Your JAVA_HOME is not where you think it is, or you have a typo: 
%JAVA_HOME%/jre/secuirty/cacerts 

Test with: 
https://github.com/UniconLabs/java-keystore-ssl-test 

> From: "Nona M" <[email protected]>
> To: "CAS Community" <[email protected]>
> Sent: Tuesday, October 17, 2017 10:12:59 AM
> Subject: [cas-user] Service-Management app not trusting CAS server

> Hi,
> I am having issues getting cas service manager app to trust cas server.

> Steps I've done :

>     * Generated a self-signed cert

> Alias name : tomcat
> Creation date : Oct 13 , 2017
> Entry type : trustedCertEntry

> Owner : CN = localhost , OU = localhost , O = localhost , L = localhost , ST =
> localhost , C = us
> Issuer : CN = localhost , OU = localhost , O = localhost , L = localhost , ST 
> =
> localhost , C = us
> Serial number : 1fe89ba1
> Valid from : Fri Oct 13 15 : 59 : 06 EDT 2017 until : Thu Jan 11 14 : 59 : 06
> EST 2018
> Certificate fingerprints :
> MD5 : B7 : DA : 16 : E8 : 63 : 35 : E9 : BC : 35 : 66 : A4 : 27 : 53 : B5 : 
> 60 :
> E0
> SHA1 : EF : 1A : 04 : 64 : 36 : 52 : C5 : 35 : AC : 54 : 38 : 4E : 74 : B2 : 
> 65
> : 30 : F8 : 88 : 38 : 35
> SHA256 : DC : 2D : 99 : 99 : CD : C4 : 38 : 64 : B0 : 5E : EE : 37 : BB : FC :
> A4 : 36 : E2 : 87 : C0 : 60 : CF : A8 : 65 : 24 : F5 : 95 : 08 : 75 : 8A : EB 
> :
> 14 : 7C
> Signature algorithm name : SHA256withRSA
> Version : 3

>    * Imported the cert into a keystore in C:\etc\cas\config\.thekeystore (the
>     keystore was previously in c:\users\{user}\.keystore)
>     * Imported the cert into %JAVA_HOME%/jre/secuirty/cacerts
>     * Added the connector for port 8443 in server.xml in %TOMCAT_HOME%/conf

> <!-- Define a SSL HTTP/1.1 Connector on port 8443 -->
> <Connector port = "8443" SSLEnabled = "true" protocol =
> "org.apache.coyote.http11.Http11NioProtocol"
> maxThreads = "150" scheme = "https" secure = "true"
> clientAuth = "false" sslProtocol = "TLS"
> keystoreFile = "C:/etc/cas/config/.thekeystore"
> keystorePass = "changeit"
> truststoreFile = "C:/Program Files/Java/jdk1.8.0_131/jre/lib/security/cacerts"
> />

> The cas app is functional, however once you sign in and navigate to
> cas-management, I get this error on the page:

> The CAS management webapp is unavailable .

> There was an error trying to complete your request . Please notify your 
> support
> desk or try again .

> And in the log the error is:

> java . lang . RuntimeException : javax . net . ssl . SSLHandshakeException : 
> sun
> . security . validator . ValidatorException : PKIX path building failed : sun 
> .
> security . provider . certpath . SunCertPathBuilderException : unable to find
> valid certification path to requested target
> at org . pac4j . core . engine . DefaultSecurityLogic . perform (
> DefaultSecurityLogic . java : 165 ) ~[ pac4j - core - 2.0 . 0.jar :?]

> Any help would be appreciated, I don't know what I am missing...

> Thanks

> --
> - Website: https://apereo.github.io/cas
> - Gitter Chatroom: https://gitter.im/apereo/cas
> - List Guidelines: https://goo.gl/1VRrw7
> - Contributions: https://goo.gl/mh7qDG
> ---
> You received this message because you are subscribed to the Google Groups "CAS
> Community" group.
> To unsubscribe from this group and stop receiving emails from it, send an 
> email
> to [email protected] .
> To view this discussion on the web visit
> https://groups.google.com/a/apereo.org/d/msgid/cas-user/39d96cf9-8e0e-4c59-b4ca-bb50aa275ceb%40apereo.org
> .

-- 
--Misagh 

-- 
- Website: https://apereo.github.io/cas
- Gitter Chatroom: https://gitter.im/apereo/cas
- List Guidelines: https://goo.gl/1VRrw7
- Contributions: https://goo.gl/mh7qDG
--- 
You received this message because you are subscribed to the Google Groups "CAS 
Community" group.
To unsubscribe from this group and stop receiving emails from it, send an email 
to [email protected].
To view this discussion on the web visit 
https://groups.google.com/a/apereo.org/d/msgid/cas-user/1082677346.5510829.1508260860139.JavaMail.zimbra%40unicon.net.

Reply via email to