admin管理员组

文章数量:1130349

问题

在搭建CAS server的过程中,Tomcat开启https,配置秘钥证书,证书是通过keytool生成的

        <Connector port="18443" protocol="org.apache.coyote.http11.Http11NioProtocol"
                connectionTimeout="20000" 
                maxThreads="150" SSLEnabled="true" 
                scheme="https" secure="true" 
                clientAuth="false" sslProtocol="TLS" 
                keystoreFile="/etc/cas/thekeystore" keystorePass="changeit" 
        />

启动tamcat后,提示如下报错

java.io.IOException: Alias name [cas] does not identify a key entry
java.lang.IllegalArgumentException: java.io.IOException: Alias name [null] does not identify a key entry
        at org.apache.tomcat.util.AbstractJsseEndpoint.createSSLContext(AbstractJsseEndpoint.java:115)
        at org.apache.tomcat.util.AbstractJsseEndpoint.initialiseSsl(AbstractJsseEndpoint.java:86)
        at org.apache.tomcat.util.NioEndpoint.bind(NioEndpoint.java:225)
        at org.apache.tomcat.util.AbstractEndpoint.init(AbstractEndpoint.java:982)
        at org.apache.tomcat.util.AbstractJsseEndpoint.init(AbstractJsseEndpoint.java:245)
        at org.apache.coyote.AbstractProtocol.init(AbstractProtocol.java:620)
        at org.apache.coyote.http11.AbstractHttp11Protocol.init(AbstractHttp11Protocol.java:66)
        at org.apache.catalina.connector.Connector.initInternal(Connector.java:997)
        at org.apache.catalina.util.LifecycleBase.init(LifecycleBase.java:107)
        at org.apache.catalina.core.StandardService.initInternal(StandardService.java:549)
        at org.apache.catalina.util.LifecycleBase.init(LifecycleBase.java:107)
        at org.apache.catalina.core.StandardServer.initInternal(StandardServer.java:875)
        at org.apache.catalina.util.LifecycleBase.init(LifecycleBase.java:107)
        at org.apache.catalina.startup.Catalina.load(Catalina.java:621)
        at org.apache.catalina.startup.Catalina.load(Catalina.java:644)
        at sun.reflect.NativeMethodAccessorImpl.invoke0(Native Method)
        at sun.reflect.NativeMethodAccessorImpl.invoke(NativeMethodAccessorImpl.java:62)
        at sun.reflect.DelegatingMethodAccessorImpl.invoke(DelegatingMethodAccessorImpl.java:43)
        at java.lang.reflect.Method.invoke(Method.java:498)
        at org.apache.catalina.startup.Bootstrap.load(Bootstrap.java:311)
        at org.apache.catalina.startup.Bootstrap.main(Bootstrap.java:494)
Caused by: java.io.IOException: Alias name [null] does not identify a key entry
        at org.apache.tomcat.util.jsse.JSSEUtil.getKeyManagers(JSSEUtil.java:237)
        at org.apache.tomcat.util.AbstractJsseEndpoint.createSSLContext(AbstractJsseEndpoint.java:113)
        ... 20 more

15-Jan-2018 16:54:55.884 严重 [main] org.apache.catalina.core.StandardService.initInternal Failed to initialize connector [Connector[HTTP/1.1-18443]]
 org.apache.catalina.LifecycleException: Failed to initialize component [Connector[HTTP/1.1-18443]]
        at org.apache.catalina.util.LifecycleBase.init(LifecycleBase.java:113)
        at org.apache.catalina.core.StandardService.initInternal(StandardService.java:549)
        at org.apache.catalina.util.LifecycleBase.init(LifecycleBase.java:107)
        at org.apache.catalina.core.StandardServer.initInternal(StandardServer.java:875)
        at org.apache.catalina.util.LifecycleBase.init(LifecycleBase.java:107)
        at org.apache.catalina.startup.Catalina.load(Catalina.java:621)
        at org.apache.catalina.startup.Catalina.load(Catalina.java:644)
        at sun.reflect.NativeMethodAccessorImpl.invoke0(Native Method)
        at sun.reflect.NativeMethodAccessorImpl.invoke(NativeMethodAccessorImpl.java:62)
        at sun.reflect.DelegatingMethodAccessorImpl.invoke(DelegatingMethodAccessorImpl.java:43)
        at java.lang.reflect.Method.invoke(Method.java:498)
        at org.apache.catalina.startup.Bootstrap.load(Bootstrap.java:311)
        at org.apache.catalina.startup.Bootstrap.main(Bootstrap.java:494)
Caused by: org.apache.catalina.LifecycleException: Protocol handler initialization failed
        at org.apache.catalina.connector.Connector.initInternal(Connector.java:1000)
        at org.apache.catalina.util.LifecycleBase.init(LifecycleBase.java:107)
        ... 12 more
Caused by: java.lang.IllegalArgumentException: java.io.IOException: Alias name [null] does not identify a key entry
        at org.apache.tomcat.util.AbstractJsseEndpoint.createSSLContext(AbstractJsseEndpoint.java:115)
        at org.apache.tomcat.util.AbstractJsseEndpoint.initialiseSsl(AbstractJsseEndpoint.java:86)
        at org.apache.tomcat.util.NioEndpoint.bind(NioEndpoint.java:225)
        at org.apache.tomcat.util.AbstractEndpoint.init(AbstractEndpoint.java:982)
        at org.apache.tomcat.util.AbstractJsseEndpoint.init(AbstractJsseEndpoint.java:245)
        at org.apache.coyote.AbstractProtocol.init(AbstractProtocol.java:620)
        at org.apache.coyote.http11.AbstractHttp11Protocol.init(AbstractHttp11Protocol.java:66)
        at org.apache.catalina.connector.Connector.initInternal(Connector.java:997)
        ... 13 more
Caused by: java.io.IOException: Alias name [null] does not identify a key entry
        at org.apache.tomcat.util.jsse.JSSEUtil.getKeyManagers(JSSEUtil.java:237)
        at org.apache.tomcat.util.AbstractJsseEndpoint.createSSLContext(AbstractJsseEndpoint.java:113)
        ... 20 more

#分析
实际测试的过程中,有操作将秘钥(证书)库文件thekeystore的私钥删除了,并且把公钥导入在了里边。
#解决
重新生成秘钥,并且通过

keytool -list -keystore thekeystore 

检查秘钥的类型,是PrivateKeyEntry就正常了。

  • PrivateKeyEntry,为私钥,配置在tomcat的server.xml(CAS服务端)
  • trustedCertEntry,为公钥,配置在jdk(应用服务端)

Waiting for your reward

问题

在搭建CAS server的过程中,Tomcat开启https,配置秘钥证书,证书是通过keytool生成的

        <Connector port="18443" protocol="org.apache.coyote.http11.Http11NioProtocol"
                connectionTimeout="20000" 
                maxThreads="150" SSLEnabled="true" 
                scheme="https" secure="true" 
                clientAuth="false" sslProtocol="TLS" 
                keystoreFile="/etc/cas/thekeystore" keystorePass="changeit" 
        />

启动tamcat后,提示如下报错

java.io.IOException: Alias name [cas] does not identify a key entry
java.lang.IllegalArgumentException: java.io.IOException: Alias name [null] does not identify a key entry
        at org.apache.tomcat.util.AbstractJsseEndpoint.createSSLContext(AbstractJsseEndpoint.java:115)
        at org.apache.tomcat.util.AbstractJsseEndpoint.initialiseSsl(AbstractJsseEndpoint.java:86)
        at org.apache.tomcat.util.NioEndpoint.bind(NioEndpoint.java:225)
        at org.apache.tomcat.util.AbstractEndpoint.init(AbstractEndpoint.java:982)
        at org.apache.tomcat.util.AbstractJsseEndpoint.init(AbstractJsseEndpoint.java:245)
        at org.apache.coyote.AbstractProtocol.init(AbstractProtocol.java:620)
        at org.apache.coyote.http11.AbstractHttp11Protocol.init(AbstractHttp11Protocol.java:66)
        at org.apache.catalina.connector.Connector.initInternal(Connector.java:997)
        at org.apache.catalina.util.LifecycleBase.init(LifecycleBase.java:107)
        at org.apache.catalina.core.StandardService.initInternal(StandardService.java:549)
        at org.apache.catalina.util.LifecycleBase.init(LifecycleBase.java:107)
        at org.apache.catalina.core.StandardServer.initInternal(StandardServer.java:875)
        at org.apache.catalina.util.LifecycleBase.init(LifecycleBase.java:107)
        at org.apache.catalina.startup.Catalina.load(Catalina.java:621)
        at org.apache.catalina.startup.Catalina.load(Catalina.java:644)
        at sun.reflect.NativeMethodAccessorImpl.invoke0(Native Method)
        at sun.reflect.NativeMethodAccessorImpl.invoke(NativeMethodAccessorImpl.java:62)
        at sun.reflect.DelegatingMethodAccessorImpl.invoke(DelegatingMethodAccessorImpl.java:43)
        at java.lang.reflect.Method.invoke(Method.java:498)
        at org.apache.catalina.startup.Bootstrap.load(Bootstrap.java:311)
        at org.apache.catalina.startup.Bootstrap.main(Bootstrap.java:494)
Caused by: java.io.IOException: Alias name [null] does not identify a key entry
        at org.apache.tomcat.util.jsse.JSSEUtil.getKeyManagers(JSSEUtil.java:237)
        at org.apache.tomcat.util.AbstractJsseEndpoint.createSSLContext(AbstractJsseEndpoint.java:113)
        ... 20 more

15-Jan-2018 16:54:55.884 严重 [main] org.apache.catalina.core.StandardService.initInternal Failed to initialize connector [Connector[HTTP/1.1-18443]]
 org.apache.catalina.LifecycleException: Failed to initialize component [Connector[HTTP/1.1-18443]]
        at org.apache.catalina.util.LifecycleBase.init(LifecycleBase.java:113)
        at org.apache.catalina.core.StandardService.initInternal(StandardService.java:549)
        at org.apache.catalina.util.LifecycleBase.init(LifecycleBase.java:107)
        at org.apache.catalina.core.StandardServer.initInternal(StandardServer.java:875)
        at org.apache.catalina.util.LifecycleBase.init(LifecycleBase.java:107)
        at org.apache.catalina.startup.Catalina.load(Catalina.java:621)
        at org.apache.catalina.startup.Catalina.load(Catalina.java:644)
        at sun.reflect.NativeMethodAccessorImpl.invoke0(Native Method)
        at sun.reflect.NativeMethodAccessorImpl.invoke(NativeMethodAccessorImpl.java:62)
        at sun.reflect.DelegatingMethodAccessorImpl.invoke(DelegatingMethodAccessorImpl.java:43)
        at java.lang.reflect.Method.invoke(Method.java:498)
        at org.apache.catalina.startup.Bootstrap.load(Bootstrap.java:311)
        at org.apache.catalina.startup.Bootstrap.main(Bootstrap.java:494)
Caused by: org.apache.catalina.LifecycleException: Protocol handler initialization failed
        at org.apache.catalina.connector.Connector.initInternal(Connector.java:1000)
        at org.apache.catalina.util.LifecycleBase.init(LifecycleBase.java:107)
        ... 12 more
Caused by: java.lang.IllegalArgumentException: java.io.IOException: Alias name [null] does not identify a key entry
        at org.apache.tomcat.util.AbstractJsseEndpoint.createSSLContext(AbstractJsseEndpoint.java:115)
        at org.apache.tomcat.util.AbstractJsseEndpoint.initialiseSsl(AbstractJsseEndpoint.java:86)
        at org.apache.tomcat.util.NioEndpoint.bind(NioEndpoint.java:225)
        at org.apache.tomcat.util.AbstractEndpoint.init(AbstractEndpoint.java:982)
        at org.apache.tomcat.util.AbstractJsseEndpoint.init(AbstractJsseEndpoint.java:245)
        at org.apache.coyote.AbstractProtocol.init(AbstractProtocol.java:620)
        at org.apache.coyote.http11.AbstractHttp11Protocol.init(AbstractHttp11Protocol.java:66)
        at org.apache.catalina.connector.Connector.initInternal(Connector.java:997)
        ... 13 more
Caused by: java.io.IOException: Alias name [null] does not identify a key entry
        at org.apache.tomcat.util.jsse.JSSEUtil.getKeyManagers(JSSEUtil.java:237)
        at org.apache.tomcat.util.AbstractJsseEndpoint.createSSLContext(AbstractJsseEndpoint.java:113)
        ... 20 more

#分析
实际测试的过程中,有操作将秘钥(证书)库文件thekeystore的私钥删除了,并且把公钥导入在了里边。
#解决
重新生成秘钥,并且通过

keytool -list -keystore thekeystore 

检查秘钥的类型,是PrivateKeyEntry就正常了。

  • PrivateKeyEntry,为私钥,配置在tomcat的server.xml(CAS服务端)
  • trustedCertEntry,为公钥,配置在jdk(应用服务端)

Waiting for your reward

本文标签: 异常证书iojavatomcat