Java keytool从url / port添加服务器证书的简便方法 [英] Java keytool easy way to add server cert from url/port

查看:113
本文介绍了Java keytool从url / port添加服务器证书的简便方法的处理方法,对大家解决问题具有一定的参考价值,需要的朋友们下面随着小编来一起学习吧!

问题描述

我有一个带有自签名证书的服务器,但也需要客户端证书身份验证。我正在尝试获取原始CA服务器证书,因此我可以将其导入密钥库。任何人都有一些关于如何轻松做到这一点的建议?谢谢。

I have a server with a self signed certificate, but also requires client side cert authentication. I am having a rough time trying to get the raw CA server cert so I can import it into a keystore. Anyone have some suggestions on how to easily do that? Thanks.

推荐答案

正在研究如何在使用jenkins cli时信任证书,并发现
https://issues.jenkins-ci.org/browse/JENKINS-12629 ,其中有一些食谱。

Was looking at how to trust a certificate while using jenkins cli, and found https://issues.jenkins-ci.org/browse/JENKINS-12629 which has some recipe for that.

这将为您提供证书:

openssl s_client -connect ${HOST}:${PORT} </dev/null

如果您只对证书感兴趣部分,通过管道将其切割成:

if you are interested only in the certificate part, cut it out by piping it to:

| sed -ne '/-BEGIN CERTIFICATE-/,/-END CERTIFICATE-/p'

并重定向到文件:

> ${HOST}.cert

然后使用keytool导入它:

Then import it using keytool:

keytool -import -noprompt -trustcacerts -alias ${HOST} -file ${HOST}.cert \
    -keystore ${KEYSTOREFILE} -storepass ${KEYSTOREPASS}

一气呵成:

HOST=myhost.example.com
PORT=443
KEYSTOREFILE=dest_keystore
KEYSTOREPASS=changeme

# get the SSL certificate
openssl s_client -connect ${HOST}:${PORT} </dev/null \
    | sed -ne '/-BEGIN CERTIFICATE-/,/-END CERTIFICATE-/p' > ${HOST}.cert

# create a keystore and import certificate
keytool -import -noprompt -trustcacerts \
    -alias ${HOST} -file ${HOST}.cert \
    -keystore ${KEYSTOREFILE} -storepass ${KEYSTOREPASS}

# verify we've got it.
keytool -list -v -keystore ${KEYSTOREFILE} -storepass ${KEYSTOREPASS} -alias ${HOST}

这篇关于Java keytool从url / port添加服务器证书的简便方法的文章就介绍到这了,希望我们推荐的答案对大家有所帮助,也希望大家多多支持IT屋!

查看全文
登录 关闭
扫码关注1秒登录
发送“验证码”获取 | 15天全站免登陆