IP difficulties: help sorting out name-based virtual hosts in conjunction with ssl

divinelighting

Verified User
Joined
Mar 17, 2008
Messages
108
Hello,
I don't know much about DNS administration and am looking for a little help. Everything appears to be working, but I know things aren't right.

I have ip range 204.152.194.120/29
My nameservers are:
ns1.divinelighting.com host ip 204.152.194.122
ns2.divinelighting.com host ip 204.152.194.123

One website uses ssl: divinelighting.com
The other sites are personal sites.

In fact, in DA, all 'A' records for all sites are set to 204.152.194.122, with the exception of 'ns2' and 'ns2.divinelighting.com' for the divinelighting.com domain, which are set to 204.152.194.123.

All sites have 'NS' records set to ns1.divinelighting.com and ns2.divinelighting.com

Sorry for all the info, I'm just not sure where I am wrong.

I am getting this apache error
[Sat Aug 22 08:21:45 2009] [warn] RSA server certificate CommonName (CN) `www.divinelighting.com' does NOT match server name!?
[Sat Aug 22 08:21:45 2009] [warn] RSA server certificate CommonName (CN) `www.divinelighting.com' does NOT match server name!?
[Sat Aug 22 08:21:45 2009] [warn] Init: SSL server IP/port conflict: www.jackie-johnson.com:443 (/usr/local/directadmin/data/users/jackie/httpd.conf:48) vs. www.kimballdj.com:443 (/usr/local/directadmin/data/users/kimballdj/httpd.conf:48)
[Sat Aug 22 08:21:45 2009] [warn] Init: SSL server IP/port conflict: www.goteam.us:443 (/usr/local/directadmin/data/users/goteam/httpd.conf:48) vs. www.kimballdj.com:443 (/usr/local/directadmin/data/users/kimballdj/httpd.conf:48)
[Sat Aug 22 08:21:45 2009] [warn] Init: SSL server IP/port conflict: www.cdustinjohnson.com:443 (/usr/local/directadmin/data/users/dustin/httpd.conf:48) vs. www.kimballdj.com:443 (/usr/local/directadmin/data/users/kimballdj/httpd.conf:48)
[Sat Aug 22 08:21:45 2009] [warn] Init: SSL server IP/port conflict: www.audioinsights.com:443 (/usr/local/directadmin/data/users/audio/httpd.conf:48) vs. www.kimballdj.com:443 (/usr/local/directadmin/data/users/kimballdj/httpd.conf:48)
[Sat Aug 22 08:21:45 2009] [warn] Init: SSL server IP/port conflict: www.alyhana.com:443 (/usr/local/directadmin/data/users/alyhana/httpd.conf:48) vs. www.kimballdj.com:443 (/usr/local/directadmin/data/users/kimballdj/httpd.conf:48)
[Sat Aug 22 08:21:45 2009] [warn] Init: SSL server IP/port conflict: www.divinelighting.com:443 (/usr/local/directadmin/data/users/divine/httpd.conf:48) vs. www.kimballdj.com:443 (/usr/local/directadmin/data/users/kimballdj/httpd.conf:48)
[Sat Aug 22 08:21:45 2009] [warn] Init: SSL server IP/port conflict: localhost:443 (/etc/httpd/conf/extra/httpd-vhosts.conf:38) vs. www.kimballdj.com:443 (/usr/local/directadmin/data/users/kimballdj/httpd.conf:48)
[Sat Aug 22 08:21:45 2009] [warn] Init: You should not use name-based virtual hosts in conjunction with SSL!!
[Sat Aug 22 08:21:45 2009] [notice] suEXEC mechanism enabled (wrapper: /usr/sbin/suexec)
[Sat Aug 22 08:21:46 2009] [warn] RSA server certificate CommonName (CN) `www.divinelighting.com' does NOT match server name!?
[Sat Aug 22 08:21:46 2009] [warn] RSA server certificate CommonName (CN) `www.divinelighting.com' does NOT match server name!?
[Sat Aug 22 08:21:46 2009] [warn] Init: SSL server IP/port conflict: www.jackie-johnson.com:443 (/usr/local/directadmin/data/users/jackie/httpd.conf:48) vs. www.kimballdj.com:443 (/usr/local/directadmin/data/users/kimballdj/httpd.conf:48)
[Sat Aug 22 08:21:46 2009] [warn] Init: SSL server IP/port conflict: www.goteam.us:443 (/usr/local/directadmin/data/users/goteam/httpd.conf:48) vs. www.kimballdj.com:443 (/usr/local/directadmin/data/users/kimballdj/httpd.conf:48)
[Sat Aug 22 08:21:46 2009] [warn] Init: SSL server IP/port conflict: www.cdustinjohnson.com:443 (/usr/local/directadmin/data/users/dustin/httpd.conf:48) vs. www.kimballdj.com:443 (/usr/local/directadmin/data/users/kimballdj/httpd.conf:48)
[Sat Aug 22 08:21:46 2009] [warn] Init: SSL server IP/port conflict: www.audioinsights.com:443 (/usr/local/directadmin/data/users/audio/httpd.conf:48) vs. www.kimballdj.com:443 (/usr/local/directadmin/data/users/kimballdj/httpd.conf:48)
[Sat Aug 22 08:21:46 2009] [warn] Init: SSL server IP/port conflict: www.alyhana.com:443 (/usr/local/directadmin/data/users/alyhana/httpd.conf:48) vs. www.kimballdj.com:443 (/usr/local/directadmin/data/users/kimballdj/httpd.conf:48)
[Sat Aug 22 08:21:46 2009] [warn] Init: SSL server IP/port conflict: www.divinelighting.com:443 (/usr/local/directadmin/data/users/divine/httpd.conf:48) vs. www.kimballdj.com:443 (/usr/local/directadmin/data/users/kimballdj/httpd.conf:48)
[Sat Aug 22 08:21:46 2009] [warn] Init: SSL server IP/port conflict: localhost:443 (/etc/httpd/conf/extra/httpd-vhosts.conf:38) vs. www.kimballdj.com:443 (/usr/local/directadmin/data/users/kimballdj/httpd.conf:48)
[Sat Aug 22 08:21:46 2009] [warn] Init: You should not use name-based virtual hosts in conjunction with SSL!!
 
This is not an error.
Is just a warning. Don't worry about it.
Is a regular message in a vhost environment.
 
References:

Running mod_ssl with Virtual Hosts:
Code:
http://www.opensourcery.com/blog/dylan-tack/running-modssl-virtual-hosts

SSL with Virtual Hosts Using SNI from apache group.
Code:
http://wiki.apache.org/httpd/NameBasedSSLVHostsWithSNI

Apache SSL with Virtual Hosts Using SNI - Server Name Indication:
Code:
http://hvera.wordpress.com/2009/09/02/apache-ssl-with-virtual-hosts-using-sni/

HOWTO: Apache 2 SSL Name-Based Virtual Hosting
Code:
http://fob.po8.org/node/289


There is so much about this subject, I get lots of errors related to ssl, my log is just full of these errors but like the guy said it's just a warning and can be ignored,
I believe a uni teacher worked out a way to at least stop the warning part browsers throw out. Last link.
I also get weird things happen, like when selecting "use server certificate on a domain with its own ip, after 30 minutes the site is dead. strange hey, so I have to disable ssl for the site until I can work out why.

I know you can get a free certificate from starcom. Fully free and usable by most browsers.
 
Last edited:
Back
Top