【发布时间】:2014-09-18 09:44:20
【问题描述】:
我正在 Tomcat 服务器上安装 SSL,并按照发行者 https://knowledge.rapidssl.com/support/ssl-certificate-support/index?page=content&actp=CROSSLINK&id=SO16181 的这些说明进行操作,并指出:
Verify the following information:
The SSL certificate is imported into the alias with the "Entry Type" of
PrivateKeyEntry or KeyEntry. If not, please import the certificate into
the Private Key alias.
当我导入我正在使用的证书(tomcat)时:
keytool -import -trustcacerts -alias your_alias_name -keystore your_keystore_filename
-file your_certificate_filename
但是当我这样做时,它会作为 trustCertEntry 导入
Keystore type: JKS
Keystore provider: SUN
Your keystore contains 3 entries
primaryca, Jul 26, 2014, trustedCertEntry,
Certificate fingerprint (SHA1): <snip>
tomcat, Jul 26, 2014, trustedCertEntry,
Certificate fingerprint (SHA1): <snip>
secondaryca, Jul 26, 2014, trustedCertEntry,
Certificate fingerprint (SHA1): <snip>
如何将别名 tomcat 导入为 PrivateKeyEntry?
【问题讨论】:
-
你的链不需要需要
primaryca。服务器应发送服务器证书和任何中间证书,以建立通往受信任机构的路径。由客户来信任权威或primaryca。如果客户不信任权威或primaryca(除了要求他们信任),您无能为力。 -
已澄清 - 这是指具有别名 tomcat 的证书,它是服务器的实际证书,而不是任何一个 ca 证书
-
那不行,你不能直接做! xinotes.net/notes/note/1007