I plan to install it on my jail: Apache/SSL + dovecot + exim.
I was already read a lot of posts here and on the Internet (too) especially:
Most of the guides I've read are either:
Can someone clear a bit the above questions - really short answers with simple english are pretty enough, because
my English is only slightly better than google translate. (Sorry, for typos too).
- for the dovecot, default location for certificates is /etc/ssl/{private,certs}/dovecot.*
- for the exim /etc/ssl/exim.{crt,pem}
- for the apache default is recommended to have them somewhere in /usr/local/etc/apache22 ...
I was already read a lot of posts here and on the Internet (too) especially:
- http://daemon-notes.com is very helpful in overall
- and here: http://forums.freebsd.org/showthread.php?t=6490&highlight=certificate is an brilliant post,
- Why the default location of the certificates does not follow the same logic (eg /etc/ss/{certs,private}/program.*)
- It is safe centralize them to one place?
- Why it is necessary to create two different certificate for dovecot and exim? Can both programs use the same certificate?
- What I should to do NOW, if someday I want to have purchased a certificate for apache? Should i now
- - generate a certificate request and
- - sign in myself (so two step solution)
- and in the future when I will ask for the signed certificate can i use the above request? Or will need create another request?
- Maybe in the future there will be also certificates for ldap and jabberd. Can/should use the same as for exin - dovecot, or need create another ones?
- Exists somewhere some coherent overall manual (or system) to manage all those certificates?
Most of the guides I've read are either:
- for only one program (eg dovecot or ldap)
- or for openssl in general
- but no one what give overall view for answers to questions like the above ...
Can someone clear a bit the above questions - really short answers with simple english are pretty enough, because
my English is only slightly better than google translate. (Sorry, for typos too).