目錄
首先要生成一個keystore證書。參考:Tomcat創(chuàng)建HTTPS訪問,java訪問https,ssl證書生成:cer&jks文件生成摘錄,spring-boot
這里復(fù)現(xiàn)一下完整過程:
安裝好java后,cmd就可以使用keytool了。
生成ssl證書:
C:\Users\miaorf>keytool -genkey -alias tomcatjks -keyalg RSA -keystore d:\tomcat.jks輸入密鑰庫口令:再次輸入新口令:您的名字與姓氏是什么? [Unknown]: ryan miao您的組織單位名稱是什么? [Unknown]: com.test您的組織名稱是什么? [Unknown]: com.test您所在的城市或區(qū)域名稱是什么? [Unknown]: sz您所在的省/市/自治區(qū)名稱是什么? [Unknown]: gd該單位的雙字母國家/地區(qū)代碼是什么? [Unknown]: cnCN=ryan miao, OU=com.test, O=com.test, L=sz, ST=gd, C=cn是否正確? [否]: y輸入 <tomcatjks> 的密鑰口令 (如果和密鑰庫口令相同, 按回車):
查看證書:
C:\Users\miaorf>keytool -list -v -keystore d:\tomcat.jks輸入密鑰庫口令:密鑰庫類型: JKS密鑰庫提供方: SUN您的密鑰庫包含 1 個條目別名: tomcatjks創(chuàng)建日期: 2016-9-5條目類型: PrivateKeyEntry證書鏈長度: 1證書[1]:所有者: CN=ryan miao, OU=com.test, O=com.test, L=sz, ST=gd, C=cn發(fā)布者: CN=ryan miao, OU=com.test, O=com.test, L=sz, ST=gd, C=cn序列號: 32d82f57有效期開始日期: Mon Sep 05 21:27:52 CST 2016, 截止日期: Sun Dec 04 21:27:52 CST 2016證書指紋: MD5: E6:03:5E:97:78:A5:F8:A4:DA:69:00:45:48:41:64:6E SHA1: 34:A7:16:80:34:69:B6:5E:35:83:1E:B6:61:1A:87:C6:99:13:1B:BD SHA256: CC:1E:E1:99:B1:EA:B6:67:F1:53:A5:11:63:4A:31:53:8D:36:2C:15:59:0E:E6:D6:35:22:E5:C4:48:B6:AC:82 簽名算法名稱: SHA256withRSA 版本: 3擴展:#1: ObjectId: 2.5.29.14 Criticality=falseSubjectKeyIdentifier [KeyIdentifier [0000: BC 2B C1 06 8C AC 5B 6D 38 BB 51 36 BA C5 9E CB .+....[m8.Q6....0010: 53 EE 28 49 S.(I]]**************************************************************************************
缺省情況下,-list 命令打印證書的 MD5 指紋。而如果指定了 -v 選項,將以可讀格式打印證書,如果指定了 -rfc 選項,將以可打印的編碼格式輸出證書。
C:\Users\miaorf>keytool -list -rfc -keystore d:\tomcat.jks輸入密鑰庫口令:密鑰庫類型: JKS密鑰庫提供方: SUN您的密鑰庫包含 1 個條目別名: tomcatjks創(chuàng)建日期: 2016-9-5條目類型: PrivateKeyEntry證書鏈長度: 1證書[1]:-----BEGIN CERTIFICATE-----MIIDYTCCAkmgAwIBAgIEMtgvVzANBgkqhkiG9w0BAQsFADBhMQswCQYDVQQGEwJjbjELMAkGA1UECBMCZ2QxCzAJBgNVBAcTAnN6MREwDwYDVQQKEwhjb20udGVzdDERMA8GA1UECxMIY29tLnRlc3QxEjAQBgNVBAMTCXJ5YW4gbWlhbzAeFw0xNjA5MDUxMzI3NTJaFw0xNjEyMDQxMzI3NTJaMGExCzAJBgNVBAYTAmNuMQswCQYDVQQIEwJnZDELMAkGA1UEBxMCc3oxETAPBgNVBAoTCGNvbS50ZXN0MREwDwYDVQQLEwhjb20udGVzdDESMBAGA1UEAxMJcnlhbiBtaWFvMIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAoorikcrv8WedDYA4LvmnXTRRtanHtsSKJXlv/NLgcVYwsBncb63qnCPgDbHpFXO2X/qg84ogneMHTu41cLzFAUsdym9aRCHnSLk1gO0ohJoNPOlYBqit4dbdF+T/dEwh5foq6JivUGPx2hc+TI4QnLrRDe1TS9ftGRStHNMJVBXm7A1gpbHLPRrC01V0uCn4SK5BQ+/P0SfClJUM7uOI7HgJKG276o3XXLUM2S5BJrAJz2iJmnIJBuwqaQXKdrWIlRXPNIVNmKSjGr/MhcnhrKWIbvNe4tlyahFQP61Rl08eqxtRmrLyWNHG22mzJ7FP4pWE8wiKH678iVGQJrGjDQIDAQABoyEwHzAdBgNVHQ4EFgQUvCvBBoysW204u1E2usWey1PuKEkwDQYJKoZIhvcNAQELBQADggEBAAjzv65Np0ju1y/fWQBR2l0+VuLN8NTaR3WciKqnerYTXGOB1///nVpJhmVvBYwim9MNuN8aG3GmQD1O8e9NJZ5fR4KIWrrtPRGHNQQEMVVOLKzTt80AGGqVcpHuSdjB0yBQPSCXhYHOiTI8bpSjW5rVRFNh1obRe0ohnbB1PZaz1U5t3Cjo8ESOa3jp/3QP81o8iL9+eJnwjcK+iD3n1F7i7izeBuOxfybEv47ZGVDkNRcKmzHWizQ66nhtGLU/nYuZzLErvQAmuzT6Boh+m8O5yMtxw4WParrTtD0dIG8wE15/I6nwPqPh9kGzs85vFTccta+Z9jm7V4rCr2JAKVs=-----END CERTIFICATE-----**************************************************************************************
將tomcat.jks復(fù)制到classpath下。并且配置application.yml:
server.port = 8443server.ssl.key-store = classpath:tomcat.jksserver.ssl.key-store-password = secretserver.ssl.key-password = password
啟動:
gradlew bootRun,
最終打印信息:
2016-09-05 21:54:05.003 INFO 6080 --- [ restartedMain] s.b.c.e.t.TomcatEmbeddedServletContainer : Tomcat started on port(s): 8443 (https)2016-09-05 21:54:05.008 DEBUG 6080 --- [ restartedMain] o.s.w.c.s.StandardServletEnvironment : Adding [server.ports] PropertySource with highest search precedence2016-09-05 21:54:05.019 INFO 6080 --- [ restartedMain] c.r.b.config.ApplicationContextConfig : Started ApplicationContextConfig in 17.621 seconds (JVM running for 21.676)
瀏覽器訪問:
https://localhost:8443/
關(guān)注我的公眾號