Re: Installing certificate chain on Tomat

2010-04-13 Thread Christopher Schultz
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 Michael, On 4/12/2010 4:55 PM, Michael Dockery wrote: > because tomcat has the root for the client cert loaded into its truststore, > and the matching client cert "subject" name (ie: user) loaded in its auth > realm > the client is therefo

Re: Installing certificate chain on Tomat

2010-04-12 Thread Michael Dockery
Mon, April 12, 2010 9:32:32 AM Subject: Re: Installing certificate chain on Tomat -BEGIN PGP SIGNED MESSAGE- Hash: SHA1 /U, On 4/10/2010 3:31 PM, /U wrote: >                    maxThreads="150" scheme="https" secure="true" >                clien

Re: Installing certificate chain on Tomat

2010-04-12 Thread Christopher Schultz
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 /U, On 4/10/2010 4:13 PM, /U wrote: > i am confused about one thing: whil keystore is explicitly specified > in connector config, what about the truststore? It can also be configured in the . Have you not read any of the documentation? > i assume t

Re: Installing certificate chain on Tomat

2010-04-12 Thread Christopher Schultz
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 /U, On 4/10/2010 3:31 PM, /U wrote: >maxThreads="150" scheme="https" secure="true" >clientAuth="false" sslProtocol="TLS" >keystoreFile="/users/me/.keystore" keystorePass="changeit" > /> Are you

Re: Installing certificate chain on Tomat

2010-04-10 Thread /U
YFAkvAtWgACgkQ9CaO5/Lv0PDQBgCgnPJP17/F6OI2UXPRaQ7xnKau > RTUAoLYShr4IVwKZJrOfyvZKGkGAvnUQ > =/uks > -END PGP SIGNATURE- > > - > To unsubscribe, e-mail: users-unsubscr...@tomcat.apache.org > For additional commands, e-mail: users-h...@tomcat.apache.org > &

Re: Installing certificate chain on Tomat

2010-04-10 Thread /U
Q9CaO5/Lv0PDQBgCgnPJP17/F6OI2UXPRaQ7xnKau > RTUAoLYShr4IVwKZJrOfyvZKGkGAvnUQ > =/uks > -----END PGP SIGNATURE- > > - > To unsubscribe, e-mail: users-unsubscr...@tomcat.apache.org > For additional comman

Re: Installing certificate chain on Tomat

2010-04-10 Thread Christopher Schultz
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 /U, On 4/10/2010 10:07 AM, /U wrote: > am i right in assuming that the identity certificate+private key is > installed > in keystoreFile of the SSL connector (C:\keystore below) and the CA > certificate chain is installed in jre/lib/security/cacerts

Re: Installing certificate chain on Tomat

2010-04-10 Thread Christopher Schultz
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 /U, On 4/10/2010 12:01 AM, /U wrote: > i am installing certificate chain on tomcat 6.x (JRE 1.6). From my CA I have > private key (PEM), > identity cert (PEM) (CA X trusts myhost) >and a cert chain file (PEM file) (entrust trusts CA X) >

Re: Installing certificate chain on Tomat

2010-04-10 Thread Crypto Sal
On 04/10/2010 12:01 AM, /U wrote: i am installing certificate chain on tomcat 6.x (JRE 1.6). From my CA I have private key (PEM), identity cert (PEM) (CA X trusts myhost) and a cert chain file (PEM file) (entrust trusts CA X) The cert chain is: (entrust) === trusts ==> (CA X) ==

Re: Installing certificate chain on Tomat

2010-04-10 Thread /U
___ > From: /U > To: users@tomcat.apache.org > Sent: Sat, April 10, 2010 10:07:47 AM > Subject: Re: Installing certificate chain on Tomat > > > hello Pid, > > am i right in assuming that the identity certificate+private key is > installed > i

Re: Installing certificate chain on Tomat

2010-04-10 Thread Michael Dockery
i had to install my ca root certs in a keystore specificed/referenced by the "truststorefile" parameter NOT the keystorefile parm From: /U To: users@tomcat.apache.org Sent: Sat, April 10, 2010 10:07:47 AM Subject: Re: Installing certificate chai

Re: Installing certificate chain on Tomat

2010-04-10 Thread /U
rom: "/U" [uma...@comcast.net] > Date: 04/10/2010 12:02 AM > To: users@tomcat.apache.org > Subject: Re: Installing certificate chain on Tomat > > Note: Original message sent as attachment > > - > T

Re: Installing certificate chain on Tomat

2010-04-10 Thread Pid *
: users@tomcat.apache.org > Subject: Re: Installing certificate chain on Tomat > > Note: Original message sent as attachment > > - > To unsubscribe, e-mail: users-unsubscr...@tomcat.apache.org > For additional

Re: Installing certificate chain on Tomat

2010-04-10 Thread nowled.excite
Maybe you are getting the certificate myhost issued by CA X is not trusted, because you a fucking virus -Original Message- From: "/U" [uma...@comcast.net] Date: 04/10/2010 12:02 AM To: users@tomcat.apache.org Subject: Re: Installing certificate chain on Tomat Note: Origin

Installing certificate chain on Tomat

2010-04-09 Thread /U
ot trrusted. It seems like browser does not get full cert chain (entrust => CA X => myhost). what could I be doing wrong? pl help. Regs, /U -- View this message in context: http://old.nabble.com/Installing-certificate-chain-on-Tomat-tp28199836p28199836.html Sent from the Tomcat - User mailin