tomcat-users mailing list archives

Site index · List index
Message view « Date » · « Thread »
Top « Date » · « Thread »
From "Alla Winter" <>
Subject Please help me to configure TOMCAT with APR connector Thanks
Date Mon, 09 Oct 2006 14:37:31 GMT
I would appreciate if you would answer on my questions.




From: Alla Winter [] 
Sent: Friday, October 06, 2006 1:13 PM
Subject: Please help me to configure TOMCAT with APR connector Thanks


I am trying to configure TOMCAT 5.5.17  JDK,  with APR on Windows
2000.  I was able to start this version of tomcat without ssl configuration
and my application is working OK with it.

Here are the steps what I did:

1.	I downloaded tcnative-1.dll into c\Cobra\nativeLib  
2.	I added a line in startup.bat :    set
3.	I put the working in production certificate and the key  ( in
production we currently using APACHE 2 and jk2 connector, I assume that  the
same certificate format is valid for OppenSSl)  under
4.	I changed the server.xml     (see the attached).

<Connector port="8443" maxHttpHeaderSize="8192" maxThreads="150"
minSpareThreads="25" maxSpareThreads="75" enableLookups="false"
disableUploadTimeout="true" acceptCount="100" scheme="https" secure="true"
clientAuth="false" sslProtocol="TLS" SSLEngine="on"
SSLCertificateKeyFile="c:/apache-tomcat-5.5.17/conf/mycobrasource.key" />


But due to whatever reason Tomcat is looking for keystore, the error message
is "SEVERE: Error initializing endpoint C:\Documents and


What I am doing wrong?


I also would appreciate if you would clarify for me a few things:

the documentation says

" APR support requires three main native components to be installed: 

*         APR library 

*         JNI wrappers for APR used by Tomcat (libtcnative) 

*         OpenSSL libraries ""

And then we are referred to download "compiled .dll which includes OpenSSL
and APR.", which is tcnative-1.dll

Does that include JNI wrapper as well?

And then it tells "In security conscious production environments, it is
recommended to use separate shared dlls for OpenSSL, APR, and

Where the binaries for those separate dlls  ( beside openSSL) can be found ?
Many Windows users do not have C compiler to build it from scratch?

It is also unclear what exactly instruct TOMCAT to use APR instead of JSSE?

Also, in the example of server.xml configuration SSLCertificateFile keyword
is referring to .crt file.  While we have signed by Thawte  .cer file.  I
just changed the extension of the file. Is that the same file?

I would greatly appreciate your help.




View raw message