Sponsored Content
Top Forums UNIX for Advanced & Expert Users List all certificates on a server Post 302965183 by sidh_arth85 on Monday 25th of January 2016 06:27:41 AM
Old 01-25-2016
Thanks Jim for your response.

I am using both Sun Solaris(5.10) and GNU Linux.

There are system certificates which are available in (/etc/pki/tls) but I need to find the certificates o websphere locations as well. If I will provide the absolute path of the websphere location, then I can find the file but its hard for me how to identifiy the certificate files alone.

If there is a way only to find the certificate files then could you please kindly let me know?

It may be with the extensions(.crt/.cer/.pem/.jks) and some of the files without extensions as well.

Thanks again

Regards
Sid
 

8 More Discussions You Might Find Interesting

1. Solaris

FTPS : FTP with certificates

Does anyone know of any products that support FTPS (FTP with SSL). Or does anyone out there run this now? any experiences? This is particularly to support the Cuncur expense system, I don tknow if anyone works with them at all, but they dont support sftp, just ftps. Thanks,!! (1 Reply)
Discussion started by: BG_JrAdmin
1 Replies

2. Cybersecurity

expiration of SSL Certificates

Does anyone know how to extract the expiration date of a Solaris 9 certificate? I have searched over the 'net and it seems this command ssl-cert-check comes up often but this does not work on my servers. Not sure how to extraxt the expiration dates of the SSL Certs so if anyone can help that would... (2 Replies)
Discussion started by: bluridge
2 Replies

3. UNIX for Dummies Questions & Answers

VSFTPD & SSL Certificates

Hello all :b: I need a little advice on securing my VSFTPD server. I currently have it setup and working using a self signed certificate by following instructions on the net and im happy with it to a certain extent. One of my clients is not... He said he cannot connect to the server unless... (1 Reply)
Discussion started by: mokachoka
1 Replies

4. AIX

Creation of SSL certificates

Can someone guide me as to how SSL certificates are created for a new AIX box? I am a novice to system administration. Thanks in advance Gayathri (1 Reply)
Discussion started by: ggayathri
1 Replies

5. UNIX for Dummies Questions & Answers

Generating server and client certificates

Hi, I am currently in the process of implementing port based authentication(802.1x) in my home network through radius(FreeRadius). I want all my clients to use a certificate for authenticating (eap-tls) However openssl's massive amount of configuration options has me a bit confused. And... (0 Replies)
Discussion started by: regexp
0 Replies

6. UNIX for Dummies Questions & Answers

Installing SSL certificates on Ubuntu Server 12.04

Hi everyone, I am working on a Nginx + Apache installation for learning purposes, and just got to the point of installing a self-signed certificate for securing some pages that will be used to send "sensitive" information such as login credentials. So far so good. What a I want to know is how can... (2 Replies)
Discussion started by: gacanepa
2 Replies

7. Red Hat

Installation of Certificates failing

Hi All, I have a few certificates that I need to install on my Apache server. The files are in /opt/keys/: # ls -ltrh total 36K -rw-r--r--. 1 root root 1.8K Apr 20 18:29 EntrustG2bridge.cer -rw-r--r--. 1 root root 1.7K Apr 20 18:29 wildcard.key -rw-r--r--. 1 root root 1.5K Apr 20... (1 Reply)
Discussion started by: Junaid Subhani
1 Replies

8. Shell Programming and Scripting

How to Find List of MQ and Websphere certificates that are installed on Linux and UNIX servers?

Dear All, I am planning to find the list of certificates(WEBshpere/MQ) on a servers. My certificates are either stored in (.jks) / (.pem)/ (.cer) . But some of the certificates are stored without these file formats. I tried using find command but unless I give the file name its difficult for... (4 Replies)
Discussion started by: sidh_arth85
4 Replies
SSL_CTX_load_verify_locations(3)				      OpenSSL					  SSL_CTX_load_verify_locations(3)

NAME
SSL_CTX_load_verify_locations - set default locations for trusted CA certificates SYNOPSIS
#include <openssl/ssl.h> int SSL_CTX_load_verify_locations(SSL_CTX *ctx, const char *CAfile, const char *CApath); DESCRIPTION
SSL_CTX_load_verify_locations() specifies the locations for ctx, at which CA certificates for verification purposes are located. The cer- tificates available via CAfile and CApath are trusted. NOTES
If CAfile is not NULL, it points to a file of CA certificates in PEM format. The file can contain several CA certificates identified by -----BEGIN CERTIFICATE----- ... (CA certificate in base64 encoding) ... -----END CERTIFICATE----- sequences. Before, between, and after the certificates text is allowed which can be used e.g. for descriptions of the certificates. The CAfile is processed on execution of the SSL_CTX_load_verify_locations() function. If CApath is not NULL, it points to a directory containing CA certificates in PEM format. The files each contain one CA certificate. The files are looked up by the CA subject name hash value, which must hence be available. If more than one CA certificate with the same name hash value exist, the extension must be different (e.g. 9d66eef0.0, 9d66eef0.1 etc). The search is performed in the ordering of the exten- sion number, regardless of other properties of the certificates. Use the c_rehash utility to create the necessary links. The certificates in CApath are only looked up when required, e.g. when building the certificate chain or when actually performing the veri- fication of a peer certificate. When looking up CA certificates, the OpenSSL library will first search the certificates in CAfile, then those in CApath. Certificate match- ing is done based on the subject name, the key identifier (if present), and the serial number as taken from the certificate to be verified. If these data do not match, the next certificate will be tried. If a first certificate matching the parameters is found, the verification process will be performed; no other certificates for the same parameters will be searched in case of failure. In server mode, when requesting a client certificate, the server must send the list of CAs of which it will accept client certificates. This list is not influenced by the contents of CAfile or CApath and must explicitly be set using the SSL_CTX_set_client_CA_list(3) family of functions. When building its own certificate chain, an OpenSSL client/server will try to fill in missing certificates from CAfile/CApath, if the cer- tificate chain was not explicitly specified (see SSL_CTX_add_extra_chain_cert(3), SSL_CTX_use_certificate(3). WARNINGS
If several CA certificates matching the name, key identifier, and serial number condition are available, only the first one will be exam- ined. This may lead to unexpected results if the same CA certificate is available with different expiration dates. If a "certificate expired" verification error occurs, no other certificate will be searched. Make sure to not have expired certificates mixed with valid ones. EXAMPLES
Generate a CA certificate file with descriptive text from the CA certificates ca1.pem ca2.pem ca3.pem: #!/bin/sh rm CAfile.pem for i in ca1.pem ca2.pem ca3.pem ; do openssl x509 -in $i -text >> CAfile.pem done Prepare the directory /some/where/certs containing several CA certificates for use as CApath: cd /some/where/certs c_rehash . RETURN VALUES
The following return values can occur: 0 The operation failed because CAfile and CApath are NULL or the processing at one of the locations specified failed. Check the error stack to find out the reason. 1 The operation succeeded. SEE ALSO
ssl(3), SSL_CTX_set_client_CA_list(3), SSL_get_client_CA_list(3), SSL_CTX_use_certificate(3), SSL_CTX_add_extra_chain_cert(3), SSL_CTX_set_cert_store(3) 0.9.7d 2002-12-01 SSL_CTX_load_verify_locations(3)
All times are GMT -4. The time now is 06:31 PM.
Unix & Linux Forums Content Copyright 1993-2022. All Rights Reserved.
Privacy Policy