Your JAVA_HOME is not where you think it is, or you have a typo: %JAVA_HOME%/jre/secuirty/cacerts
Test with: https://github.com/UniconLabs/java-keystore-ssl-test > From: "Nona M" <[email protected]> > To: "CAS Community" <[email protected]> > Sent: Tuesday, October 17, 2017 10:12:59 AM > Subject: [cas-user] Service-Management app not trusting CAS server > Hi, > I am having issues getting cas service manager app to trust cas server. > Steps I've done : > * Generated a self-signed cert > Alias name : tomcat > Creation date : Oct 13 , 2017 > Entry type : trustedCertEntry > Owner : CN = localhost , OU = localhost , O = localhost , L = localhost , ST = > localhost , C = us > Issuer : CN = localhost , OU = localhost , O = localhost , L = localhost , ST > = > localhost , C = us > Serial number : 1fe89ba1 > Valid from : Fri Oct 13 15 : 59 : 06 EDT 2017 until : Thu Jan 11 14 : 59 : 06 > EST 2018 > Certificate fingerprints : > MD5 : B7 : DA : 16 : E8 : 63 : 35 : E9 : BC : 35 : 66 : A4 : 27 : 53 : B5 : > 60 : > E0 > SHA1 : EF : 1A : 04 : 64 : 36 : 52 : C5 : 35 : AC : 54 : 38 : 4E : 74 : B2 : > 65 > : 30 : F8 : 88 : 38 : 35 > SHA256 : DC : 2D : 99 : 99 : CD : C4 : 38 : 64 : B0 : 5E : EE : 37 : BB : FC : > A4 : 36 : E2 : 87 : C0 : 60 : CF : A8 : 65 : 24 : F5 : 95 : 08 : 75 : 8A : EB > : > 14 : 7C > Signature algorithm name : SHA256withRSA > Version : 3 > * Imported the cert into a keystore in C:\etc\cas\config\.thekeystore (the > keystore was previously in c:\users\{user}\.keystore) > * Imported the cert into %JAVA_HOME%/jre/secuirty/cacerts > * Added the connector for port 8443 in server.xml in %TOMCAT_HOME%/conf > <!-- Define a SSL HTTP/1.1 Connector on port 8443 --> > <Connector port = "8443" SSLEnabled = "true" protocol = > "org.apache.coyote.http11.Http11NioProtocol" > maxThreads = "150" scheme = "https" secure = "true" > clientAuth = "false" sslProtocol = "TLS" > keystoreFile = "C:/etc/cas/config/.thekeystore" > keystorePass = "changeit" > truststoreFile = "C:/Program Files/Java/jdk1.8.0_131/jre/lib/security/cacerts" > /> > The cas app is functional, however once you sign in and navigate to > cas-management, I get this error on the page: > The CAS management webapp is unavailable . > There was an error trying to complete your request . Please notify your > support > desk or try again . > And in the log the error is: > java . lang . RuntimeException : javax . net . ssl . SSLHandshakeException : > sun > . security . validator . ValidatorException : PKIX path building failed : sun > . > security . provider . certpath . SunCertPathBuilderException : unable to find > valid certification path to requested target > at org . pac4j . core . engine . DefaultSecurityLogic . perform ( > DefaultSecurityLogic . java : 165 ) ~[ pac4j - core - 2.0 . 0.jar :?] > Any help would be appreciated, I don't know what I am missing... > Thanks > -- > - Website: https://apereo.github.io/cas > - Gitter Chatroom: https://gitter.im/apereo/cas > - List Guidelines: https://goo.gl/1VRrw7 > - Contributions: https://goo.gl/mh7qDG > --- > You received this message because you are subscribed to the Google Groups "CAS > Community" group. > To unsubscribe from this group and stop receiving emails from it, send an > email > to [email protected] . > To view this discussion on the web visit > https://groups.google.com/a/apereo.org/d/msgid/cas-user/39d96cf9-8e0e-4c59-b4ca-bb50aa275ceb%40apereo.org > . -- --Misagh -- - Website: https://apereo.github.io/cas - Gitter Chatroom: https://gitter.im/apereo/cas - List Guidelines: https://goo.gl/1VRrw7 - Contributions: https://goo.gl/mh7qDG --- You received this message because you are subscribed to the Google Groups "CAS Community" group. To unsubscribe from this group and stop receiving emails from it, send an email to [email protected]. To view this discussion on the web visit https://groups.google.com/a/apereo.org/d/msgid/cas-user/1082677346.5510829.1508260860139.JavaMail.zimbra%40unicon.net.
