Make plans now to attend XMPP integration with CVP 2012/06/14 @ 10:00 AM at Cisco Live! in San Diego. ...Read More

 



Cisco Developer Network will be presenting a CDN Developer Track at Cisco Live! London the week of January 31, 2011.

We are presenting technical sessions which highlight Application Programming interfaces (APIs) and Software Developer Kits (SDKs) for Cisco technologies such as Unified Communications, IOS, and Access Routing Technologies ¿ including the new Cisco Cius ...Read More

 

Recently noticed that there have been repeated questions from our developer community complaining that they can't seem to get the beep to work with <record>. They have set the beep attribute to "true" alright, and the reference guide even says this is supported but why doesn't it work?
...Read More

 

August 01, 2006
Earlier today, as I was typing a comment in our internal issuing-tracking system, I hit backspace to correct a typo. WHAM! I go back to the previous page, and my long-winded comment is gone. Apparently I somehow left the context of the text area (did I tab, or spuriously click, or??), which causes backspace to act as a hotkey for "Back". The web browser was not very forgiving of my mistake.

Are your IVR applications forgiving? They should be.
...Read More

 

Mark Gibbs over at Network World has put together a spiffy little scoring system for customer service systems (including many criteria for IVR systems). How would callers score your IVR using Mark's guidelines? Place a call and find out, you may be surprised.
...Read More

 

If you're using JNDI to connect to your database through Tomcat, then it's possible you've had to deal with database connection pool leaks. Your code tests fine, it's been reviewed, but in load tests or in production your app is unable to acquire database connections, the pool is empty!

Fear not, there are some handy parameters which can be set in your application's XML configuration file (in tomcat/conf/Catalina/YOUR_IP/YOUR_APP.xml):
...Read More

 

Showing 6 results.
Items per Page 50
of 1

CVP Forum

« Back to CVP - All Versions

Two step (mutual authentication) SSL - CVP/Tomcat - 403 response

Combination View Flat View Tree View
Threads [ Previous | Next ]
Hi everyone.
 
I'm in the process of helping our application developers figure out an issue.
 
In summary:
 
We have an application that lives on the vxml app server (tomcat).  This application is required to hit a webservice from a third party using https.  We are required to use SSL obvisouly and we are also required to present a .pfx (digitl certificate) when challenged.
 
We have the digital cert and all the certificate chains loaded up properly (at least I think we do).  I can do a list on the keystore and see my personal key entry and the cert chains.  A packet capture proves we get the SSL handshake started but when challenged for the cert I don't think tomcat knows what to do or which certificate to present to the third party.
 
This writes an error out in the STD out log in the Tomcat folder complaining about a 403 failure.  Which it's probably a 403.4 or 403.7 (SSL required) error.  I've loaded the certs up in the windows key store and can hit the same URL from the IE browser.  IE prompts me to select the cert I want to use when challenged and then SSL starts and I can see the data from the webservice.
 
So - is two step or mutual SSL even possible on CVP (tomcat) version 8.5.1(ES4)?  If so, is there any other way to debug SSL and figure out why tomcat can't or does not present the correct cert?
 
Thanks in advance,
 
Jason

What are the commands you used to import the security certs into tomcat. Did you import a .cer ?

What are the commands you used to import the security certs into tomcat. Did you import a .cer ?


 
Hi.
 
We were issued a .pfx file.  In that file is the private key, and the certificate chain.  We point our keytore to a specific keystore using the java options in the tomcat confing.
 
Here is the command I used to import the file:
 
keytool -importkeystore -srckeystore C:\mycert.pfx -srcstoretype PKCS12 -destkeystore C:\cvp.keystore

Everything seemed to work with the keytool.  I can do a list on the keystore and the private key entry is there.

Did you import the root certificate also. I do this all the time. I mainly work with .cer though I store it on cacerts. Can you make sure and check the certs using the command:
C:\Cisco\CVP\jre1.6\lib\security>C:\Cisco\CVP\jre1.6\bin\keytool -list -v -keyst
ore cacerts

replace it with your dir and keystore

Did you import the root certificate also. I do this all the time. I mainly work with .cer though I store it on cacerts. Can you make sure and check the certs using the command:
C:\Cisco\CVP\jre1.6\lib\security>C:\Cisco\CVP\jre1.6\bin\keytool -list -v -keyst
ore cacerts

replace it with your dir and keystore


Hi.
 
Yes, the list command shows all the certs and no issues.
 
I actually just got word back from Cisco TAC that mutual SSL is not even supported on tomcat/cvp 8.5(1) ES4 yet.  I'm not sure I buy that answer yet but I will keep digging.



Did you import the root certificate also. I do this all the time. I mainly work with .cer though I store it on cacerts. Can you make sure and check the certs using the command:
C:\Cisco\CVP\jre1.6\lib\security>C:\Cisco\CVP\jre1.6\bin\keytool -list -v -keyst
ore cacerts

replace it with your dir and keystore



Hi.
 
Yes, the list command shows all the certs and no issues.
 
I actually just got word back from Cisco TAC that mutual SSL is not even supported on tomcat/cvp 8.5(1) ES4 yet.  I'm not sure I buy that answer yet but I will keep digging.


Last update on this:
 
Turns out that CVP/TOMCAT will not do this internally but we were told it can be done from the application perspective with java.  Developers are still researching how to make that actually work. emoticon
 
If anyone has any code snippets I can send over that would be great.