Home | Contact Us | FAQ | Search & Site Map | Link to Us
Sign In | Join | Other 45 Sites in Network
HomeAnnouncementsWhite Papers
Discussion GroupsFirst AidDatabasesJavaBeansGUIJava 3DVirtual MachineCORBASecurityToolsGeneral
Java DirectoryOpen Source ProjectsSample Book ChaptersUser GroupsWeb Resources
Related Topics
Databases.NETMore Topics ...

Java Forum / Security / May 2004

Tip: Looking for answers? Try searching our database.

HTTPS Servlet with Tomcat

Thread view: 
David G. Folch - 07 May 2004 15:06 GMT
Hi folks!!

I'm new to SSL and I've been working arround for 3 days to adapt my servlets
to HTTPS.

I've correctly configured jakarta-tomcat 4.1.30 as shown in
http://jakarta.apache.org/tomcat-4.1-doc/ssl-howto.html on a WinXP box.

My servlet "users" works fine with
http://localhost:8080/myapp/services/users

But when I call it with https://localhost:8443/myapp/services/users on IE6.0
and Mozilla1.6 both show me info about certificate and I accept,  then two
results occurs on each client:

1. Internet Explorer: show me the user form correctly, but no security
status icon is shown, if i click where it should be the icon, IE show me
info aboud the certificate and tells me is valid, every thing seems to be
correct.  But no icon is shown.

2. Mozilla: tells me "You have requested an encripted page that contains
some unencrypted information.  Information that you see or enter on this
page could easily be read by a third party." and the security status icon is
closed but scratched in red.

When I change to a non SSL address both clients tell me I'm leaving a "ssl
connection".

I've generated the certificate with keyTool from JDK1.4.1_04.

Mi servlet does nothing at all about security, because I understand that
tomcat is container security based.

And now I'm lost at this point.  Did I forget something??? I hope nop!

Please, anyone can help to solve what's going on??
Saludos
David G. Folch (Barcelona/Spain)
Juha Laiho - 08 May 2004 19:32 GMT
"David G. Folch" <davidgfolch@ya.com> said:
>But when I call it with https://localhost:8443/myapp/services/users on IE6.0
>and Mozilla1.6 both show me info about certificate and I accept,  then two
>results occurs on each client:
...
>2. Mozilla: tells me "You have requested an encripted page that contains
>some unencrypted information.  Information that you see or enter on this
>page could easily be read by a third party." and the security status icon is
>closed but scratched in red.

Could it be that the servlet creates HTML which refers to some inline
objects (images? frame contents?) to be retrieved via the non-SSL port?

Also, you might try to find out about the page structure with Mozilla;
something like File->Properties might give a nice amount of info.
Signature

Wolf  a.k.a.  Juha Laiho     Espoo, Finland
(GC 3.0) GIT d- s+: a C++ ULSH++++$ P++@ L+++ E- W+$@ N++ !K w !O !M V
        PS(+) PE Y+ PGP(+) t- 5 !X R !tv b+ !DI D G e+ h---- r+++ y++++
"...cancel my subscription to the resurrection!" (Jim Morrison)



Free Magazines

Get these publications absolutely FREE for up to 12 months. There are no hidden fees and no obligation. Simply choose a title, complete the application form and submit it. Read more ...

Oracle MagazineNetwork ComputingComputer WorldBio-IT WorldeWeekInformation WeekInfosecurity
 
Sign In
Join
My Latest Posts
My Monitored Threads
My Blog
My Photo Gallery
My Profile
My Homepage

Start New Thread
Enable EMail Alerts
Rate this Thread



©2008 Advenet LLC   Privacy Policy - Terms of Use
This website includes both content owned or controlled by Advenet as well as content owned or controlled by third parties.