Return-Path: X-Original-To: apmail-hc-httpclient-users-archive@www.apache.org Delivered-To: apmail-hc-httpclient-users-archive@www.apache.org Received: from mail.apache.org (hermes.apache.org [140.211.11.3]) by minotaur.apache.org (Postfix) with SMTP id 63DDEDF3F for ; Fri, 14 Sep 2012 13:58:56 +0000 (UTC) Received: (qmail 72947 invoked by uid 500); 14 Sep 2012 13:58:56 -0000 Delivered-To: apmail-hc-httpclient-users-archive@hc.apache.org Received: (qmail 72863 invoked by uid 500); 14 Sep 2012 13:58:55 -0000 Mailing-List: contact httpclient-users-help@hc.apache.org; run by ezmlm Precedence: bulk List-Help: List-Unsubscribe: List-Post: List-Id: Reply-To: "HttpClient User Discussion" Delivered-To: mailing list httpclient-users@hc.apache.org Received: (qmail 72855 invoked by uid 99); 14 Sep 2012 13:58:55 -0000 Received: from nike.apache.org (HELO nike.apache.org) (192.87.106.230) by apache.org (qpsmtpd/0.29) with ESMTP; Fri, 14 Sep 2012 13:58:55 +0000 X-ASF-Spam-Status: No, hits=0.7 required=5.0 tests=SPF_NEUTRAL X-Spam-Check-By: apache.org Received-SPF: neutral (nike.apache.org: local policy) Received: from [217.150.250.48] (HELO kalnich.nine.ch) (217.150.250.48) by apache.org (qpsmtpd/0.29) with ESMTP; Fri, 14 Sep 2012 13:58:47 +0000 Received: from [192.168.42.181] (unknown [213.55.184.230]) (using TLSv1 with cipher AES256-SHA (256/256 bits)) (No client certificate requested) by kalnich.nine.ch (Postfix) with ESMTPSA id 33644B8011C for ; Fri, 14 Sep 2012 15:58:27 +0200 (CEST) Message-ID: <1347631101.1758.9.camel@ubuntu> Subject: Re: SSL Self-signed certificate problem JDK1.5 & 1.6 From: Oleg Kalnichevski To: HttpClient User Discussion Date: Fri, 14 Sep 2012 15:58:21 +0200 In-Reply-To: References: Content-Type: text/plain; charset="UTF-8" X-Mailer: Evolution 3.2.3-0ubuntu6 Content-Transfer-Encoding: 7bit Mime-Version: 1.0 On Fri, 2012-09-14 at 14:40 +0530, Susanta Mohapatra wrote: > Thanks Jose, > > I was trying to connector to Microsoft Share Point server which was > configured with SSL + NTLM v2 support. Interesting thing I found was that > after java disabled unsafe re-negotiation in Jre 1.6._22, the client code > started giving error - connection reset. I didn't find any solution other > than to include that flag in JVM after which code started working. This > might be because of the NTLM authentication process. > > Hope this helps someone in search for similar error. > > -Susanta > > On Mon, Sep 10, 2012 at 4:50 PM, Jose Escobar wrote: > > > Hi Susanta, > > > > I had a similar problem and Oleg Kalnichevski answered me: > > > > > Possibly a better option might be a custom socket factory that can > > > create SSL connections with different SSL contexts using different trust > > > and key material based on the hostname of the target server. > > > > I decided to make a little change on HttpClient to set a new > > SchemeRegistry on each request thread that need > > specific trust and key material and I add it as a SCHEME_REGISTRY > > attribute to a Context variable. > > > > You can find this talk at > > http://marc.info/?l=httpclient-users&m=133830124402823&w=2 > > > > Jose Escobar > > Jose As of version 4.3 HttpClient will allow SCHEME_REGISTRY to be overridden though HttpContext. Oleg > > 2012/9/10 Susanta Mohapatra : > > > Hi all, > > > > > > I am trying to import a self-signed certificate into the default java > > > keystore "cacerts" ( Java version 1.5 ). The certificate is imported > > > successfully but when I try to use HttpClient library to connect to the > > > server, I run into the error > > > > > > sun.security.validator.ValidatorException: PKIX path building failed: > > > sun.security.provider.certpath.SunCertPathBuilderException: unable to > > find > > > valid certification path to requested target > > > javax.net.ssl.SSLHandshakeException > > > com.sun.net.ssl.internal.ssl.Alerts:getSSLException > > > > > > I found some articles by googling that you need to make a new jks > > keystore > > > by importing the self-signed certificate. But I want to do it on the > > > default keystore "cacerts". I don't want to relax the constraints of > > > certificate checks at client side. > > > > > > Please help me out with the correct solution for the issue. > > > > > > Thanks > > > Susanta > > > > --------------------------------------------------------------------- > > To unsubscribe, e-mail: httpclient-users-unsubscribe@hc.apache.org > > For additional commands, e-mail: httpclient-users-help@hc.apache.org > > > > --------------------------------------------------------------------- To unsubscribe, e-mail: httpclient-users-unsubscribe@hc.apache.org For additional commands, e-mail: httpclient-users-help@hc.apache.org