java - How to integrate 'Bouncy Castle' in JBoss 4 -
i use jboss 4.4 (java 6) , know how integrate/enable tlsv1.2 it. tried add:
security.provider.1=org.bouncycastle.jce.provider.bouncycastleprovider
into java.security under java/jre/lib/security/ still have handshake_failure
.
caused by: javax.net.ssl.sslhandshakeexception: received fatal alert: handshake_failure @ com.sun.net.ssl.internal.ssl.alerts.getsslexception(alerts.java:174) @ com.sun.net.ssl.internal.ssl.alerts.getsslexception(alerts.java:136) @ com.sun.net.ssl.internal.ssl.sslsocketimpl.recvalert(sslsocketimpl.java:1822) @ com.sun.net.ssl.internal.ssl.sslsocketimpl.readrecord(sslsocketimpl.java:1004) @ com.sun.net.ssl.internal.ssl.sslsocketimpl.performinitialhandshake(sslsocketimpl.java:1188) @ com.sun.net.ssl.internal.ssl.sslsocketimpl.starthandshake(sslsocketimpl.java:1215) @ com.sun.net.ssl.internal.ssl.sslsocketimpl.starthandshake(sslsocketimpl.java:1199) @ sun.net.www.protocol.https.httpsclient.afterconnect(httpsclient.java:476) @ sun.net.www.protocol.https.abstractdelegatehttpsurlconnection.connect(abstractdelegatehttpsurlconnection.java:166) @ sun.net.www.protocol.http.httpurlconnection.getinputstream(httpurlconnection.java:1195) @ java.net.httpurlconnection.getresponsecode(httpurlconnection.java:379) @ sun.net.www.protocol.https.httpsurlconnectionimpl.getresponsecode(httpsurlconnectionimpl.java:318) @ com.paypal.core.httpconnection.execute(httpconnection.java:99) @ com.paypal.core.apiservice.makerequest(apiservice.java:140) @ com.paypal.core.baseservice.call(baseservice.java:149) @ urn.ebay.api.paypalapi.paypalapiinterfaceserviceservice.setexpresscheckout(paypalapiinterfaceserviceservice.java:1415) @ urn.ebay.api.paypalapi.paypalapiinterfaceserviceservice.setexpresscheckout(paypalapiinterfaceserviceservice.java:1445)
thanks in advance.
this not possible. java 6/jdk 6 not support tls 1.2
. if recall correctly jboss 4.x never tested jdk7.
you should disable sslv3 due known vulnerability poodle.
you need upgrade jboss eap 6.4 if have red hat subscription or wildfly 9.0.2 tls 1.2 support , should use jdk8. after can configure trust store , keys in ssl subsystem explained in other post.
hope helps.
Comments
Post a Comment