glassfish 证书过期错误SEVERE: SEC5054: Certificate has expired:

本文介绍了解决因证书过期导致的GlassFish服务器错误的方法。通过定位到cacerts.jks文件并使用keytool命令来查找和删除过期的GTE CyberTrust Root 5证书。



from: http://www.adam-bien.com/roller/abien/entry/how_to_fix_expired_certificate


The following error:


com.sun.enterprise.security.ssl.impl.SecuritySupportImpl checkCertificateDates
SEVERE: SEC5054: Certificate has expired: [
[
  Version: V3
  Subject: CN=GTE CyberTrust Root 5, OU="GTE CyberTrust Solutions, Inc.", O=GTE Corporation, C=US
  Signature Algorithm: SHA1withRSA, OID = 1.2.840.113549.1.1.5

  Key:  Sun RSA public key, 2048 bits


Is caused by certificate expiration in the keystore file: cacerts.jks. The cacerts.jks file usually resides in the folder: [GLASSFISH_HOME]/glassfish4/glassfish/domains/[DOMAIN_NAME]/config. With embedded GlassFish the certificate is extracted into the folder [USER]/.glassfishv3-arquillian[...]/config.

Copy the keystore file cacerts.jks into src/test/resources/config and mvm clean install you project.




To find if the ca is included in cacerts.jks, just use the following command,

then find get the alias: gtecybertrust5ca.


C:\Java\glassfish4\glassfish\domains\domain1\config>keytool -list -v -keystore cacerts.jks
 -storepass changeit|find "CN=GTE CyberTrust Root 5"






In case the keystore file also contains the expired certificate, simply delete the affected certificate:

keytool -delete -keystore ./cacerts.jks -alias gtecybertrust5ca
Password: changeit






 

评论
添加红包

请填写红包祝福语或标题

红包个数最小为10个

红包金额最低5元

当前余额3.43前往充值 >
需支付:10.00
成就一亿技术人!
领取后你会自动成为博主和红包主的粉丝 规则
hope_wisdom
发出的红包
实付
使用余额支付
点击重新获取
扫码支付
钱包余额 0

抵扣说明:

1.余额是钱包充值的虚拟货币,按照1:1的比例进行支付金额的抵扣。
2.余额无法直接购买下载,可以购买VIP、付费专栏及课程。

余额充值