从JAVA应用程序使用SSL连接到MongoDb

Gur*_*kha 5 java ssl mongodb

我有一个MongoDb正在运行的实例(单个实例)已SSL启用。我可以使用以下选项卡上的RoboMongo位置进行连接SSL:

CA File : /path to my certificate/testCA.pem 
PEM certificate/key: /path to my key/testKey.pem
Run Code Online (Sandbox Code Playgroud)

哪个成功连接。现在,我尝试从Java应用程序连接到同一mondodb。我使用以下命令将testCA.pem导入了cacerts中:

keytool -import -keystore cacerts -file testCA.pem -storepass changeit
Run Code Online (Sandbox Code Playgroud)

我可以看到一个新条目已添加到商店中。试图在其中添加另一个密钥,并显示证书无效。在Java应用程序上,我将系统属性设置如下:

System.setProperty ("javax.net.ssl.trustStore","C:\\Program Files\\Java\\jre1.8.0_91\\lib\\security\\cacerts");
System.setProperty ("javax.net.ssl.trustStorePassword","changeit");
Run Code Online (Sandbox Code Playgroud)

并且出现以下错误:

org.springframework.dao.DataAccessResourceFailureException: Timed out after 10000 ms while waiting to connect. Client view of cluster state is {type=Unknown, servers=[{address=test.mongo.com:27017, type=Unknown, state=Connecting, exception={com.mongodb.MongoException$Network: Exception opening the socket}, caused by {java.io.EOFException}}]; nested exception is com.mongodb.MongoTimeoutException: Timed out after 10000 ms while waiting to connect. Client view of cluster state is {type=Unknown, servers=[{address=test.mongo.com:27017, type=Unknown, state=Connecting, exception={com.mongodb.MongoException$Network: Exception opening the socket}, caused by {java.io.EOFException}}]
    at org.springframework.data.mongodb.core.MongoExceptionTranslator.translateExceptionIfPossible(MongoExceptionTranslator.java:75)
    at org.springframework.data.mongodb.core.MongoTemplate.potentiallyConvertRuntimeException(MongoTemplate.java:2075)
    at org.springframework.data.mongodb.core.MongoTemplate.executeFindMultiInternal(MongoTemplate.java:1918)
Run Code Online (Sandbox Code Playgroud)

我在这里想念的是什么,谢谢!

Gur*_*kha 5

除了CAFile.pem使用命令导入:

(导航到您java_home/jre/lib/security要运行的命令)

1. keytool -import -trustcacerts -file testCA.pem -keystore cacerts -storepass "changeit"

我还必须将其导出key.pem为pkcs12格式(默认密码'changeit')

2. openssl pkcs12 -export -out mongodb.pkcs12 -in testKey.pem

除了设置系统属性 trustStore/password 之外,还应该设置 keyStore/password:

System.setProperty ("javax.net.ssl.trustStore",JAVA_HOME + "\\lib\\security\\cacerts");
System.setProperty ("javax.net.ssl.trustStorePassword","changeit");
System.setProperty ("javax.net.ssl.keyStore",JAVA_HOME + "\\lib\\security\\mongodb.pkcs12");
System.setProperty ("javax.net.ssl.keyStorePassword","changeit");
Run Code Online (Sandbox Code Playgroud)