And it is in fact: "%JAVA_HOME%/jre/lib/security/cacerts" 

> From: "Misagh Moayyed" <[email protected]>
> To: [email protected]
> Sent: Tuesday, October 17, 2017 10:21:00 AM
> Subject: Re: [cas-user] Service-Management app not trusting CAS server

> Your JAVA_HOME is not where you think it is, or you have a typo:
> %JAVA_HOME%/jre/secuirty/cacerts

> Test with:
> https://github.com/UniconLabs/java-keystore-ssl-test

>> From: "Nona M" <[email protected]>
>> To: "CAS Community" <[email protected]>
>> Sent: Tuesday, October 17, 2017 10:12:59 AM
>> Subject: [cas-user] Service-Management app not trusting CAS server

>> Hi,
>> I am having issues getting cas service manager app to trust cas server.

>> Steps I've done :

>>     * Generated a self-signed cert

>> Alias name : tomcat
>> Creation date : Oct 13 , 2017
>> Entry type : trustedCertEntry

>> Owner : CN = localhost , OU = localhost , O = localhost , L = localhost , ST 
>> =
>> localhost , C = us
>> Issuer : CN = localhost , OU = localhost , O = localhost , L = localhost , 
>> ST =
>> localhost , C = us
>> Serial number : 1fe89ba1
>> Valid from : Fri Oct 13 15 : 59 : 06 EDT 2017 until : Thu Jan 11 14 : 59 : 06
>> EST 2018
>> Certificate fingerprints :
>> MD5 : B7 : DA : 16 : E8 : 63 : 35 : E9 : BC : 35 : 66 : A4 : 27 : 53 : B5 : 
>> 60 :
>> E0
>> SHA1 : EF : 1A : 04 : 64 : 36 : 52 : C5 : 35 : AC : 54 : 38 : 4E : 74 : B2 : 
>> 65
>> : 30 : F8 : 88 : 38 : 35
>> SHA256 : DC : 2D : 99 : 99 : CD : C4 : 38 : 64 : B0 : 5E : EE : 37 : BB : FC 
>> :
>> A4 : 36 : E2 : 87 : C0 : 60 : CF : A8 : 65 : 24 : F5 : 95 : 08 : 75 : 8A : 
>> EB :
>> 14 : 7C
>> Signature algorithm name : SHA256withRSA
>> Version : 3

>>    * Imported the cert into a keystore in C:\etc\cas\config\.thekeystore (the
>>     keystore was previously in c:\users\{user}\.keystore)
>>     * Imported the cert into %JAVA_HOME%/jre/secuirty/cacerts
>>     * Added the connector for port 8443 in server.xml in %TOMCAT_HOME%/conf

>> <!-- Define a SSL HTTP/1.1 Connector on port 8443 -->
>> <Connector port = "8443" SSLEnabled = "true" protocol =
>> "org.apache.coyote.http11.Http11NioProtocol"
>> maxThreads = "150" scheme = "https" secure = "true"
>> clientAuth = "false" sslProtocol = "TLS"
>> keystoreFile = "C:/etc/cas/config/.thekeystore"
>> keystorePass = "changeit"
>> truststoreFile = "C:/Program 
>> Files/Java/jdk1.8.0_131/jre/lib/security/cacerts"
>> />

>> The cas app is functional, however once you sign in and navigate to
>> cas-management, I get this error on the page:

>> The CAS management webapp is unavailable .

>> There was an error trying to complete your request . Please notify your 
>> support
>> desk or try again .

>> And in the log the error is:

>> java . lang . RuntimeException : javax . net . ssl . SSLHandshakeException : 
>> sun
>> . security . validator . ValidatorException : PKIX path building failed : 
>> sun .
>> security . provider . certpath . SunCertPathBuilderException : unable to find
>> valid certification path to requested target
>> at org . pac4j . core . engine . DefaultSecurityLogic . perform (
>> DefaultSecurityLogic . java : 165 ) ~[ pac4j - core - 2.0 . 0.jar :?]

>> Any help would be appreciated, I don't know what I am missing...

>> Thanks

>> --
>> - Website: https://apereo.github.io/cas
>> - Gitter Chatroom: https://gitter.im/apereo/cas
>> - List Guidelines: https://goo.gl/1VRrw7
>> - Contributions: https://goo.gl/mh7qDG
>> ---
>> You received this message because you are subscribed to the Google Groups 
>> "CAS
>> Community" group.
>> To unsubscribe from this group and stop receiving emails from it, send an 
>> email
>> to [email protected] .
>> To view this discussion on the web visit
>> https://groups.google.com/a/apereo.org/d/msgid/cas-user/39d96cf9-8e0e-4c59-b4ca-bb50aa275ceb%40apereo.org
>> .

> --
> --Misagh

> --
> - Website: https://apereo.github.io/cas
> - Gitter Chatroom: https://gitter.im/apereo/cas
> - List Guidelines: https://goo.gl/1VRrw7
> - Contributions: https://goo.gl/mh7qDG
> ---
> You received this message because you are subscribed to the Google Groups "CAS
> Community" group.
> To unsubscribe from this group and stop receiving emails from it, send an 
> email
> to [email protected] .
> To view this discussion on the web visit
> https://groups.google.com/a/apereo.org/d/msgid/cas-user/1082677346.5510829.1508260860139.JavaMail.zimbra%40unicon.net
> .

-- 
--Misagh 

-- 
- Website: https://apereo.github.io/cas
- Gitter Chatroom: https://gitter.im/apereo/cas
- List Guidelines: https://goo.gl/1VRrw7
- Contributions: https://goo.gl/mh7qDG
--- 
You received this message because you are subscribed to the Google Groups "CAS 
Community" group.
To unsubscribe from this group and stop receiving emails from it, send an email 
to [email protected].
To view this discussion on the web visit 
https://groups.google.com/a/apereo.org/d/msgid/cas-user/1048696375.5510912.1508260905457.JavaMail.zimbra%40unicon.net.

Reply via email to