Unable to get SSL + Tomcat working correctly

Hi All,
Issue: Enabled SSL on Tomcat. First HTTPS request to JSP works, all HTTPS requests to JSPs after the first request fail (sever not found - page cannot be displayed error). The error does not get logged in the log files. The same JSPs work fine with HTTP.
Background info:
1. Installed Tomcat 4.1.24
2. Installed J2sdk1.4.1_01 (includes JSSE)
3. Created a .keystore using keytool
With the default .keystore the HTTPS requests to JSPs work fine.
4. Imported the server cert (given by our internal security folks) using
keytool -alias key skey - import -file server.crt.der
Upon accessing the JSPs using HTTPS. I am getting an error: Could'nt find trusted certs.
5. I also imported the CA cert into .keystore using
keytool -alias cakey -import -file ca.crt.der - trustcacerts
I still get the error: Couldnt find trusted certs.
Could any one please help me figure out why I am getting this error.
NOTE: I had to convert the certs (given by our internal security folks) from pkcs12 format to x509 and I had used Openssl 0.9.6g for that.
Thank you,
-Bala

Okay, my post did not fully qualify why
I suggested explicitly locating your keystore
file.
The tomcat source uses:
private String keystoreFile =
System.getProperty("user.home") + File.separator + ".keystore";
to identify the location of the keystore file.
A simple java program that echo's the user.home property will
tell you exactly where tomcat is looking for the keystore. Often
it is easier to explicitly locate the keystore file so you can
run the tomcat process from your developer user and you know
exactly which keystore you're using.
If you look at the SSLServerSocketFactory code in the tomcat/catalina
source you can see how it derives the values for parameters it
uses to configure the SSL socket.
-Steve

Similar Messages

  • Unable to get my Alphatrack working correctly in Adobe Audition CS6

    I am getting very frustrated with Adobe CS6 Audition, I cannot get my Alphatrack device to work properly.
    Also has anyone any experience of setting up Alphatrack as a Mackie device and how to setup button assignments
    Thanks

    Hi dieghen89
    Nice to know I'm not the only one pulling out hair over here
    I was playing around and did the following:
    1. Exit nm-applet completely
    2. $ gnome-keyring-daemon --start //I know that the daemon is running. --help states that it starts or initialize an already running daemon
    3. Run nm-applet again
    And the keyring dialog actually did pop up asking for the password to unlock it.
    Now I thought a quick-fix would be to add gnome-keyring-daemon --start to my startup script before nmapplet &
    But alas. doesn't work

  • Unable to get Phone Dialer working

    Hello everyone,
    I have setup a brand new client. And I am unable to get the dialer working correctly.
    I have followed the directions here: Re: The Top10 most frequently asked questions and answers (FAQ) January 2009
    - Telephony service is started
    - Windows XP Phone and Modem settings correctly configured
    - Phone Dialer does work and does show the progress of the "manual" test call
    - Phone Dialer is running and minimized
    - SAP/b1 General Settings/Service is setup with an area code.. nothing needed for an outside line
    When I pull up a Business Partner and hover over a phone number, I hit CTRL+TAB and nothing happens... the next field is just highlighted and no dialing occurs.
    Any thoughts as to what I'm missing to get this working correctly?
    All input is welcome.
    Thanks!
    ~ terry o.

    Finally got this working. Please setup your dialer using these directions;
    - Telephony service is started
    - Windows Phone and Modem settings correctly configured with any required settings like area code or country
    - Run Phone Dialer (dialer.exe) and confirm it does work and does show the progress of a "manual" test call
    - Change SAP/b1 General Settings/"Service" is setup with an area code.. and outside line requirements
    Open SAP/b1 and hover your cursor over a phone number. When the "phone" icon is displayed, press "CTRL + double-click".
    The dialer should open and you should see the progres of your call.
    Good luck!
    ~ terry o.

  • PLEASE HELP ME??? Lost itunes trying to downgrade back from 11.0 & unable to get itunes to work at all now..

    New Itunes setup is the worst one yet!!! I couldn't stand it, so I tried uninstalling it and reinstalling older versions, but now I am unable to get it to work in any version. I have uninstalled & reinstalled several times (trying this with multiple versions). Strange thing is that ever since I uninstalled 11.0 I have not been able to get any of the other versions to open at all.. Sometimes an error message box dings & pops up that says something about how to adjust the volume through your itunes, or unable to open file.. other times when I click on the icon it just does absolutely nothing. WILL SOMEONE PLEASE HELP ME??? I'm going crazy without my music & I am panicking because I am afraid I may have lost all music (I have thousands & thousands of songs on there).. I'm hoping to find a way to reinstall an older version, but at this point if I can't find a way to bring back the old version, I'll take 11.0 if I absolutely have to (meaning if it's the only way to retrieve itunes without losing my entire library)

    Have latest version of iTunes installed and running. Also make sure you have internet access working and can access Apple websites. Also, make sure you don't have any entries in your hosts file referring to gs.apple.com....If your not sure about how to do that, go ahead and do the rest first. You can come back to that later.....Plug in phone. Put phone in DFU mode.(google put iphone in DFU mode for instructions) Then restore the phone in iTunes by highliting your device in the left column and click on the Restore button. The latest iOS version is 4.3.3. That's what iTunes will restore it to. When it's done restoring, iTunes will ask if you want to restore from a backup or setup as a new phone. I would use the Setup as a New Phone option. Once it's done, you should have a clean install of the iOS and an operating phone, as long as there are no hardware issues with it.

  • Currently working on OpenSPARC. Unable to get ModelSim for working on Linux

    We are working on OpenSPARC. We need to get ModelSim to compile the code in Verilog. We are unable to get ModelSim to work on Fedora Linux Version 9, as ModelSim only works on Windows.Is there a way to get Modelsim for Fedora Linux version 9.
    Regards,
    K.Pradheep Kumar
    19.08.08

    They have a Modelsim LE version for Linux. Check this out:
    http://www.model.com/products/default.asp

  • I am also unable to get the 551L working with Windows 8 Beta 1. Any advice?

    I am also unable to get the 551L working with Windows 8 Beta 1 and Mac OS X 10.8 Mountain Lion Developer Preview 2. Any Advice?

    It should be noted that I was previously in those Windows Beta's and I am also a member of both Microsoft Technet (Retail Subscription), and all 3 Apple Developer Programs (IOS, Mac and Safari), which is the reason why I am running Microsoft Windows 8 Beta 1 on 2 of my 3 Dell's (the oldest one has Microsoft Windows XP Service Pack 3 and Microsoft Office 2003 on it, which is the PC that I am using the 551L on), and the Mid Year 2010 Apple Mac Mini has Mac OS X 10.8 Mountain Lion Server Edition on it (something that I am technically am NOT supposed to be talking about here due to my NDA so this will be the last time I mention it here (as you can see I am known for being the type of  Computer Nerd that loves Alpha and Beta Testing)! :-)

  • I am unable to get my bluetooth working message says "make sure car mutli media is in range" how do I get connected?

    I am unable to get my bluetooth working on my phone. the message says "make sure car mutli media is in range" how do I get connected and what does that mean?

    Have you tried a soft-reset ? Press and hold both the sleep and home buttons for about 10 to 15 seconds (ignore the red slider if it appears), after which the Apple logo should appear - you won't lose any content, it's the iPad equivalent of a reboot.

  • I am unable to get quicktime to work in IE10

    I am unable to get quicktime to work in IE10 each time it just redirects me to the quicktime download, I've uninstalled and reinstalled quicktime, I've done a reset on IE, tried unchecking ActiveX filtering...Any other ideas?

    I'm working my way through Dreamweaver CC Classroom in a Book. The template in the exercise I'm trying to complete has sections that you can edit and those that you cannot. The links involved are to buttons in the non-editable sections. Since they're non-editable, you can't employ Property Inspector to alter content in those sections. I surmise that the through the Assets Panel approach is supposed to give you the capacity to add hyperlinks to those sections. Double clicking the template does not give you access to those non-editable sections. I've tried that along with a number of other circumventing the Assets Panel approaches. I've dug up a verson of the template from an earlier exercise that doesn't have any non-editable sections and the Property Inspector works fine. With some fumbling aboutI 'm sure I could go right to the code as well.
    Ultimately, I don't think I'll have any difficulty with my project working around the Assets Panel. The deal is... it's supposed to work... and it doesn't. And being blown off by support really ticks me off. I'm sure yoou understand.
    Thanks for your time and effort on my behaf. Being a really stubborn son of a *****... I'll probably keep after this until I get an answer... whether I ever need to use the Assets Panel or not.
                                                                Thanks again.

  • How do I get dictation to work correctly in Microsoft Word 2011?

    I am trying to get dictation to work correctly in Microsoft Word. It is not responding to commands like "new paragraph" or "new line".  All of the text ends up in the same paragraph.  Dictation works fine in Pages and Gmail, but not in Word.
    Any ideas?  Thanks in advance...

    Same here. I'm using office 2013. It is hard to believe, That there is still no solution for that problem. Parallels desktop and office 2013 lets you dictate, Though there is still no way to get the  new line or new paragraph 
    command to get to work in word or outlook. Do you think this isn't a apple issue or a Microsoft issue? On Windows in the ordinary editor the commands work well.
    I actually changed to mac for this killerfeature and i really need it. Now it does not work in the most common office app..

  • Can't get SSL to work for WebVPN

    Hi all,
    I'm trying to get webvpn setup, and have it all configured correctly.... but there seems to be a problem with the SSL part.
    I can connect on port 80, it redirects to port 443... but never shows the login box, just keeps trying to load.
    I can telnet to port 443 fine and i've disabled all other services using port 443 (like http secure-server).
    The status is UP for the gateway and context. I've no idea what to do next. It appears to be trying, but not succeeding. I've tried different IPs, on different sides of the NAT. I've tried with loopback ip, ips on the VLAN, the public IP etc.
    Please please help, here's some info...
    MD1#sh webvpn gate MD
    Admin Status: up
    Operation Status: up
    Error and Event Logging: Disabled
    IP: 192.168.2.199, port: 443
    SSL Trustpoint: SSLVPN
    FVRF Name not configured
    MD1#sh webvpn cont MD
    Admin Status: up
    Operation Status: up
    Error and Event Logging: Disabled
    CSD Status: Disabled
    Certificate authentication type: All attributes (like CRL) are verified
    AAA Authentication List: default
    AAA Authentication Domain not configured
    Default Group Policy not configured
    Associated WebVPN Gateway: MD
    Domain Name and Virtual Host not configured
    Maximum Users Allowed: 25
    NAT Address not configured
    VRF Name not configured
    MD1#sh webvpn install st svc
    SSLVPN Package SSL-VPN-Client version installed:
    CISCO STC win2k+ 1.0.0
    1,1,3,173
    Mon 12/11/2006 18:41:54.43
    MD1#sh webvpn install st csd
    SSLVPN Package Cisco-Secure-Desktop version installed:
    CISCO CSD IOS
    3,1,1,45
    Mon 10/23/2006 11:18:00.42
    Thanks
    ~Matt

    PS: I've tried recreating the SSL certificate to no avail.
    If i enable the https server for SDM etc, the SSL certificate works fine.

  • How do you get SSL to work on Mac OS X Server 10.5.8?

    Hi, I have created a SSL certificate (twice with the server admin tools and once with the openssl command) and I get this in the log of the apache web service:
    [error] Init: Pass phrase incorrect
    I have searched but aside from changing the httpd.conf file to not use:
    SSLPassPhraseDialog exec:/etc/apache2/getsslpassphrase
    and instead echo a generic passphrase, I don't know what to do. I have not tried this btw. It seems the wrong answer, even if it works.
    I have also seen to uncheck the performance cache option in the sites, option pane, but 10.5 does not have this and I don't know if it exists in a config file somewhere.
    Does anyone know how to get SSL working on the mac leopard server? it's a stock, advanced install.
    Thank you for any help.

    Easiest way is to not use a passphrase on the cert. It isn't required and can be left blank. That way apache doesn't need to know it and will use the certificate.
    Of course, this means you need to manage access to your certificates, but that should be the case anyway.

  • Can't get SSL to work :(

    Hi guys,
    Little question: I can't get SSL up and running . I used the cer. that was created by the installation of my new mac OSX 10.6 Server. I exported the cer. and have imported it in my Macbook Pro (Mac OSX 10.6.1) now I want to use it with a VPN connection but can't connect (without using the cer. everthing works). Any ideas?? I'm not the Mac OSX expert but I know my way .
    Grtz
    Sgt Van de Vyver
    Belgium - Antwerp

    PS: I've tried recreating the SSL certificate to no avail.
    If i enable the https server for SDM etc, the SSL certificate works fine.

  • Unable to get following example working

    http://java.sun.com/products/jlf/ed2/samcode/textme1.html
    i am unable to get this example of file menus working.
    i have created a new project in JBuilder called TextMenu.jpx
    i have altered the project properties to look for TextMenu as the main method but it gives me a compilation error:
    "java.lang.NoClassDefFoundError: TextMenu
    Exception in thread "main" "
    can anyone else get this example working???

    Hi there,
    OK So its been two years since the last reply to this thread, but just incase anyone else out there is having problems with getting this example working in JBuilder here is how we did it.
    First off remove the "package samples;" line from the top of the .java file
    then locate the following line
    resources = ResourceBundle.getBundle( "samples.resources.bundles.TextMenuResources", locale);
    and change the part in the quotes to just "TextMenuResources".
    Finally open the samples.jar file and extract the file "TextMenuResources.properties" to the class folder of the project you are working on (for example if your project was called "TextMenu" then locate the "\TextMenu\class" folder and extract the file to there).
    Then compile the .java file in jbuilder and it runs, hopefully.
    I'm guessing there are easier ways to achieve a working state, but i had to get this working on a college computer with a variety of security precautions in place (including no command prompt, and no control panel which makes altering the classpath environment variable hard unfortunately).
    Hope that this helps someone.
    Sheepy / Andy

  • Unable to get Twitter Stream working in SocialMiner

    I've had this working in the past but recently the Twitter Stream stopped working in SocialMiner 8.5(3).  I can create a Twitter Stream but when I add it to Campaigns the state "Twitter Stream read error.  Last successful fetch time was NEVER, Success rate is 0%"  I don't see anything was changed, DNS is working, username/password for the Twitter Stream is correct, I just can't seem to figure out what the issue is.  What specific logs can I look at to determine the issue?
    Thanks
    Travis

    @travis 
    Have you tried google chat?  I have a system set up with google chat XMPP so I know that works (my other system is using webex connect.  I don't have one set up with CUP at this time.)
    Create a gmail account.
    The SocialMiner settings are:
    Enabled:
    Yes
    Enable Service Lookup:            Yes
    XMPP Service Name:gmail.com
    User Name:
    [email protected]
    Password: *******
    Again, SocialMiner should work with CUP as well and TAC should be able to start troubleshooting process on that but if you just want to get the XMPP working then you can see how that works with Google chat (also note: getting it to work with google may help narrow the issue with CUP.)

  • HT2213 I am unable to get this to work. Anyone have success on this?

    I recently had a firmware update go bad on me. I did as it said and it flashed the led and beeped once and the screen remained black. After a long time with nothing happening I shut it down and tried again but this time got the 3 quick 3 long 3 quick beeps/flashes. I downloaded the firmware restoration cd and I am unable to get the cd to work. My mac is a macbook core duo and I have both the restoration cds 1.3 and 1.4. Neither work. I would appreciate any help.

    Never mind. I found out that there isnt a disk for this model yet.

Maybe you are looking for