super

          tomcat ssl的配置



          keytool -genkey -alias tomcat -keyalg RSA -keysize 1024 -keypass changeit -storepass changeit -keystore tomcat.keystore -validity 3600
           
          --這兩步可以不用
          keytool -export -trustcacerts -alias tomcat -file tomcat.cer -keystore  tomcat.keystore -storepass changeit
          keytool -import -trustcacerts -alias tomcat -file tomcat.cer -keystore  %JAVA_HOME%/jre/lib/security/cacerts -storepass changeit
           
           
          Tomcat4.1.34配置:
          <Connector className="org.apache.coyote.tomcat4.CoyoteConnector"             port="8443" enableLookups="true" scheme="https" secure="true"             acceptCount="100"             useURIValidationHack="false" disableUploadTimeout="true"             clientAuth="false" sslProtocol="TLS"               keystoreFile="tomcat.keystore"               keystorePass="changeit"/> 
          Tomcat5.5.9配置: 
            
          <Connector port="8443" maxHttpHeaderSize="8192"  
                     maxThreads="150" minSpareThreads="25" maxSpareThreads="75"  
                     enableLookups="false" disableUploadTimeout="true"  
                     acceptCount="100" scheme="https" secure="true"  
                     clientAuth="false" sslProtocol="TLS"    
                     keystoreFile="tomcat.keystore"    
                     keystorePass="changeit"/>  
          Tomcat5.5.20配置(此配置同樣可用于Tomcat6.0):
          <Connector protocol="org.apache.coyote.http11.Http11Protocol"    
                               port="8443" maxHttpHeaderSize="8192"  
                     maxThreads="150" minSpareThreads="25" maxSpareThreads="75"  
                     enableLookups="false" disableUploadTimeout="true"  
                     acceptCount="100" scheme="https" secure="true"  
                     clientAuth="false" sslProtocol="TLS"                   
                     keystoreFile="tomcat.keystore"    
                     keystorePass="changeit"/>  
          Tomcat6.0.10配置:
          <Connector protocol="org.apache.coyote.http11.Http11NioProtocol"  
                     port="8443" minSpareThreads="5" maxSpareThreads="75"  
                     enableLookups="true" disableUploadTimeout="true"    
                     acceptCount="100"  maxThreads="200"  
                     scheme="https" secure="true" SSLEnabled="true"  
                     clientAuth="false" sslProtocol="TLS"  
                     keystoreFile="D:/tools/apache-tomcat-6.0.10/tomcat.keystore"    
                     keystorePass="changeit"/>  
             

          其他有用keytool命令(列出信任證書庫中所有已有證書,刪除庫中某個證書):
          keytool -list -v -keystore D:/sdks/jdk1.5.0_11/jre/lib/security/cacerts
          keytool -delete -trustcacerts -alias tomcat  -keystore  D:/sdks/jdk1.5.0_11/jre/lib/security/cacerts -storepass changeit

          posted on 2009-04-02 15:14 王衛(wèi)華 閱讀(476) 評論(0)  編輯  收藏


          只有注冊用戶登錄后才能發(fā)表評論。


          網(wǎng)站導航:
           
          主站蜘蛛池模板: 宾川县| 临洮县| 阆中市| 齐齐哈尔市| 内黄县| 榆中县| 临颍县| 尖扎县| 繁昌县| 成都市| 永平县| 塘沽区| 景宁| 邢台县| 贡山| 富平县| 吴川市| 三门县| 左云县| 库尔勒市| 同江市| 丰宁| 碌曲县| 高安市| 榆树市| 和田县| 湖北省| 新巴尔虎左旗| 五台县| 黔江区| 新田县| 察哈| 绥滨县| 灵川县| 遂宁市| 马公市| 运城市| 额济纳旗| 临澧县| 兴山县| 峡江县|