[{"data":1,"prerenderedAt":581},["ShallowReactive",2],{"i-lucide:menu":3,"i-lucide:arrow-up-right":8,"i-lucide:moon":10,"i-lucide:sun":12,"i-lucide:rss":14,"i-simple-icons:github":16,"i-simple-icons:linkedin":18,"post-\u002F2016\u002Fserving-https-web-pages-with-apache-and-letsencrypt":21,"surround-\u002F2016\u002Fserving-https-web-pages-with-apache-and-letsencrypt":568,"i-lucide:arrow-left":577,"i-lucide:arrow-right":579},{"left":4,"top":4,"width":5,"height":5,"rotate":4,"vFlip":6,"hFlip":6,"body":7},0,24,false,"\u003Cpath fill=\"none\" stroke=\"currentColor\" stroke-linecap=\"round\" stroke-linejoin=\"round\" stroke-width=\"2\" d=\"M4 5h16M4 12h16M4 19h16\"\u002F>",{"left":4,"top":4,"width":5,"height":5,"rotate":4,"vFlip":6,"hFlip":6,"body":9},"\u003Cpath fill=\"none\" stroke=\"currentColor\" stroke-linecap=\"round\" stroke-linejoin=\"round\" stroke-width=\"2\" d=\"M7 7h10v10M7 17L17 7\"\u002F>",{"left":4,"top":4,"width":5,"height":5,"rotate":4,"vFlip":6,"hFlip":6,"body":11},"\u003Cpath fill=\"none\" stroke=\"currentColor\" stroke-linecap=\"round\" stroke-linejoin=\"round\" stroke-width=\"2\" d=\"M20.985 12.486a9 9 0 1 1-9.473-9.472c.405-.022.617.46.402.803a6 6 0 0 0 8.268 8.268c.344-.215.825-.004.803.401\"\u002F>",{"left":4,"top":4,"width":5,"height":5,"rotate":4,"vFlip":6,"hFlip":6,"body":13},"\u003Cg fill=\"none\" stroke=\"currentColor\" stroke-linecap=\"round\" stroke-linejoin=\"round\" stroke-width=\"2\">\u003Ccircle cx=\"12\" cy=\"12\" r=\"4\"\u002F>\u003Cpath d=\"M12 2v2m0 16v2M4.93 4.93l1.41 1.41m11.32 11.32l1.41 1.41M2 12h2m16 0h2M6.34 17.66l-1.41 1.41M19.07 4.93l-1.41 1.41\"\u002F>\u003C\u002Fg>",{"left":4,"top":4,"width":5,"height":5,"rotate":4,"vFlip":6,"hFlip":6,"body":15},"\u003Cg fill=\"none\" stroke=\"currentColor\" stroke-linecap=\"round\" stroke-linejoin=\"round\" stroke-width=\"2\">\u003Cpath d=\"M4 11a9 9 0 0 1 9 9M4 4a16 16 0 0 1 16 16\"\u002F>\u003Ccircle cx=\"5\" cy=\"19\" r=\"1\"\u002F>\u003C\u002Fg>",{"left":4,"top":4,"width":5,"height":5,"rotate":4,"vFlip":6,"hFlip":6,"body":17},"\u003Cpath fill=\"currentColor\" d=\"M12 .297c-6.63 0-12 5.373-12 12c0 5.303 3.438 9.8 8.205 11.385c.6.113.82-.258.82-.577c0-.285-.01-1.04-.015-2.04c-3.338.724-4.042-1.61-4.042-1.61C4.422 18.07 3.633 17.7 3.633 17.7c-1.087-.744.084-.729.084-.729c1.205.084 1.838 1.236 1.838 1.236c1.07 1.835 2.809 1.305 3.495.998c.108-.776.417-1.305.76-1.605c-2.665-.3-5.466-1.332-5.466-5.93c0-1.31.465-2.38 1.235-3.22c-.135-.303-.54-1.523.105-3.176c0 0 1.005-.322 3.3 1.23c.96-.267 1.98-.399 3-.405c1.02.006 2.04.138 3 .405c2.28-1.552 3.285-1.23 3.285-1.23c.645 1.653.24 2.873.12 3.176c.765.84 1.23 1.91 1.23 3.22c0 4.61-2.805 5.625-5.475 5.92c.42.36.81 1.096.81 2.22c0 1.606-.015 2.896-.015 3.286c0 .315.21.69.825.57C20.565 22.092 24 17.592 24 12.297c0-6.627-5.373-12-12-12\"\u002F>",{"left":4,"top":4,"width":5,"height":5,"rotate":4,"vFlip":6,"hFlip":6,"body":19,"hidden":20},"\u003Cpath fill=\"currentColor\" d=\"M20.447 20.452h-3.554v-5.569c0-1.328-.027-3.037-1.852-3.037c-1.853 0-2.136 1.445-2.136 2.939v5.667H9.351V9h3.414v1.561h.046c.477-.9 1.637-1.85 3.37-1.85c3.601 0 4.267 2.37 4.267 5.455v6.286zM5.337 7.433a2.06 2.06 0 0 1-2.063-2.065a2.064 2.064 0 1 1 2.063 2.065m1.782 13.019H3.555V9h3.564zM22.225 0H1.771C.792 0 0 .774 0 1.729v20.542C0 23.227.792 24 1.771 24h20.451C23.2 24 24 23.227 24 22.271V1.729C24 .774 23.2 0 22.222 0z\"\u002F>",true,{"id":22,"title":23,"body":24,"category":555,"comments":556,"date":557,"description":558,"excerpt":556,"extension":559,"image":556,"meta":560,"navigation":20,"path":561,"readingTime":562,"seo":563,"stem":564,"subtitle":565,"tags":556,"wordCount":566,"__hash__":567},"posts\u002F2016\u002Fserving-https-web-pages-with-apache-and-letsencrypt.md","Serving HTTPS Web Pages With Apache and Letsencrypt",{"type":25,"value":26,"toc":547},"minimark",[27,39,42,47,69,73,76,85,92,95,101,104,110,116,120,123,129,138,176,179,185,188,194,197,201,208,214,218,226,235,278,285,297,300,306,309,315,318,324,330,333,339,345,348,351,357,364,515,518,524,528,531,534,543],[28,29,30,31,38],"p",{},"The topic of encryption and privacy has been widely focused on after the ",[32,33,37],"a",{"href":34,"rel":35},"https:\u002F\u002Fen.wikipedia.org\u002Fwiki\u002FEdward_Snowden",[36],"nofollow","Snowden revalations",". Suddenly, people realize that much of everything we do online is done using insecure channels. One of those channels is unencrypted web traffic.",[28,40,41],{},"In this tutorial, we'll look at how you can set up an encrypted web page quickly and for free. We will provision a new virtual server, install a web server and set up HTTPS.",[43,44,46],"h2",{"id":45},"you-will-need","You Will Need",[48,49,50,60,63,66],"ul",{},[51,52,53,54,59],"li",{},"A computer with a SSH client (Linux or ",[32,55,58],{"href":56,"rel":57},"http:\u002F\u002Fwww.chiark.greenend.org.uk\u002F~sgtatham\u002Fputty",[36],"Putty"," on Windows)",[51,61,62],{},"A domain name you control",[51,64,65],{},"A Ubuntu 14.04  Server or a credit card",[51,67,68],{},"Basic knowledge of Ubuntu server administration",[43,70,72],{"id":71},"provisioning-a-server","Provisioning a Server",[28,74,75],{},"If you already have a server, skip this step.",[28,77,78,79,84],{},"We'll create a new web server using DigitalOcean. Log in to your account (or ",[32,80,83],{"href":81,"rel":82},"https:\u002F\u002Fm.do.co\u002Fc\u002F6866ad4ad2b9",[36],"create one","). Create a new Droplet using Ubuntu 14.04 as the base image.",[28,86,87],{},[88,89],"img",{"alt":90,"src":91},"Create Ubuntu Server","\u002Fcontent\u002F2016\u002F05\u002Fapache\u002Fcreate-1.png",[28,93,94],{},"Add your SSH key to the server and give the server a host name.",[28,96,97],{},[88,98],{"alt":99,"src":100},"Naming the Server","\u002Fcontent\u002F2016\u002F05\u002Fapache\u002Fcreate-2.png",[28,102,103],{},"After about a minute, the server is ready. Copy the IP and log in with SSH:",[28,105,106],{},[88,107],{"alt":108,"src":109},"Server is Ready","\u002Fcontent\u002F2016\u002F05\u002Fapache\u002Fcreate-3.png",[28,111,112],{},[88,113],{"alt":114,"src":115},"SSH Login","\u002Fcontent\u002F2016\u002F05\u002Fapache\u002Fssh-login.png",[43,117,119],{"id":118},"installing-the-web-server","Installing The Web Server",[28,121,122],{},"We now have a server on the Internet, but there's nothing there yet - visiting the IP address with a browser gives an error.",[28,124,125],{},[88,126],{"alt":127,"src":128},"No Reply","\u002Fcontent\u002F2016\u002F05\u002Fapache\u002Fno-reply.png",[28,130,131,132,137],{},"Let's install ",[32,133,136],{"href":134,"rel":135},"https:\u002F\u002Fapache.com",[36],"Apache",", an open-source web server.",[139,140,145],"pre",{"className":141,"code":142,"language":143,"meta":144,"style":144},"language-bash shiki shiki-themes github-light github-dark","apt-get update\napt-get install -y apache2\n","bash","",[146,147,148,161],"code",{"__ignoreMap":144},[149,150,153,157],"span",{"class":151,"line":152},"line",1,[149,154,156],{"class":155},"sScJk","apt-get",[149,158,160],{"class":159},"sZZnC"," update\n",[149,162,164,166,169,173],{"class":151,"line":163},2,[149,165,156],{"class":155},[149,167,168],{"class":159}," install",[149,170,172],{"class":171},"sj4cs"," -y",[149,174,175],{"class":159}," apache2\n",[28,177,178],{},"After the command finishes, we can refresh the browser - the web server is running and displays the default welcome page.",[28,180,181],{},[88,182],{"alt":183,"src":184},"Welcome Page","\u002Fcontent\u002F2016\u002F05\u002Fapache\u002Fwelcome.png",[28,186,187],{},"Notice that the site is running over HTTP and is not encrypted in transit. This is how much of the Internet currently looks. In practical terms, this means that if you, the visitor, browse to this page in a public airport  network and I, the mean person am there too, I could see everything you do.",[28,189,190],{},[88,191],{"alt":192,"src":193},"Inspecting HTTP traffic","\u002Fcontent\u002F2016\u002F05\u002Fapache\u002Fwireshark.png",[28,195,196],{},"To avoid this and maintain communication privacy, we'll configure the server with HTTPS.",[43,198,200],{"id":199},"binding-a-domain","Binding a Domain",[28,202,203,204,207],{},"To get a HTTPS certificate, we need a domain name. Log in to your domain name server management interface and add a new A-record. I want my web page to be located at ",[146,205,206],{},"secret.sqroot.eu"," (1), so I added the following:",[28,209,210],{},[88,211],{"alt":212,"src":213},"Create a DNS record","\u002Fcontent\u002F2016\u002F05\u002Fapache\u002Fdns.png",[43,215,217],{"id":216},"ordering-certificates","Ordering Certificates",[28,219,220,225],{},[32,221,224],{"href":222,"rel":223},"https:\u002F\u002Fletsencrypt.org",[36],"LetsEncrypt"," is a free certificate authority that is revolutionizing the way we think of basic SSL certificates. It used to be that people would have to pay for HTTPS certificates - cryptographic proofs of identity that \"prove\" the web site is who it says it is. Those certificates are needed to enable HTTPS, hence HTTPS was costing money - at least 10€ \u002F year. LetsEncrypt was created to make HTTPS available for everyone.",[28,227,228,229,234],{},"Let us install the ",[32,230,233],{"href":231,"rel":232},"https:\u002F\u002Fletsencrypt.org\u002Fgetting-started",[36],"LetsEncrypt client",". The client is used for making certificate requests to LetsEncrypt server as well as configuring our local web server with certificate information.",[139,236,238],{"className":141,"code":237,"language":143,"meta":144,"style":144},"apt-get install git\ngit clone https:\u002F\u002Fgithub.com\u002Fletsencrypt\u002Fletsencrypt\ncd letsencrypt\n.\u002Fletsencrypt-auto --help\n",[146,239,240,249,260,269],{"__ignoreMap":144},[149,241,242,244,246],{"class":151,"line":152},[149,243,156],{"class":155},[149,245,168],{"class":159},[149,247,248],{"class":159}," git\n",[149,250,251,254,257],{"class":151,"line":163},[149,252,253],{"class":155},"git",[149,255,256],{"class":159}," clone",[149,258,259],{"class":159}," https:\u002F\u002Fgithub.com\u002Fletsencrypt\u002Fletsencrypt\n",[149,261,263,266],{"class":151,"line":262},3,[149,264,265],{"class":171},"cd",[149,267,268],{"class":159}," letsencrypt\n",[149,270,272,275],{"class":151,"line":271},4,[149,273,274],{"class":155},".\u002Fletsencrypt-auto",[149,276,277],{"class":171}," --help\n",[28,279,280,281,284],{},"Running ",[146,282,283],{},"letsencrypt-auto"," will install all the dependencies of LetsEncrypt. This might take a while. When the install finishes, we'll run LetsEncrypt again, this time in interactive mode:",[139,286,288],{"className":141,"code":287,"language":143,"meta":144,"style":144},".\u002Fletsencrypt-auto --apache\n",[146,289,290],{"__ignoreMap":144},[149,291,292,294],{"class":151,"line":152},[149,293,274],{"class":155},[149,295,296],{"class":171}," --apache\n",[28,298,299],{},"The first screen is a warning about our web server - we have not configured the domain name for it.",[28,301,302],{},[88,303],{"alt":304,"src":305},"No names found","\u002Fcontent\u002F2016\u002F05\u002Fapache\u002Fno-names.png",[28,307,308],{},"Choose \"Yes\" and enter the domain name you plan to use.",[28,310,311],{},[88,312],{"alt":313,"src":314},"Set domain name","\u002Fcontent\u002F2016\u002F05\u002Fapache\u002Fset-name.png",[28,316,317],{},"Next, enter your e-mail. This will be used for recovery purposes, should you loose your certificate.",[28,319,320],{},[88,321],{"alt":322,"src":323},"Set email","\u002Fcontent\u002F2016\u002F05\u002Fapache\u002Fset-email.png",[28,325,326],{},[88,327],{"alt":328,"src":329},"Agree TOS","\u002Fcontent\u002F2016\u002F05\u002Fapache\u002Ftos.png",[28,331,332],{},"Choosing \"Secure\" will \"force\" visitors to use a secure connection. HTTP connections will be redirected to HTTPS.",[28,334,335],{},[88,336],{"alt":337,"src":338},"Redirect HTTP","\u002Fcontent\u002F2016\u002F05\u002Fapache\u002Fhttp-redirect.png",[28,340,341],{},[88,342],{"alt":343,"src":344},"Success","\u002Fcontent\u002F2016\u002F05\u002Fapache\u002Fsuccess.png",[28,346,347],{},"When the wizard finishes, open the domain in your browser - you should still see the same default server page, but now, over a domain name and in encrypted form.",[28,349,350],{},"One final thing to note - although the contents of the current page are now secure, it's references it tries to fetch over HTTP are not. The default page loads some CSS files from an insecure (HTTP) source and the browser warns us about it.",[28,352,353],{},[88,354],{"alt":355,"src":356},"Secure","\u002Fcontent\u002F2016\u002F05\u002Fapache\u002Fsecure.png",[28,358,359,360,363],{},"Let's edit the file ",[146,361,362],{},"\u002Fvar\u002Fwww\u002Fhtml\u002Findex.html"," and replace its contents with",[139,365,369],{"className":366,"code":367,"language":368,"meta":144,"style":144},"language-html shiki shiki-themes github-light github-dark","\u003C!DOCTYPE html>\n\u003Chtml lang=\"en\">\n  \u003Chead>\n    \u003Cmeta charset=\"utf-8\">\n    \u003Ctitle>Secure Page\u003C\u002Ftitle>\n  \u003C\u002Fhead>\n  \u003Cbody>\n    \u003Ch1>Secure Page\u003C\u002Fh1>\n    \u003Cp>This page was securely sent from the server to your computer. No-one eavesdropped or changed this content.\u003C\u002Fp>\n  \u003C\u002Fbody>\n\u003C\u002Fhtml>\n","html",[146,370,371,387,405,415,433,448,458,468,482,496,505],{"__ignoreMap":144},[149,372,373,377,381,384],{"class":151,"line":152},[149,374,376],{"class":375},"sVt8B","\u003C!",[149,378,380],{"class":379},"s9eBZ","DOCTYPE",[149,382,383],{"class":155}," html",[149,385,386],{"class":375},">\n",[149,388,389,392,394,397,400,403],{"class":151,"line":163},[149,390,391],{"class":375},"\u003C",[149,393,368],{"class":379},[149,395,396],{"class":155}," lang",[149,398,399],{"class":375},"=",[149,401,402],{"class":159},"\"en\"",[149,404,386],{"class":375},[149,406,407,410,413],{"class":151,"line":262},[149,408,409],{"class":375},"  \u003C",[149,411,412],{"class":379},"head",[149,414,386],{"class":375},[149,416,417,420,423,426,428,431],{"class":151,"line":271},[149,418,419],{"class":375},"    \u003C",[149,421,422],{"class":379},"meta",[149,424,425],{"class":155}," charset",[149,427,399],{"class":375},[149,429,430],{"class":159},"\"utf-8\"",[149,432,386],{"class":375},[149,434,436,438,441,444,446],{"class":151,"line":435},5,[149,437,419],{"class":375},[149,439,440],{"class":379},"title",[149,442,443],{"class":375},">Secure Page\u003C\u002F",[149,445,440],{"class":379},[149,447,386],{"class":375},[149,449,451,454,456],{"class":151,"line":450},6,[149,452,453],{"class":375},"  \u003C\u002F",[149,455,412],{"class":379},[149,457,386],{"class":375},[149,459,461,463,466],{"class":151,"line":460},7,[149,462,409],{"class":375},[149,464,465],{"class":379},"body",[149,467,386],{"class":375},[149,469,471,473,476,478,480],{"class":151,"line":470},8,[149,472,419],{"class":375},[149,474,475],{"class":379},"h1",[149,477,443],{"class":375},[149,479,475],{"class":379},[149,481,386],{"class":375},[149,483,485,487,489,492,494],{"class":151,"line":484},9,[149,486,419],{"class":375},[149,488,28],{"class":379},[149,490,491],{"class":375},">This page was securely sent from the server to your computer. No-one eavesdropped or changed this content.\u003C\u002F",[149,493,28],{"class":379},[149,495,386],{"class":375},[149,497,499,501,503],{"class":151,"line":498},10,[149,500,453],{"class":375},[149,502,465],{"class":379},[149,504,386],{"class":375},[149,506,508,511,513],{"class":151,"line":507},11,[149,509,510],{"class":375},"\u003C\u002F",[149,512,368],{"class":379},[149,514,386],{"class":375},[28,516,517],{},"Refresh the browser and you can now see the tell-tale sign of a green padlock, indicating a secure connection.",[28,519,520],{},[88,521],{"alt":522,"src":523},"HTTPS page","\u002Fcontent\u002F2016\u002F05\u002Fapache\u002Fdone.png",[43,525,527],{"id":526},"conclusion","Conclusion",[28,529,530],{},"We have now successfully set up a new HTTPS web site. All traffic from that site is encrypted in transit between the web server and a visitors computer and thus protected from eavesdropping, analysis and modification - things that have increasing importance as global mass-surveillance levels increase. Open source software and LetsEncrypt are both free which means people won't have to pay for the privilege of security any more. If you're not already running your site over HTTPS - not would be the time.",[532,533],"hr",{},[28,535,536],{},[537,538,539,540,542],"em",{},"(1) ",[146,541,206],{}," is used as an example and is not a working website. To see how a LetsEncrypt validated certificate looks like, inspect the certificate of this blog (sqroot.eu).",[544,545,546],"style",{},"html pre.shiki code .sScJk, html code.shiki .sScJk{--shiki-default:#6F42C1;--shiki-dark:#B392F0}html pre.shiki code .sZZnC, html code.shiki .sZZnC{--shiki-default:#032F62;--shiki-dark:#9ECBFF}html pre.shiki code .sj4cs, html code.shiki .sj4cs{--shiki-default:#005CC5;--shiki-dark:#79B8FF}html .default .shiki span {color: var(--shiki-default);background: var(--shiki-default-bg);font-style: var(--shiki-default-font-style);font-weight: var(--shiki-default-font-weight);text-decoration: var(--shiki-default-text-decoration);}html .shiki span {color: var(--shiki-default);background: var(--shiki-default-bg);font-style: var(--shiki-default-font-style);font-weight: var(--shiki-default-font-weight);text-decoration: var(--shiki-default-text-decoration);}html .dark .shiki span {color: var(--shiki-dark);background: var(--shiki-dark-bg);font-style: var(--shiki-dark-font-style);font-weight: var(--shiki-dark-font-weight);text-decoration: var(--shiki-dark-text-decoration);}html.dark .shiki span {color: var(--shiki-dark);background: var(--shiki-dark-bg);font-style: var(--shiki-dark-font-style);font-weight: var(--shiki-dark-font-weight);text-decoration: var(--shiki-dark-text-decoration);}html pre.shiki code .sVt8B, html code.shiki .sVt8B{--shiki-default:#24292E;--shiki-dark:#E1E4E8}html pre.shiki code .s9eBZ, html code.shiki .s9eBZ{--shiki-default:#22863A;--shiki-dark:#85E89D}",{"title":144,"searchDepth":163,"depth":163,"links":548},[549,550,551,552,553,554],{"id":45,"depth":163,"text":46},{"id":71,"depth":163,"text":72},{"id":118,"depth":163,"text":119},{"id":199,"depth":163,"text":200},{"id":216,"depth":163,"text":217},{"id":526,"depth":163,"text":527},"Learning",null,"2016-05-01","The topic of encryption and privacy has been widely focused on after the Snowden revalations. Suddenly, people realize that much of everything we do online is done using insecure channels. One of those channels is unencrypted web traffic.","md",{},"\u002F2016\u002Fserving-https-web-pages-with-apache-and-letsencrypt","about 4 minutes",{"title":23,"description":558},"2016\u002Fserving-https-web-pages-with-apache-and-letsencrypt","A step-by-step tutorial on how to set up a web server with HTTPS support",861,"REf7PIpf3Aj-KiMSA9uqpGLlR52Na7zSSXHe1SVMYT0",[569,573],{"title":570,"path":571,"stem":572,"children":-1},"Securing SSH Keys","\u002F2016\u002Fsecuring-ssh-keys","2016\u002Fsecuring-ssh-keys",{"title":574,"path":575,"stem":576,"children":-1},"Military Starter Kit","\u002F2016\u002Fmilitary-starter-kit","2016\u002Fmilitary-starter-kit",{"left":4,"top":4,"width":5,"height":5,"rotate":4,"vFlip":6,"hFlip":6,"body":578},"\u003Cpath fill=\"none\" stroke=\"currentColor\" stroke-linecap=\"round\" stroke-linejoin=\"round\" stroke-width=\"2\" d=\"m12 19l-7-7l7-7m7 7H5\"\u002F>",{"left":4,"top":4,"width":5,"height":5,"rotate":4,"vFlip":6,"hFlip":6,"body":580},"\u003Cpath fill=\"none\" stroke=\"currentColor\" stroke-linecap=\"round\" stroke-linejoin=\"round\" stroke-width=\"2\" d=\"M5 12h14m-7-7l7 7l-7 7\"\u002F>",1790886932712]