Show Some Love

Tomcat intermediate certificate `sec_error_unknown_issuer'

This forum was posted on Monday, May 20, 2013 2:13:11 AM

I hv a test scenario where a root certificate authority called Root signs a certificate signing request made by an intermediate certificate authority called Intermediate which in turn signs a certificate signing request made by a subject called Subject.
I use Tomcat as my webserver and I have configured it to use the Subject key store (which having the Root certificate the Intermediate certificate the Subject certificate chain and the Subject private key) and I start it to listen on the ports 80 (HTTP) and 443 (HTTPS).
I install the Root certificate (as a trusted certificate) in Firefox and I hit up my domain and this is what I get: uses an invalid security certificate.
The certificate is not trusted becoz no issuer chain was provided.
(Error code snippet: sec_error_unknown_issuer)

definitely Firefox could not confirm the believe of chain or something similar. Now before I go into details about my configuration and the steps that I took: I have Updated my Tomcat configuration so that it use the Intermediate key store Rather of using the Subject key store (the Intermediate key store having the Root certificate the Intermediate certificate chain and the Intermediate private key). Using this configuration everything works good.
I use the below tools:
Java: 1.7.0_05
Tomcat: 7.0.29
Firefox: 14.0.1
I generate the key stores in problem with the below script pasted over here (it is quite lengthy). someone with a Java keytool can execute it (it possibly will not be too speedy operation becoz of the 4096 RSA key size).
After the script runs I can confirm that my Subject key store having the complete chain of believe (as I see it):
c:\>keytool -list -keystore c:\subject.jks -storepass changeit -rfc

It prints out the below (again quite lengthy) o/p which is pasted over here. It appears OK to me (at least after hours of struggling I can not appear to start seeing anything wrong with it).
I set up Tomcat (below this how-to) via it is server.xml like this (I update nothing aside from this single tag which is by default commented-out).

(After I start up Tomcat connect to it - while it is using the Subject or the Intermediate key store - there're no errors logged.)
While searching for solutions I got that with openssl I can confirm my service as a novice member of the tool I ran the below command against my domain (using Cygwin):
$ openssl s_client -connect -CAfile /cygdrive/c/root.pem -showcerts &> /cygdrive/c/openssl.log

Yet again I have pasted the lengthy o/p over here.
It tells that confirm return code snippet: 24 (invalid CA certificate) which is wonder as it refers (as I see) to the Root certificate. Now when I have told I reconfigured Tomcat to use the Intermediate key store previously I have also execute this similar command and then it checked out with confirm return code snippet: 0 (ok). So I guest the Root certificate is OK.
The domain and sub-domain names I have mentioned thru the post and pastes are free domains registered at and every of them points to my current address (I thought I would mention it can be it matters).
Any solution what I am doing wrong?

143 Viewed this Question

 Recent Replies on "Tomcat intermediate certificate `sec_error_unknown_issuer'"

  • Nobody has replied on this post, be first to post answer.

Post Your Solution for this Question

Note: Please Put Code into <code></code> block.

Threads related to "Tomcat intermediate certificate `sec_error_unknown_issuer'":

How to use Servlets and Ajax?

I'm very new to web apps and Servlets and I hv the following issue:Whenever I print something inside the servlet and call it by the webbrowser it returns a new page containing that text. do you know approach to print the text in the current page using Ajax?

Handling events between classes

I hv a main class with an Editor class (with a JTextPane) and a Toolbar class (with a JList and a Jbutton I don't wish to use JToolBar). These two classes are composed by various components and i wish not to mix them into the similar class. i require the editor and the toolbar to communicate.Let's say I write "Hello" in the toolbar and then click on Submit. i require the text pane to show me "Hello".I make the classes this approach:public class Main{ public MainGUI(){ initCompon

does hibernate support partitioning?

I used Hibernate3 and Oracle database in my project and now i require to update my DB from oracle to Microsoft SQl Server.There is Partition Tables in oracle which is not available in Microsoft SQl Server.does anyone know if hibernate have a built-in support for table partitioning or not?It seems implementing such a functions in hibernate is not it a big problem.if There is no built-in table partitioning in hibernate can i manipulate my own table partitioning? -- any hint?

How to Set up and run Omniscient Debugger

I hv been trying to set up omniscient debugger and i can not appear to get it to work. hv placed the debugger.jar file in c:/Debugger ran jar xf debugger.jar Microsoft and run debug.bat from the Microsoft folder.i'm working with Win 7 64 bit with jdk1.7.0_05 and jre7 installed. I hv tried running it on a simple "Hello World" java program by selecting the class file The code snippet runs and i see the o/p but the debugger doesn't show anything. I hav

Java double input

I am trying to let the user freedom of entering a number at his own style like he can select to enter 2 or 2.00 but as you know the double can not accept this (2). i require the double to accept this with 2 decimal places only (generally I am representing money). this is what I am not sure How do I take the input and update that in to the 2decimals format. New to java.tksattempted google but can not find where i can format at the input itself means don't even let the user type any more de

Custom Service Builder Methods in Hooked JSP

i require to extend the members admin portlet that is located in the control panel. I hooked the jsp and wanted to use methods from the service builder that are in the similar hook as the jsp.The problem is that the jsp can not find the classes. So I copied the *-service.jar to the tomcat lib/ext folder and removed it from the hook when deploying it.But that doesn't work. After a while I get an exception that says Cache is not alive or this web application instance has been stopped already. do you know

Efficient scalable sequence generator implementation

problem :i require to manipulate multiple shared sequence generators that will be used by 50-100 Tomcat servers. each sequence generator should start with 1 and be incremented by one after each request. Sequence generator implementation should have atomic increment command.Java member should be available.Scale:Up to 50000 sequence generators actively used for each of them we expect one increment request in 5-10 seconds.Up to 20000 requests per second50-100 java clients(Tomcat servers). The access to

BufferReader readline() method hangs for

I am executing a simple java application in eclipse.Sample code snippet snippet: BufferedReader input = new BufferedReader( new InputStreamReader(; String line; while((line = input.readLine()) != null && line.length() != 0) { System.out.println("------"+line); }In the above code snippet snippet the readline() method hangs when reading the last line of my input.I hv gone through little threads and understood that it waits for the end of line.I don't wish to give any '' or '\r' at the end of my

SwingWorker updating multiple comboboxes in multilpe panels

I hv a little gui program that on startup reads data from an Excel file and little of these data require to go to the related comboboxes. I know How do I do this by using a separate SwingWorker for each combobox:public class ExcelReader extends SwingWorker { private final DefaultComboBoxModel model; // Constructor called from a panel that has a combobox public ExcelReader(DefaultComboBoxModel model) { this.model = model; } @Override protected DefaultComboBoxModel doInBackground() throws Excep

Why are half of my “word count” Hadoop Reducer output files 0 bytes when run on AWS/EMR?

I hv a set of data that is generally the Mapping o/p of a simple Word Count (text files w/ word & count pairs tab delimited) and i require to reduce it. there's about 160 GB of data compressed into bz2 files. When I run my job on Amazon Web Services Elastic Map Reduce (AWS EMR) I use 10 cc2.8xlarge slaves and an m1.xlarge as master. There ends up being 1200 map tasks and 54 reduce tasks. absolutely half of the reduce tasks finish instantly after the map tasks finish and the o/p of