1
votes

I spent last 2 days trying to find the solution to my issue.

HTTP works fine http://jackrus.net, but HTTPS won't work.

1.I created an instance on Amazon Linux EC2. 2.Redirected my domain jackrus.net to my public IP 3. Opened listeners 443, 22, 80. (security groups) 4. Followed the instructions from aws documentation from here 5. Checked all permissions 6. apachectl -t - says syntax is fine. 7. Restarted the server. no problem here too.

Here is my ssl.conf

.... .... .... SSLCertificateFile /etc/pki/tls/certs/certificate.crt

SSLCertificateKeyFile /etc/pki/tls/private/private1.key

SSLCACertificateFile /etc/pki/tls/certs/intermediate.crt ... ... ...

The response i get here: This site can’t be reached

jackrus.net refused to connect. Try: Checking the connection Checking the proxy and the firewall ERR_CONNECTION_REFUSED

1
Can you SSH into it? Are you sure you've configured your security groups correctly to allow the traffic? Try to ping the public IP - Henry
I can ssh and checked the security group. Everything is fine. However one of my friends told me that the problem can be in the default SSL settings... however again I followed the AWS instructions.. - Jack Rus

1 Answers

2
votes

You might need to add your virtual host to your http/config.d file

You can check what vhosts you have running like this:

apachectl -t -D DUMP_VHOSTS

Look up where your config could be

find /etc/httpd -name *.conf

then edit you config with vim or nano or whatever you prefer

vi /etc/httpd/conf/httpd.conf

Add your virtual host ( type i first to insert if in vim)

#Virtual Host added
<VirtualHost *:80>
    DocumentRoot "/var/www/html"
    ServerName "example.com"
    ServerAlias "example"
RewriteEngine on
RewriteCond %{SERVER_NAME} =example
RewriteRule ^ https://%{SERVER_NAME}%{REQUEST_URI} [END,NE,R=permanent]
</VirtualHost>

to save and exit:

:wq

then try restarting the server.

I also recommend the letsencrypt certbot-auto for a quick solution as it has a debug feature to tell you exactly what the error is. If you are using Letsencrypt then you sould look up the ACMEv1 to v2 upgrade or end of life cycle for ACMEv1