른록노트
[tomcat] jks 인증서 설치방법 본문
@ 방법
톰캣 conf 폴더에 server.xml 수정
-Tomcat 6.x 이하 버전의 설정
<Connector port="443"
protocol="HTTP/1.1"
SSLEnabled="true"
maxThreds="150"
scheme="https"
secure="true"
clientAuth="false"
keystoreFile="/usr/local/tomcat/conf/domain.jks"
keystorePass="password"
sslProtocol="TLS"
/>
-Tomcat 7.x 이하 버전의 설정
<Connector port="443"
protocol="HTTP/1.1"
SSLEnabled="true"
maxThreds="150"
scheme="https"
secure="true"
clientAuth="false"
keystoreFile="/usr/local/tomcat/conf/domain.jks"
keystorePass="password"
sslEnabledProtocols="TLSv1.1,TLSv1.2"
ciphers="TLS_ECDHE_RSA_WITH_AES_128_CBC_SHA256
,TLS_ECDHE_RSA_WITH_AES_128_CBC_SHA
,TLS_ECDHE_RSA_WITH_AES_256_CBC_SHA384
,TLS_ECDHE_RSA_WITH_AES_256_CBC_SHA
,TLS_RSA_WITH_AES_128_CBC_SHA256
,TLS_RSA_WITH_AES_128_CBC_SHA
,TLS_RSA_WITH_AES_256_CBC_SHA256
,TLS_RSA_WITH_AES_256_CBC_SHA"
/>
@에러 참고
com.notnoop.exceptions.InvalidSSLConfig: java.io.IOException: DerInputStream.getLength(): lengthTag=109, too big.
=> 발생시 keystoreType="PKCS12" 속성 삭제
@참고사이트
https://cheezred.tistory.com/124
반응형
Comments