04-11-2013
SSL certificate generation on OS level or application level
We have a RHEL 5.8 server at the production level and we have a Java application on this server. I know of the SSL certificate generation at the OS (RHEL) level but it is implemented on the Java application by our development team using the Java keytool. My doubt is that is the SSL generation can be done at the OS level or at the application level also?
I hope, my query is clear that can the SSL generation be done at the application level also in addition to the SSL generation at the OS level.
Please revert with the reply to my query
Regards
10 More Discussions You Might Find Interesting
1. UNIX for Advanced & Expert Users
Hi,
I'm working in an application and the related Java code and the envrionment is in Unix server. We are generating the log messages using loggers of Java.util.log . But, the logs are not getting generated in the log files.
We feel that the people who developed the system might have done some... (6 Replies)
Discussion started by: kelangovan
6 Replies
2. Web Development
Hello everybody
Hope somebody can help me
I'm trying to install SSL Certificate on Apache/mod_ssl on Linux with Zend for Oracle.
I bought and downloaded certificate from certificate from Network Solutions. Than I followed the instructions to the dot.
I created a directory for certificate... (2 Replies)
Discussion started by: Trusevich
2 Replies
3. Web Development
Dear All
Anyone know how to issue two different certification on apache virtualhost fyi i have one virtualhost eg 69.192.1.25:443 already signed with verisign how can i configure another virtualhost 69.192.1.25:443 which signing with another certificate which self signing. i search net not... (1 Reply)
Discussion started by: netxus
1 Replies
4. AIX
Hello,
I am new in UNIX, and some one asks me to install SSL certificates to allow exchange with an external system.
Can someone tell how to install certificate (ex : verisignxxx.cer) on a UNIX server?
Many thanks.
Tibo (4 Replies)
Discussion started by: tibo51
4 Replies
5. Solaris
what are the major Difference Between run level & init level (2 Replies)
Discussion started by: rajaramrnb
2 Replies
6. Cybersecurity
Hi guys.
I have some questions about ssl certificates.
I looked at SSL providers and saw that they are providing 2 types of certificates: per server or per domain.
my server host name is: srv1.example.com
I have a smtp, imap, web server on this box. but all services accessed by different... (1 Reply)
Discussion started by: majid.merkava
1 Replies
7. Web Development
we are doing TCP for our systems. I have a working SSL certificate on prodction webserver. Im planning to export it to our DR server for TCP purposes. However when I export based on the procedure below, it doesn't work. When I restart the DR webserver, it still says the certifcate is expired.Any... (1 Reply)
Discussion started by: lhareigh890
1 Replies
8. UNIX for Advanced & Expert Users
Hi
We are facing Application hanging issue from users who log in to applications from the server. But through other server , all the transactions are working fine.
Now how can i can compare the OS level parameter setting on both servers.
Or please suggest me your ideas to debug thes... (1 Reply)
Discussion started by: susa_dgl
1 Replies
9. Red Hat
Hi guys,
I'm trying to generate a key using the genkey command in centos 6.4 and RHEL6.4, Every thing seems to go cool but I get this error message bad certificate request error -8016 and no key/cert is generated. I don't want use the many openssl(s) commands instead since genkey is a shourtcut... (4 Replies)
Discussion started by: leo_ultra_leo
4 Replies
10. Cybersecurity
Hey everyone, I'm trying to get a lay of the land for OS and Application Certificate Stores. Can someone confirm that I have this concept right?
If the application you're using say Firefox has it's own trusted CA store, it uses that exclusively. So if you're running firefox in Windows, Firefox... (4 Replies)
Discussion started by: Lost in Cyberia
4 Replies
LEARN ABOUT PHP
openssl_x509_checkpurpose
OPENSSL_X509_CHECKPURPOSE(3) 1 OPENSSL_X509_CHECKPURPOSE(3)
openssl_x509_checkpurpose - Verifies if a certificate can be used for a particular purpose
SYNOPSIS
int openssl_x509_checkpurpose (mixed $x509cert, int $purpose, [array $cainfo = array()], [string $untrustedfile])
DESCRIPTION
openssl_x509_checkpurpose(3) examines a certificate to see if it can be used for the specified $purpose.
PARAMETERS
o $x509cert
- The examined certificate.
o $purpose
-
openssl_x509_checkpurpose(3) purposes
+---------------------------+---------------------------------------------------+
| Constant | |
| | |
| | Description |
| | |
+---------------------------+---------------------------------------------------+
| X509_PURPOSE_SSL_CLIENT | |
| | |
| | Can the certificate be used for the client side |
| | of an SSL connection? |
| | |
| X509_PURPOSE_SSL_SERVER | |
| | |
| | Can the certificate be used for the server side |
| | of an SSL connection? |
| | |
|X509_PURPOSE_NS_SSL_SERVER | |
| | |
| | Can the cert be used for Netscape SSL server? |
| | |
| X509_PURPOSE_SMIME_SIGN | |
| | |
| | Can the cert be used to sign S/MIME email? |
| | |
|X509_PURPOSE_SMIME_ENCRYPT | |
| | |
| | Can the cert be used to encrypt S/MIME email? |
| | |
| X509_PURPOSE_CRL_SIGN | |
| | |
| | Can the cert be used to sign a certificate revo- |
| | cation list (CRL)? |
| | |
| X509_PURPOSE_ANY | |
| | |
| | Can the cert be used for Any/All purposes? |
| | |
+---------------------------+---------------------------------------------------+
These options are not bitfields - you may specify one only!
o $cainfo
-$cainfo should be an array of trusted CA files/dirs as described in Certificate Verification.
o $untrustedfile
- If specified, this should be the name of a PEM encoded file holding certificates that can be used to help verify the certifi-
cate, although no trust is placed in the certificates that come from that file.
RETURN VALUES
Returns TRUE if the certificate can be used for the intended purpose, FALSE if it cannot, or -1 on error.
PHP Documentation Group OPENSSL_X509_CHECKPURPOSE(3)