- Products
- Learn
- Local User Groups
- Partners
- More
MVP 2026: Submissions
Are Now Open!
What's New in R82.10?
Watch NowOverlap in Security Validation
Help us to understand your needs better
CheckMates Go:
Maestro Madness
Hi all:
This morning we followed the steps in sk147272 , after that we realized Apache server in api went down in SMS (R80.40 T158) In /var/log/httpd2_error_log file we saw entries like this:
[Tue Jun 28 15:21:20.792788 2022] [mime_magic:error] [pid 25154] (2)No such file or directory: AH01515: mod_mime_magic: can't read magic file /web/conf/magic
[Tue Jun 28 15:21:20.792954 2022] [ssl:emerg] [pid 25154] AH02231: No SSL protocols available [hint: SSLProtocol]
[Tue Jun 28 15:21:20.792963 2022] [ssl:emerg] [pid 25154] AH02311: Fatal error initialising mod_ssl, exiting. See /usr/local/apache2/logs/error_log for more information
AH00016: Configuration Failed
The ciper suites and protocols in /web/templates/httpd-ssl.conf.templ before the change were these:
SSLCipherSuite HIGH:!RC4:!LOW:!EXP:!aNULL:!SSLv2:!MD5
SSLProtocol -ALL {ifcmp = $httpd:ssl3_enabled 1}+{else}-{endif}SSLv3 +TLSv1 +TLSv1.1 +TLSv1.2
We fixed the issue by replacing the httpd-ssl.conf.templ by the original one. We want to delete weak ciphers and protocols but the apache server must be running afther that.
Any advices?
Thanks a lot
Fran
I recall having this exact problem in R80.40 in lab sms and when I upgraded to R81.10, it went away.
If an sk tells you to do something and it doesn't work, best to open a TAC case.
It seems I found the solution. The changes you have to do in /web/templates/httpd-ssl.conf.templ file (acoording the sk I mentioned), should be done in /web/conf/extra/httpd-ssl.conf as well. After restart HTTPD daemon the Apache process restart and keeps stable.
Regards
Wrong - see the SK:
7. Save the changes in the file and exit Vi editor.
8. Remove the 'write' permission from the /web/templates/httpd-ssl.conf.templ file:
[Expert@HostName:0]# ls -l /web/templates/httpd-ssl.conf.templ
[Expert@HostName:0]# chmod u-w /web/templates/httpd-ssl.conf.templ
[Expert@HostName:0]# ls -l /web/templates/httpd-ssl.conf.templ
9. Update the current configuration of the HTTPD daemon based on the modified configuration template:
[Expert@HostName:0]# /bin/template_xlate : /web/templates/httpd-ssl.conf.templ /web/conf/extra/httpd-ssl.conf < /config/active
10. Restart the HTTPD daemon:
[Expert@HostName:0]# tellpm process:httpd2
[Expert@HostName:0]# tellpm process:httpd2 t
--> So changing /web/conf/extra/httpd-ssl.conf by hand is not suggested !
Leaderboard
Epsum factorial non deposit quid pro quo hic escorol.
| User | Count |
|---|---|
| 16 | |
| 15 | |
| 7 | |
| 5 | |
| 5 | |
| 5 | |
| 4 | |
| 4 | |
| 4 | |
| 4 |
Tue 16 Dec 2025 @ 05:00 PM (CET)
Under the Hood: CloudGuard Network Security for Oracle Cloud - Config and Autoscaling!Thu 18 Dec 2025 @ 10:00 AM (CET)
Cloud Architect Series - Building a Hybrid Mesh Security Strategy across cloudsTue 16 Dec 2025 @ 05:00 PM (CET)
Under the Hood: CloudGuard Network Security for Oracle Cloud - Config and Autoscaling!Thu 18 Dec 2025 @ 10:00 AM (CET)
Cloud Architect Series - Building a Hybrid Mesh Security Strategy across cloudsAbout CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY