Nar*_*esh 1 java ssl tomcat keytool
我们的一位客户从 GoDaddy 购买了通配符 SSL 证书 (*.example.com),他只是下载了而没有提供 CSR 数据。我们在那个 zip 文件中有 3 个文件。那些是fce4f111a61ea3f4.crt,gd_bundle-g2-g1.crt和gdig2.crt.pem。
我搜索了很多关于此的文章,但每个人都说首先从您的服务器获取 CSR 数据并将其传递到 GoDaddy 中以获取 SSL 证书。
就我而言,我们没有向 GoDaddy 提供 CSR 数据,这意味着我没有密钥库文件。
现在,我尝试在我的服务器上安装没有密钥库的证书。为此,我使用了以下命令但没有成功:
keytool -import -alias root -keystore tomcat.keystore -trustcacerts -file fce4f111a61ea3f4.crt
keytool -import -alias interm -keystore tomcat.keystore -trustcacerts -file gd_bundle-g2-g1.crt
keytool -import -alias tomcat -keystore tomcat.keystore -trustcacerts -file gdig2.crt.pem
Run Code Online (Sandbox Code Playgroud)
我假设您已经按照上面的陈述维护了密钥库。首先备份您的密钥库以避免发生任何事故。
除了您拥有的文件之外,您还应该拥有生成的证书的私钥。
现在按照命令执行步骤。
keytool -delete -alias tomcat -keystore domain.jks
Run Code Online (Sandbox Code Playgroud)
您还可以通过删除来查看任何其他现有条目。keytool -list -keystore domain.jks
openssl pkcs12 -export -in fce4f111a61ea3f4.crt -inkey private.key -out cert_and_key.p12 -name tomcat -CAfile gd_bundle-g2-g1.crt -caname root
Run Code Online (Sandbox Code Playgroud)
如果您收到类似以下错误
unable to load private key
139995851216720:error:0906D06C:PEM routines:PEM_read_bio:no start line:pem_lib.c:707:Expecting: ANY PRIVATE KEY
Run Code Online (Sandbox Code Playgroud)
这意味着您的private.key格式不正确,您需要更改编码才能ASCII text运行以下命令来转换您的私钥
unable to load private key
139995851216720:error:0906D06C:PEM routines:PEM_read_bio:no start line:pem_lib.c:707:Expecting: ANY PRIVATE KEY
Run Code Online (Sandbox Code Playgroud)
# You can do a dry run before manipulating the actual file
tail -c +4 private.key | file -
# Change encoding
tail -c +4 private.key > private.key
Run Code Online (Sandbox Code Playgroud)
keytool -importkeystore -srckeystore cert_and_key.p12 -srcstoretype PKCS12 -alias tomcat -keystore domain.jks
Run Code Online (Sandbox Code Playgroud)
server.xmlkeytool -import -trustcacerts -alias root -file $certdir/gd_bundle-g2-g1.crt -noprompt -keystore domain.jks
Run Code Online (Sandbox Code Playgroud)
不要忘记替换xxxxxx为您的 JKS 密钥库密码和keystoreFile参数
<Connector port="8443" protocol="org.apache.coyote.http11.Http11Protocol" maxThreads="150"
SSLEnabled="true" scheme="https" secure="true" clientAuth="false" sslProtocol="TLS"
keystoreFile="/path/to/keysore/domain.jks" keystorePass="xxxxxx"
ciphers="TLS_ECDHE_RSA_WITH_AES_128_CBC_SHA256, TLS_ECDHE_RSA_WITH_AES_128_CBC_SHA,
TLS_ECDHE_RSA_WITH_AES_256_CBC_SHA384, TLS_ECDHE_RSA_WITH_AES_256_CBC_SHA,
TLS_ECDHE_RSA_WITH_RC4_128_SHA, TLS_RSA_WITH_AES_128_CBC_SHA256,TLS_RSA_WITH_AES_128_CBC_SHA,
TLS_RSA_WITH_AES_256_CBC_SHA256,TLS_RSA_WITH_AES_256_CBC_SHA, SSL_RSA_WITH_RC4_128_SHA" />
Run Code Online (Sandbox Code Playgroud)
注意:替换domain.jks为您的实际密钥库文件。
| 归档时间: |
|
| 查看次数: |
4436 次 |
| 最近记录: |