Find Map About MIT Academics Research Administration Resources Groups News MIT mit site menu

the apache-ssl locker (rev5)

The apache-ssl locker contains software supported and recommended by the CWIS group of MIT Information Systems for providing secure web servers. MIT's apache-ssl software is based on the Apache webserver, and includes support for ssl, fast cgi and Java servlet development. (Support for Java servlets is just for the Sun platform, due to the lack of JSDK for any other platform)
Contents of apache-ssl locker:
Pros and Cons of Running Your Own Webserver:
Current versions: Solaris and Linux
Windows NT:
How to Get, Install and Run MIT's apache-ssl software:

To set up an apache-ssl webserver for the first time:

Obsolete versions:
Previous versions of apache-ssl are still available :

For the time being rev4 is still available at rev4


Known Users:
A few of the users of the software are :
lcs@mit.edu
ccount@mit.edu
salemme@mit.edu
They may be willing to answer questions or help others in setting up their servers.
Keep informed:
If you use this software, please let us know so we can inform you of problems, new releases and so on by sending mail to
apache-ssl@mit.edu

If you have an Athena account, you can add yourself to the
apache-ssl-users@mit.edu
mailing list.
Known problems and defects
Problem with secure server not recognizing user certificates, 2/2/2000: On February 2, 2000, one of the certificate files included in the apache-ssl distribution expired, causing secure servers (https) to reject user certificates with the confusing (to the user) message, "Your certificate has expired...". See the README for information on how to make the fix to your apache-ssl webserver, which requires a new mitCAclient.pem file.

Security Note Received on 7/6/98:
On 7/6/98 we received a security warning on having the script test-cgi in the cgi-bin of an Apache server. Please, after testing the installation, remove /var/https/cgi-bin/test-cgi. For more information, see http://128.196.109.25/sploits/test-cgi.server_protocol.html.


Support and Maintenance

Consulting:
The main supporter of this software is miki@mit.edu
Address general questions regarding webservers at MIT to cwis-help@mit.edu
Users group:
Send general questions to the apache-ssl users at MIT at apache-ssl-users@mit.edu
Bug Reports:
Send bug reports to
apache-ssl@mit.edu
Maintainer(s):

Revision History


mit Comments to web-request@mit.edu
$Date: 2000/03/03 16:49:23 $