# self signed sertificate

**URL:** https://dietpi.com/forum/t/self-signed-sertificate/5371
**Category:** General Discussion
**Created:** [29 May 2021 10:29 UTC](https://dietpi.com/forum/t/self-signed-sertificate/5371 "2021-05-29T10:29:44Z")
**Posts on this page:** 11
**Page:** 2

<div class="post-metadata">

### Author: ![Joulinar](https://dietpi.com/forum/user_avatar/dietpi.com/joulinar/32/57_2.png) [@Joulinar](https://dietpi.com/forum/u/Joulinar)
#### Post date: [6 December 2021 20:13 UTC](https://dietpi.com/forum/t/self-signed-sertificate/5371/21 "2021-12-06T20:13:15Z")

</div>

You can verify the failed configuration as follow

```nohighlight
/usr/sbin/lighttpd -tt -f /etc/lighttpd/lighttpd.conf

```

---

<div class="post-metadata">

### Author: ![willis936](https://dietpi.com/forum/letter_avatar_proxy/v4/letter/w/c77e96/32.png) [@willis936](https://dietpi.com/forum/u/willis936)
#### Post date: [6 December 2021 20:15 UTC](https://dietpi.com/forum/t/self-signed-sertificate/5371/22 "2021-12-06T20:15:46Z")

</div>

```nohighlight
# /usr/sbin/lighttpd -tt -f /etc/lighttpd/lighttpd.conf
2021-12-06 15:14:18: plugin.c.195) dlopen() failed for: /usr/lib/lighttpd/mod_openssl.so /usr/lib/lighttpd/mod_openssl.so: cannot open shared object file: No such file or directory
2021-12-06 15:14:18: server.c.1238) loading plugins finally failed

```

It looks like the openssl module for lighttpd is missing.  
  
  
Edit: upon searching I found this solution that works for me:

```nohighlight
# apt install lighttpd-mod-openssl

```

[https://dietpi.com/forum/t/enabling-ssl-for-internal-network/5861/9](https://dietpi.com/forum/t/enabling-ssl-for-internal-network/5861/9)  
  
  
Now I get a 400 Bad Request response when going to the /admin webpage in a browser. I’ll poke around the settings more.

---

<div class="post-metadata">

### Author: ![Joulinar](https://dietpi.com/forum/user_avatar/dietpi.com/joulinar/32/57_2.png) [@Joulinar](https://dietpi.com/forum/u/Joulinar)
#### Post date: [6 December 2021 20:26 UTC](https://dietpi.com/forum/t/self-signed-sertificate/5371/23 "2021-12-06T20:26:23Z")

</div>

Can you open the default site on the web server without any sub folder?

---

<div class="post-metadata">

### Author: ![willis936](https://dietpi.com/forum/letter_avatar_proxy/v4/letter/w/c77e96/32.png) [@willis936](https://dietpi.com/forum/u/willis936)
#### Post date: [6 December 2021 20:31 UTC](https://dietpi.com/forum/t/self-signed-sertificate/5371/24 "2021-12-06T20:31:24Z")

</div>

Yes. It returns the lighttpd placeholder page. I remember in the past this used to have some landing page.

Here is the contents of /etc/lighttpd/conf-enabled.

```nohighlight
10-fastcgi.conf
15-fastcgi-php.conf
50-dietpi-https.conf
98-dietpi-https_redirect.conf
99-dietpi-pihole-block_public_admin.conf
99-dietpi-pihole.conf
99-unconfigured.conf

```

Also, I can confirm pihole is installing and running.

```nohighlight
# pihole status
  [✓] DNS service is listening
     [✓] UDP (IPv4)
     [✓] TCP (IPv4)
     [✓] UDP (IPv6)
     [✓] TCP (IPv6)

  [✓] Pi-hole blocking is enabled

```

---

<div class="post-metadata">

### Author: ![Joulinar](https://dietpi.com/forum/user_avatar/dietpi.com/joulinar/32/57_2.png) [@Joulinar](https://dietpi.com/forum/u/Joulinar)
#### Post date: [6 December 2021 21:02 UTC](https://dietpi.com/forum/t/self-signed-sertificate/5371/25 "2021-12-06T21:02:52Z")

</div>

pihole status is displaying the status of your AdBlocker. It has nothing to do with the web gui shown via web server. PiHole core is working even without web server totally fine 😉

can you check following

```nohighlight
ls -la /var/www/
cat /etc/lighttpd/lighttpd.conf

```

---

<div class="post-metadata">

### Author: ![willis936](https://dietpi.com/forum/letter_avatar_proxy/v4/letter/w/c77e96/32.png) [@willis936](https://dietpi.com/forum/u/willis936)
#### Post date: [6 December 2021 21:24 UTC](https://dietpi.com/forum/t/self-signed-sertificate/5371/26 "2021-12-06T21:24:43Z")

</div>

```nohighlight
# ls -la /var/www/
total 132
drwxr-xr-x 3 root root 4096 Nov 30 21:32 .
drwxr-xr-x 12 root root 4096 Nov 30 00:22 ..
lrwxrwxrwx 1 root root 19 Nov 30 21:32 admin -> /var/www/html/admin
-rw-r--r-- 1 root root 38294 Nov 30 21:28 apc.php
drwxr-xr-x 4 root root 4096 Nov 30 21:30 html
-rw-r--r-- 1 root root 3388 Nov 30 00:24 index.lighttpd.html
-rw-r--r-- 1 root root 71038 Nov 30 21:28 opcache.php
-rw-r--r-- 1 root root 20 Nov 30 21:28 phpinfo.php
lrwxrwxrwx 1 root root 20 Nov 30 21:32 pihole -> /var/www/html/pihole

```

```nohighlight
# cat /etc/lighttpd/lighttpd.conf
server.modules = (
        "mod_indexfile",
        "mod_setenv",
        "mod_access",
        "mod_alias",
        "mod_redirect",
)

server.document-root = "/var/www"
server.upload-dirs = ( "/var/cache/lighttpd/uploads" )
server.errorlog = "/var/log/lighttpd/error.log"
server.pid-file = "/run/lighttpd.pid"
server.username = "www-data"
server.groupname = "www-data"
server.port = 80

# features
#https://redmine.lighttpd.net/projects/lighttpd/wiki/Server_feature-flagsDetails
server.feature-flags += ("server.h2proto" => "enable")
server.feature-flags += ("server.h2c" => "enable")
server.feature-flags += ("server.graceful-shutdown-timeout" => 5)
#server.feature-flags += ("server.graceful-restart-bg" => "enable")

# strict parsing and normalization of URL for consistency and security
# https://redmine.lighttpd.net/projects/lighttpd/wiki/Server_http-parseoptsDetails
# (might need to explicitly set "url-path-2f-decode" = "disable"
# if a specific application is encoding URLs inside url-path)
server.http-parseopts = (
  "header-strict" => "enable",# default
  "host-strict" => "enable",# default
  "host-normalize" => "enable",# default
  "url-normalize-unreserved"=> "enable",# recommended highly
  "url-normalize-required" => "enable",# recommended
  "url-ctrls-reject" => "enable",# recommended
  "url-path-2f-decode" => "enable",# recommended highly (unless breaks app)
 #"url-path-2f-reject" => "enable",
  "url-path-dotseg-remove" => "enable",# recommended highly (unless breaks app)
 #"url-path-dotseg-reject" => "enable",
 #"url-query-20-plus" => "enable",# consistency in query string
)

index-file.names = ( "index.php", "index.html" )
url.access-deny = ( "~", ".inc" )
static-file.exclude-extensions = ( ".php", ".pl", ".fcgi" )

# default listening port for IPv6 falls back to the IPv4 port
include_shell "/usr/share/lighttpd/use-ipv6.pl " + server.port
include_shell "/usr/share/lighttpd/create-mime.conf.pl"
include "/etc/lighttpd/conf-enabled/*.conf"

#server.compat-module-load = "disable"
server.modules += (
        "mod_dirlisting",
        "mod_staticfile",
)

```

Did I bork lighttpd.conf along the way? I’ll try an uninstall/reinstall of pi-hole and LLSP.

---

<div class="post-metadata">

### Author: ![Joulinar](https://dietpi.com/forum/user_avatar/dietpi.com/joulinar/32/57_2.png) [@Joulinar](https://dietpi.com/forum/u/Joulinar)
#### Post date: [6 December 2021 21:35 UTC](https://dietpi.com/forum/t/self-signed-sertificate/5371/27 "2021-12-06T21:35:55Z")

</div>

did you tried to use a different browser or to clear cache / cookies?

---

<div class="post-metadata">

### Author: ![willis936](https://dietpi.com/forum/letter_avatar_proxy/v4/letter/w/c77e96/32.png) [@willis936](https://dietpi.com/forum/u/willis936)
#### Post date: [6 December 2021 21:50 UTC](https://dietpi.com/forum/t/self-signed-sertificate/5371/28 "2021-12-06T21:50:31Z")

</div>

I started from scratch and observed the same behavior. It is indeed a cached page. When browsing the page from a private tab I get a page not found error from the browser for both the base page and /admin.

---

<div class="post-metadata">

### Author: ![Joulinar](https://dietpi.com/forum/user_avatar/dietpi.com/joulinar/32/57_2.png) [@Joulinar](https://dietpi.com/forum/u/Joulinar)
#### Post date: [6 December 2021 22:15 UTC](https://dietpi.com/forum/t/self-signed-sertificate/5371/29 "2021-12-06T22:15:56Z")

</div>

is the web server working in a standard setup, without the modifications on SSL?

---

<div class="post-metadata">

### Author: ![willis936](https://dietpi.com/forum/letter_avatar_proxy/v4/letter/w/c77e96/32.png) [@willis936](https://dietpi.com/forum/u/willis936)
#### Post date: [7 December 2021 00:05 UTC](https://dietpi.com/forum/t/self-signed-sertificate/5371/30 "2021-12-07T00:05:56Z")

</div>

Yes. When the dietpi-https and dietpi-https\_redirect are disabled and external.conf removed the /admin interface works as expected.

Edit: The strangest thing. I undid the changes in order to go back to https and everything now works as expected.

---

<div class="post-metadata">

### Author: ![Joulinar](https://dietpi.com/forum/user_avatar/dietpi.com/joulinar/32/57_2.png) [@Joulinar](https://dietpi.com/forum/u/Joulinar)
#### Post date: [7 December 2021 14:47 UTC](https://dietpi.com/forum/t/self-signed-sertificate/5371/31 "2021-12-07T14:47:31Z")

</div>

hmm maybe some typo or config issue on one of the files you adjusted?

[Previous page](https://dietpi.com/forum/t/self-signed-sertificate/5371.md?page=1)
