SSL/TLS Certificates and Weblogic
Let us learn about SSL/TLS and how it applies to Weblogic and Fusion Middleware.
1) What is SSL/TLS?
Transport Layer Secuity (TLS) and Secure Socket Layer (SSL) are cryptographic protocols used to securely communicate over a computer network. SSL was deprecated in 2014 after finding a vulnerability.
TLS became new standard for secured http. TLS 1.3 is latest TLS version.
2) Why SSL/TLS?
It is easy to intercept and read data transmitted in plain text over a network. Obviously we don’t like bank details, email or personal information fall in wrong hands. TLS protects from this by encrypting data between client and server.
3) How TLS works?
TLS uses public key infrastructure to encrypt data exchange. TLS handshake at high level:
i) Agree on version of TLS to use.
ii) Agree on Cipher suites to use.
iii) Validate identity of the server using server certificate by client. In case of two way ssl, server validates identity to client too.
iv) Generate symmetric keys for encryption of data being exchanged. Both client and servers will use symmetric keys at this stage as both need to understand data being exchanges. But it is still secured as no other person knows these session keys apart from client and server.
4) What are the public and private keys?
Asymmetric key infrastructure uses public and private keys for encrypting data exchange between client and server. As you know, public is used to encrypt the data and private key is used to decrypt it. Public key is widely shared as part of certificate but private key should be safely secured as anyone with access to private key can decrypt the traffic.
5) What is a certificate?
The certificate is a container for the public key. It includes the public key, the server name, some extra information about the server, and a signature computed by a certification authority (CA).
6) What is Certificate Authority (CA)?
It is an entity that issues digital certificates. It acts as a trusted third party – trusted by owner of the certificate (mostly server) and one who relies on it (mostly client). Some of the clients like browsers and java are shipped with widely well known trusted root CA certificates DigiCert, Entrust etc. If we trust a CA but it is not part of trusted CAs, we need to import them to trust store.
7) What are intermediate certificates?
Intermediate CAs are subordinate for root CAs. Root CAs use intermediate CAs for securing root CA keys. So, mostly certificates are issues by intermediate CAs.
8) What is the certificate chain?
As mentioned above mostly certificates (not always) issues by intermediate CAs. But clients only trust root CA. So, clients will not be able to trust server. So comes the concept of certificate chain. If a certificate is issued by intermediate CA, server sends its intermediate certificates along with its certificate. Then, client tries to establish a link between the intermediate certificates and one of the trusted root certificates. If it can establish chain of trust by linking intermediate certs with root CA, identity of the server is accepted. It is not uncommon to have more than one intermediate certificate in a chain.
9) What is two-way SSL?
Most of the applications use one-way SSL. That is clients check authenticity of the server what it claims to be. For highly sensitive applications, servers also check identity of client. Clients have to provide their certificate to prove their identity and server checks if it is valid certificate. This is called two-way SSL.
10) What are different certificate formats?
X.509 is the standard for defining the format of public key certificates. There are several file extensions for X.509 certificates. Usually these are used for certificates and public keys. But some are used for private keys as well. Some of the formats are:
DER (Distinguished Encoding Rules) encodes certificate in binary form. Not routinely used by much outside of Windows.
PEM can have a variety of extensions (.pem, .key, .cer, .cert etc). It can be thought of as a binary version of the base64-encoded DER file. When you look at the contents of the file, it is enclosed between “—–BEGIN CERTIFICATE—–” and “—–END CERTIFICATE—–”
DER file can be used only for a single certificate, while a .pemfile can be used for multiple certificates. The order is important (include the files in the order of trust). The server digital certificate should be the first digital certificate in the file, followed by intermediate certificates and finally root certificate.
PKCS12 It provides enhanced security versus the plain-text PEM format. This can contain private key material. It can be freely converted to PEM format using openssl.
.pfx file is similar to PKCS#12.
11) What are keystores?
Keystores can be viewed as secured repository for storing private keys and trusted certificates. Even though both can be stored in a single keystore, It is better to use separate keystores for trust and private keys. These are called trust and identity stores respectively. We could provide more protection for your private keys if you store them in a keystore with restricted access.
Keystores can also be classified based on how they are stored on disk.
jks – Java Key Store – Used in Java based application.
kss – Weblogic specific db based keystore. It is default keystore from weblogic 12c onwards.
12) How can certificate be imported to jks store?
keytool that is provided with JDK can be used to import certificates into jks stores. Here are few expamples:
To import certificate:
keytool -import -alias <alias> -file <cert location> -keystore <keystore location> -storepass <store password>
keytool -import -alias demoCert -file mycert.cer -keystore Trust.jks -storepass mypassword
To list certificates in a keystore:
keytool -list -v -keystore <keystoreLocation>
To import private key entry with different alias (friendly name) from source:
keytool -importkeystore -srckeystore <source_keystoreFile> -srcstoretype PKCS12 -destkeystore <destination_keystoreFile> -deststoretype JKS -srcstorepass mysecret -deststorepass mysecret -srcalias myalias -destalias myalias -srckeypass mykeypass -destkeypass mykeypass -nopromp
13) How to manage ohs wallets?
orapki which is based on C language can used to manage OHS wallets.
14) What openSSL tool?
openSSL is open source library that can be used to generate keys, generating Certificate Signing Request (CSR), viewing certificate information and may other uses. Let us see some uses with examples:
To display certificates of an url:
openssl s_client -showcerts -connect www.example.com:443 </dev/null 2>/dev/null | openssl x509 -outform PEM >mycertfile.pem
To extract only keys without certificates:
openssl pkcs12 -in myfile.p12 -nodes -nocerts -out privateKey.pem
15) How SSL can be configured in weblogic?
FMW 12c offers support for different types of keystore: Java KeyStores (JKS) or the OPSS Keystore Service (KSS). JKS can be used in both standalone WebLogic domains, and also those FMW domains that have Fusion Middleware Control. KSS can only be used with WebLogic if using Fusion Middleware Control as OPSS relies on EM/Oracle JRF templates applied to the WebLogic domain.
Keystore tab in weblogic is used to specify the keystore locations. SSL tab specifies the private key alias name and required password.
16) How to debug java/weblogic SSL problems?
Couple of debug parameters can be enabled to troubleshoot ssl related issues. Modify EXTRA_JAVA_PROPERTIES in setDomainEnv.cmd to include the following parameters.
-Dssl.debug=true -Dweblogic.StdoutDebugEnabled=true -Dweblogic.security.SSL.verbose=true -Djavax.net.debug=all
References:
Comments
Post a Comment