Skip to main content

By clicking Submit, you agree to the developerWorks terms of use.

The first time you sign into developerWorks, a profile is created for you. Select information in your developerWorks profile is displayed to the public, but you may edit the information at any time. Your first name, last name (unless you choose to hide them), and display name will accompany the content that you post.

All information submitted is secure.

  • Close [x]

The first time you sign in to developerWorks, a profile is created for you, so you need to choose a display name. Your display name accompanies the content you post on developerworks.

Please choose a display name between 3-31 characters. Your display name must be unique in the developerWorks community and should not be your email address for privacy reasons.

By clicking Submit, you agree to the developerWorks terms of use.

All information submitted is secure.

  • Close [x]

Boost the security of your Apache Geronimo applications with SSL and HTTPS

Configure Geronimo optimally with SSL and protect your data

Duane O'Brien, Java Developer, 自由职业者
Duane O'Brien has been a technological Swiss Army knife since the Oregon Trail was text only. His favorite color is sushi. He has never been to the moon.

Summary:  You can't get very far into Web application development without discovering the need for varying levels of security. And when it's time to pass around sensitive or private data, you need to look at encrypting that data. Using Secure Sockets Layer (SSL) to secure your applications is an excellent first step toward protecting your data. This tutorial helps you navigate the tricky waters of application-to-application encryption. Learn how to configure Apache Geronimo -- both version 1.0 and 1.1 -- with SSL and test the SSL with the Geronimo Hello World application.

Date:  29 Aug 2006
Level:  Intermediate PDF:  A4 and Letter (1488 KB | 31 pages)Get Adobe® Reader®

Activity:  8501 views
Comments:  

Before you start

This tutorial is for Java™ developers who want to use SSL to secure their applications on Apache Geronimo. You'll focus on the configuration of Geronimo with a brief example of how to access an SSL session ID within a basic application (the Hello World application from the Geronimo documentation is used as an example). You'll learn how to create keystores and private keys using the Geronimo Server Console and how to configure a new Hypertext Transfer Protocol Secure (HTTPS) listener within Geronimo using your new keystore.

About this tutorial

Apache Geronimo is the Java 2 Platform, Enterprise Edition (J2EE) server project of the Apache Software Foundation (ASF). The aim of the project is to produce a large and healthy community of J2EE developers tasked with the development of an open source, certified J2EE server that:

  • Is licensed under the Apache License.
  • Passes Sun's Technology Compatibility Kit (TCK) for J2EE 1.4.
  • Reuses the best ASF/BSD licensed code available today, with new ASF code to complete the J2EE stack.

HTTPS is the first tier of security, because it works directly with the browser at the application layer. The browser encrypts the data using SSL certificates and sends the request; the hosting server decrypts the data using keys. This application-to-application encryption is highly secure, but getting it to work takes a little know-how.

This tutorial configures Geronimo with SSL and tests the SSL with the Geronimo Hello World application using sessions with security controlled via SSL.


Prerequisites

This tutorial assumes:

  • You have not done any keystore configuration.
  • You have successfully built and deployed the Hello World sample application provided in the Apache Geronimo 1.0 or 1.1 documentation.

System requirements

You need to have Apache Geronimo 1.0 or 1.1 installed, configured, and successfully started on your local machine.

1 of 8 | Next

Comments



Help: Update or add to My dW interests

What's this?

This little timesaver lets you update your My developerWorks profile with just one click! The general subject of this content (AIX and UNIX, Information Management, Lotus, Rational, Tivoli, WebSphere, Java, Linux, Open source, SOA and Web services, Web development, or XML) will be added to the interests section of your profile, if it's not there already. You only need to be logged in to My developerWorks.

And what's the point of adding your interests to your profile? That's how you find other users with the same interests as yours, and see what they're reading and contributing to the community. Your interests also help us recommend relevant developerWorks content to you.

View your My developerWorks profile

Return from help

Help: Remove from My dW interests

What's this?

Removing this interest does not alter your profile, but rather removes this piece of content from a list of all content for which you've indicated interest. In a future enhancement to My developerWorks, you'll be able to see a record of that content.

View your My developerWorks profile

Return from help

static.content.url=http://www.ibm.com/developerworks/js/artrating/
SITE_ID=1
Zone=Open source, Java technology
ArticleID=156330
TutorialTitle=Boost the security of your Apache Geronimo applications with SSL and HTTPS
publish-date=08292006
author1-email=d@duaneobrien.com
author1-email-cc=ruterbo@us.ibm.com

Tags

Help
Use the search field to find all types of content in My developerWorks with that tag.

Use the slider bar to see more or fewer tags.

Popular tags shows the top tags for this particular content zone (for example, Java technology, Linux, WebSphere).

My tags shows your tags for this particular content zone (for example, Java technology, Linux, WebSphere).

Use the search field to find all types of content in My developerWorks with that tag. Popular tags shows the top tags for this particular content zone (for example, Java technology, Linux, WebSphere). My tags shows your tags for this particular content zone (for example, Java technology, Linux, WebSphere).

Try IBM PureSystems. No charge.