Return-Path: Delivered-To: apmail-geronimo-user-archive@www.apache.org Received: (qmail 40230 invoked from network); 13 Nov 2006 14:51:55 -0000 Received: from hermes.apache.org (HELO mail.apache.org) (140.211.11.2) by minotaur.apache.org with SMTP; 13 Nov 2006 14:51:55 -0000 Received: (qmail 93104 invoked by uid 500); 13 Nov 2006 14:52:03 -0000 Delivered-To: apmail-geronimo-user-archive@geronimo.apache.org Received: (qmail 93081 invoked by uid 500); 13 Nov 2006 14:52:03 -0000 Mailing-List: contact user-help@geronimo.apache.org; run by ezmlm Precedence: bulk list-help: list-unsubscribe: List-Post: Reply-To: user@geronimo.apache.org List-Id: Delivered-To: mailing list user@geronimo.apache.org Received: (qmail 93070 invoked by uid 99); 13 Nov 2006 14:52:03 -0000 Received: from herse.apache.org (HELO herse.apache.org) (140.211.11.133) by apache.org (qpsmtpd/0.29) with ESMTP; Mon, 13 Nov 2006 06:52:03 -0800 X-ASF-Spam-Status: No, hits=3.5 required=10.0 tests=FROM_HAS_MIXED_NUMS,HTML_MESSAGE,SPF_PASS X-Spam-Check-By: apache.org Received-SPF: pass (herse.apache.org: domain of c1vamsi1c@gmail.com designates 64.233.182.185 as permitted sender) Received: from [64.233.182.185] (HELO nf-out-0910.google.com) (64.233.182.185) by apache.org (qpsmtpd/0.29) with ESMTP; Mon, 13 Nov 2006 06:51:50 -0800 Received: by nf-out-0910.google.com with SMTP id l23so480085nfc for ; Mon, 13 Nov 2006 06:51:29 -0800 (PST) DomainKey-Signature: a=rsa-sha1; q=dns; c=nofws; s=beta; d=gmail.com; h=received:message-id:date:from:to:subject:in-reply-to:mime-version:content-type:references; b=o2NJYkB5Ayv0nU4hMBzanbfq3QVqgsb1gQwJiKNyPztZspgbie9xUv2N89DVlzD4HsLd0YwrHqmCt2nAqlajAwof5vRJDA1GX5A31qDb7h0G+HAfgEt5oVRhvjTlP2Cthv9yNP2tto2iS12L32+cpOoWIziSL6IeU13n8nRDwQU= Received: by 10.48.210.20 with SMTP id i20mr9998269nfg.1163429489131; Mon, 13 Nov 2006 06:51:29 -0800 (PST) Received: by 10.49.6.4 with HTTP; Mon, 13 Nov 2006 06:51:29 -0800 (PST) Message-ID: <22d56c4d0611130651p7a86313exa02f948dcc37734d@mail.gmail.com> Date: Mon, 13 Nov 2006 20:21:29 +0530 From: "Vamsavardhana Reddy" To: user@geronimo.apache.org Subject: Re: Certificate setup - Geronimo 1.1.1 In-Reply-To: <60387EB8-F4E2-4F17-AE0C-9D5B315046FC@mac.com> MIME-Version: 1.0 Content-Type: multipart/alternative; boundary="----=_Part_7939_26119351.1163429489091" References: <60387EB8-F4E2-4F17-AE0C-9D5B315046FC@mac.com> X-Virus-Checked: Checked by ClamAV on apache.org ------=_Part_7939_26119351.1163429489091 Content-Type: text/plain; charset=ISO-8859-1; format=flowed Content-Transfer-Encoding: 7bit Content-Disposition: inline Bob, The KeyStore portlet functionality in 1.1.1 has been tested. I have done end-to-end test of importing trusted certificate, importing CA reply, setting up HTTPS with Client Authentication and sample applications. I did not come across any problems. If you send the root, intermediate and your personal certificate, I will be able to investigate the problem (if indeed there is one). Thanks, Vamsi On 11/13/06, Bob Dushok wrote: > > I was expecting an error to appear within the console is something > had gone wrong during the keystore operations. I just checked the > server logs and found the following errors: > > When importing the intermediate certificate (as a trust certificate): > 47825: 19:20:15,746 ERROR [ConfirmCertificateHandler] Unable to > import certificate > > When importing the CA root certificate (as the trust certificate): > 47897: 19:22:23,388 ERROR [FileKeystoreInstance] Unable to import > certificate > > When attempting to import the CA reply: > 47826: 19:20:52,707 ERROR [BaseKeystoreHandler] Error importing CA reply > > TIA, > Bob > > On Nov 12, 2006, at 7:33 PM, Bob Dushok wrote: > > > I'm having difficulty completing the setup of an HTTPS listener. > > I'm following the docs named "Certificate Properties File Realm" at > > "http://cwiki.apache.org/confluence/display/GMOxDOC11/Certificate > > +Properties+File+Realm". > > > > I've created the keystore, generated the private key, and generated > > a CSR without a problem. I've submitted the CSR to GoDaddy and > > have obtained their reply. > > > > When I click "Import CA Reply" I copy/paste the data from GoDaddy > > (including the BEGIN CERTIFICATE and END CERTIFICATE lines), but > > Geronimo seems to ignore my entry. No errors appear. I'm placed > > back on the keystore config page and the issuer is still listed as > > myself, not GoDaddy (Starfield). > > > > Any suggestions on how to proceed would be appreciated. > > > > In addition to their reply, GoDaddy also provides a root and > > intermediate certificate. I assume the root certificate is what I > > need to add as a trusted certificate, but Geronimo again refuses to > > accept it. How do I add the intermediate certificate to my config? > > > > Thanks, > > Bob > > ------=_Part_7939_26119351.1163429489091 Content-Type: text/html; charset=ISO-8859-1 Content-Transfer-Encoding: 7bit Content-Disposition: inline Bob,

The KeyStore portlet functionality in 1.1.1 has been tested.  I have done end-to-end test of importing trusted certificate, importing CA reply, setting up HTTPS with Client Authentication and sample applications.  I did not come across any problems.  If you send the root, intermediate and your personal certificate, I will be able to investigate the problem (if indeed there is one).

Thanks,
Vamsi

On 11/13/06, Bob Dushok <bdushok@mac.com> wrote:
I was expecting an error to appear within the console is something
had gone wrong during the keystore operations.  I just checked the
server logs and found the following errors:

When importing the intermediate certificate (as a trust certificate):
47825: 19:20:15,746 ERROR [ConfirmCertificateHandler] Unable to
import certificate

When importing the CA root certificate (as the trust certificate):
47897: 19:22:23,388 ERROR [FileKeystoreInstance] Unable to import
certificate

When attempting to import the CA reply:
47826: 19:20:52,707 ERROR [BaseKeystoreHandler] Error importing CA reply

TIA,
Bob

On Nov 12, 2006, at 7:33 PM, Bob Dushok wrote:

> I'm having difficulty completing the setup of an HTTPS listener.
> I'm following the docs named "Certificate Properties File Realm" at
> "http://cwiki.apache.org/confluence/display/GMOxDOC11/Certificate
> +Properties+File+Realm".
>
> I've created the keystore, generated the private key, and generated
> a CSR without a problem.   I've submitted the CSR to GoDaddy and
> have obtained their reply.
>
> When I click "Import CA Reply" I copy/paste the data from GoDaddy
> (including the BEGIN CERTIFICATE and END CERTIFICATE lines), but
> Geronimo seems to ignore my entry.  No errors appear.  I'm placed
> back on the keystore config page and the issuer is still listed as
> myself, not GoDaddy (Starfield).
>
> Any suggestions on how to proceed would be appreciated.
>
> In addition to their reply, GoDaddy also provides a root and
> intermediate certificate.  I assume the root certificate is what I
> need to add as a trusted certificate, but Geronimo again refuses to
> accept it.  How do I add the intermediate certificate to my config?
>
> Thanks,
> Bob


------=_Part_7939_26119351.1163429489091--