2016-11-14 59 views
0

我試圖在我們正在構建的新Web服務上實現雙向SSL,並且出現了一些問題。Tomcat - 雙向SSL作爲服務器

首先有關環境的一些信息。

Server version: Apache Tomcat/8.0.36 
Server built: Jun 9 2016 13:55:50 UTC 
Server number: 8.0.36.0 
OS Name:  Linux 
OS Version:  3.10.0-514.el7.x86_64 
Architecture: amd64 
JVM Version: 1.8.0_111-b14 
JVM Vendor:  Oracle Corporation 

我們使用內部證書頒發機構簽署我們所有的證書。所以所有的客戶端證書都由我們的內部根簽名。當我信任客戶端信任庫中的根證書時,一切正常。所有由內部根工作簽名的客戶端證書。

但是,如果我從客戶端信任存儲庫中刪除根證書,並添加單個客戶端證書,則會出現證書鏈錯誤。


*** ECDH ServerKeyExchange 
Signature Algorithm SHA512withRSA 
Server key: Sun EC public key, 256 bits 
    public x coord: 107108750176335210433834926983330116805775068919227166974389735341685270962458 
    public y coord: 93195725734236902743006469378087068209149058097948526490562555560744449337507 
    parameters: secp256r1 [NIST P-256, X9.62 prime256v1] (1.2.840.10045.3.1.7) 
*** CertificateRequest 
Cert Types: RSA, DSS, ECDSA 
Supported Signature Algorithms: SHA512withECDSA, SHA512withRSA, SHA384withECDSA, SHA384withRSA, SHA256withECDSA, SHA256withRSA, SHA256withDSA, SHA224withECDSA, SHA224withRSA, SHA224withDSA, SHA1withECDSA, SHA1withRSA, SHA1withDSA Cert Authorities: 
<CN=Client, OU=Information Technology, O=Company, L=Calgary, ST=Alberta, C=CA> 
*** ServerHelloDone 
http-nio2-8443-exec-4, WRITE: TLSv1.2 Handshake, length = 4482 http-nio2-8443-exec-2, READ: TLSv1.2 Handshake, length = 7 
*** Certificate chain 
<Empty> 
*** 
http-nio2-8443-exec-2, fatal error: 42: null cert chain 
javax.net.ssl.SSLHandshakeException: null cert chain %% Invalidated:[Session-2, TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256] 
http-nio2-8443-exec-2, SEND TLSv1.2 ALERT: fatal, description = bad_certificate http-nio2-8443-exec-2, WRITE: TLSv1.2 Alert, length = 2 http-nio2-8443-exec-2, fatal: engine already closed. Rethrowing javax.net.ssl.SSLHandshakeException: null cert chain http-nio2-8443-exec-2, called closeOutbound() http-nio2-8443-exec-2, closeOutboundInternal() 

這對我們來說是一個問題,因爲我們不能在公司的所有客戶端證書授予訪問這個端點,它那種失敗的目的。

公司根證書位於服務器啓動時使用的另一個信任存儲區中。這是我的配置。

server.xml中的連接器:

<Connector protocol="org.apache.coyote.http11.Http11Nio2Protocol" 
      port="8443" maxThreads="24" minSpareThreads="4" maxSpareThreads="4" acceptCount="1000" server=" " 
      scheme="https" secure="true" SSLEnabled="true" 
      keystoreFile="certs/servercert.jks" keystorePass=" CrazyPasswordHere" 
      clientAuth="true" truststoreFile="/usr/local/tomcat/certs/clienttrust.jks" truststorePass="CrazyPasswordHere" 
      sslEnabledProtocols="TLSv1.2" sslProtocol="TLS" 
      ciphers="TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256,TLS_ECDHE_RSA_WITH_AES_128_CBC_SHA256,TLS_ECDHE_RSA_WITH_AES_128_CBC_SHA, 
      TLS_DHE_RSA_WITH_AES_128_GCM_SHA256,TLS_DHE_RSA_WITH_AES_128_CBC_SHA256,TLS_DHE_RSA_WITH_AES_128_CBC_SHA" 
      useServerCipherSuitesOrder="true" compression="on" compressionMinSize="2048" 
      compressableMimeType="text/html,text/xml,text/plain,text/css,text/javascript,application/javascript" /> 

Systemd初始化:

# Systemd unit file for tomcat 
[Unit] 
Description=Apache Tomcat 
After=syslog.target network.target 

[Service] 
Type=forking 

Environment=JAVA_HOME=/usr/lib/jvm/jre 
Environment=CATALINA_PID=/usr/local/tomcat/temp/tomcat.pid 
Environment=CATALINA_HOME=/usr/local/tomcat 
Environment=CATALINA_BASE=/usr/local/tomcat 
Environment='CATALINA_OPTS= -Xms2048M -Xmx2048M -server -XX:+UseParallelGC \ -Dcom.sun.management.jmxremote \ 
-Dcom.sun.management.jmxremote.port=8090 \ -Dcom.sun.management.jmxremote.ssl=false \ -Dcom.sun.management.jmxremote.authenticate=true \ -Dcom.sun.management.jmxremote.password.file=/usr/local/tomcat/conf/jmxremote.password \ -Dcom.sun.management.jmxremote.access.file=/usr/local/tomcat/conf/jmxremote.access \ -Djavax.net.debug=SSL \ -Djavax.net.ssl.trustStore=/usr/local/tomcat/certs/servertrust.jks \ -Djavax.net.ssl.trustStorePassword=CrazyPasswordHere \ -Djavax.net.ssl.keyStore=/usr/local/tomcat/certs/serverclient.jks \ -Djavax.net.ssl.keyStorePassword=CrazyPasswordHere ' 
Environment='JAVA_OPTS=-Djava.awt.headless=true -Djava.security.egd=file:/dev/./urandom' 

ExecStart=/usr/local/tomcat/bin/startup.sh 
ExecStop=/bin/kill -15 $MAINPID 

User=tomcat 
Group=tomcat 

[Install] 
WantedBy=multi-user.target 

這裏任何投入將是巨大的!我無法想象這裏的解決方案是每個由特定授權機構簽署的客戶證書應該有權訪問...

謝謝!

回答

3

經典。您正在將認證與授權混爲一談。 SSL的工作是通過您已經設置的機制進行身份驗證,以及您所說的正在完美工作。 Tomcat或應用程序的工作是使用該信息來定義誰有權使用該Web應用程序。這是通過web.xml,CMA等完成的。

+0

謝謝,你說得對。我不應該在我的連接字符串中啓用clientauth,而是在我的web.xml中。我現在有這個設置並且很好地工作。 – user2735454