douzuizhuo0587 2015-01-31 17:05 采纳率: 0%
浏览 45
已采纳

ssl on apache2 debian safe没有公开认可的CA用于cURL设置

I have two servers, A and B. They both run on the same code base and run on debian with apache2.

I need to securely & periodically check a REST response from serverA with serverB.

I have built a simple cURL script to connect to serverA from serverB with basic auth:

<?php
$url = 'http://mydomain/restpath/get';
$ch = curl_init($url);
$username = 'username';
$password = 'password';
// Timeout in seconds
curl_setopt($ch, CURLOPT_TIMEOUT, 10);
// Include header in result? (0 = yes, 1 = no)
curl_setopt($ch, CURLOPT_HEADER, 0 );
// Should cURL return or print out the data? (true = return, false = print)
curl_setopt($ch, CURLOPT_RETURNTRANSFER, true);
//set the basic auth to any then set the creds
curl_setopt($ch, CURLOPT_HTTPAUTH, CURLAUTH_ANY);
curl_setopt($ch, CURLOPT_USERPWD, "$username:$password");
$status_code = curl_getinfo($ch, CURLINFO_HTTP_CODE);   //get status code
// Download the given URL, and return output
$output = curl_exec($ch);
// Close the cURL resource, and free system resources
curl_close($ch);

The credentials here will be passed in plaintext.. to secure I intend to use a HTTPS connection.

## My knowledge on https certs is beginner ##

is it safe to just use the defualt certs declared in the example ssl vhost conf supplied with apache:

SSLCertificateFile      /etc/ssl/certs/ssl-cert-snakeoil.pem
SSLCertificateKeyFile /etc/ssl/private/ssl-cert-snakeoil.key

Or is there a little more that I would need to do?

Thanks, John

  • 写回答

1条回答 默认 最新

  • dtntjwkl83750 2015-01-31 17:21
    关注

    In writing the question and realised what the correct question should have been, and has already been answered here:

    https://superuser.com/questions/700170/are-ssls-default-snake-oil-certificates-truly-snake-oil-as-opposed-to-being-gen

    本回答被题主选为最佳回答 , 对您是否有帮助呢?
    评论

报告相同问题?

悬赏问题

  • ¥15 乘性高斯噪声在深度学习网络中的应用
  • ¥15 运筹学排序问题中的在线排序
  • ¥15 关于docker部署flink集成hadoop的yarn,请教个问题 flink启动yarn-session.sh连不上hadoop,这个整了好几天一直不行,求帮忙看一下怎么解决
  • ¥30 求一段fortran代码用IVF编译运行的结果
  • ¥15 深度学习根据CNN网络模型,搭建BP模型并训练MNIST数据集
  • ¥15 C++ 头文件/宏冲突问题解决
  • ¥15 用comsol模拟大气湍流通过底部加热(温度不同)的腔体
  • ¥50 安卓adb backup备份子用户应用数据失败
  • ¥20 有人能用聚类分析帮我分析一下文本内容嘛
  • ¥30 python代码,帮调试,帮帮忙吧