[jruby-user] Issue: Specifing jruby SSL keystore location
Chason Choate <[email protected]> Fri, 1 May 2015 10:43:05 -0500
| Newsgroups | gmane.comp.lang.jruby.user |
|---|---|
| Message-ID | <CADgFOvpb_uw-4tMqqPFDRRx10rx4kMk7n6YUfoKpAG=J7Jnmuw@mail.gmail.com> |
--047d7b874e627e2497051507115b
Content-Type: text/plain; charset=UTF-8
Hello everyone,
I've been having some trouble specifying a custom keystore for use with
SSL. I'm creating a local CA and then creating a self-signed cert from that
CA. Now I want to be able to start a Jetty server and hit it with jruby. My
current issue is I can't seem to get jruby to pick up the local keystore
and trust it. I'm hopeful someone has ran into this issue before or can
walk me through how to fix it. Below is my test case:
*Env:*
* CentOS 6.5
* Java 7
* jruby-complete-1.7.12
*Steps to reproduce:*
* Install this simple jetty server (
http://blog.knoldus.com/2013/09/10/configure-ssl-on-jetty-server-to-run-it-with-https/
)
* Run the commands to generate the CA and self-signed cert.
* Start the jetty server (should be on 8443)
* Use the following jruby script to contact the jetty server over SSL:
require 'java'
require 'net/https'
host = 'localhost'
path = '/'
puts 'javax.net.ssl.trustStore = ' +
java.lang.System.getProperty('javax.net.ssl.trustStore')
puts 'javax.net.ssl.trustStorePassword = ' +
java.lang.System.getProperty('javax.net.ssl.trustStorePassword')
https = Net::HTTP.new(host, 8443)
https.use_ssl = true
https.ssl_timeout = 2
https.verify_mode = OpenSSL::SSL::VERIFY_PEER
response = https.request(Net::HTTP::Get.new('/'))
puts response.body
* If everything is working correctly you should see HTML dumped to your
terminal.
* Otherwise if there are issues verifying the certificates you'll see an
error like: (which is what i'm seeing)
[vagrant@localhost ~]$ java
-Djavax.net.ssl.trustStore=~/jetty-hightide-8.1.8.v20121106/etc/certs/keystore
-D -Djavax.net.ssl.trustStorePassword=changeit -jar
/path/to/jruby-complete-1.7.12.jar local.rb
javax.net.ssl.trustStore =
~/jetty-hightide-8.1.8.v20121106/etc/certs/keystore
javax.net.ssl.trustStorePassword = changeit
OpenSSL::SSL::SSLError: certificate verify failed
connect at org/jruby/ext/openssl/SSLSocket.java:170
connect at
file:/synthesysserver/lib/jruby-complete-1.7.12.jar!/META-INF/jruby.home/lib/ruby/1.9/net/http.rb:799
timeout at org/jruby/ext/timeout/Timeout.java:104
connect at
file:/synthesysserver/lib/jruby-complete-1.7.12.jar!/META-INF/jruby.home/lib/ruby/1.9/net/http.rb:799
do_start at
file:/synthesysserver/lib/jruby-complete-1.7.12.jar!/META-INF/jruby.home/lib/ruby/1.9/net/http.rb:755
start at
file:/synthesysserver/lib/jruby-complete-1.7.12.jar!/META-INF/jruby.home/lib/ruby/1.9/net/http.rb:744
request at
file:/synthesysserver/lib/jruby-complete-1.7.12.jar!/META-INF/jruby.home/lib/ruby/1.9/net/http.rb:1292
(root) at local.rb:13
--
Thanks,
Chason Choate
--047d7b874e627e2497051507115b
Content-Type: text/html; charset=UTF-8
Content-Transfer-Encoding: quoted-printable
<div dir=3D"ltr">Hello everyone,<div><br></div><div>I've been having so=
me trouble specifying a custom keystore for use with SSL. I'm creating =
a local CA and then creating a self-signed cert from that CA. Now I want to=
be able to start a Jetty server and hit it with jruby. My current issue is=
I can't seem to get jruby to pick up the local keystore and trust it. =
I'm hopeful someone has ran into this issue before or can walk me throu=
gh how to fix it. Below is my test case:<div><br></div><div><b>Env:</b></di=
v><div><br></div><div>* CentOS 6.5</div><div>* Java 7</div><div>* jruby-com=
plete-1.7.12</div><div><br></div><div><b>Steps to reproduce:</b><br><div><b=
r></div><div>* Install this simple jetty server (<a href=3D"http://blog.kno=
ldus.com/2013/09/10/configure-ssl-on-jetty-server-to-run-it-with-https/">ht=
tp://blog.knoldus.com/2013/09/10/configure-ssl-on-jetty-server-to-run-it-wi=
th-https/</a>)</div><div>* Run the commands to generate the CA and self-sig=
ned cert.</div><div>* Start the jetty server (should be on 8443)</div><div>=
* Use the following jruby script to contact the jetty server over SSL:</div=
><div><br></div><div><div><font face=3D"monospace, monospace">require '=
java'</font></div><div><font face=3D"monospace, monospace">require '=
;net/https'</font></div><div><font face=3D"monospace, monospace">host =
=3D 'localhost'</font></div><div><font face=3D"monospace, monospace=
">path =3D '/'</font></div><div><font face=3D"monospace, monospace"=
><br></font></div><div><font face=3D"monospace, monospace">puts 'javax.=
net.ssl.trustStore =3D ' + java.lang.System.getProperty('javax.net.=
ssl.trustStore')</font></div><div><font face=3D"monospace, monospace">p=
uts 'javax.net.ssl.trustStorePassword =3D ' + java.lang.System.getP=
roperty('javax.net.ssl.trustStorePassword')</font></div><div><font =
face=3D"monospace, monospace"><br></font></div><div><font face=3D"monospace=
, monospace">https =3D Net::HTTP.new(host, 8443)</font></div><div><font fac=
e=3D"monospace, monospace">https.use_ssl =3D true</font></div><div><font fa=
ce=3D"monospace, monospace">https.ssl_timeout =3D 2</font></div><div><font =
face=3D"monospace, monospace">https.verify_mode =3D OpenSSL::SSL::VERIFY_PE=
ER</font></div><div><font face=3D"monospace, monospace">response =3D https.=
request(Net::HTTP::Get.new('/'))</font></div><div><font face=3D"mon=
ospace, monospace">puts response.body</font></div></div><div><div><br></div=
><div>* If everything is working correctly you should see HTML dumped to yo=
ur terminal.</div><div>* Otherwise if there are issues verifying the certif=
icates you'll see an error like: (which is what i'm seeing)</div><d=
iv><br></div><div><div><font face=3D"monospace, monospace">[vagrant@localho=
st ~]$ java -Djavax.net.ssl.trustStore=3D~/jetty-hightide-8.1.8.v20121106/e=
tc/certs/keystore -D -Djavax.net.ssl.trustStorePassword=3Dchangeit -jar /pa=
th/to/jruby-complete-1.7.12.jar local.rb</font></div><div><font face=3D"mon=
ospace, monospace">javax.net.ssl.trustStore =3D ~/jetty-hightide-8.1.8.v201=
21106/etc/certs/keystore</font></div><div><font face=3D"monospace, monospac=
e">javax.net.ssl.trustStorePassword =3D changeit</font></div><div><font fac=
e=3D"monospace, monospace">OpenSSL::SSL::SSLError: certificate verify faile=
d</font></div><div><font face=3D"monospace, monospace">=C2=A0 =C2=A0connect=
at org/jruby/ext/openssl/SSLSocket.java:170</font></div><div><font face=3D=
"monospace, monospace">=C2=A0 =C2=A0connect at file:/synthesysserver/lib/jr=
uby-complete-1.7.12.jar!/META-INF/jruby.home/lib/ruby/1.9/net/http.rb:799</=
font></div><div><font face=3D"monospace, monospace">=C2=A0 =C2=A0timeout at=
org/jruby/ext/timeout/Timeout.java:104</font></div><div><font face=3D"mono=
space, monospace">=C2=A0 =C2=A0connect at file:/synthesysserver/lib/jruby-c=
omplete-1.7.12.jar!/META-INF/jruby.home/lib/ruby/1.9/net/http.rb:799</font>=
</div><div><font face=3D"monospace, monospace">=C2=A0 do_start at file:/syn=
thesysserver/lib/jruby-complete-1.7.12.jar!/META-INF/jruby.home/lib/ruby/1.=
9/net/http.rb:755</font></div><div><font face=3D"monospace, monospace">=C2=
=A0 =C2=A0 =C2=A0start at file:/synthesysserver/lib/jruby-complete-1.7.12.j=
ar!/META-INF/jruby.home/lib/ruby/1.9/net/http.rb:744</font></div><div><font=
face=3D"monospace, monospace">=C2=A0 =C2=A0request at file:/synthesysserve=
r/lib/jruby-complete-1.7.12.jar!/META-INF/jruby.home/lib/ruby/1.9/net/http.=
rb:1292</font></div><div><font face=3D"monospace, monospace">=C2=A0 =C2=A0 =
(root) at local.rb:13</font></div></div><div><font face=3D"monospace, monos=
pace"><br></font></div><div><font face=3D"monospace, monospace"><br></font>=
</div>-- <br><div class=3D"gmail_signature"><div dir=3D"ltr">Thanks,<div>Ch=
ason Choate</div></div></div>
</div></div></div></div>
--047d7b874e627e2497051507115b--