background image

RSA Data Security

<< Creating a Server Certificate | Signing Digital Certificates >>
<< Creating a Server Certificate | Signing Digital Certificates >>

RSA Data Security

Note ­
RSA is public-key encryption technology developed by RSA Data Security, Inc. The
acronym stands for Rivest, Shamir, and Adelman, the inventors of the technology.
From the directory in which you want to create the keystore, run keytool with the following
parameters.
1. Generate the server certificate. (Type the keytool command all on one line.)
java-home\bin\keytool -genkey -alias server-alias-keyalg RSA -keypass changeit
-storepass changeit -keystore keystore.jks
When you press Enter, keytool prompts you to enter the server name, organizational unit,
organization, locality, state, and country code.
You must enter the server name in response to keytool's first prompt, in which it asks for
first and last names. For testing purposes, this can be localhost.
When you run the example applications, the host specified in the keystore must match the
host identified in the javaee.server.name property specified in the file
tut-install/javaeetutorial5/examples/bp-project/build.properties.
2. Export the generated server certificate in keystore.jks into the file server.cer. (Type the
keytool
all on one line.)
java-home\bin\keytool -export -alias server-alias -storepass changeit
-file server.cer -keystore keystore.jks
3. If you want to have the certificate signed by a CA, read
"Signing Digital Certificates" on
page 791
for more information.
4. To create the truststore file cacerts.jks and add the server certificate to the truststore, run
keytool
from the directory where you created the keystore and server certificate. Use the
following parameters:
java-home\bin\keytool -import -v -trustcacerts -alias server-alias -file server.cer
-keystore cacerts.jks -keypass changeit -storepass changeit
Information on the certificate, such as that shown next, will display.
% keytool -import -v -trustcacerts -alias server-alias -file server.cer
-keystore cacerts.jks -keypass changeit -storepass changeit
Owner: CN=localhost, OU=Sun Micro, O=Docs, L=Santa Clara, ST=CA,
C=USIssuer: CN=localhost, OU=Sun Micro, O=Docs, L=Santa Clara, ST=CA,
C=USSerial number: 3e932169Valid from: Tue Apr 08Certificate
fingerprints:MD5: 52:9F:49:68:ED:78:6F:39:87:F3:98:B3:6A:6B:0F:90 SHA1:
EE:2E:2A:A6:9E:03:9A:3A:1C:17:4A:28:5E:97:20:78:3F:
Trust this certificate? [no]:
Establishing a Secure Connection Using SSL
The Java EE 5 Tutorial · September 2007
790