Tomcat 8 +在SSL

时间:2016-11-10 13:14:44

标签: java security tomcat ssl

我想指定tomcat连接器使用的提供程序,以便从java.security文件中获取默认值。

根据tomcat文档:

  

要用于服务器的密钥库提供程序的名称   证书。如果未指定,则注册的提供商列表为   以优先顺序遍历并支持第一个提供者   使用了keystoreType。

<Connector algorithm="SunX509" port="9443" keystoreProvider="" truststoreProvider="SunProvider"  protocol="org.apache.coyote.http11.Http11NioProtocol" SSLEnabled="true"
                maxThreads="100" minSpareThreads="10" maxConnections="1000" scheme="https" secure="true"
                keystoreFile="xxx.jks" keystorePass="xxx" keystoreType="jks"
                truststoreFile="yyy.jks" truststorePass="yy" truststoreType="jks"
                clientAuth="want" sslProtocol="TLSv1.2">

但我不知道可能为这个属性添加值。 我试过这个,得到错误:

org.apache.tomcat.util.net.jsse.JSSESocketFactory.getStore Failed to load keystore type jks with path /app/tomcat/conf/jks/xxx.jks due to no such provider: SunProvider
 java.security.NoSuchProviderException: no such provider: SunProvider
        at sun.security.jca.GetInstance.getService(GetInstance.java:83)
        at sun.security.jca.GetInstance.getInstance(GetInstance.java:206)
        at java.security.Security.getImpl(Security.java:698)
        at java.security.KeyStore.getInstance(KeyStore.java:896)
        at org.apache.tomcat.util.net.jsse.JSSESocketFactory.getStore(JSSESocketFactory.java:424)
        at org.apache.tomcat.util.net.jsse.JSSESocketFactory.getKeystore(JSSESocketFactory.java:339)
        at org.apache.tomcat.util.net.jsse.JSSESocketFactory.getKeyManagers(JSSESocketFactory.java:597)
        at org.apache.tomcat.util.net.jsse.JSSESocketFactory.getKeyManagers(JSSESocketFactory.java:537)
        at org.apache.tomcat.util.net.NioEndpoint.bind(NioEndpoint.java:358)
        at org.apache.tomcat.util.net.AbstractEndpoint.init(AbstractEndpoint.java:737)
        at org.apache.coyote.AbstractProtocol.init(AbstractProtocol.java:457)
        at org.apache.coyote.http11.AbstractHttp11JsseProtocol.init(AbstractHttp11JsseProtocol.java:120)

我的java安全文件如下:

#
# List of providers and their preference orders (see above):
#
security.provider.1=sun.security.provider.Sun
security.provider.2=sun.security.rsa.SunRsaSign
security.provider.4=sun.security.ec.SunEC
security.provider.5=com.sun.net.ssl.internal.ssl.Provider
security.provider.6=com.sun.crypto.provider.SunJCE
security.provider.7=sun.security.jgss.SunProvider
security.provider.8=com.sun.security.sasl.Provider
security.provider.9=org.jcp.xml.dsig.internal.dom.XMLDSigRI
security.provider.10=sun.security.smartcardio.SunPCSC
security.provider.3=com.safenetinc.luna.provider.LunaProvider

修改: -

我尝试过使用SunJSSE提供程序,但没有发现JKS的错误。

java.security.KeyStoreException: jks not found
    at java.security.KeyStore.getInstance(KeyStore.java:899)
    at org.apache.tomcat.util.net.jsse.JSSESocketFactory.getStore(JSSESocketFactory.java:424)
    at org.apache.tomcat.util.net.jsse.JSSESocketFactory.getKeystore(JSSESocketFactory.java:339)
    at org.apache.tomcat.util.net.jsse.JSSESocketFactory.getKeyManagers(JSSESocketFactory.java:597)
    at org.apache.tomcat.util.net.jsse.JSSESocketFactory.getKeyManagers(JSSESocketFactory.java:537)
    at org.apache.tomcat.util.net.NioEndpoint.bind(NioEndpoint.java:358)
    at org.apache.tomcat.util.net.AbstractEndpoint.init(AbstractEndpoint.java:737)
    at org.apache.coyote.AbstractProtocol.init(AbstractProtocol.java:457)
    at org.apache.coyote.http11.AbstractHttp11JsseProtocol.init(AbstractHttp11JsseProtocol.java:120)
    at org.apache.catalina.connector.Connector.initInternal(Connector.java:960)
    at org.apache.catalina.util.LifecycleBase.init(LifecycleBase.java:102)
    at org.apache.catalina.core.StandardService.initInternal(StandardService.java:567)
    at org.apache.catalina.util.LifecycleBase.init(LifecycleBase.java:102)
    at org.apache.catalina.core.StandardServer.initInternal(StandardServer.java:851)
    at org.apache.catalina.util.LifecycleBase.init(LifecycleBase.java:102)
    at org.apache.catalina.startup.Catalina.load(Catalina.java:576)
    at org.apache.catalina.startup.Catalina.load(Catalina.java:599)
    at sun.reflect.NativeMethodAccessorImpl.invoke0(Native Method)
    at sun.reflect.NativeMethodAccessorImpl.invoke(NativeMethodAccessorImpl.java:62)
    at sun.reflect.DelegatingMethodAccessorImpl.invoke(DelegatingMethodAccessorImpl.java:43)
    at java.lang.reflect.Method.invoke(Method.java:497)
    at org.apache.catalina.startup.Bootstrap.load(Bootstrap.java:310)
    at org.apache.catalina.startup.Bootstrap.main(Bootstrap.java:484)
Caused by: java.security.NoSuchAlgorithmException: no such algorithm: jks for provider SunJSSE
    at sun.security.jca.GetInstance.getService(GetInstance.java:87)
    at sun.security.jca.GetInstance.getInstance(GetInstance.java:206)
    at java.security.Security.getImpl(Security.java:698)
    at java.security.KeyStore.getInstance(KeyStore.java:896)
    ... 22 more

0 个答案:

没有答案