this example
(a shell command / go.mod file stored as a TopicExample, a language
feature the configured runner version doesn't support, or output
that blows a runner's sandbox limit) -- see TopicExample.norun.
Never render the run button for these, regardless of language,
since it would just fail at execute_code (or worse, hang the
Judge0 queue on a submission that can never finish cleanly). #}
- एक बार certificate set up करना और यह कभी verify न करना कि auto-renewal actually काम करता है, फिर महीनों बाद इसके चुपचाप expire होने पर site down हो जाना।
- SSLProtocol explicitly set न करके पुराने TLS versions (SSLv3, TLS 1.0/1.1) enabled छोड़ना, जिसे कुछ security scanners और compliance checks flag करते हैं।
- certificate के domain name को VirtualHost के ServerName से confuse करना -- एक certificate सिर्फ उन exact domains के लिए valid होता है जिनके लिए यह issue हुआ था।
Chapter Quiz — Complete all 4 topics to unlock
0/4 topics done
Complete these topics first: