Re: cert/key config woes

2022-06-15 Thread Rob Sargent
Chris, Back at my desk and going through you notes again. On 6/14/22 14:43, Rob Sargent wrote: Let's get one thing working at a time. I reviewed this thread, and I honestly can't figure out exactly what you are trying to do. Can you please clarify? 1. "I want to get Tomcat working as a serv

Re: cert/key config woes

2022-06-15 Thread Rob Sargent
> On Jun 15, 2022, at 7:45 AM, Christopher Schultz > wrote: > > Rob, > >> On 6/14/22 15:38, Rob Sargent wrote: >> On 6/14/22 13:06, Christopher Schultz wrote: >> Thanks so much for your perseverance. > > No problem. Anything to avoid doing $work. Away from my desk this morning but will re

Re: cert/key config woes

2022-06-15 Thread Christopher Schultz
Rob, On 6/14/22 15:38, Rob Sargent wrote: On 6/14/22 13:06, Christopher Schultz wrote: Thanks so much for your perseverance. No problem. Anything to avoid doing $work. On 6/14/22 14:43, Rob Sargent wrote: Let's get one thing working at a time. I reviewed this thread, and I honestly can't

Re: cert/key config woes

2022-06-14 Thread Rob Sargent
On 6/14/22 13:06, Christopher Schultz wrote: Thanks so much for your perseverance. On 6/14/22 14:43, Rob Sargent wrote: Let's get one thing working at a time. I reviewed this thread, and I honestly can't figure out exactly what you are trying to do. Can you please clarify? 1. "I want to

Re: cert/key config woes

2022-06-14 Thread Christopher Schultz
Rob, On 6/14/22 14:43, Rob Sargent wrote: I have my environment working again but not with supplying both keystore and truststore to both the server and the client.  Clearly scrogged somewhere Let's get one thing working at a time. I reviewed this thread, and I honestly can't figure out exac

Re: cert/key config woes

2022-06-14 Thread Rob Sargent
On 6/14/22 12:43, Rob Sargent wrote: On 6/2/22 16:06, Rob Sargent wrote: I'm starting both the server and the client with both key and trust. Does that bite? I would avoid giving access to the key to anything that doesn't absolutely need it. Usually, only the server needs access to the

Re: cert/key config woes

2022-06-14 Thread Rob Sargent
On 6/2/22 16:06, Rob Sargent wrote: I'm starting both the server and the client with both key and trust. Does that bite? I would avoid giving access to the key to anything that doesn't absolutely need it. Usually, only the server needs access to the key. -chris -

Re: cert/key config woes

2022-06-02 Thread Rob Sargent
I'm starting both the server and the client with both key and trust. Does that bite? I would avoid giving access to the key to anything that doesn't absolutely need it. Usually, only the server needs access to the key. -chris ---

Re: cert/key config woes

2022-06-02 Thread Christopher Schultz
Rob, On 6/2/22 14:19, Rob Sargent wrote:    Caused by: java.lang.IllegalArgumentException: Alias name [sgsAgent]    does not identify a key entry         at > [...] but I believe the alias is in place, both places    ## check, different files    [ec2-user@ip-10-0-2-118 certs]ls

Re: cert/key config woes

2022-06-02 Thread Rob Sargent
    java  -Djavax.net.ssl.keyStore=/ppr/certs/sgstrust.p12     -Djavax.net.ssl.keyStoreType=PKCS12 -Djavax.net.ssl.keyStorePassword=p1     -Djavax.net.ssl.trustStore=/ppr/certs/fullca.p12     -Djavax.net.ssl.trustStoreType=PKCS12     -Djavax.net.ssl.trustStorePassword=p2     --oper=1 --seg=id

Re: cert/key config woes

2022-06-02 Thread Rob Sargent
Hang on.  I'm panicking.  I have a plane to catch in 3 hours and need this working by then.    ws s3 cp fullca.p12 s3://691459864434-sgs-source/certs/sgstrust.p12 splatting one file on top of the other Midway through this email when you last came in:  "Not running" is spot-on becase... T

Re: cert/key config woes

2022-06-02 Thread Christopher Schultz
Rob, On 6/2/22 13:43, Rob Sargent wrote: I had this overall configuration working until I 'terminated' the AWS server instance and am trying to rebuild. Could a lack of network connectivity between client and server present this same symptom? Hmm. Your SAN looks okay to me. Are you 100%

Re: cert/key config woes

2022-06-02 Thread Rob Sargent
On 6/2/22 11:43, Rob Sargent wrote: I had this overall configuration working until I 'terminated' the AWS server instance and am trying to rebuild. Could a lack of network connectivity between client and server present this same symptom? Hmm. Your SAN looks okay to me. Are you 100% sure

Re: cert/key config woes

2022-06-02 Thread Rob Sargent
I had this overall configuration working until I 'terminated' the AWS server instance and am trying to rebuild. Could a lack of network connectivity between client and server present this same symptom? Hmm. Your SAN looks okay to me. Are you 100% sure you have that certificate configured

Re: cert/key config woes

2022-06-02 Thread Christopher Schultz
Rob, On 6/2/22 01:13, Rob Sargent wrote: This part always confuses me I supply the trust and key store files on the command line and I see the SAN for the tomcat server IP (in ObjectId #3). I try to connect to tomcat by host-IP and port.  Here's the text of the keystore sent in.    Keystor

RE: Cert

2013-08-02 Thread Kyle Shattuck
riginal Message- From: Martin Gainty [mailto:mgai...@hotmail.com] Sent: Friday, August 02, 2013 10:06 AM To: Tomcat Users List Subject: RE: Cert Kyle the ldap server requires the LDAP Attributes contained within the p7b dn: cn=username,o=organization,c=country objectclas

RE: Cert

2013-08-02 Thread Martin Gainty
nt donné que les email peuvent facilement être sujets à la manipulation, nous ne pouvons accepter aucune responsabilité pour le contenu fourni. From: ky...@montcalm.edu To: users@tomcat.apache.org Subject: RE: Cert Date: Fri, 2 Aug 2013 13:23:12 + My Server( CAS) is using SSL and the LDAP(

Re: Cert

2013-08-02 Thread Daniel Mikusa
> From: Daniel Mikusa [mailto:dmik...@gopivotal.com] > Sent: Friday, August 02, 2013 8:59 AM > To: Tomcat Users List > Subject: Re: Cert > > On Aug 2, 2013, at 7:33 AM, Kyle Shattuck wrote: > >> Hello, >> I am using Tomcat 7 on a windows server 2012 build for

RE: Cert

2013-08-02 Thread Kyle Shattuck
Daniel Mikusa [mailto:dmik...@gopivotal.com] Sent: Friday, August 02, 2013 8:59 AM To: Tomcat Users List Subject: Re: Cert On Aug 2, 2013, at 7:33 AM, Kyle Shattuck wrote: > Hello, > I am using Tomcat 7 on a windows server 2012 build for this: > https://wiki.jasig.org/display/CASUM/Bes

RE: Cert

2013-08-02 Thread Martin Gainty
nterdite. Ce message sert à l'information seulement et n'aura pas n'importe quel effet légalement obligatoire. Étant donné que les email peuvent facilement être sujets à la manipulation, nous ne pouvons accepter aucune responsabilité pour le contenu fourni. > Subject: Re: Cer

Re: Cert

2013-08-02 Thread Daniel Mikusa
On Aug 2, 2013, at 7:33 AM, Kyle Shattuck wrote: > Hello, > I am using Tomcat 7 on a windows server 2012 build for this: > https://wiki.jasig.org/display/CASUM/Best+Practice+-+Setting+Up+CAS+Locally+using+the+Maven2+WAR+Overlay+Method > > I don't think SSL is not working correctly because every