[jboss-jira] [JBoss JIRA] (WFLY-3483) Improve the ability to use MS Windows keystore for the web servers ssl connector
Tomaz Cerar (JIRA)
issues at jboss.org
Thu Jun 12 06:10:39 EDT 2014
[ https://issues.jboss.org/browse/WFLY-3483?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=12975590#comment-12975590 ]
Tomaz Cerar commented on WFLY-3483:
-----------------------------------
Same still applies to WildFly & Undertow.
There is major work going on in SSL area for WildFly 9 as part of WFLY-3224 probably this will be covered in same batch of work.
> Improve the ability to use MS Windows keystore for the web servers ssl connector
> --------------------------------------------------------------------------------
>
> Key: WFLY-3483
> URL: https://issues.jboss.org/browse/WFLY-3483
> Project: WildFly
> Issue Type: Enhancement
> Security Level: Public(Everyone can see)
> Components: Security
> Affects Versions: 8.1.0.Final
> Reporter: Derek Horton
> Assignee: Darran Lofthouse
>
> It is possible to configure the web ssl connector to use the Windows certificate keystore (access provided by the SunMSCAPI provider). However, the JSSESocketFactory checks for a keystore file. This check should likely be skipped when the connector is configured to use the Windows keystore.
> Here is what the configuration looks like:
> {noformat}
> <connector name="https" protocol="HTTP/1.1" scheme="https" socket-binding="https" secure="true">
> <ssl name="https"
> key-alias="jbossweb"
> keystore-type="Windows-MY"
> protocol="TLSv1"
> </connector>
> {noformat}
> This results in an error like this:
> 13:54:01,821 ERROR [org.apache.coyote.http11] (MSC service thread 1-5) JBWEB003043: Error initializing endpoint: java.io.FileNotFoundException: C:\Users\imauser\.keystore (The system cannot find the file specified)
> You can work around this issue by creating this keystore (C:\Users\imauser\.keystore).
> More info on using the Windows keystores can be found here:
> http://docs.oracle.com/javase/7/docs/technotes/guides/security/SunProviders.html#SunMSCAPI
> http://www.oracle.com/technetwork/articles/javase/security-137537.html
--
This message was sent by Atlassian JIRA
(v6.2.6#6264)
More information about the jboss-jira
mailing list