基於tomcat的https搭建

Server須要:

  1.  KeyStore: 其中保存服務端的私鑰
  2. Trust KeyStore:其中保存客戶端的受權證書

Client須要:

  1. KeyStore:其中保存客戶端的私鑰
  2. Trust KeyStore:其中保存服務端的受權證書

KeyStore獲取方式:

  1. 第三方機構授予
  2. 使用Java自帶的KeyTool命令生成.

證書:

  1. 使用keytool工具生成證書.
  2. 使用keytool工具導入客戶端/服務端證書.

keytool命令

  1. 生成keystore: keytool -genkey -alias serverkey -keystore keyserver.keystore
  2. 導出證書: keytool -export -alias serverkey -keystore keyserver.keystore -file server.crt 
  3. 將證書添加信任的keystore: keytool -import -alias serverkey -file server.crt -keystore tclient.keystore tclient.keystore

tomcat配置:

打開server.xmlapache

<Connector
           protocol="org.apache.coyote.http11.Http11AprProtocol"
           port="8443" maxThreads="200"
           scheme="https" secure="true" SSLEnabled="true"
           SSLCertificateFile="/usr/local/ssl/server.crt"
           SSLCertificateKeyFile="/usr/local/ssl/server.pem"
           SSLVerifyClient="optional" SSLProtocol="TLSv1+TLSv1.1+TLSv1.2"/>

或者tomcat

<Connector
  port="8443"
  protocol="HTTP/1.1"
  SSLEnabled="true"
  enableLookups="false"
  disableUploadTimeout="true"
  scheme="https"
  secure="true"
  clientAuth="want"
  sslProtocol="TLS"
  keystoreFile="conf/.ssl/keystore.jks"
  keyAlias="tomcat"
  keystorePass="&#99;&#104;&#105;&#107;&#115;"
  truststoreFile="conf/.ssl/trustedstore.jks"
  truststorePass="&#99;&#104;&#105;&#107;&#115;"
/>
<Connector
           protocol="org.apache.coyote.http11.Http11NioProtocol"
           port="8443" maxThreads="200"
           scheme="https" secure="true" SSLEnabled="true"
           keystoreFile="${user.home}/.keystore" keystorePass="changeit"
           clientAuth="false" sslProtocol="TLS"/>
相關文章
相關標籤/搜索