--
You received this message because you are subscribed to the Google Groups "rabbitmq-users" group.
To unsubscribe from this group and stop receiving emails from it, send an email to rabbitmq-user...@googlegroups.com.
To post to this group, send email to rabbitm...@googlegroups.com.
For more options, visit https://groups.google.com/d/optout.
Out of frustration I decided to take another approach. I started completely over from scratch. Fully brand new AWS instance using Amazon Linux (CentOS 6 like) instead of Ubuntu (my preference anyways). Installed everything from scratch. Currently I have Sensu/RabbitMQ/Uchiwa/Redis running, and the UI served via Apache my using ProxyPass for Uchiwa 3000 <-> 443. SSL in the browser is working fine. And so far no glaring errors in any of the logs.Next step is to install a remote client and then if that works give SSL a shot. What a pain in the neck this has been. I have to take a break for a bit, but will follow up soon on whether or not this works.
> I'm a bit out of my normal realm on this one. Erlang is totally
> new to me. dpkg -s erlang-nox says "Version: 1:16.b.3-dfsg-1ubuntu2.1".
> You're saying go to erlang site, download version 17 or 18, and
> compile from source. Correct?
SSL: certify: ssl_handshake.erl:1625:Fatal error: unknown ca
{ssl_listeners, [{"127.0.0.1", 5671}, {"10.x.y.z", 5671}]},
{ssl_options, [{cacertfile, "/var/lib/rabbitmq/certs/ca-chain.pem"},
{certfile, "/var/lib/rabbitmq/certs/dssweb-dev-cert.pem"},
{keyfile, "/var/lib/rabbitmq/certs/dssweb-dev-key.pem"},
{versions, ['tlsv1.2']},
{depth, 5},
{ciphers, [
{ecdhe_ecdsa,aes_256_gcm,null,sha384},
{ecdhe_rsa,aes_256_gcm,null,sha384},
{ecdh_ecdsa,aes_256_gcm,null,sha384},
{ecdh_rsa,aes_256_gcm,null,sha384},
{dhe_rsa,aes_256_gcm,null,sha384},
{rsa,aes_256_gcm,null,sha384},
{ecdhe_ecdsa,aes_128_gcm,null,sha256},
{ecdhe_rsa,aes_128_gcm,null,sha256},
{ecdh_ecdsa,aes_128_gcm,null,sha256},
{ecdh_rsa,aes_128_gcm,null,sha256},
{dhe_rsa,aes_128_gcm,null,sha256},
{ecdh_rsa,aes_128_gcm,null,sha256}
]},
{honor_cipher_order, true},
{honor_ecc_order, true},
{secure_renegotiate, true},
{password, "************************"},
{verify, verify_peer},
{fail_if_no_peer_cert,true}]}
]}
--
You received this message because you are subscribed to the Google Groups "rabbitmq-users" group.
To unsubscribe from this group and stop receiving emails from it, send an email to rabbitmq-users+unsubscribe@googlegroups.com.
To post to this group, send email to rabbitmq-users@googlegroups.com.
To post to this group, send email to rabbitm...@googlegroups.com.
For more options, visit https://groups.google.com/d/optout.
--MKStaff Software Engineer, Pivotal/RabbitMQ
--
You received this message because you are subscribed to a topic in the Google Groups "rabbitmq-users" group.
To unsubscribe from this topic, visit https://groups.google.com/d/topic/rabbitmq-users/NK9gZeFOTwQ/unsubscribe.
To unsubscribe from this group and all its topics, send an email to rabbitmq-users+unsubscribe@googlegroups.com.
To unsubscribe from this group and stop receiving emails from it, send an email to rabbitmq-user...@googlegroups.com.
To post to this group, send email to rabbitm...@googlegroups.com.
For more options, visit https://groups.google.com/d/optout.
--MKStaff Software Engineer, Pivotal/RabbitMQ
--
You received this message because you are subscribed to a topic in the Google Groups "rabbitmq-users" group.
To unsubscribe from this topic, visit https://groups.google.com/d/topic/rabbitmq-users/NK9gZeFOTwQ/unsubscribe.
To unsubscribe from this group and all its topics, send an email to rabbitmq-user...@googlegroups.com.
To post to this group, send email to rabbitm...@googlegroups.com.
For more options, visit https://groups.google.com/d/optout.
--
You received this message because you are subscribed to the Google Groups "rabbitmq-users" group.
To unsubscribe from this group and stop receiving emails from it, send an email to rabbitmq-user...@googlegroups.com.
To post to this group, send email to rabbitm...@googlegroups.com.
For more options, visit https://groups.google.com/d/optout.
--MKStaff Software Engineer, Pivotal/RabbitMQ
subject= /C=DE/O=Verein zur Foerderung eines Deutschen Forschungsnetzes e. V./OU=DFN-PKI/CN=DFN-Verein Global Issuing CAHere is some bits of information from the Server-cert
subject= /C=DE/O=Verein zur Foerderung eines Deutschen Forschungsnetzes e. V./OU=DFN-PKI/CN=DFN-Verein Certification Authority 2
subject= /C=DE/O=T-Systems Enterprise Services GmbH/OU=T-Systems Trust Center/CN=T-TeleSec GlobalRoot Class 2
{'OCSP': ('http://ocsp.pca.dfn.de/OCSP-Server/OCSP',),
'caIssuers': ('http://cdp1.pca.dfn.de/dfn-ca-global-g2/pub/cacert/cacert.crt',
'http://cdp2.pca.dfn.de/dfn-ca-global-g2/pub/cacert/cacert.crt'),
'crlDistributionPoints': ('http://cdp1.pca.dfn.de/dfn-ca-global-g2/pub/crl/cacrl.crl',
'http://cdp2.pca.dfn.de/dfn-ca-global-g2/pub/crl/cacrl.crl'),
'issuer': ((('countryName', 'DE'),),
(('organizationName',
'Verein zur Foerderung eines Deutschen Forschungsnetzes e. '
'V.'),),
(('organizationalUnitName', 'DFN-PKI'),),
(('commonName', 'DFN-Verein Global Issuing CA'),)),
'notAfter': 'Nov 17 06:05:33 2020 GMT',
'notBefore': 'Aug 21 06:05:33 2017 GMT',
'serialNumber': '1DB9F5BCFBD60B1CC1F67B0D',
'subject': ((('countryName', 'DE'),),
(('stateOrProvinceName', 'Bayern'),),
(('localityName', 'somewhere'),),
(('organizationName', 'some org'),),
(('organizationalUnitName', 'some department'),),
(('commonName', 'someserver.de'),)),
'subjectAltName': (('DNS', 'someserver.de'),),
'version': 3}
'caIssuers'
I'll be fine. I was not.