how to set up ssl on tomcat?

684 byte By Rinzia at 2007-10-2 13:40:04
Hi,I am trying to configure ssl on tomcat web server.The versions i'm using are... Apache Tomcat 5.5, jdk1.5.0_02 on windowsNT platform.i'm using self signed certificate...i could generate a certificate with my name.although i followed all the steps provided in the tomcat docs n various ...

SSL and UDP

451 byte By smithsaa at 2007-10-2 13:42:21
We all know that if I have some protocol that's based on TCP, it is simple to secure it by using an SSL socket instead of a TCP socket. What if my protocol is based on UDP? Is there some standard way of tunneling UDP over SSL to also make it secure? I realize that this adds a lot of overhead ...

Possible to sign with an expired certificate ?

495 byte By boran_bloka at 2007-10-2 14:14:49
Hi, i'm building an application that verifies digital signatures placed on a document. I can obtain all info about the certificate chain (valid, revoked, expired, and such).But now i'm wondering if it is possible to sign a document with an expired signature. (one way or another) because if it ...

SSL Client certificate validation through a proxy

368 byte By FreeSoul001a at 2007-10-2 14:16:32
Brief run down on the environment:Requests to the web site occur via IISIIS is in the DMZIIS implements SSL IIS routes request to a cluster of weblogic serversQuestion:If we set up IIS to require client certificates, will the cert credentials be available in the request object when it comes to ...

Reading the property file at Runtime of project

172 byte By Shrinatha at 2007-10-2 14:19:07
hii have problem with Reading the property file at Runtime of projectits work with compile time using resourseBundle please help Shrinath

Accessing JAAS Subject and Principal from within a JSP

346 byte By Roshanta at 2007-10-2 14:30:42
Hi,I'm trying to test my custom Login Module to see if it is passing all the personalization parameters correctly to the client. I need to write a JSP from within which I can access the Subject and the Principal from within the Subject. If anyone knows how to do this, your help will be ...

HTTP Status 408 - The time allowed for the login process has been exceeded

1003 byte By vjoyweba at 2007-10-2 14:44:07
hi,I getting this message with tomcat.I am using j_security check.the full message is:HTTP Status 408 - The time allowed for the login process has been exceeded. If you wish to continue you must either click back twice and re-click the link you requested or close and re-open your browser--type ...

Securing data

254 byte By Printisora at 2007-10-2 14:44:26
HiAnyone knows how i can secure files that reside on removable cards, like a Multi-Media Card, or a Flash Memory Card so that they can be accessed only if the user knows some password, or has a license or a key?Thank you,Mihai

j_security check

2638 byte By spear_arrowa at 2007-10-2 14:45:53
Hi,I want to use j_security_check but i have a few problems. I have the following in my web.xml <security-constraint><web-resource-collection><web-resource-name>All JSP direct ...

Fail to generate CertPath

1204 byte By leo.ckpa at 2007-10-2 14:46:58
Hi all, I'm developing a little test program that required eCert, and the program like this:-public class TestHadh {private String str;public static void main(String[] args) {// TODO Auto-generated method stubtry {// soultion 1CertificateFactory cf = ...

PKCS7

752 byte By superglooa at 2007-10-2 15:00:40
Hello,I'm chasing my tail and hoping someone can help out?Client sends me a .p7b (PKCS#7) file which includes key, the issuing CA, and the Root CA to be used Java code on my end. Next, client is sending me two things:1) Signature data2) Encrypted dataI need to verify the signature and then ...

LDAP Authention Error

1028 byte By lvguangchuana at 2007-10-2 15:01:21
Hi,ALLI use LDAP to access Windows 2003 server active directory.It works pretty good.However, since some reason, I have reinstalled windows 2003 server.and my LDAP can not pass authencation.Error:LDAP: error code 49 - 80090308: LdapErr: DSID-0C090334, comment: AcceptSecurityContext error, data ...

Enveloped XML Digital Signature - Issues.

7042 byte By muruganselvaraja at 2007-10-2 15:02:27
Hi,I am using JSR 105 XML Digital Signature 1.0.1 (JavaTM Web Services Developer Pack 2.0) for signing only the specific element in the XML file and then put the XML signature element back to the specific element in the same XML file using enveloped signing.The issue is I am able to pass the ...

what type of authentication will suite best

177 byte By teekama at 2007-10-2 15:35:25
i am developng a web application which will authenticate user by username & password which type of authentication i should use & where i will find more about this

What do you do with an Encryption key when you close your program?

143 byte By jay_dawga at 2007-10-2 15:51:51
How do you store your key when you exit your program? Don't wanna store it in a file as plain text. Don't think that\s a secure option

Confused about RBAC in J2EE

2127 byte By adcworksa at 2007-10-2 15:52:06
Hi,So I'm just setting up some BASIC authentication in my web application which hasn't been too painful. I am however a little stuck with a good strategy for my use case which I assume many people come across. Most of the examples of security for web apps I come across just try and protect a ...

How to automate JAAS authentication

397 byte By xoomooa at 2007-10-2 15:54:19
I am using JAAS form-based authentication to prevent unauthorized page access. Once logged in the user's roles remain in effect untilt he session expires. Users are demanding a "remember me" check box. That requires programmatic login in addition to, not in place of, the form-based intercept. ...

Advantages of Java vs. C++ to the cryptographic app developer

152 byte By _bensmytha at 2007-10-2 16:01:42
What advantages does Java provide to the crypto applications developer in comparision with say C++?What disadvantages does Java introduce?

Issue in authentication, web service running in IIS server.

1270 byte By _Error_webserice@calla at 2007-10-2 16:06:45
We are trying to make a web service call to Microsoft share point portal server. This share point portal run on top of Microsoft IIS server and my client in javaSo I get a error like (401)Unauthorized when ever I try to call the web service.This problem is because IIS server use windows ...

SSLEngine: What happens with/after invalid SSL packets?

832 byte By nostradamus_a at 2007-10-2 16:13:48
Hello,this may sound rather weird and unusual, but before I can consider using SSLEngine + NIO I should have an answer for that :)I want to have an application where two entities e1 and e2 can communicate via a SSL-secured stream. The SSL packets may come from different sources ...

Virus

286 byte By pbear489a at 2007-10-2 16:23:46
Help I got 8 virus on my computer. I'm using SBC virus scan and got 8 virus hits and it said it on java/Byteverifyexploit, java/Byte Verify!exploit, Java/shinwow.AK, Java/Byte Verify!exploit, and then Win32/SillyDI.YUWin32/SillyDI.TFso does anybody know what to do

JAAS

315 byte By Smurfera at 2007-10-2 16:45:51
I am building a GUI for a Bioinformatics application. I need to be able to allow users to login and out of the program. Is there a reason I should use the JAAS or should I just use the Jpassword field? I am currently planning on using Jpassword to create my own login component. Is this just as ...

Problem with Policy in Applet

3481 byte By El_Chinoa at 2007-10-2 16:57:52
Hi everybody:I'm developing an Applet that parse an ontology make a representation of it in a JTree. My applet have the following package structure:appletui|tree|utils|__ config|__ icons|__ libappletui have the applet's class (MenuApplet.class)tree have the classes to represent the tree of ...

Keytool password prompt option

425 byte By tilbr01a at 2007-10-2 16:58:30
I'm trying to call keytool inside a java program with Runtime.exec(). I want to call keytool to add a certificate to keystore. I can do it manually but when I do, it requires a password prompt. I'm using the command$ keytool -import -file myCert.crt -trustcacerts -alias ldap-keystore ...

SSLSocket and certificate issue

1737 byte By Robert.Heisea at 2007-10-2 16:59:35
Im attempting to build a client side app that creates a sslsocket connection. I have similiar client code running in Perl utilizing Net::SSLeay and Socket and I do not have any issues using this code w/o certificates. Here is my code using javax.net.ssl.*TrustManager[] trustAllCerts = new ...

HttpURLConnection Problem - Please Help

3079 byte By bds_60a at 2007-10-2 17:08:49
We抮e having an issue with HttpURLConnection when executing from a servlet, initially reached through a Proxy server. A little background of our environment and overall processing taking place:We have a typical multi-tier extranet architecture with firewalls between our Web, App and Data layers. ...

AccessControlException

267 byte By JavaJohn06a at 2007-10-2 17:09:37
I receive that secuirity error when I load a applet on Internet Explorer. The error doesn't occur when I load it in JCreator. The error occurs when I try to access a .txt file. Any advice on how to solve these problems would greatly be appreciated, thank-you.

regarding configuration tools n security

346 byte By fun-braina at 2007-10-2 17:12:51
hi,i developed a web application..now i want to develope configuration wizards,which configures my product at client side.it should take care of available modules in my product.it should add selected modules,and if need it should add plug-ins too......any tools available to develope such a ...

Kerberos login succeeded, but GSSAPI doesn't find a ticket?

7390 byte By MarkusKargQUIPSYa at 2007-10-2 17:15:39
I studied all the samples and forum posts to success in accessing my Win2003 based Active Directory from my WinXP client, but nothing helped:Login using ticket cache works well, but LDAP complains about GSSAPI not beeing able to find a ticket. So what to do? Where's my fault?Please help, I am ...

request Authentication

664 byte By Kanua at 2007-10-2 17:19:43
Hello all, I have a small query. Suppose you have a very secured site. Now after the user has logged in, the user copies the URL from the address bar of the browser. Then in the same browser window user opens another site (google.com). Now the user pastes the copied URL in the address bar. Here ...

Own Extensions

729 byte By NashuAa at 2007-10-2 17:30:16
Hello,I've made a program, in which I use a file to calculate some stuff.This file is a txt. - file.My problem is, that this file may not be readable by any user. And in fact, they can open it in some kind op spreadsheet like WordPad, and change it if they want to.So I was wondering if it was ...

JAAS can't read config from JAR

2685 byte By NickDGa at 2007-10-2 17:32:28
We have an application that uses JAAS for security. Until now the JAAS config file was in a folder (conf/) and the application just ran fine. To prepare for the deployment of the application with Webstart I packed the folder with the config file in the application's JAR. Now JAAS can't seem ...

How to extract / read email value (RFC822) from X509Certificate

610 byte By jpadrona at 2007-10-2 17:48:46
HelloSimply want to read the email of a certificate (X.509) attached to a digital signature of pdf files.I am using BouncyCastleProvider as scurtiy provider, and profit to obtain certificates, but I cannot obtain the email.IssueDN: C=ES,O=FNMT,OU=FNMT Clase 2 CASubjectDN returns: C=ES, o=fnmt, ...

JAAS and Container Manager Security

1314 byte By John76Johna at 2007-10-2 17:58:09
Hi,I m stucked in a security authentication/authorization issue, which I hope you have some advice for me.In simple words, I want to use the Web container security (for authorization) together with my own JAAS implementation (for authentication).How to achieve this ?I don't want to use the ...

keytool - Whats the difference between

1517 byte By psu99a at 2007-10-2 17:59:04
Please help. Its been 14 hours of no sleep and I cant find the answer.Can someone please tell me why when using the keytool to create my keystore the "keystore password" and the "key password" must be the same?When these values are the same, I can hit my Tomcat server over the https call?So, ...

Building Biometric Authentication for J2EE, Web, and Enterprise Application

133 byte By shady-tannousa at 2007-10-2 18:13:30
hello i'm doing my senior project on this subject so if anyone can help and tell me from where can i get the biobex software?

SSO and SAML (OASIS)

504 byte By Yazada at 2007-10-2 18:40:51
Hi Guys,I am expected to work on SAML to implement SSO. I am working on weblogic 8.1 whic doesnt have any built in support. Are there any standard apis available for SAML? I found one on apache - wss4j.I believe there are 2 independent SAML standards, I have to implement the one proposed by ...

JAAS Tomcat PB..

966 byte By fvisticota at 2007-10-2 18:54:29
I try to integrate JAAS with Tomcat 5.028 and JSFI read a lot of FAQs BUT i have a pb for authorization.My web.xml seems OKThe Login module seems OKI always have a HTTP 403 error for bad authorization.I launch Tomcat with 2 JVM options:-Djava.security.auth.policy=<path to ...

About dependent objects

1385 byte By Sarah_Mahdavia at 2007-10-2 18:58:26
Hi, we are developing a distributed application (with standard java library) and our application has more than 20 sub-system/service. some services need another services to accomplish their tasks. in the other hand there are some method in one service that may calling another mothod in the ...

Java 5.0 and the OCSP capabilities of the SUN provider

111 byte By wil93a at 2007-10-2 19:04:59
please see this post for details: http://forum.java.sun.com/thread.jspa?threadID=731429TIA

JAAS Authorization for the method based access for database

1019 byte By Sachin.S.Kulkarnia at 2007-10-2 19:05:16
Hi,My application is swing based, rmi application for the distributed database. I am doing JAAS based secure development for it. I want to acheive method and role based security from it. The methods are generally the methods to communicate with the database.I have done the JAAS authentication ...

Sending certificates over a socket connection

587 byte By dodgeyhacka at 2007-10-2 19:10:24
HiI am sending a certificate over a socket connection.I am having a problem on the receiving end recognising when the certificates have been sent.Currently X509Certificate cert = (X509Certificate)cf.generateCertificate( in);is blocking until the output stream is closed. Since I want to continue ...

AccessControlException in JAAS Authorization

2019 byte By Sachin.S.Kulkarnia at 2007-10-2 19:12:17
Hi,While using JAAS framework for the rmi application for distributed database communication in secure way i have following problem. I have done each login user as Subject and its related roles as principles. Now every principle (role) will give permissions to some methods.The code ...

JAAS to RSA RADIUS Server

473 byte By MikeSummersa at 2007-10-2 19:14:06
I need to write a JAAS module that will validate passwords against an RSA RADIUS Server (via RSA's Authentication Manager).I'm not seeing the sort of api's I saw when I did a similar module for Siteminder, so a couple of questions:- Is there a Java API for RSA Authentication Manager? (I'm ...

How do I get an extended SecurityManager to handle privileged code?

1066 byte By fredrik_aslina at 2007-10-2 19:16:16
Hi.I have written my own SecurityManager which asks if the user wants to allow the action before denying it. It also offers to write the whole permission into the current policy file.The problem I have is that I can't get the securitymanager to handle privileged code. At the moment I get the ...

Tomcat (org.apache.jasper.JasperException: access denied )

8600 byte By mina at 2007-10-2 19:25:56
I developed a web application which allows users to upload files to server machine. It worked fine on my localhost with no errors.Now I have migrated the site to a server. When I try to upload files to the server, I got the following:org.apache.jasper.JasperException: access denied ...

Questions on javax.net.ssl.keyStore

806 byte By Andrew_sga at 2007-10-2 19:27:44
I have enabled Tomcat two-way SSL by creating server cert, creating client cert, importing server's cert into the client's truststore, and importing client's cert into the server's truststore. In my client program, I need to insert codes like System.setProperty("javax.net.ssl.keyStore", ...

Configuration Issue

938 byte By JAM-MSCa at 2007-10-2 19:35:00
Hi all,This issue has been driving me crazy for a few days now...any help at all is greatly appreciated.System : Win XP Pro - jdk1.5 - jwsdp2.0 - apache xml Security 1.3For some reason, when i hit this line of code : XMLSignature sig = sigFactory.newXMLSignature(signedInfo, keyInfo);I get this ...

Message does not conform to configured policy?

868 byte By jerry_hewetta at 2007-10-2 19:35:49
Does anyone know what this JAX-RPC (WS-Security) error message is trying to tell me?error: Message does not conform to configured policy [ AuthenticationTokenPolicy(S) ]: No Security Header foundjavax.xml.rpc.soap.SOAPFaultException: Message does not conform to configured policy [ ...

JAAS login problem

3198 byte By D.Wilhelma at 2007-10-2 19:44:32
Hello,i'm playing around a bit with connecting to a Microsoft Active Directory using JAAS and the Kerberos module.I created a config file like this:LoginJaas { com.sun.security.auth.module.Krb5LoginModule required debug=true useTicketCache=true; };My test code looks like this:URL url = ...