1
votes

I'm trying to have https for a website which is hosted in AWS EC2. I have followed the steps mention in the following link.

https://www.digitalocean.com/community/tutorials/how-to-create-a-ssl-certificate-on-apache-for-ubuntu-14-04

But still its showing the privacy thing to all user who are visiting the website. How can make the certificate as trusted or how long it will take Amazon to make it a trusted one.

Please help me to solve this. I'm stuck with this for last 2 days. Answers will be appreciated and Thank you.

4

4 Answers

0
votes

You can use AWS Certificate Manager to issue free SSL certificate signed by AWS Certificate Authority. However for this to work, you need to use a Load Balancer and attach the certificate to the Load Balancer which will forward the traffic to the EC2 instance.

0
votes

Depending on your requirements you may wish to use SSL termination on an Elastic Load Balancer (ELB) instead.

This involves creating a free AWS certificate and an ELB. Attach both your instance the certificate to the ELB with HTTPS forwarded to port 80 on your instance.

Then just point your DNS name to the ELB. If you're using Route53 then you can just use an A-record alias.

Edit: If you want to automatically direct HTTP to HTTPS you'll need to check the X-Forwarded-Proto header in Apache's .htaccess file. More information here.

0
votes

The certificate which you are using is a "Self Signed Certificate (https://en.wikipedia.org/wiki/Self-signed_certificate)".

In order to get rid of insecure certificate or privacy issues on HTTPS, you need to get your CSR signed from a trusted CA like Comodo, Godaddy etc.

Ref -

https://in.godaddy.com/help/apache-generate-csr-certificate-signing-request-5269 https://help.comodo.com/topic-437-1-843-10843-.html

OR

In case you want free verified SSL certificates, "letsencrypt" is the way to go.
https://letsencrypt.org/

0
votes

You don't need to pay anyone for a certificate. Just use LetsEncrypt and their CertBot ACME client. The CertBot automates the task of issuing and renewing certificates.

LetsEncrypt is the leading free SSL certificate authority (CA) and their certs are as good as any paid cert.