How to use a .pem SSL certificate for REST API developed as Spring Boot application

Viewed 13390

We have a Spring Boot application for REST web services which is still under development. And we are using self signed certificate for now.

Now, it will be deployed into a system along with 1 more already developed application. This pre-existing application uses self signed certificate by default but gives client an option to upload CA certificates if they want. Now, we want to use the same certificate for this new application.

Basically, we want the client to use 1 certificate for 2 application running in 1 system.

Now, this existing application has certificate files like .pem and .cer.
How can I use this certificate in my Spring Boot application which uses certificate in the format of jks?

And off course, in case of any update, the certificate should be available to both of the applications.

3 Answers

PEM is a well-known file format when it comes to certificates. Except when it comes to Java. As Java does only use JKS (its Java-only, binary Keystore) or PKCS12 for keys and certificates. So we have to convert PEM encoded certificates to JKS or PKCS12 so that Java can consume that. But that may be ugly in a lot of situations.

you can use below dependency in your spring-boot application.

<dependency>
  <groupId>de.dentrassi.crypto</groupId>
  <artifactId>pem-keystore</artifactId>
  <version>2.0.0</version>
</dependency>

then add

KeyStore keyStore = KeyStore.getInstance("PEM");

for more info

https://github.com/ctron/pem-keystore

application.properties

 server.ssl.enabled=true
 server.ssl.key-store=/path/to/keystore.properties
 server.ssl.key-store-type=PEMCFG
 server.ssl.key-store-password=dummy
 server.ssl.key-alias=keycert

And then you create the file keystore.properties:

alias=keycert
source.cert=/etc/…/fullchain.pem
source.key=/etc/…/privkey.pem

As of Spring Boot 2.7 it's possible to use PEM-encoded certificate and private key files.
See the below example.

server:
  port: 8443
  ssl:
    certificate: "classpath:my-cert.crt"
    certificate-private-key: "classpath:my-cert.key"
    trust-certificate: "classpath:ca-cert.crt"
    key-store-password: "secret"

You can omit key-store-password if the private key is not password-protected.

for testing secured API you can use Fiddler a tool for bypassing or faking the SSL.

(OR)

you can configure application properties like below.

server.port: 8443
security.require-ssl=true
server.ssl.key-store:/etc/letsencrypt/live/seeld.eu/keystore.p12
server.ssl.key-store-password: <your-password>
server.ssl.keyStoreType: PKCS12
server.ssl.keyAlias: tomcat
Related