Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]
Groups > comp.lang.java.security > #141 > unrolled thread
| Started by | "Dave Miller" <dave.miller@THRWHITE.remove-dii-this> |
|---|---|
| First post | 2011-04-27 16:08 +0000 |
| Last post | 2011-04-27 16:08 +0000 |
| Articles | 4 — 2 participants |
Back to article view | Back to comp.lang.java.security
This discussion starts older than the indexed window; earlier articles aren't shown. The article labeled Started by
below is the oldest one visible, not the original post.
Re: Loading keystores fro "Dave Miller" <dave.miller@THRWHITE.remove-dii-this> - 2011-04-27 16:08 +0000
Re: Loading keystores fro "Thomaspantalacci311" <thomaspantalacci311@THRWHITE.remove-dii-this> - 2011-04-27 16:08 +0000
Re: Loading keystores fro "Dave Miller" <dave.miller@THRWHITE.remove-dii-this> - 2011-04-27 16:08 +0000
Re: Loading keystores fro "Thomaspantalacci311" <thomaspantalacci311@THRWHITE.remove-dii-this> - 2011-04-27 16:08 +0000
| From | "Dave Miller" <dave.miller@THRWHITE.remove-dii-this> |
|---|---|
| Date | 2011-04-27 16:08 +0000 |
| Subject | Re: Loading keystores fro |
| Message-ID | <zoZjk.414$wS4.50@trnddc03> |
To: comp.lang.java.security Thomaspantalacci311@hotmail.com wrote: > I solved my problem. In fact i had to install jss (some dll and a jar > file to place in the current jre) in mozilla firefox. This done, the > JVM can access the firefox keystore and the client authentication is > OK (and so the applet is loaded). I also must check "Use certificates > and keys in browser keystore" in the java control panel->advanced- >> security. If you have access to the client side, there are many ways to load certs. Applets are usually delivered to clients to which you do not have access. -- Dave Miller Java Web Hosting at: http://www.cheap-jsp-hosting.com/ --- * Synchronet * The Whitehouse BBS --- whitehouse.hulds.com --- check it out free usenet! --- Synchronet 3.15a-Win32 NewsLink 1.92 Time Warp of the Future BBS - telnet://time.synchro.net:24
[toc] | [next] | [standalone]
| From | "Thomaspantalacci311" <thomaspantalacci311@THRWHITE.remove-dii-this> |
|---|---|
| Date | 2011-04-27 16:08 +0000 |
| Message-ID | <5bea81f5-d7db-4990-86ea-00b74857dbda@p25g2000hsf.googlegroups.com> |
| In reply to | #141 |
To: comp.lang.java.security
I had an other question, but i couldn't found any response. I have two
certificates in my smartcard. How can i load the both certificates.
I tryed this code
char[] pin = smartCardPIN.toCharArray();
KeyStore keyStore = null;
try{
keyStore = KeyStore.getInstance("PKCS11");//
}catch(Exception e){
e.printStackTrace();
}
keyStore.load(null, pin);
Enumeration aliases = keyStore.aliases();
if (aliases.hasMoreElements()) {
String alias = (String)aliases.nextElement();
System.out.println("alias:"+alias);
//getting the certificate chain and the private key
Certificate[] certificationChain =
keyStore.getCertificateChain(alias);
PrivateKey privateKey = (PrivateKey) keyStore.getKey(alias,
null);
....
}
...
But aliases enumeration has only one element, since it prints
"Signature certificate" (the alias of my signature certificate)
It seems that the other certificate is not loaded. Maybe i must
instantiate a new keystore ?
Maybe the problem (if it's a problem) is due to my pkcs11 provider. Do
you have any suggestion?
Thanks for your answers
---
* Synchronet * The Whitehouse BBS --- whitehouse.hulds.com --- check it out free usenet!
--- Synchronet 3.15a-Win32 NewsLink 1.92
Time Warp of the Future BBS - telnet://time.synchro.net:24
[toc] | [prev] | [next] | [standalone]
| From | "Dave Miller" <dave.miller@THRWHITE.remove-dii-this> |
|---|---|
| Date | 2011-04-27 16:08 +0000 |
| Message-ID | <OFakk.477$Ht4.473@trnddc01> |
| In reply to | #143 |
To: comp.lang.java.security
Thomaspantalacci311@hotmail.com wrote:
> I had an other question, but i couldn't found any response. I have two
> certificates in my smartcard. How can i load the both certificates.
> I tryed this code
>
> char[] pin = smartCardPIN.toCharArray();
> KeyStore keyStore = null;
> try{
> keyStore = KeyStore.getInstance("PKCS11");//
> }catch(Exception e){
> e.printStackTrace();
> }
> keyStore.load(null, pin);
> Enumeration aliases = keyStore.aliases();
> if (aliases.hasMoreElements()) {
> String alias = (String)aliases.nextElement();
> System.out.println("alias:"+alias);
> //getting the certificate chain and the private key
> Certificate[] certificationChain =
> keyStore.getCertificateChain(alias);
> PrivateKey privateKey = (PrivateKey) keyStore.getKey(alias,
> null);
> ....
>
> }
>
> ...
>
>
> But aliases enumeration has only one element, since it prints
You've created a keystore and placed one element into it. When you say
"show me elements" it... shows you the one that you've entered.
I've never tried to manipulate the keystore on the client's machine so I
won't be any help there. My sense is that doing so would take a bit of a
hack (or crack). As the keystore holds the keys (literally) to the
client's security, the JVM probably tries to keep it pretty well locked up.
--
Dave Miller
Java Web Hosting at:
http://www.cheap-jsp-hosting.com/
---
* Synchronet * The Whitehouse BBS --- whitehouse.hulds.com --- check it out free usenet!
--- Synchronet 3.15a-Win32 NewsLink 1.92
Time Warp of the Future BBS - telnet://time.synchro.net:24
[toc] | [prev] | [next] | [standalone]
| From | "Thomaspantalacci311" <thomaspantalacci311@THRWHITE.remove-dii-this> |
|---|---|
| Date | 2011-04-27 16:08 +0000 |
| Message-ID | <1bf19431-274e-4b62-b4c1-44b2f68d265e@59g2000hsb.googlegroups.com> |
| In reply to | #144 |
To: comp.lang.java.security
My bad, the keystore does contain the both certificates. In my code,
replace " if (aliases.hasMoreElements()) " with "while
( aliases.hasMoreElements() ){ ...
Sorry for such a trivial error lol
So everything is OK.
Thanks for the time you spent answering my questions (whose some are a
little bit stupid..)
---
* Synchronet * The Whitehouse BBS --- whitehouse.hulds.com --- check it out free usenet!
--- Synchronet 3.15a-Win32 NewsLink 1.92
Time Warp of the Future BBS - telnet://time.synchro.net:24
[toc] | [prev] | [standalone]
Back to top | Article view | comp.lang.java.security
csiph-web