-
Notifications
You must be signed in to change notification settings - Fork 32
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
nitro-enclaves-acm not working for httpd on Amazon Linux 2 #74
Comments
@leonblueconic in order for things to work you need
|
The package was / is installed but it wasn't working nonetheless. Not until I did overwrite that mentioned file with the file found on the test instance. |
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
After installing / configuring nitro-enclaves-acm for Apache httpd as described on https://docs.aws.amazon.com/enclaves/latest/user/nitro-enclave-refapp.html I noticed it wasn't working. I couldn't setup a working TLS connection to the site in question. The instances in questions is a fully patched / up to date AL2 instance
I verified the setup by launching an https://aws.amazon.com/marketplace/pp/prodview-f4gcl7narsmle instance (to be referenced as test instance) which seems to work correctly. I used the same certificate and the same IAM role as on the original instance. And it worked out of the box. So I was confident the configuration on the original instance should also work. Checking around on the system I noticed my instance contains
openssl-pkcs11-0.4.10-3.amzn2.0.1.x86_64
this packages doesn't seem to be present on the test instance. However on the test instance/usr/lib64/openssl/engines/pkcs11.so
which is normally be provided by this package is nonetheless precent. When I copy this file from the test instance over to my original instance things suddenly start to work. And the last part of theopenssl s_client
command now looks likeDoes this mean we need and updated
openssl-pkcs11
to appear in the AL2 package repository that will allow nitro-enclaves-acm to work?The text was updated successfully, but these errors were encountered: