August 06, 2006

Documented securing (HTTPS) virtual hosts in Apache

Posted in: Apache

Just a quick post, after I just found out how to do this in a very simple way, about some new documentation I created on how-to simply secure multiple virtual domains on your webserver. It’s not perfect (there will be warnings in the browser), but it will work. Continue and read the page to see how simple it can be.

It’s the most simple way to do this without spending any money on official certificates or multiple ip-addresses. Especially that last point was the most difficult to solve. It seems, but I don’t know for sure as I’m not an expert on the subject, that it isn’t possible to configure more than one certificate per ip-address. Forgot the correct explanation and won’t go into wild guessing…

It works for me and I hope it will for you as well.

Note: People will get a warning that your certificate isn’t signed by a certified authority and if you use different domain names the browser will complain that the certificate and the domain don’t match. But if the user will accept the warning and continues the access to the website will be secured by SSL. This is very usefull if you don’t want your password to be send in the clear.

