permaculture playing cards*
The moose likes Servlets and the fly likes SSL With a Self-signed Certificate Big Moose Saloon
  Search | Java FAQ | Recent Topics | Flagged Topics | Hot Topics | Zero Replies
Register / Login

Win a copy of Android Security Essentials Live Lessons this week in the Android forum!
JavaRanch » Java Forums » Java » Servlets
Bookmark "SSL With a Self-signed Certificate" Watch "SSL With a Self-signed Certificate" New topic

SSL With a Self-signed Certificate

Alec Lee
Ranch Hand

Joined: Jan 28, 2004
Posts: 569
In a web application used within an intranet, we want sensitive information be still sent thru SSL. We generated a server certificate by 'keytool' and configured it for tomcat. The problem is, as the application is not a public web site, we will not obtain a formal certificate from any CA. Now whenever SSL is used the browser always prompts a warning message saying the server certificate is invalid (because the server certicate cannot be verified by some real CA).

Is there any simple method to get rid of this warning message in IE?
David O'Meara

Joined: Mar 06, 2001
Posts: 13459

I've seen some VBScript that can load a self-signed certificate into the certificate registry, all the user has to do is visit the page. Good 'ol Microsoft. I can't find it but maybe you can search the net for the script (it embeds the certificate as a Base64 encoded string), I'll try to remeber to ask at work.

David O'Meara

Joined: Mar 06, 2001
Posts: 13459


1) Export you certificate as PKCS-7 format to a file.
2) Base64 the contents.
3) paste the Base64 contents into the 'credentials' below (you'll have many more lines than this), save the page and load it in IE
4) Click 'yes' and 'yes' when prompted.
5) Certificate should be loaded, verify by viewing the encrypted site.

Note that as mentioned in the HTML below, it is possible to do this using the 'add certificate' wizard, but this is painfl when you need to explain it to multiple users.

David O'Meara

Joined: Mar 06, 2001
Posts: 13459

Note that ON_LOAD needs to have the underscore removed, UBB wouldn't let me post the word without the underscore included :roll:
It is sorta covered in the JavaRanch Style Guide.
subject: SSL With a Self-signed Certificate
Similar Threads
all-permissions and free signing
Non SSL based Flex application access to SSL Webservice
SSL for a client/server app ?
SSL Problem in Weblogic 6.1 sp3
SSL Problem in WLS 6.1 sp3