Showing posts with label certificate. Show all posts
Showing posts with label certificate. Show all posts

Monday, July 9, 2018

Kibana container to elasticsearch cloud auth err

Leave a Comment

I have a production instance of elasticsearch 5.6.9 deployed on elastic.cloud.

WIth an http elastic all is OK but I would run a localhost kibana connected to that https instance!

I have tried:

docker run --name kibana-prod-user       -e ELASTICSEARCH_URL=https://####.eu-west-1.aws.found.io:9243       -e ELASTICSEARCH_PASSWORD=####       -v /host/workspace/cert:/usr/share/elasticsearch/config/certificates       -p 3501:5601 --b kibana 

but i get:

auth err

In my mount dir I have put the cert.cer of elastic cloud.

Any ideas?

Thank you very much

1 Answers

Answers 1

I have find the solution, after understand that the error wasn't a certificate problem.

The right script for kibana 5.6.10 is:

docker run --name kibana-prod-provider -v "$(pwd)":/etc/kibana/ -p 3502:5601 --rm kibana 

because the ELASTICSEARCH_PASSWORD envvar is not managed by the docker file, only le URL is.

Then in the $(pwd) directory I have put this kibana.yml file:

server.host: '0' elasticsearch.url: 'https://###.eu-west-1.aws.found.io:9243' elasticsearch.username: elastic elasticsearch.password: ### 
Read More

Saturday, December 23, 2017

Accessing Gmail (or a secure website) without getting a PKIX certification path error

Leave a Comment

Sending an e-mail via gmail resulted in getting a PKIX certification path error. The same applied to sending an e-mail from Tomcat.

After solving the issue, I hope you find this post useful. This post provides you with a step by step diagnosis for these kinds of errors.

Step 1: I tried to solve the problem using this post and another post, but that did not help me. In most cases this will be sufficient. You can use the keytool to list the certificates via 'keytool -list -keystore "%JAVA_HOME%/jre/lib/security/cacerts"'

I added the certificate by clicking the lock-icon of the gmail URL and exporting/importing the certificate to the cacert file of my used JDK version. I could see with keytool -list that the certificate was added. This process is described well in the (linked) posts.

Step 2A: Was I using the right truststore? I added the JVM arguments to direct the certificate search, like -Djavax.net.ssl.trustStore="..../jre/lib/security/cacerts" -Djavax.net.ssl.trustStorePassword="changeit".

Step 2B: When I change the value of the cacerts file to cacertsXYZ I get the error. So, this proofed that the 'cacert' was used.

Caused by: javax.mail.MessagingException: Can't send command to SMTP host; nested exception is: javax.net.ssl.SSLException: java.lang.RuntimeException: Unexpected error: java.security.InvalidAlgorithmParameterException: the trustAnchors parameter must be non-empty

Step 2C: Was this also the case for my Tomcat webserver? I verified that in the cacerts of my JRE_HOME that the certificate was there. In Tomcat my JRE_HOME is "C:\Program Files\Java\jdk1.8.0_144\jre". My JAVA_HOME = C:\Program Files\Java\jdk1.8.0_144.

Step 3: I tried with publicly available 'SSLPoke' Java class to see whether I could connect with Google and or smtp.gmail.com. The results are in the listing: I could connect with SSL to google.com AND mail.google.com via port 443.

try {             SSLSocketFactory sslsocketfactory = (SSLSocketFactory) SSLSocketFactory.getDefault();             // **Fail** TLS - SSLSocket sslsocket = (SSLSocket) sslsocketfactory.createSocket("smtp.gmail.com", 587);             // **Fail** SSL - SSLSocket sslsocket = (SSLSocket) sslsocketfactory.createSocket("smtp.gmail.com", 465);             // **OK**             SSLSocket sslsocket = (SSLSocket) sslsocketfactory.createSocket("google.com", 443);             // OK             SSLSocket sslsocket2 = (SSLSocket) sslsocketfactory.createSocket("mail.google.com", 443);              InputStream in = sslsocket.getInputStream();             OutputStream out = sslsocket.getOutputStream();             out.write(1); // write test byte to get reaction.             while (in.available() > 0) {                 System.out.print(in.read());             }             System.out.println("Successfully connected");         } catch (Exception exception) {             exception.printStackTrace();         } 

Step 4: The trusted store could be corrupt? I installed a newer version of the JDK1.8 being v152. I restarted the application without any success. Had this to do with the difference between JDK and JRE? Only the JRE has a lib\security\cacerts file. I tried both the SSL (465) and TLS (587) ports. Nope.

Step 5: Running openssl (with s_client -connect smtp.gmail.com:587 -starttls smtp) showed that my virus scanner (Avast) was prohibiting the sending of secure mail. So, for a moment I disabled this email-shield. That gave the following error:

java.lang.RuntimeException: javax.mail.AuthenticationFailedException

Step 6: After releasing the virusscanner web shield, using the openssl gave the following error: CN = Google Internet Authority G3 verify error:num=20:unable to get local issuer certificate.

OpenSSL> s_client -connect smtp.gmail.com:587 -starttls smtp CONNECTED(00000280) depth=1 C = US, O = Google Trust Services, CN = Google Internet Authority G3 verify error:num=20:unable to get local issuer certificate ....

Allowing the 'gmail account to be accessable from weakly authenticated apps', a setting in your google account, that finally yielded in correctly sending the e-mail. This is the link to the security settings of your Google account.

Step 7: Sending e-mail from another server may be a problem. Authentication errors are (still) the result. To overcome these errors, you can do:

Notice: The mkyong example is the base of my simple test application.

1 Answers

Answers 1

Finally I found the answer.

1 - Of course the google/gmail certifcates were ok ;-) Step 1 was performing these kinds of checks. Trying to add the certificate CA by hand, etc. See above.

2 - Step 2 was checking whether the known 'SSLPoke' Java class Java class could get contact with the secure website.

3 - After checking all above checks, executing 'openssl' showed that my virus scanner email-shield blocked the traffic. Stopping this defence for some time was step 3.

4 - Then I got the 'not authenticated' error from Gmail. Allowing the 'gmail account accessable from weakly authenticated apps', that finally gave a correctly sent e-mail. This is an Google account security setting

Read More

Monday, November 20, 2017

In SSL/TLS communication with IIS, Certificate Request does not contain my client cert

Leave a Comment

One of my clients java/Cold Fusion application is trying to access my WCF web service endpoint using client certificate mutual authentication. We moved our wcf service to windows 2008 R2/IIS 7 machine and generated new certificate using 3rd party CA. After the change, client is getting 403.13 error. On investigation, I found that the Certificate Request does not include the new certificate in the distinguished names list. How can I configure IIS to include the client certificate in the trusted certificate list? enter image description here

1 Answers

Answers 1

You can't add trusted certificates, it's done on machine level. If you open MMC and add the certificate plugin you should be able to add it to the Trusted Root Certification Authorities on the server.

Read More

Thursday, October 12, 2017

Intercepting proxy's certificates generated on-the-fly provoke browser errors

Leave a Comment

I've written an intercepting proxy in Python 3 which uses a man-in-the-middle "attack" technique to be able to inspect and modify pages coming through it on the fly. Part of the process of "installing" or setting up the proxy involves generating a "root" certificate which is to be installed in the browser and every time a new domain is hit via HTTPS through the proxy, the proxy generates a new site certificate on-the-fly (and caches all certificates generated to disk so it doesn't have to re-generate certificates for domains for which certificates have already been generated) signed by the root certificate and uses the site certificate to communicate with the browser. (And, of course, the proxy forges its own HTTPS connection to the remote server. The proxy also checks the validity of the server certificate if you're curious.)

Well, it works great with the browser surf. (And, this might be relevant -- as of a few versions back, at least, surf didn't check/enforce certificate validity. I can't attest to whether that's the case for more recent versions.) But, Firefox gives a SEC_ERROR_REUSED_ISSUER_AND_SERIAL error on the second (and all later) HTTPS request(s) made through the proxy and Chromium (I haven't tested with Chrome proper) gives NET::ERR_CERT_COMMON_NAME_INVALID on every HTTPS request. These obviously present a major problem when trying to browse through my intercepting proxy.

The SSL library I'm using is pyOpenSSL 0.14 if that makes any difference.

Regarding Firefox's SEC_ERROR_REUSED_ISSUER_AND_SERIAL error, I'm pretty sure I'm not reusing serial numbers. (If anybody wants to check my work, that would be pretty rad: cert.py - note the "crt.set_serial_number(getrandbits(20 * 8))" on line 168.) The root certificate issuer of course doesn't change, but that wouldn't be expected to change, right? I'm not sure what exactly is meant by "issuer" in the error message if not the root certificate issuer.

Also, Firefox's "view certificate" dialog displays completely different serial numbers for different certificates generated by the proxy. (As an example, I've got one generated for www.google.com with a serial number of 00:BF:7D:34:35:15:83:3A:6E:9B:59:49:A8:CC:88:01:BA:BE:23:A7:AD and another generated for www.reddit.com with a serial number of 78:51:04:48:4B:BC:E3:96:47:AC:DA:D4:50:EF:2B:21:88:99:AC:8C .) So, I'm not really sure what Firefox is complaining about exactly.

My proxy reuses the private key (and thus public key/modulus) for all certificates it creates on the fly. I came to suspect this was what Firefox was balking about and tried changing the code to generate a new key pair for every certificate the proxy creates on the fly. That didn't solve the problem in Firefox. I still get the same error message. I have yet to test whether it solves the Chromium issue.

Regarding Chromium's NET::ERR_CERT_COMMON_NAME_INVALID error, the common name for site certificate is just supposed to be the domain, right? I shouldn't be including a port number or anything, right? (Again, if anybody would like to check my work, see cert.py .) If it helps any, my intercepting proxy isn't using any wildcards in the certificate common names or anything. Every certificate generated is for one specific fqdn.

I'm quite certain making this work without making Firefox or Chrome (or Chromium or IE etc) balk is possible. A company I used to work for purchased and set up a man-in-them-middling proxy through which all traffic from within the corporate network to the internet had to pass. The PC administrators at said company installed a self-signed certificate as a certificate authority in every browser on every company-owned computer used by the employees and the result never produced any errors like the ones Firefox and Chromium have been giving me for the certificates my own intercepting proxy software produces. It's possible the PC administrators tweaked some about:config settings in Firefox to make this all work or something, but I kindof doubt it.

To be fair, the proxy used at this company was either network or transport layer, not application layer like mine. But I'd expect the same can be accomplished in an application-layer HTTP(s) proxy.

Edit: I've tried setting the subjectAltName as suggested by brain99. Following is the line I added in the location brain99 suggested:

r.add_extensions([crypto.X509Extension(b"subjectAltName", False, b"DNS:" + cn.encode("UTF-8"))])

I'm still getting SEC_ERROR_REUSED_ISSUER_AND_SERIAL from Firefox (on the second and subsequent HTTPS requests and I'm getting ERR_SSL_SERVER_CERT_BAD_FORMAT from Chromium.

Here are a couple of certificates generated by the proxy:

google.com: https://pastebin.com/YNr4zfZu

stackoverflow.com: https://pastebin.com/veT8sXZ4

1 Answers

Answers 1

I noticed you only set the CN in your X509Req. Both Chrome and Firefox require the subjectAltName extension to be present; see for example this Chrome help page or this Mozilla wiki page discussing CA required or recommended practices. To quote from the Mozilla wiki:

Some CAs mistakenly believe that one primary DNS name should go into the Subject Common Name and all the others into the SAN.

According to the CA/Browser Forum Baseline Requirements:

  • BR #9.2.1 (section 7.1.4.2.1 in BR version 1.3), Subject Alternative Name Extension
    • Required/Optional: Required
    • Contents: This extension MUST contain at least one entry. Each entry MUST be either a dNSName containing the Fully-Qualified Domain Name or an iPAddress containing the IP address of a server.

You should be able to do this easily with pyOpenSSL:

if not os.path.exists(path):     r = crypto.X509Req()     r.get_subject().CN = cn     r.add_extensions([crypto.X509Extension("subjectAltName", False, "DNS:" + cn])     r.set_pubkey(key)     r.sign(key, "sha1") 

If this does not solve the issue, or if it only partially solves it, please post one or two example certificates that exhibit the problem.


Aside from this, I also noticed you sign using SHA1. Note that certificates signed with SHA1 have been deprecated in several major browsers, so I would suggest switching to SHA-256.

r.sign(key, "sha256") 
Read More

Thursday, March 16, 2017

Maven fails to transfer one of many artifacts on same repo

Leave a Comment

I'm trying to create an archetype from an existing project using mvn archetype:create-from-project but I'm getting

Could not transfer artifact org.apache.maven.archetype:archetype-packaging:pom:3.0.0  from/to central (https://repo.maven.apache.org/maven2): sun.security.validator.ValidatorException: PKIX path building failed: sun.security.provider.certpath.SunCertPathBuilderException:  unable to find valid certification path to requested target 

I am behind a firewall so I followed this post http://stackoverflow.com/a/25912982/358794 and then executed:

$ mvn archetype:create-from-project -Djavax.net.ssl.keyStore=trustCARoot.jks  -Djavax.net.ssl.keyStorePassword=password    -Djavax.net.ssl.keyStoreType=JKS  -Djavax.net.ssl.trustStore=trustCARoot.jks    -Djavax.net.ssl.trustStorePassword=password    -Djavax.net.ssl.trustStoreType=JKS 

I still get the same PKIX path build failure but just for archetype-packaging

[INFO] Setting default groupId: com.domain.rozycki [INFO] Setting default artifactId: SkillsApp [INFO] Setting default version: 0.0.1-SNAPSHOT [INFO] Setting default package: com.domain.skillsapp [INFO] Scanning for projects... [INFO] Downloading: https://repo.maven.apache.org/maven2/org/apache/maven/archetype/archetype-packaging/3.0.0/archetype-packaging-3.0.0.pom [ERROR] [ERROR] Some problems were encountered while processing the POMs: [ERROR] Unresolveable build extension: Plugin org.apache.maven.archetype:archetype-packaging:3.0.0 or one of its dependencies could not be resolved: Failed to read artifact descriptor for org.apache.m aven.archetype:archetype-packaging:jar:3.0.0 @ [ERROR] Unknown packaging: maven-archetype @ line 8, column 14  @ [ERROR] The build could not read 1 project -> [Help 1] [ERROR] [ERROR]   The project com.gdeb.rozycki:SkillsApp-archetype:0.0.1-SNAPSHOT (C:\Users\jrozycki\Development\Archetype\SkillsApp\target\generated-sources\archetype\pom.xml) has 2 errors [ERROR]     Unresolveable build extension: Plugin org.apache.maven.archetype:archetype-packaging:3.0.0 or one of its dependencies could not be resolved: Failed to read artifact descriptor for org.apac he.maven.archetype:archetype-packaging:jar:3.0.0: Could not transfer artifact org.apache.maven.archetype:archetype-packaging:pom:3.0.0 from/to central (https://repo.maven.apache.org/maven2): sun.secur ity.validator.ValidatorException: PKIX path building failed: sun.security.provider.certpath.SunCertPathBuilderException: unable to find valid certification path to requested target -> [Help 2] [ERROR]     Unknown packaging: maven-archetype @ line 8, column 14 [ERROR] [INFO] ------------------------------------------------------------------------ [INFO] BUILD FAILURE [INFO] ------------------------------------------------------------------------ 

enter image description here

If I clear a dependency as a test of setting up my trustStore, mv archetype-catalog archetype-catalog_backup and rerun it does connect to the repo and redownloads archetype-catalog but still gets hung up on archetype-packaging

Downloading: https://repo.maven.apache.org/maven2/org/apache/maven/archetype/archetype-catalog/3.0.0/archetype-catalog-3.0.0.pom Downloaded: https://repo.maven.apache.org/maven2/org/apache/maven/archetype/archetype-catalog/3.0.0/archetype-catalog-3.0.0.pom (2 KB at 2.5 KB/sec) Downloading: https://repo.maven.apache.org/maven2/org/apache/maven/archetype/archetype-catalog/3.0.0/archetype-catalog-3.0.0.jar Downloaded: https://repo.maven.apache.org/maven2/org/apache/maven/archetype/archetype-catalog/3.0.0/archetype-catalog-3.0.0.jar (19 KB at 70.1 KB/sec) [INFO] Setting default groupId: com.domain.rozycki [INFO] Setting default artifactId: SkillsApp [INFO] Setting default version: 0.0.1-SNAPSHOT [INFO] Setting default package: com.domain.skillsapp [INFO] Scanning for projects... [INFO] Downloading: https://repo.maven.apache.org/maven2/org/apache/maven/archetype/archetype-packaging/3.0.0/archetype-packaging-3.0.0.pom [ERROR] [ERROR] Some problems were encountered while processing the POMs: [ERROR] Unresolveable build extension: Plugin org.apache.maven.archetype:archetype-packaging:3.0.0 or one of its dependencies could not be resolved: Failed to read artifact descriptor for org.apache.m aven.archetype:archetype-packaging:jar:3.0.0 @ [ERROR] Unknown packaging: maven-archetype @ line 8, column 14  @ [ERROR] The build could not read 1 project -> [Help 1] [ERROR] [ERROR]   The project com.gdeb.rozycki:SkillsApp-archetype:0.0.1-SNAPSHOT (C:\Users\jrozycki\Development\Archetype\SkillsApp\target\generated-sources\archetype\pom.xml) has 2 errors [ERROR]     Unresolveable build extension: Plugin org.apache.maven.archetype:archetype-packaging:3.0.0 or one of its dependencies could not be resolved: Failed to read artifact descriptor for org.apac he.maven.archetype:archetype-packaging:jar:3.0.0: Could not transfer artifact org.apache.maven.archetype:archetype-packaging:pom:3.0.0 from/to central (https://repo.maven.apache.org/maven2): sun.secur ity.validator.ValidatorException: PKIX path building failed: sun.security.provider.certpath.SunCertPathBuilderException: unable to find valid certification path to requested target -> [Help 2] [ERROR]     Unknown packaging: maven-archetype @ line 8, column 14 [ERROR] [INFO] ------------------------------------------------------------------------ [INFO] BUILD FAILURE [INFO] ------------------------------------------------------------------------ 

Trying to download just archetype-packaging yields the same error

mvn org.apache.maven.plugins:maven-dependency-plugin:2.1:get \     -DrepoUrl=https://repo.maven.apache.org/maven2 \     -Dartifact=org.apache.maven.archetype:archetype-packaging:3.0.0     -Djavax.net.ssl.keyStore=trustCARoot.jks -Djavax.net.ssl.keyStorePassword=password -Djavax.net.ssl.keyStoreType=JKS  -Djavax.net.ssl.trustStore=trustCARoot.jks  -Djavax.net.ssl.trustStorePassword=password -Djavax.net.ssl.trustStoreType=JKS 

Any ideas on how to get a BUILD SUCCESS? I'm able to right click on each file in the browser and save into the local repository but when I try to execute goal mvn archetype:create-from-project maven still tries to download the archetype-packaging

1 Answers

Answers 1

The answer provided here, adding the new maven repository in my settings.xml finally solved the issue Problems using Maven and SSL behind proxy

Earlier, I kept focusing on trying to generate the cert and including it in my trustStore but that never solved the issue.

I still needed to specify my proxy in the settings.xml as well

Read More

Thursday, April 21, 2016

Apple developer - Invalid CSR, Invalid Certificate

Leave a Comment

I generate .certSigningRequest file via Keychain Access (Keychain Access -> Certificate Assistant -> Request a Certificate From a Certificate Authority..., I fill in my mail and I save it to disk).

When I log into Apple developer account and try to generate Certificate with it I get message: "Invalid CSR - Invalid Certificate"

enter image description here

What is reason for this? Why this message appears, what could be wrong?

I've seen several StackOverflow questions like this: iPhone Developer Portal won't accept my CSR and I haven't found solution:

  • I tried downloading WWDR certificate
  • I'm using Safari (but button works)
  • there is only one developer certificate on account...

2 Answers

Answers 1

Try to delete an apple WWDR(World Wide Developer Relation) certificate expiring on February 14, 2016 from your keychain (if you got one on your system), this can be found in the login tab. Then download the updated CSR from apple, can be found here- https://developer.apple.com/support/certificates/expiration/ Restart xCode and you will be able to regenerate a CSR normaly, deleting this expired certificate made tons of bugs in the developers tools, I hope this will help you.

Answers 2

The command below should print the contents of the Certificate Signing Request

openssl req -in certSigningRequest -text 

If the command is not able to decode the CSR it means it was not properly generated. You might want to inspect the file with a text editor to tr to find clues about why the CSR generation failed

Read More

Wednesday, March 16, 2016

How to embed a keystore certificate only during runtime from classpath?

Leave a Comment

I have an application that should connect to a https webservice.

The webservice offers a zip file containing the following 3 files: *.crt, *.csr, *.key

Question: can I place them into the classpath of the application jar, and then load the cert only on startup (maybe in an own keystore/truststore that is is created on the fly)?

Or do I necessairly have to intall them into the java keystore on each machine, before I can use the my app client?

My preferred way would be to not having install them to the local java keystore, but load them on the fly during application startup.

1 Answers

Answers 1

I found it's actually possible, also from classpath:

//pass a p12 or pfx file (file may be on classpath also) public void initSSL(String keyStoreFile, String pass) {         InputStream keyStoreStream = this.getClass().getClassLoader().getResourceAsStream(keyStoreFile);                        KeyManagerFactory kmf = KeyManagerFactory.getInstance(KeyManagerFactory.getDefaultAlgorithm());             KeyStore keyStore = KeyStore.getInstance("PKCS12");              keyStore.load(keyStoreStream, keyPassword.toCharArray());             kmf.init(keyStore, keyPassword.toCharArray());               KeyStore trustStore = KeyStore.getInstance(KeyStore.getDefaultType());             trustStore.load(null, null);              // init the trust manager factory by read certificates             TrustManagerFactory tmf = TrustManagerFactory.getInstance(TrustManagerFactory.getDefaultAlgorithm());             tmf.init(trustStore);              // 3. init the SSLContext using kmf and tmf above             SSLContext sslContext = SSLContext.getInstance("TLS");             sslContext.init(kmf.getKeyManagers(), tmf.getTrustManagers(), null);             SSLContext.setDefault(sslContext); } 
Read More