Showing posts with label keytool. Show all posts
Showing posts with label keytool. Show all posts

Tuesday, January 31, 2017

Jar Signing For E-Business Suite

Before completion of validity of Code-Signing Certificate , I have done signing process for E-Business Suite. This process provided , prevent blocking of Java based forms screen because of not valid certificate.

To do this ,

1. List certificates in JKS file to detect alias

    keytool -list -keystore mycert.jks
    Output should like below

   1, 23.Jan.2017, PrivateKeyEntry,
   Certificate fingerprint (SHA1): DA::****************

2. You can change the alias of key,

   keytool -changealias -keystore mycert.jks -alias 1 -destalias myalias

   For this scenario my alias was "1" and changed it to "myalias". After change of alias output would like below,

   myalias, 23.Jan.2017, PrivateKeyEntry,
   Certificate fingerprint (SHA1): DA:****************

3. Upload edited JKS (mycert.jks) to EBS application tier $APPL_TOP/admin folder

4. Import new jks into existing adkeystore.dat

   keytool -importkeystore -srckeystore mycert.jks -destkeystore adkeystore.dat

5. Change keypass of new key to the E-Business Suite expected value

 keytool -keypasswd -keystore adkeystore.dat -keypass <YourKeyStorePass> -new <EBSStorePassword> -alias myalias 

  <YourKeyStorePass> defines  your keystore password for code-signing certificate which is given from Official CA like Verisign etc.

  <EBSStorePassword> defines EBS store (adkeystore.dat) password which can taken from below script if you do not know,

declare
  spass varchar2(30);
  kpass varchar2(30);
begin
  ad_jar.get_jripasswords(spass,kpass) ;
  dbms_output.put_line(spass);
  dbms_output.put_line(kpass);
end;

6. Edit adsign.txt file which will show new key alias . With this change , while regeneration of jar files  adadmin will use new key alias.

7. Regenerate all jar files via adadmin , after stopping application tier services.

Friday, May 6, 2016

Using SSL web service certificates in Oracle EBS

In this blog post, i would like to give some basic information about using SSL certificates in Oracle EBS applications. This requirement came from new development which takes data from web service over SSL. In order to connect securely, distributed certificate must be imported into keystore which your program will use to connect.

The keystore (cacerts) located in $AF_JRE_TOP/lib/security was used for this.To import related certificates into this truststore $AF_JRE_TOP/bin/keytool is used.

Change directory into $AF_JRE_TOP/bin

cd $AF_JRE_TOP/bin
./keytool -keystore ../lib/security/cacerts -importcert -file "your_cert_file" -alias "your_alias"

Default keystore password is : changeit

After answer "trust this certificate "as Yes , your certificate will be imported.

You can query certificate with following command,

./keytool -keystore ../lib/security/cacerts -list | grep "your_alias"

Output should show your certificate information .The keystore is now used in any code for using web service calls.

Friday, January 24, 2014

jarsigner: unable to recover key from keystore

I have encountered this problem while signing EBS jarfiles with new digital certificate.Codesigning certificate is used to sign jar files , in order to pass through security issues which come with new Java version 1.7.0_51. 


New cert file has private key with different password. When keystore and keyentry have different password , this issue can become. 

ERROR: JarSigner subcommand exited with status 1

JarSigner standard output:
jarsigner: unable to recover key from keystore

JarSigner error output:

Enter Passphrase for keystore: Enter key password for <Alias>

In order to pass over , keyentry password should be changed to keystore password.

keytool -keypasswd -keystore adkeystore.dat -keypass <KeyEntryPass> -new <KeyStorePass> -alias ykxcodesign