We have to consume a web service that needs authentication with digital certificate for External Data Service in Case Manager, and we are sending the SSL data according to the following configuration:
String sslAlias = null;
String host = “serviceUrl";
String port = "443";
HashMap<Object, Object> connectionInfo = new HashMap<>();
connectionInfo.put(JSSEHelper.CONNECTION_INFO_DIRECTION, JSSEHelper.DIRECTION_OUTBOUND);
connectionInfo.put(JSSEHelper.CONNECTION_INFO_REMOTE_HOST, host);
connectionInfo.put(JSSEHelper.CONNECTION_INFO_REMOTE_PORT, Integer.parseInt(port));
connectionInfo.put(JSSEHelper.CONNECTION_INFO_ENDPOINT_NAME, JSSEHelper.ENDPOINT_IIOP);
java.util.Properties props = jsseHelper.getProperties(sslAlias, connectionInfo, null);
props.put("com.ibm.ssl.trustStore", “pathTrustCertificate");
props.put("com.ibm.ssl.alias", “MyConfigSSL");
props.put("com.ibm.ssl.trustStorePassword", "password");
props.put("com.ibm.ssl.trustStoreName", “MyTrustStore");
props.put("com.ibm.ssl.trustStoreType", "jks");
props.put("com.ibm.ssl.keyStorePassword", “password");
props.put("com.ibm.ssl.keyStore", "/C:/certificate.pfx");
props.put("com.ibm.ssl.keyStoreName", “MyKeystore");
jsseHelper.setSSLPropertiesOnThread(props);
When we make the call this way, specifying a Keystore in a file, the system is able to establish the communication. The problem is that the costumer demands that we use the certificate installed on the server (Windows), which means we need to use the Windows repository to get the certificate, and, if we make the substitution, the application can no longer open the connection, returning the attached error when establishing the communication.
Configurations used for Windows Authentication:
props.put("com.ibm.ssl.keyStoreType", "Windows-MY");
props.put("com.ibm.ssl.keyStoreProvider", "IBMCAC");
props.put("com.ibm.ssl.keyStorePassword", “");
props.put("com.ibm.ssl.keyStore", "”);
We also tried to remove the properties com.ibm.ssl.keyStorePassword and com.ibm.ssl.keyStore, but by removing them, the Websphere uses the TrustStore as Keystore when communicating, that ends up resulting in the same error.
Questions:
What is the correct way to make websphere use the windows installed certificate to make the communication when the security team does not want to use the websphere installed certificate?
Is there a way to specify a dynamic SocketSSL, so it's possible to use the Windows installed keystore?
Configurations in my server:
Windows Server 2012 R2 Websphere Application Server 9.0
Thanks for helping!!