users@glassfish.java.net

keytool and domain.xml

From: <glassfish_at_javadesktop.org>
Date: Wed, 27 Aug 2008 19:36:59 PDT

Hello,
         I was wondering if anyone was available to help me out. I imported both the
intermediate CA certificate and the certificate that we had issued into the keystore, and

I can see them listed as follows:

C:\Sun\SDK\domains\domain1\config>keytool -list -keystore .\keystore.jks
Enter keystore password: changeit

Keystore type: jks
Keystore provider: SUN

Your keystore contains 3 entries

intermediateca, Aug 27, 2008, trustedCertEntry,
Certificate fingerprint (MD5): 2A:C8:48:C0:85:F3:27:DE:32:29:44:BB:B0:2C:79:F8
jpl-apps, Aug 27, 2008, trustedCertEntry,
Certificate fingerprint (MD5): 36:5C:AF:4D:E4:77:57:5F:F0:0A:C4:A8:DB:7D:58:EF
s1as, Jul 31, 2008, keyEntry,
Certificate fingerprint (MD5): A3:DB:08:95:61:94:98:BE:8F:68:57:C3:EC:86:A1:12

I then used the admin interface to modify domain.xml.
by going to Configuration -> HTTP Service -> HTTP Listeners -> http-listener-2
then clicking on the SSL tab
If I attempt to change the Certificate NickName: to "jpl-apps" or anything but "s1as", it doesn't work.
I note that the web page states: "Takes a single value, identifies the server's keypair and certificate "
Does this imply that it's possible that my cert does not correspond to the "s1as" key,
or is there something that I am missing?
Please help.
Thank you.
[Message sent by forum member 'pward' (pward)]

http://forums.java.net/jive/thread.jspa?messageID=295792