super

          tomcat ssl的配置



          keytool -genkey -alias tomcat -keyalg RSA -keysize 1024 -keypass changeit -storepass changeit -keystore tomcat.keystore -validity 3600
           
          --這兩步可以不用
          keytool -export -trustcacerts -alias tomcat -file tomcat.cer -keystore  tomcat.keystore -storepass changeit
          keytool -import -trustcacerts -alias tomcat -file tomcat.cer -keystore  %JAVA_HOME%/jre/lib/security/cacerts -storepass changeit
           
           
          Tomcat4.1.34配置:
          <Connector className="org.apache.coyote.tomcat4.CoyoteConnector"             port="8443" enableLookups="true" scheme="https" secure="true"             acceptCount="100"             useURIValidationHack="false" disableUploadTimeout="true"             clientAuth="false" sslProtocol="TLS"               keystoreFile="tomcat.keystore"               keystorePass="changeit"/> 
          Tomcat5.5.9配置: 
            
          <Connector port="8443" maxHttpHeaderSize="8192"  
                     maxThreads="150" minSpareThreads="25" maxSpareThreads="75"  
                     enableLookups="false" disableUploadTimeout="true"  
                     acceptCount="100" scheme="https" secure="true"  
                     clientAuth="false" sslProtocol="TLS"    
                     keystoreFile="tomcat.keystore"    
                     keystorePass="changeit"/>  
          Tomcat5.5.20配置(此配置同樣可用于Tomcat6.0):
          <Connector protocol="org.apache.coyote.http11.Http11Protocol"    
                               port="8443" maxHttpHeaderSize="8192"  
                     maxThreads="150" minSpareThreads="25" maxSpareThreads="75"  
                     enableLookups="false" disableUploadTimeout="true"  
                     acceptCount="100" scheme="https" secure="true"  
                     clientAuth="false" sslProtocol="TLS"                   
                     keystoreFile="tomcat.keystore"    
                     keystorePass="changeit"/>  
          Tomcat6.0.10配置:
          <Connector protocol="org.apache.coyote.http11.Http11NioProtocol"  
                     port="8443" minSpareThreads="5" maxSpareThreads="75"  
                     enableLookups="true" disableUploadTimeout="true"    
                     acceptCount="100"  maxThreads="200"  
                     scheme="https" secure="true" SSLEnabled="true"  
                     clientAuth="false" sslProtocol="TLS"  
                     keystoreFile="D:/tools/apache-tomcat-6.0.10/tomcat.keystore"    
                     keystorePass="changeit"/>  
             

          其他有用keytool命令(列出信任證書(shū)庫(kù)中所有已有證書(shū),刪除庫(kù)中某個(gè)證書(shū)):
          keytool -list -v -keystore D:/sdks/jdk1.5.0_11/jre/lib/security/cacerts
          keytool -delete -trustcacerts -alias tomcat  -keystore  D:/sdks/jdk1.5.0_11/jre/lib/security/cacerts -storepass changeit

          posted on 2009-04-02 15:14 王衛(wèi)華 閱讀(476) 評(píng)論(0)  編輯  收藏


          只有注冊(cè)用戶登錄后才能發(fā)表評(píng)論。


          網(wǎng)站導(dǎo)航:
           
          主站蜘蛛池模板: 安平县| 临邑县| 宣威市| 海安县| 博野县| 铅山县| 横山县| 乌拉特前旗| 玛多县| 栾川县| 祁连县| 临城县| 尚志市| 乳山市| 项城市| 红安县| 龙州县| 雅安市| 湛江市| 静海县| 定日县| 彭州市| 鹤壁市| 土默特左旗| 潼关县| 株洲县| 四平市| 兴义市| 仪征市| 龙里县| 普陀区| 忻城县| 锡林郭勒盟| 勐海县| 邢台市| 阿鲁科尔沁旗| 桃园市| 枣强县| 黄石市| 楚雄市| 油尖旺区|