Linux cesa-www-main 6.1.0-49-cloud-amd64 #1 SMP PREEMPT_DYNAMIC Debian 6.1.174-1 (2026-05-26) x86_64
Apache/2.4.68 (Debian)
Server IP : 10.218.0.2 & Your IP : 216.73.216.28
Domains :
Cant Read [ /etc/named.conf ]
User : www-data
Terminal
Auto Root
Create File
Create Folder
Localroot Suggester
Backdoor Destroyer
Readme
/
usr /
share /
doc /
openssl /
Delete
Unzip
Name
Size
Permission
Date
Action
HOWTO
[ DIR ]
drwxr-xr-x
2026-06-10 06:50
NEWS.Debian.gz
252
B
-rw-r--r--
2026-04-15 19:55
NEWS.md.gz
19.38
KB
-rw-r--r--
2026-04-07 12:46
README-ENGINES.md.gz
5.83
KB
-rw-r--r--
2026-04-07 12:46
README.Debian
2.53
KB
-rw-r--r--
2026-06-06 19:56
README.md.gz
2.52
KB
-rw-r--r--
2026-04-07 12:46
README.optimization
1.35
KB
-rw-r--r--
2026-06-06 19:56
changelog.Debian.gz
5.48
KB
-rw-r--r--
2026-06-06 19:56
changelog.gz
245.41
KB
-rw-r--r--
2026-04-07 12:46
copyright
2.48
KB
-rw-r--r--
2026-06-06 14:02
fingerprints.txt
858
B
-rw-r--r--
2026-04-07 12:46
Save
Rename
openssl for DEBIAN ---------------------- openssl replaces ssleay. The application links to openssl like req, ca, verify and s_client have been removed. Instead of `<application>` please call now `openssl <application>` eg: instead of `req` please call `openssl req` TLS protovol version and RSA key size ------------------------------------- The default system global policy is to support TLSv1.2+ and security level two. Please see https://www.openssl.org/docs/man1.1.1/man5/config.html https://www.openssl.org/docs/man1.1.1/man3/SSL_CTX_set_security_level.html#DEFAULT-CALLBACK-BEHAVIOUR for configurations details of `MinProtocol' and `CipherString' in /etc/ssl/openssl.cnf case you really require to support legacy systems. PATENT ISSUES ------------- Some algorithms used in the library are covered by patents. As a result, the following algorithms in libcrypto have been disabled: - RC5 - MDC2 - IDEA Also see the patents section in the README file. Self-signed certs and webservers: --------------------------------- If you get with a selfsigned certificate and a webserver: > "The certificate is not approved for the attempted operation." Bodo_Moeller@public.uni-hamburg.de (Bodo Moeller) writes: >Probably you are using a CA certificate for your server; if you use >"openssl req" to generate a new key and self-signed certificate with >the default openssl.cnf, the certificate you get includes certain >X.509v3 extensions that make it unfit for use as a server certificate. >This was not so with earlier versions of the software because back >then there was far less X.509v3 support. > >To look at the certificate some HTTPS server presents to its cliens, >use "openssl s_client -port 443 -host your.server", store the output >(at least the part from "-----BEGIN CERTIFICATE-----" up to "-----END >CERTIFICATE-----", including these separators) in a file and use >"openssl x509 -in the_file_you_just_stored -text" to look at it in >readable form. If it has in the "X509v3 extensions section" any of >the following entries, it is not usable as a server certificate: > > X509v3 Basic Constraints: > CA:TRUE > > X509v3 Key Usage: > Certificate Sign, CRL Sign > >To quickly create a new server key and certificate that works with >Netscape, you can just copy the original openssl.cnf file and comment >out the "x509_extensions" entry in the "[ req ]" section. >The, use "openssl req ..." as before to create a new certificate and >key. Christoph Martin <martin@uni-mainz.de>, Wed, 31 Mar 1999 16:00:51 +0200