Differences

This shows you the differences between two versions of the page.

Link to this comparison view

java:ssl [02/05/2014 17:09]
Anthony Arents [Tomcat in netbeans]
java:ssl [23/10/2018 15:07] (current)
Anthony Arents [Use the keytool tool in the JDK]
Line 2: Line 2:
  
 In case a certificate changes, a server moves, ... In case a certificate changes, a server moves, ...
 +
 +First : download the certificate, I recommend using firefox to navigate to the url, clicking the security icon, view certificate -> details -> export.
  
 ===== Use the keytool tool in the JDK ===== ===== Use the keytool tool in the JDK =====
  
 on most of our servers : on most of our servers :
-<code bash>/usr/lib/jvm/jdk1.7.0/jre/bin/keytool -importcert -file ~/\*.innosystems.net -keystore /usr/lib/jvm/jdk1.7.0/jre/lib/security/cacerts</code>+<code bash>sudo /usr/lib/jvm/jdk1.7.0/jre/bin/keytool -importcert -trustcacerts -file ~/\*.innosystems.net -keystore /usr/lib/jvm/jdk1.7.0/jre/lib/security/cacerts</code> 
 + 
 +on finanzprofi server : 
 +<code bash>sudo /usr/lib/jvm/java-7-openjdk-amd64/jre/bin/keytool -importcert -trustcacerts -file ~/\*.innosystems.net -alias inno201708 -keystore /usr/lib/jvm/java-7-openjdk-amd64/jre/lib/security/cacerts</code> 
 + 
 +on profiberatung server (apella/finakom) : 
 +<code bash>sudo /usr/lib/jvm/java-7-oracle/jre/bin/keytool -importcert -trustcacerts -file ~/\*.innosystems.net -alias inno201708  -keystore /usr/lib/jvm/java-7-oracle/jre/lib/security/cacerts</code>
  
 on java6sun : on java6sun :
 <code bash>/etc/java-6-sun/security/cacerts</code> <code bash>/etc/java-6-sun/security/cacerts</code>
  
-password = changeit 
  
 +on our newest servers :
 +<code bash>sudo /usr/lib/jvm/default-java/jre/bin/keytool -importcert -trustcacerts -file ~/\*.innosystems.net -keystore /usr/lib/jvm/default-java/jre/lib/security/cacerts</code>
  
 +on MAC osX :
 +<code bash>sudo /Library/Java/JavaVirtualMachines/jdk1.8.0_181.jdk/Contents/Home/jre/bin/keytool -importcert -trustcacerts -file ~/Desktop/mobi.crt -keystore /Library/Java/JavaVirtualMachines/jdk1.8.0_181.jdk/Contents/Home/jre/lib/security/cacerts</code>
 +
 +''password = changeit''\\
 +\\
 +It's possible you don't need to reïnitialize Tomcat if it has been configured to use the keystore.
 ===== Mac : Tomcat in netbeans ===== ===== Mac : Tomcat in netbeans =====
  
Line 24: Line 39:
  
 example : /Library/Java/JavaVirtualMachines/jdk1.7.0_45.jdk/Contents/Home example : /Library/Java/JavaVirtualMachines/jdk1.7.0_45.jdk/Contents/Home
 +then use the following code
 +<code bash>cd <PATH TO JAVA INSTALLATION>
 +sudo bin/keytool -importcert -trustcacerts -file ~/\*.innosystems.net -keystore lib/security/cacerts</code>
  
-adjust the keytool code above to use the path you've found.+===== certificate already exists with that key =====
  
-===== No permission =====+add --alias RANDOMNAME
  
-Use sudo ! 
  
-===== certificate already exists with that key =====+===== ! PRODUCTION =====
  
-add --alias RANDOMNAME+When multiple instances of tomcat are running, the cacerts cache will only renew when ALL of them are closed. \\  
 +This is ofcourse NOT desirable so... as a quick fix you can tell tomcat, to use the file it should be using anyways :
  
 +''-Djavax.net.ssl.trustStore=/usr/lib/jvm/jdk1.7.0/jre/lib/security/cacerts''
 +
 +this bypasses the incomprehensible caching feature of the java keystore.
  
 ===== Last STEP : Tomcat restart ===== ===== Last STEP : Tomcat restart =====
 +
 +Only if it was not already configured with keystore. Rule of thumb : test before restart