The digitally signed certificate(s) returned by the CA can be in any accepted format but the PEM format (usually have extensions such as .pem, .crt, .cer, .key ) is the most common format that CA issue certificates in.
They PEM are Base64 encoded ASCII files and contain “ -----BEGIN CERTIFICATE -----” and “-----END CERTIFICATE -----” statements.
SSL certificates, root anf intermediate CA certificates, and private keys can all be put into the PEM format.
A Keystore file is used to store cryptographic keys and certificates.
There are three kinds of entries that can be stored in a Keystore file depending upon the type of Keystore file it is:
Private Key: This is a type of key that is used in asymmetric cryptography. It is usually protected with a password because of its sensitivity. It can also be used to sign a digital signature.
Certificate: A certificate contains a public key that can identify the subject claimed in the certificate. It is usually used to verify the identity of a server.
Secret Key: A key entry that is used in symmetric cryptography.
If you will have the following PEM-encoded files:
- cert.pem: Your domain's certificate
- chain.pem: The Let's Encrypt chain certificate
- fullchain.pem: cert.pem and chain.pem combined
- privkey.pem: Your certificate's private key
- account.key
- domain.key
- intermediate.crt
- domain.crt
- domain.p12
- domain.jks
The password of the P12-Certifcate and the password of the Keystore has to be the same.
To avoid: Unable to start service Caused by: Cannot recover key
openssl pkcs12 -export -name domain -in domain.crt -inkey domain.key -out domain.p12
Enter Export Password: ...
Verifying - Enter Export Password: ...
keytool -importkeystore -srckeystore domain.p12 -srcstoretype pkcs12 -destkeystore domain.jks -deststoretype JKS
Immettere la password del keystore di destinazione: ...
Immettere nuovamente la nuova password: ...
Immettere la password del keystore di origine: ...
La voce dell' alias domain è stata importata.
Importazione completata: 1 voci importate, 0 voci non importate o annullate
keytool -import -trustcacerts -alias intermediate -file intermediate.crt -keystore domain.jks
Immettere la password del keystore:
Considerare attendibile questo certificato? [no]: si
Il certificato è stato aggiunto al keystore
keytool -import -trustcacerts -alias domain -file domain.crt -keystore domain.jks
Immettere la password del keystore:
Considerare attendibile questo certificato? [no]: si
Il certificato è stato aggiunto al keystore
keytool -list -v -keystore domain.jks
Immettere la password del keystore:
Tipo keystore: JKS
Provider keystore: SUN
Il keystore contiene 2 entry
<security-realm name="SslRealm">
<keystore path="keystore.jks" relative-to="jboss.server.config.dir" keystore-password="changeme"/>
<subsystem xmlns="urn:jboss:domain:undertow:1.2">
<buffer-cache name="default"/>
<server name="default-server">
<http-listener name="default" socket-binding="http"/>
<https-listener name="default-ssl" socket-binding="https" security-realm="SslRealm"/>
<socket-binding-group name="standard-sockets" default-interface="public" port-offset="${jboss.socket.binding.port-offset:0}">
<socket-binding name="https" port="${jboss.https.port:8443}"/>
Add a unix redirect, because port 80 is open only by root user
sudo iptables -t nat -A PREROUTING -p tcp --dport 80 -j REDIRECT --to-port 8080
sudo iptables -t nat -A PREROUTING -p tcp --dport 443 -j REDIRECT --to-port 8443
Generate self-signed ssl cert with keytool:
keytool -keystore ssl-server.jks -genkey -alias testssl -keyalg RSA
Enter keystore password: --the keystore password--
Re-enter new password:
What is your first and last name?
[Unknown]: Marco Rossi
What is the name of your organizational unit?
[Unknown]: Net
What is the name of your organization?
[Unknown]: ACN
What is the name of your City or Locality?
[Unknown]: Rome
What is the name of your State or Province?
[Unknown]: RM
What is the two-letter country code for this unit?
[Unknown]: IT
Is CN=Marco Rossi, OU=Net, O=ACN, L=Rome, ST=RM, C=IT correct?
[no]: y
Use it, for example, on spring-boot project:
- copy the file on /src/main/resources classpath directory of a java project
- write on file the following configuration parameters
server.ssl.key-store-password= --the keystore password--