Posts

Showing posts with the label Certificate

Generating a Self Signed Certificate and Keystore And TrustStore

keytool -genkey -alias mykey -keyalg RSA -keysize 2048 -sigalg SHA256withRSA -validity 365 -keypass password-keystore Keystore.jks -storepass password keytool  -export -alias mykey -file root.cer -keystore Keystore.jks -storepass password keytool -import -alias mykey -file root.cer -keystore Trustore.jks -storepass password

Debugging the SSL Issues in Linux

First of all the JVM Needs to start in the Debug mode as many servers report the errors vaguely. It is better to start in Debug mode Add the JVM parameter -Djavax.net.debug=all After that before Even trying to run the transaction try to connect the server with the certificate using openssl openssl s_client -showcerts -connect 10.24.256.69:443 If the certificate is present it shows the last statement as Verify return code: 0 (ok) Check the link below for a more detailed tutorial. http://www.cyberciti.biz/faq/test-ssl-certificates-diagnosis-ssl-certificate/ If for some reason is receiving an error OpenSSL: socket: Connection refused connect:errno=111 It means that the PORT might be wrong in the connection. So we need to find the right port on which https is running. This can be done using nmap So what u do is nmap -sS 10.24.256.69 sample output for above command  Host is up (0.0051s latency). Not shown: 999 closed ports PORT    STATE ...

How to import .cer file in to .truststore file?

# Copy the certificate into the directory Java_home\Jre\Lib\Security # Change your directory to Java_home\Jre\Lib\Security> # Import the certificate to a trust store. keytool -import -alias ca -file somecert.cer -keystore cacerts –storepass changeit [Return] Trust this certificate: [Yes]