Glassfish V3, Webstart & annoying exception

From: <>
Date: Sat, 26 Dec 2009 12:02:03 PST

I have built an Enteprise Application in Netbeans 6.8 and deployed it onto my Glassfish Server (v3) as part of my project's EAR file.

I have added a "sun-application-client.xml" file to the app with the following


I have also signed the jar file after build. The app runs fine within the Netbeans IDE.

If I select that I want the app made available for Webstart (using the Glassfish admin site) I can then try and launch the app via the glassfish admin page, but his results in an exception:

Here's the launch file and exception, any ideas how what I'm doing wrong as its very close to sending me nuts

<?xml version="1.0" encoding="UTF-8"?>
 * To change this template, choose Tools | Templates
 * and open the template in the editor.
 * Copyright 1997-2009 Sun Microsystems, Inc. All rights reserved.
 * The contents of this file are subject to the terms of either the GNU
 * General Public License Version 2 only ("GPL") or the Common Development
 * and Distribution License("CDDL") (collectively, the "License"). You
 * may not use this file except in compliance with the License. You can obtain
 * a copy of the License at
 * or glassfish/bootstrap/legal/LICENSE.txt. See the License for the specific
 * language governing permissions and limitations under the License.
 * When distributing the software, include this License Header Notice in each
 * file and include the License file at glassfish/bootstrap/legal/LICENSE.txt.
 * Sun designates this particular file as subject to the "Classpath" exception
 * as provided by Sun in the GPL Version 2 section of the License file that
 * accompanied this code. If applicable, add the following below the License
 * Header, with the fields enclosed by brackets [] replaced by your own
 * identifying information: "Portions Copyrighted [year]
 * [name of copyright owner]"
 * Contributor(s):
 * If you wish your version of this file to be governed by only the CDDL or
 * only the GPL Version 2, indicate your decision by adding "[Contributor]
 * elects to include this software in this distribution under the [CDDL or GPL
 * Version 2] license." If you don't indicate a single choice of license, a
 * recipient has the option to distribute your version of this file under
 * either the CDDL, the GPL Version 2 or to extend the choice of license to
 * its licensees as provided above. However, if you add GPL Version 2 code
 * and therefore, elected the GPL Version 2 license, then the option applies
 * only if the new code is made subject to such option by the copyright
 * holder.
        <vendor>SWB Systems</vendor>
        <homepage href="${appclient.information.homepage.filepath}"/>
        <description kind="one-line">TestACC</description>
        <description kind="short">TestACC</description>


<!-- <java version="1.6+"
             java-vm-args="-showversion -javaagent=glassfish/modules/gf-client.jar=mode=jws,${agent.args} " /> -->
        <java version="1.6+" java-vm-args="" />
            In v3, run the client facade as the main JAR. Eventually Java Web
            Start might support the splash screen in the JAR.
        <jar href="StDavidEEAClient/TestACCClient.jar" main="true" />
            If the client is part of an EAR then there will be an EAR-level
            generated facade JAR file.
        <jar href="StDavidEEAClient.jar"/>

            These next JARs will have been signed using the
            deployer-specified alias, if specified, or the default domain alias.
            Note that even though these are fetched within the code base of the
            app, we do not sign these once for each app but reuse ones
            signed with the same alias.
        <jar href="glassfish/modules/gf-client.jar"/>
        <jar href="glassfish/modules/gf-client-module.jar"/>

            Refer to extension JNLP documents which list other resources - JARs and JNLPs.

            The system extension lists the JARs that are common to all apps. The
            facade extension lists the generated facade JAR file for the client.
            The client extension lists the client JAR. The library extension
            lists JARs from the EAR application to which the client directly
            or indirectly refers.
        <extension name="___system" href="http://localhost:8080/___JWSappclient/___system/___dyn/___system.jnlp"/>
        <extension name="___client" href="___dyn/TestACC.jarClient/___client.jnlp"/>

        <extension name="libJars-s1as" href="___lib/client-libs-s1as.jnlp"/>

        <property name="appclient.system.codebase" value="http://localhost:8080/___JWSappclient/___system"/>
        <property name="" value="true"/>

        <property name="agent.args" value="mode=jws,client=url=http://localhost:8080/___JWSappclient/___app/StDavidEEA/StDavidEEAClient/TestACCClient.jar,arg=-targetserver,arg=localhost:3700"/>

        <property name="client.facade.jar.path" value="StDavidEEAClient/TestACCClient.jar"/>
        <property name="" value="http://localhost:8080/___JWSappclient/___app/StDavidEEA"/>
            Properties specified on the request as query parameters (if any)

            Content normally read from files during an appclient script launch.
        <property name="sun-acc.xml.content" value="&lt;?xml version=&quot;1.0&quot; encoding=&quot;UTF-8&quot;?&gt;

   Copyright 2004-2005 Sun Microsystems, Inc. All rights reserved.
   Use is subject to license terms.

   Please remember to customize this file for your environment. The defaults for
   following fields may not be appropriate.
   - target-server name, address and port
   - Property security.config in message-security-config

&lt;!DOCTYPE client-container PUBLIC &quot;-//Sun Microsystems Inc.//DTD Application Server 8.0 Application Client Container//EN&quot; &quot;;&gt;

  &lt;target-server name=&quot;localhost&quot; address=&quot;localhost&quot; port=&quot;3700&quot;/&gt;
  &lt;log-service file=&quot;&quot; level=&quot;WARNING&quot;/&gt;
  &lt;message-security-config auth-layer=&quot;SOAP&quot;&gt;
    &lt;!-- turned off by default --&gt;
    &lt;provider-config class-name=&quot;com.sun.xml.wss.provider.ClientSecurityAuthModule&quot; provider-id=&quot;XWS_ClientProvider&quot; provider-type=&quot;client&quot;&gt;
      &lt;request-policy auth-source=&quot;content&quot;/&gt;
      &lt;response-policy auth-source=&quot;content&quot;/&gt;
      &lt;property name=&quot;encryption.key.alias&quot; value=&quot;s1as&quot;/&gt;
      &lt;property name=&quot;signature.key.alias&quot; value=&quot;s1as&quot;/&gt;
      &lt;property name=&quot;dynamic.username.password&quot; value=&quot;false&quot;/&gt;
      &lt;property name=&quot;debug&quot; value=&quot;false&quot;/&gt;
    &lt;provider-config class-name=&quot;com.sun.xml.wss.provider.ClientSecurityAuthModule&quot; provider-id=&quot;ClientProvider&quot; provider-type=&quot;client&quot;&gt;
      &lt;request-policy auth-source=&quot;content&quot;/&gt;
      &lt;response-policy auth-source=&quot;content&quot;/&gt;
      &lt;property name=&quot;encryption.key.alias&quot; value=&quot;s1as&quot;/&gt;
      &lt;property name=&quot;signature.key.alias&quot; value=&quot;s1as&quot;/&gt;
      &lt;property name=&quot;dynamic.username.password&quot; value=&quot;false&quot;/&gt;
      &lt;property name=&quot;debug&quot; value=&quot;false&quot;/&gt;
      &lt;property name=&quot;security.config&quot; value=&quot;${security.config.path}&quot;/&gt;
        <property name="appclient.login.conf.content" value="/* Copyright 2004 Sun Microsystems, Inc. All rights reserved. */
/* SUN PROPRIETARY/CONFIDENTIAL. Use is subject to license terms. */

default { required debug=false;

certificate { required debug=false;
        <property name=""
Copyright 2004 Sun Microsystems, Inc. All rights reserved.
SUN PROPRIETARY/CONFIDENTIAL. Use is subject to license terms.
 This client side config file pairs with wss-server-config-1.0.xml on the server
 and supports the following UseCases:
 Usecase 1: Authentication by Protected UsernameToken
 Usecase 3: Encrypted UsernameToken and MessageBody
 Usecase 4: Response Encryption Key Learnt from Incoming Message

 Certificate Alias Information :
 1. A certificateAlias under the &lt;xwss:Encrypt&gt; element signifies the certificate
    of the recipient of the message.
 2. A certificateAlias under the &lt;xwss:Sign&gt; element signifies the certificate of the


   1. the certificateAlias has the above meaning for all the Sign and Encrypt elements below
   2. there are several Sign and Encrypt elements below and similarly several RequireSignature and
      RequireEncryption elements. Which of them would be actually used at runtime will depend on
      the AuthPolicy passed to the module.

      For Example : if Auth-Source=Sender then only the &lt;xwss:UsernameToken&gt; elements will be used
      and none of the &lt;xwss:Sign&gt; elements will be used.
      If Auth-Source=Content then the &lt;xwss:Sign&gt; element will be used

   3. The different variations of &lt;xwss:Encrypt&gt; elements in this configuration file are to accomodate
       default encryption of the UsernameToken.

   4. The actual certificate alias to be used for any Signature operation can be modified during AuthModule
       initialization by setting the alias as the value of &quot;signature.key.alias&quot; property in the Module Options Map.
   5. The actual certificate alias to be used for any Encrypt operation can be modified during AuthModule
       initialization by setting the alias as the value of &quot;encryption.key.alias&quot; property in the Module Options Map.

   6. D
jnlp file truncated after 10K

Here's the exception http://localhost:8080/___JWSappclient/___system/___dyn/___system.jnlp
        at sun.reflect.GeneratedConstructorAccessor2.newInstance(Unknown Source)
        at sun.reflect.DelegatingConstructorAccessorImpl.newInstance(Unknown Source)
        at java.lang.reflect.Constructor.newInstance(Unknown Source)
        at$ Source)
        at Method)
        at Source)
        at Source)
        at Source)
        at Source)
        at Source)
        at Source)
        at Source)
        at Source)
        at com.sun.javaws.LaunchDownload.downloadExtensionsHelper(Unknown Source)
        at com.sun.javaws.LaunchDownload.downloadExtensions(Unknown Source)
        at com.sun.javaws.Launcher.downloadResources(Unknown Source)
        at com.sun.javaws.Launcher.prepareLaunchFile(Unknown Source)
        at com.sun.javaws.Launcher.prepareToLaunch(Unknown Source)
        at com.sun.javaws.Launcher.prepareToLaunch(Unknown Source)
        at com.sun.javaws.Launcher.launch(Unknown Source)
        at com.sun.javaws.Main.launchApp(Unknown Source)
        at com.sun.javaws.Main.continueInSecureThread(Unknown Source)
        at com.sun.javaws.Main$ Source)
        at Source)
Caused by: http://localhost:8080/___JWSappclient/___system/___dyn/___system.jnlp
        at Source)
        at Source)
        ... 17 more
[Message sent by forum member 'jaredkrull' (]