Crypto Lab: PKI Submission Template
Use this template to add your screenshots and supporting documentation. You can copy and paste and/or edit your results under each bulleted topic area. Add space as needed to fully respond and answer each topic.
Student and semester Details:
Student name:
Date:
Professor:
Semester (e.g. Spring 2021) :
openssl s_server documentation:
· Create a screenshot of the Certificate using the View Certificate link. Be sure to display all of the components of the certificate. Hint: You may need to take several shots to capture all of the information.
· Create a screen capture of the SSL Session parameters and Shared Ciphers from EC2 instance.
· Describe any challenges you faced and how you resolved them during the many steps involved in generating the certificates and testing using openssl s_server and your browser.
· Make a copy of the server.pem file (e.g. cp server.pem server.pem.bak) and then modify a single byte of server.pem using the nano text editor. Restart the server and reload the URL. Were you successful? You may need to experiment with changes in different locations within the server.pem file. Document your experimentation and results with screenshots and descriptions of the results. Make sure you restore the original server.pem afterward. Note: The server may not be able to restart if certain parts of server.pem are corrupted; if that happens, revert your change and choose another place to modify.
Apache2 Configuration and Results:
· Include a copy of your new default-ssl.conf file that clearly shows the SSLCertificateFile and SSLCertificateKeyFile
· Include a screenshot of the final outcome showing that you can successfully browse to the HTTPS site you created.
· Describe any challenges you faced and how you resolved them during the many steps involved in installing and configuring Apache2 to support your self-signed certificates.
· Conduct additional research on Man-in-the-Middle (MITM) attacks. Describe scenarios where this type of an attack could occur even if a valid certificate was in place. Also, describe proven mitigation approaches to MITM attacks. Be sure to provide the references in APA style








Recent Comments