<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Activiti over https using self signed SSL certificate in Alfresco Archive</title>
    <link>https://connect.hyland.com/t5/alfresco-archive/activiti-over-https-using-self-signed-ssl-certificate/m-p/105609#M73832</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;SPAN&gt;Hi,&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;I think that it's not the right forum to ask this question because it's related to tomcat but I'm posting if here to see if somebody already has tried this and could help me.&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;I'm trying to create a self signed certificate using keytool java and import it in firefox and chrome. On the other hand the keystore is in tomcat and server.xml has updated for https. I want activiti explore running over https where the client can also be authenticated against the created certificate.&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;I'm using following batch file;&lt;/SPAN&gt;&lt;BR /&gt;&lt;PRE class="language-none line-numbers"&gt;&lt;CODE&gt;@echo off&lt;BR /&gt;if "%1" == "" goto usage&lt;BR /&gt;&lt;BR /&gt;keytool -genkeypair -alias servercert -keyalg RSA -dname "CN=Web Server,OU=Unit,O=Organization,L=City,S=State,C=US" -keypass password -keystore server.jks -storepass password&lt;BR /&gt;keytool -genkeypair -alias %1 -keystore %1.p12 -storetype pkcs12 -keyalg RSA -dname "CN=%1,OU=Unit,O=Organization,L=City,S=State,C=US" -keypass password -storepass password&lt;BR /&gt;keytool -exportcert -alias %1 -file %1.cer -keystore %1.p12 -storetype pkcs12 -storepass password&lt;BR /&gt;keytool -importcert -keystore server.jks -alias %1 -file %1.cer -v -trustcacerts -noprompt -storepass password&lt;BR /&gt;keytool -list -v -keystore server.jks -storepass password&lt;BR /&gt;del %1.cer&lt;BR /&gt;goto end&lt;BR /&gt;&lt;BR /&gt;:usage&lt;BR /&gt;echo Need user id as first argument: generate_keystore [username]&lt;BR /&gt;goto end&lt;BR /&gt;&lt;BR /&gt;:end&lt;BR /&gt;pause&lt;SPAN class="line-numbers-rows"&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/CODE&gt;&lt;/PRE&gt;&lt;BR /&gt;&lt;SPAN&gt;The results are two files. One called server.jks that I dropped into Tomcat and another file called {username}.p12 that I imported into firefox and chrome both. The server.jks file has the client certificate added as a trusted cert.&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;And here is the the XML that I updated in Tomcat conf/sever.xml file &lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;PRE class="language-none line-numbers"&gt;&lt;CODE&gt;&amp;lt;Connector port="8443" protocol="HTTP/1.1" SSLEnabled="true"&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; maxThreads="150" scheme="https" secure="true"&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; keystoreFile="${user.home}/server.jks" keystorePass="changeit"&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; clientAuth="true" sslProtocol="TLS" /&amp;gt;&lt;SPAN class="line-numbers-rows"&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/CODE&gt;&lt;/PRE&gt;&lt;BR /&gt;&lt;STRONG&gt;Now the problem is when I use clientAuth="false", actitivi explorer runs over https&lt;/STRONG&gt;&lt;SPAN&gt; but when I use &lt;/SPAN&gt;&lt;STRONG&gt;clientAuth="true"&lt;/STRONG&gt;&lt;SPAN&gt; the imported certificate is not authenticated and activiti explorer doesn't show up. Does anybody know what problem could be? If anybody has tried the same thing in a different way then please share it with me. I want activiti explorer running over https using SSL certificate for authenticating the client.&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;Thank you in advance.&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;regards,&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;Salman&lt;/SPAN&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Fri, 09 Nov 2012 14:36:21 GMT</pubDate>
    <dc:creator>nommyravian</dc:creator>
    <dc:date>2012-11-09T14:36:21Z</dc:date>
    <item>
      <title>Activiti over https using self signed SSL certificate</title>
      <link>https://connect.hyland.com/t5/alfresco-archive/activiti-over-https-using-self-signed-ssl-certificate/m-p/105609#M73832</link>
      <description>Hi,I think that it's not the right forum to ask this question because it's related to tomcat but I'm posting if here to see if somebody already has tried this and could help me.I'm trying to create a self signed certificate using keytool java and import it in firefox and chrome. On the other hand th</description>
      <pubDate>Fri, 09 Nov 2012 14:36:21 GMT</pubDate>
      <guid>https://connect.hyland.com/t5/alfresco-archive/activiti-over-https-using-self-signed-ssl-certificate/m-p/105609#M73832</guid>
      <dc:creator>nommyravian</dc:creator>
      <dc:date>2012-11-09T14:36:21Z</dc:date>
    </item>
    <item>
      <title>Re: Activiti over https using self signed SSL certificate</title>
      <link>https://connect.hyland.com/t5/alfresco-archive/activiti-over-https-using-self-signed-ssl-certificate/m-p/105610#M73833</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;SPAN&gt;This is a more general tomcat/HTTPS question, rather than an activiti-question. I think you'll have more luck on forums specialized in that, than an on activiti user-forum…&lt;/SPAN&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 16 Nov 2012 10:14:02 GMT</pubDate>
      <guid>https://connect.hyland.com/t5/alfresco-archive/activiti-over-https-using-self-signed-ssl-certificate/m-p/105610#M73833</guid>
      <dc:creator>frederikherema1</dc:creator>
      <dc:date>2012-11-16T10:14:02Z</dc:date>
    </item>
    <item>
      <title>Re: Activiti over https using self signed SSL certificate</title>
      <link>https://connect.hyland.com/t5/alfresco-archive/activiti-over-https-using-self-signed-ssl-certificate/m-p/105611#M73834</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;SPAN&gt;Too bad I was looking for the exact same stuff, having issues also.&lt;/SPAN&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 06 Nov 2014 08:05:18 GMT</pubDate>
      <guid>https://connect.hyland.com/t5/alfresco-archive/activiti-over-https-using-self-signed-ssl-certificate/m-p/105611#M73834</guid>
      <dc:creator>bam</dc:creator>
      <dc:date>2014-11-06T08:05:18Z</dc:date>
    </item>
  </channel>
</rss>

