<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: Configuring Tomcat SSL Client/Server Authentication</title>
	<atom:link href="http://www.maximporges.com/2009/11/18/configuring-tomcat-ssl-clientserver-authentication/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.maximporges.com/2009/11/18/configuring-tomcat-ssl-clientserver-authentication/</link>
	<description>Winning At Yelling</description>
	<lastBuildDate>Wed, 09 Nov 2011 16:13:16 -0800</lastBuildDate>
	<generator>http://wordpress.org/?v=2.8.4</generator>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
		<item>
		<title>By: Maxim Porges</title>
		<link>http://www.maximporges.com/2009/11/18/configuring-tomcat-ssl-clientserver-authentication/comment-page-1/#comment-836</link>
		<dc:creator>Maxim Porges</dc:creator>
		<pubDate>Mon, 05 Sep 2011 18:34:08 +0000</pubDate>
		<guid isPermaLink="false">http://www.maximporges.com/?p=415#comment-836</guid>
		<description>I don&#039;t see any reason why what you are saying couldn&#039;t be accomplished with the contents of this article. All you need to do is send the certificate to the client, make sure it&#039;s installed in the server, and the configuration as described will work.</description>
		<content:encoded><![CDATA[<p>I don&#8217;t see any reason why what you are saying couldn&#8217;t be accomplished with the contents of this article. All you need to do is send the certificate to the client, make sure it&#8217;s installed in the server, and the configuration as described will work.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Bibekananda Mishra</title>
		<link>http://www.maximporges.com/2009/11/18/configuring-tomcat-ssl-clientserver-authentication/comment-page-1/#comment-835</link>
		<dc:creator>Bibekananda Mishra</dc:creator>
		<pubDate>Sun, 04 Sep 2011 06:00:29 +0000</pubDate>
		<guid isPermaLink="false">http://www.maximporges.com/?p=415#comment-835</guid>
		<description>Hi,
 Thanks for your article.It really  help me a lot. It would be better if you can reply to my quires.

My requirement is : A client can access server resource if the certificate is installed in client trust stores. But this certificate has to be provided by the server to client explicitly .I mean by mail or any other medium.

I want the server resource can be accessed to whom with i hv shared the certificate.</description>
		<content:encoded><![CDATA[<p>Hi,<br />
 Thanks for your article.It really  help me a lot. It would be better if you can reply to my quires.</p>
<p>My requirement is : A client can access server resource if the certificate is installed in client trust stores. But this certificate has to be provided by the server to client explicitly .I mean by mail or any other medium.</p>
<p>I want the server resource can be accessed to whom with i hv shared the certificate.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Denise Blair</title>
		<link>http://www.maximporges.com/2009/11/18/configuring-tomcat-ssl-clientserver-authentication/comment-page-1/#comment-824</link>
		<dc:creator>Denise Blair</dc:creator>
		<pubDate>Thu, 11 Aug 2011 10:38:05 +0000</pubDate>
		<guid isPermaLink="false">http://www.maximporges.com/?p=415#comment-824</guid>
		<description>Very useful, thank you Maxim.</description>
		<content:encoded><![CDATA[<p>Very useful, thank you Maxim.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Sri</title>
		<link>http://www.maximporges.com/2009/11/18/configuring-tomcat-ssl-clientserver-authentication/comment-page-1/#comment-814</link>
		<dc:creator>Sri</dc:creator>
		<pubDate>Fri, 10 Jun 2011 15:34:04 +0000</pubDate>
		<guid isPermaLink="false">http://www.maximporges.com/?p=415#comment-814</guid>
		<description>The sample used old httpclient library 3.1 and does not work with current library. Related library that can be downloaded from archives at:
http://archive.apache.org/dist/httpcomponents/commons-httpclient/binary/?C=M;O=D</description>
		<content:encoded><![CDATA[<p>The sample used old httpclient library 3.1 and does not work with current library. Related library that can be downloaded from archives at:<br />
<a href="http://archive.apache.org/dist/httpcomponents/commons-httpclient/binary/?C=M;O=D" rel="nofollow">http://archive.apache.org/dist/httpcomponents/commons-httpclient/binary/?C=M;O=D</a></p>
]]></content:encoded>
	</item>
	<item>
		<title>By: horrabin</title>
		<link>http://www.maximporges.com/2009/11/18/configuring-tomcat-ssl-clientserver-authentication/comment-page-1/#comment-806</link>
		<dc:creator>horrabin</dc:creator>
		<pubDate>Fri, 20 May 2011 09:20:21 +0000</pubDate>
		<guid isPermaLink="false">http://www.maximporges.com/?p=415#comment-806</guid>
		<description>Excellent article. Clear and easy to understand. Works perfectly for me too.

Thanks!</description>
		<content:encoded><![CDATA[<p>Excellent article. Clear and easy to understand. Works perfectly for me too.</p>
<p>Thanks!</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Matabares</title>
		<link>http://www.maximporges.com/2009/11/18/configuring-tomcat-ssl-clientserver-authentication/comment-page-1/#comment-542</link>
		<dc:creator>Matabares</dc:creator>
		<pubDate>Tue, 30 Mar 2010 22:27:29 +0000</pubDate>
		<guid isPermaLink="false">http://www.maximporges.com/?p=415#comment-542</guid>
		<description>Thanks!!!!!! Excellent Post. Works for me.</description>
		<content:encoded><![CDATA[<p>Thanks!!!!!! Excellent Post. Works for me.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Maxim Porges</title>
		<link>http://www.maximporges.com/2009/11/18/configuring-tomcat-ssl-clientserver-authentication/comment-page-1/#comment-468</link>
		<dc:creator>Maxim Porges</dc:creator>
		<pubDate>Sun, 03 Jan 2010 05:50:04 +0000</pubDate>
		<guid isPermaLink="false">http://www.maximporges.com/?p=415#comment-468</guid>
		<description>Pankil,

Here are the answers to your questions to the best of my ability.

===&gt; how the server sends the client certificate to client side?
The server doesn&#039;t send the client certificate to the client side. When you configure a truststore, the Tomcat server expects the client to send a certificate to the server. You may get prompted for a client certificate explicitly, or the server may just respond with an error indicating that a certificate was not sent.

To configure a client to send a certificate, you have to follow specific instructions depending on the browser (or other user agent) you are using. There are a few examples at this URL - just Google for &quot;client certificate installation in [browser name]&quot; if you need help.

http://web.asu.edu/community/installing-client-certificate-windows-machine</description>
		<content:encoded><![CDATA[<p>Pankil,</p>
<p>Here are the answers to your questions to the best of my ability.</p>
<p>===&gt; how the server sends the client certificate to client side?<br />
The server doesn&#8217;t send the client certificate to the client side. When you configure a truststore, the Tomcat server expects the client to send a certificate to the server. You may get prompted for a client certificate explicitly, or the server may just respond with an error indicating that a certificate was not sent.</p>
<p>To configure a client to send a certificate, you have to follow specific instructions depending on the browser (or other user agent) you are using. There are a few examples at this URL &#8211; just Google for &#8220;client certificate installation in [browser name]&#8221; if you need help.</p>
<p><a href="http://web.asu.edu/community/installing-client-certificate-windows-machine" rel="nofollow">http://web.asu.edu/community/installing-client-certificate-windows-machine</a></p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Maxim Porges</title>
		<link>http://www.maximporges.com/2009/11/18/configuring-tomcat-ssl-clientserver-authentication/comment-page-1/#comment-467</link>
		<dc:creator>Maxim Porges</dc:creator>
		<pubDate>Sun, 03 Jan 2010 05:45:11 +0000</pubDate>
		<guid isPermaLink="false">http://www.maximporges.com/?p=415#comment-467</guid>
		<description>Thanks Peter, glad you liked it.

To your point, I expect that both the truststore and keystore must be present to enable the appropriate SSL handshaking to take place. I&#039;ve only ever configured keystore by itself (for server-only auth for SSL connections) and both truststore and keystore (for client/server auth) - never truststore only.</description>
		<content:encoded><![CDATA[<p>Thanks Peter, glad you liked it.</p>
<p>To your point, I expect that both the truststore and keystore must be present to enable the appropriate SSL handshaking to take place. I&#8217;ve only ever configured keystore by itself (for server-only auth for SSL connections) and both truststore and keystore (for client/server auth) &#8211; never truststore only.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Peter Mularien</title>
		<link>http://www.maximporges.com/2009/11/18/configuring-tomcat-ssl-clientserver-authentication/comment-page-1/#comment-466</link>
		<dc:creator>Peter Mularien</dc:creator>
		<pubDate>Sat, 02 Jan 2010 21:56:17 +0000</pubDate>
		<guid isPermaLink="false">http://www.maximporges.com/?p=415#comment-466</guid>
		<description>Thank you for the great tutorial - it&#039;s the best write-up of an often confused topic I&#039;ve seen online. One thing that you may want to note is that it is mandatory to configure both the truststore and the keystore, otherwise Tomcat will not consider a certificate, even if everything is otherwise correctly configured.</description>
		<content:encoded><![CDATA[<p>Thank you for the great tutorial &#8211; it&#8217;s the best write-up of an often confused topic I&#8217;ve seen online. One thing that you may want to note is that it is mandatory to configure both the truststore and the keystore, otherwise Tomcat will not consider a certificate, even if everything is otherwise correctly configured.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Pankil</title>
		<link>http://www.maximporges.com/2009/11/18/configuring-tomcat-ssl-clientserver-authentication/comment-page-1/#comment-458</link>
		<dc:creator>Pankil</dc:creator>
		<pubDate>Fri, 18 Dec 2009 11:02:14 +0000</pubDate>
		<guid isPermaLink="false">http://www.maximporges.com/?p=415#comment-458</guid>
		<description>good post,
thanx but when client requests server page, at that time when client trust servers certificate, server certificate installed on client side.....its happening in my pcs...

please give me some help

thnax in advance</description>
		<content:encoded><![CDATA[<p>good post,<br />
thanx but when client requests server page, at that time when client trust servers certificate, server certificate installed on client side&#8230;..its happening in my pcs&#8230;</p>
<p>please give me some help</p>
<p>thnax in advance</p>
]]></content:encoded>
	</item>
</channel>
</rss>

