Introduction
Nowdays, it's common to setup SSL for communication between different internal micro-services. In order to setup it, various steps are required.
My concrete example was that I was trying to setup secure communication for Kafka cluster, so that brokers communicate over SSL and that clients also use SSL when communicating with kafka brokers.
Struggle
Usually, I would follow some tutorial steps just to get working example locally. But it can be hard to troubleshoot when it doesn't work. You don't know did you made mistake while generating root certificate or when creating keystore and truststore, or maybe something is wrong with your configuration.
Good thing is to read as much documentation before to try to understand what you are doing. And not just blindly follow some tutorial steps.
The thing is that it can be overwhelming to learn bunch of stuff all at once. Because you need to use various things: openssl, keytool, Kafka (or whatever else)
I've tried to search is there any existing tool or if keytool can be use directly to give it keystore, truststore and hostname and that result would be YES/NO if your those files are "compatible".
I know that there is possible to use
openssl s_client -connect my-host:my-port
But in order to use it you first need to spin up web server with your keystore.
Question
How to ensure that among all configuration you need to do, that keystore.jks and trustore.jks that you've generated will work properly for some of your hostname?
So, that you can rule-out them as problematic and focus on another things that might cause your system not working.
Update
Some comments suggest other approaches:
- use
opensslto start it withs_serverand start it withs_client- pros: likely more reliable, better debug output
- cons: if you only have
.jksfiles you need to usekeytoolto convert them to.p12
- use
Keystore explorerorkeytool -v -list ...to inspect contents- this is manual work and it's not clear what values need to match in order to guarantee that communication will actually work between (
serverhavingkeystore.jks) and (clienthavingtruststore.jks)
- this is manual work and it's not clear what values need to match in order to guarantee that communication will actually work between (