super

          tomcat ssl的配置



          keytool -genkey -alias tomcat -keyalg RSA -keysize 1024 -keypass changeit -storepass changeit -keystore tomcat.keystore -validity 3600
           
          --這兩步可以不用
          keytool -export -trustcacerts -alias tomcat -file tomcat.cer -keystore  tomcat.keystore -storepass changeit
          keytool -import -trustcacerts -alias tomcat -file tomcat.cer -keystore  %JAVA_HOME%/jre/lib/security/cacerts -storepass changeit
           
           
          Tomcat4.1.34配置:
          <Connector className="org.apache.coyote.tomcat4.CoyoteConnector"             port="8443" enableLookups="true" scheme="https" secure="true"             acceptCount="100"             useURIValidationHack="false" disableUploadTimeout="true"             clientAuth="false" sslProtocol="TLS"               keystoreFile="tomcat.keystore"               keystorePass="changeit"/> 
          Tomcat5.5.9配置: 
            
          <Connector port="8443" maxHttpHeaderSize="8192"  
                     maxThreads="150" minSpareThreads="25" maxSpareThreads="75"  
                     enableLookups="false" disableUploadTimeout="true"  
                     acceptCount="100" scheme="https" secure="true"  
                     clientAuth="false" sslProtocol="TLS"    
                     keystoreFile="tomcat.keystore"    
                     keystorePass="changeit"/>  
          Tomcat5.5.20配置(此配置同樣可用于Tomcat6.0):
          <Connector protocol="org.apache.coyote.http11.Http11Protocol"    
                               port="8443" maxHttpHeaderSize="8192"  
                     maxThreads="150" minSpareThreads="25" maxSpareThreads="75"  
                     enableLookups="false" disableUploadTimeout="true"  
                     acceptCount="100" scheme="https" secure="true"  
                     clientAuth="false" sslProtocol="TLS"                   
                     keystoreFile="tomcat.keystore"    
                     keystorePass="changeit"/>  
          Tomcat6.0.10配置:
          <Connector protocol="org.apache.coyote.http11.Http11NioProtocol"  
                     port="8443" minSpareThreads="5" maxSpareThreads="75"  
                     enableLookups="true" disableUploadTimeout="true"    
                     acceptCount="100"  maxThreads="200"  
                     scheme="https" secure="true" SSLEnabled="true"  
                     clientAuth="false" sslProtocol="TLS"  
                     keystoreFile="D:/tools/apache-tomcat-6.0.10/tomcat.keystore"    
                     keystorePass="changeit"/>  
             

          其他有用keytool命令(列出信任證書(shū)庫(kù)中所有已有證書(shū),刪除庫(kù)中某個(gè)證書(shū)):
          keytool -list -v -keystore D:/sdks/jdk1.5.0_11/jre/lib/security/cacerts
          keytool -delete -trustcacerts -alias tomcat  -keystore  D:/sdks/jdk1.5.0_11/jre/lib/security/cacerts -storepass changeit

          posted on 2009-04-02 15:14 王衛(wèi)華 閱讀(473) 評(píng)論(0)  編輯  收藏


          只有注冊(cè)用戶登錄后才能發(fā)表評(píng)論。


          網(wǎng)站導(dǎo)航:
           
          主站蜘蛛池模板: 泸西县| 和顺县| 拜城县| 芜湖县| 南木林县| 汝南县| 高陵县| 临沧市| 安多县| 焦作市| 涟水县| 沙田区| 百色市| 达拉特旗| 大城县| 吉首市| 崇明县| 中卫市| 乳山市| 芒康县| 邢台市| 嘉鱼县| 平安县| 喀什市| 双辽市| 江阴市| 邓州市| 西峡县| 柳江县| 威远县| 天水市| 景东| 天津市| 恭城| 安国市| 阿瓦提县| 巍山| 陇川县| 洞口县| 华安县| 于田县|