Skip to main content

SSL problem with glassfish v3.1

Please note these java.net forums are being decommissioned and use the new and improved forums at https://community.oracle.com/community/java.
2 replies [Last post]
bilgehan
Offline
Joined: 2007-10-06

Hi, i am having problems with ssl connection over http. I followed the steps at http://weblogs.java.net/blog/kalali/archive/2010/02/27/how-install-godad... and imported new certificate, replaced s1as with new certificate but when i try to connect over https, nothing happens and after a while i get timeout error. I checked server log and no error is given.
Thanks in advance for any help.

Reply viewing options

Select your preferred way to display the comments and click "Save settings" to activate your changes.
Kumar Jayanti Guest
Offline
Joined: 2011-04-02

On 27-Apr-2011, at 1:16 AM, forums@java.net wrote:

> Hi, i am having problems with ssl connection over http. I followed the
> steps
> at http://weblogs.java.net/blog/kalali/archive/2010/02/27/how-install-godad...
> [1] and imported new certificate, replaced s1as with new certificate but
> when i try to connect over https, nothing happens and after a while i get
> timeout error. I checked server log and no error is given.
>
> Thanks in advance for any help.

set jvm-option -Djavax.net.debug=all

http://download.oracle.com/javase/1.5.0/docs/guide/security/jsse/ReadDeb...

And send us the relevant debug log...

>
>
> [1] http://weblogs.java.net/blog/kalali/archive/2010/02/27/how-install-godad...
>
> --
>
> [Message sent by forum member 'bilgehan']
>
> View Post: http://forums.java.net/node/795840
>
>

bilgehan
Offline
Joined: 2007-10-06

I solved the problem but not sure this is a bug or something. I had imported the certificate into keystore file server.keystore (not default keystore.jks) and in the glassfish admin, i used that server.keystore in SSL section of https listener but i think that parameter wasn't used or found. I solved the problem by changing <jvm-options>-Djavax.net.ssl.keyStore=${com.sun.aas.instanceRoot}/config/keystore.jks</jvm-options> option with <jvm-options>-Djavax.net.ssl.keyStore=${com.sun.aas.instanceRoot}/config/server.keystore</jvm-options>. I don't know why that is needed and why doesn't changing keystore name in the admin work.
Bilgehan