【问题标题】:Unable to lookup if SSL is enabled in Websphere 8.5如果在 Websphere 8.5 中启用 SSL,则无法查找
【发布时间】:2016-05-02 09:31:38
【问题描述】:

我编写了一个简单的 ejb 瘦客户端来查找部署在 IBM WebSphere 8.5 中的 bean。

当服务器上未启用 SSL 时,我能够成功查找 bean,但一旦启用 SSL,我就开始收到下面提到的异常。

这就是我通过管理控制台启用安全性的方式:

例外:

javax.naming.NamingException: Error getting WsnNameService properties [Root exception is org.omg.CORBA.TRANSIENT: initial and forwarded IOR inaccessible  vmcid: IBM  minor code: E07  completed: No]
at com.ibm.ws.naming.util.WsnInitCtxFactory.mergeWsnNSProperties(WsnInitCtxFactory.java:1552)
at com.ibm.ws.naming.util.WsnInitCtxFactory.getRootContextFromServer(WsnInitCtxFactory.java:1042)
at com.ibm.ws.naming.util.WsnInitCtxFactory.getRootJndiContext(WsnInitCtxFactory.java:962)
at com.ibm.ws.naming.util.WsnInitCtxFactory.getInitialContextInternal(WsnInitCtxFactory.java:614)
at com.ibm.ws.naming.util.WsnInitCtx.getContext(WsnInitCtx.java:128)
at com.ibm.ws.naming.util.WsnInitCtx.getContextIfNull(WsnInitCtx.java:765)
at com.ibm.ws.naming.util.WsnInitCtx.lookup(WsnInitCtx.java:164)
at com.ibm.ws.naming.util.WsnInitCtx.lookup(WsnInitCtx.java:179)
at javax.naming.InitialContext.lookup(InitialContext.java:436)
at nh.indi.test.S2SCommTest.lookupServiceEJB(S2SCommTest.java:55)
at nh.indi.test.S2SCommTest.main(S2SCommTest.java:22) 
Caused by: org.omg.CORBA.TRANSIENT: initial and forwarded IOR inaccessible  vmcid: IBM  minor code: E07  completed: No
at com.ibm.rmi.corba.ClientDelegate.createRequest(ClientDelegate.java:1276)
at com.ibm.CORBA.iiop.ClientDelegate.createRequest(ClientDelegate.java:1342)
at com.ibm.rmi.corba.ClientDelegate.createRequest(ClientDelegate.java:1164)
at com.ibm.CORBA.iiop.ClientDelegate.createRequest(ClientDelegate.java:1308)
at com.ibm.rmi.corba.ClientDelegate.request(ClientDelegate.java:1886)
at com.ibm.CORBA.iiop.ClientDelegate.request(ClientDelegate.java:1264)
at org.omg.CORBA.portable.ObjectImpl._request(ObjectImpl.java:458)
at com.ibm.WsnBootstrap._WsnNameServiceStub.getProperties(_WsnNameServiceStub.java:38)
at com.ibm.ws.naming.util.WsnInitCtxFactory.mergeWsnNSProperties(WsnInitCtxFactory.java:1549)
... 10 more

代码:

public static void main(String args[]) throws NamingException {

    Properties ejbProps = new Properties();
    ejbProps.put("org.omg.CORBA.ORBClass", "com.ibm.CORBA.iiop.ORB");
    ejbProps.put(Context.INITIAL_CONTEXT_FACTORY,
            "com.ibm.websphere.naming.WsnInitialContextFactory");
    ejbProps.put(Context.PROVIDER_URL, "corbaloc:iiop:160.XX.XX.XX:2809");

    InitialContext ffmContext = new InitialContext(ejbProps);
    Object remoteObject = ffmContext
            .lookup("ejb/MyAppEar-CLUSTER/MyAppEJB.jar/BatchIdTrackingBean#indi.nh.business.framework.bos.di.BatchIdTrackingBeanRemote");

    BatchIdTrackingBeanRemote serviceTester = (BatchIdTrackingBeanRemote) PortableRemoteObject
            .narrow(remoteObject, BatchIdTrackingBeanRemote.class);

    System.out.println(serviceTester);

}

在运行程序时,我还传递了我的本地文件系统中存在的 sas.client.props 文件位置,如此处所述。 1

-Dcom.ibm.CORBA.ConfigURL=file:///C:/Temp/docs/S2S_Docs/sas.client.props

1 : How to connect to a websphere Application Server 8.5 Message Queue while Administrative Security is enabled

谁能帮助我如何在 websphere 应用服务器上启用 SSL 或我的客户端或服务器端配置中缺少的情况下成功测试它。

【问题讨论】:

  • 在您的 SSL 配置中,您当前已根据需要设置 Client certificate authentication。你真的想这样做吗?因为在这种情况下,您必须设置双向 SSL。将 WAS 证书放入客户端信任库,并将客户端证书放入 WAS 信任库。如果您只想启用 SSL,请将客户端证书设置为从不,并确保您的客户端信任库中有 WAS 证书。
  • 将客户端证书身份验证设置为 never 后,该异常消失了。

标签: java ssl ejb websphere websphere-8


【解决方案1】:

您还需要将此属性添加到 java 命令:-Dcom.ibm.CORBA.ConfigURL=file:///home/user1/sas.client.props

您可以从 WebSphere Application Server 安装中复制 ssl.client.props 文件(除了 sas.client.props)。您至少需要将 ssl.client.props 文件中的密钥文件的位置更新为您创建或复制密钥文件的位置。例如,

-Dcom.ibm.ssl.keyStore=/home/user1/etc/key.p12 -Dcom.ibm.ssl.trustStore=/home/user1/etc/trust.p12

当您再次运行客户端时,它会提示您将签名者添加到信任库(如果信任库不存在)。

更多详情请访问:https://www-01.ibm.com/support/knowledgecenter/SSAW57_8.5.5/com.ibm.websphere.nd.doc/ae/tcli_ejbthinclient.html

【讨论】:

  • 谢谢, - 根据 Gas 的 cmets 进行更改并按照您的步骤进行更改后,我能够成功查找启用了 SSL-Required 的 bean。既然回答了这个问题,我的下一个担心是确保握手使用 SSL 协议。我打算使用wireshark来捕获网络流量。如果我看到不同的东西,我会告诉你的。
猜你喜欢
  • 1970-01-01
  • 1970-01-01
  • 1970-01-01
  • 1970-01-01
  • 1970-01-01
  • 1970-01-01
  • 1970-01-01
  • 1970-01-01
  • 1970-01-01
相关资源
最近更新 更多