Install SSL cert on BOA

Events happening in the community are now at Drupal community events on www.drupal.org.
juc1's picture

Hi all,

Has anyone installed an SSL certificate on a BOA website eg for a shop? There are some instructions here for installing an SSL cert on nginx but I wonder if BOA will diverge from this eg at steps five and six where it mentions /etc/nginx/sites-available. Any ideas please??

Comments

Have you read the docs on the

jamiet's picture

Have you read the docs on the Barracuda drupalcode project link below may be a good start.

http://drupalcode.org/project/barracuda.git/blob/HEAD:/docs/SSL.txt

@ jamiet thanks but isn't

juc1's picture

@ jamiet thanks but isn't that link a different subject = "How to use multiple IPs on your server" ?

SSL

ar-jan's picture

That's because typically you'll want to add at least one extra IP address.
See this discussion.

So (as far as I understand) you can either replace BOA's built-in wildcard certificate and use that for everything, or add an extra IP address and configure another local proxy for it following the recipe.

exactly

jimsmith's picture

To get SSL to work you need to follow the documentation exactly as written at http://drupalcode.org/project/barracuda.git/blob/HEAD:/docs/SSL.txt. Don't do as I did and over-think it or assume you know better. When I followed the documentation it worked as expected. I guess that's why it's there.

exactly

jimsmith's picture

And I'm not trying to be snarky; just speaking from experience.

@ ar-jan and JimSmith ok

juc1's picture

@ ar-jan and JimSmith ok thanks. I am thinking of hosting on Digital Ocean for now and they do not allow multiple IPs on the same server. So I think for now (ie not meant to be ideal or permanent) I will use the second method mentioned by Omega8cc said in ar-jan's link above:

You can also replace the self-signed cert created by Barracuda and then it will work with our standard, built-in SSL proxy, without extra IP...

If so are there any instructions out there for this? Going back to the link I mentioned in my first post above do I still need to go through the steps of creating the new certificate before I replace the existing BOA certificate?

Thanks...

BOA

Group organizers

Group notifications

This group offers an RSS feed. Or subscribe to these personalized, sitewide feeds: