Showing posts with label Java. Show all posts
Showing posts with label Java. Show all posts

Wednesday, July 29, 2015

Using GoDaddy Certificate to Sign Your Oracle EBS Jar Files

GoDaddy provide the cheapest Jar-signing certificate that they also give different bargain / discount off the shelf price actively ( I get their discount spam mail everyday).  However if you ask their support about how to do the jar signing, they are absolute clueless.  Okay. That's why their price is low.

Here are the steps of signing the jar files:

(1) Download KeyStore Explorer (KSE), install, and make sure it runs well.  You will use this excellent software throughout the steps

(2) Before creating you private key, check the $APPL_TOP/admin/adsign.txt file.  It should look like

[sid]_[hostname] 1 CUST

Use KSE to open the $APPL_TOP/admin/adkeystore.dat.  The keystore password is "puneet".  This is the default keystore password used by Oracle.  Every time you open/modify this keystore file, you need this password to continue.


(3) Generate the private key pair

Oracle told you the command is "adjkey -initialize -keysize 2048 -alias mycompany"
But you can run this instead:
keytool -keystore adkeystore.dat -genkey -alias mycompany -keyalg RSA -keysize 2048

- You're supposed to use your company name for mycompany.  Use lower case characters for alias name. 
- Use "myxuan" for certificate password.  Oracle uses this default password for certificates.

Enter keystore password: puneet
What is your first and last name?
  [Unknown]:
What is the name of your organizational unit?
  [Unknown]:  Happy Valley
What is the name of your organization?
  [Unknown]:  Happy Valley
What is the name of your City or Locality?
  [Unknown]:  Toronto
What is the name of your State or Province?
  [Unknown]:  Ontario
What is the two-letter country code for this unit?
  [Unknown]:  CA
Is CN=Unknown, OU=Happy Valley, O=Happy Valley, L=Toronto, ST=Ontario, C=CA correct?
  [no]:  Yes

Enter key password for myxuan
        (RETURN if same as keystore password):
Re-enter new password: myxuan

Use KSE to open the adkeystore.dat file, you will see the new entry you just created:


(3) Generate CSR

keytool -sigalg SHA256withRSA -certreq -keystore adkeystore.dat -file mycompany.csr -alias mycompany

Enter keystore password: puneet
Enter key password for myxuan

A new file mycompany.csr is created.  You can use KSE to open up this CSR file to see the details.

(4) Paid money to GoDaddy  (through web site, or you can call / email their salesrep, if you have corporate account or you need quotation / paper work / invoice / bargain / discount etc).  Finally they will give you a ZIP file.  It contains one file with SPC extension.

(5)  Add signed certificate to keystore

keytool -keystore adkeystore.dat -import -trustcacerts -alias mycompany -file godaddy.spc

Enter keystore password: puneet
Enter key password for myxuan
Certificate reply was installed in keystore

Use KSE to open adkeystore.dat again. This time you will see the signed certificate and it's chain:



(6) Optional: In KSE, delete the default private key with alias [SID]_[hostname].   Change the alias name of the GoDaddy-signed certificate if needed. 

(7) Put this alias name (mycompany or whatever you have) to adsign.txt

mycompany 1 CUST

(8) Run adadmin to force regenerate all jar file.

(9) Bounce Apache and Form Servers.  BINGO.  


Sunday, November 3, 2013

Get Rid of Applet Security Warning when Using Self-Signed Certificate in EBS (Part III)

In Part II I'd provided the solution for all the possible warning message and you will see if you uses a self-signed certificate for Applet Jar signing.  In this blog I discuss how to do mass deployment of such solution to hundred of employees in you company.

The ultimate solution is to add your in-house CA root certificate to User Signer CA, and add the certificate for jar signing to User Trusted Certificate. The relationship between added certificate and physical file is shown below.


Assumption:
In the client machine --
In-house CA Certificate File = C:\certs\cacert.pem (this is the same file as C:\OpenSSL\CA\private\cacert.pem)
Certificate for jar signing = C:\cert\adkeystore.der (this is the same file as in $APPL_TOP/admin)
The JRE is installed using all default installation settings, and no extra tweaking has been done on top of it.

(1) Set a local variable for keystore location:
set KEYSTORE_LOC=%USERPROFILE%\AppData\LocalLow\Sun\Java\Deploymenr\security

(2) Add in-house CA Certificate to User Signer CA:
keytool -import -alias symplik_ca -file C:\certs\cacert.pem -file -keystore %KEYSTORE_LOC%\trusted.cacerts -storepass "" -noprompt

(3) Add certificate for jar-signing to User Trusted Certificate:
keytool -import -alias ebs12appltop -file C:\certs\adkeystore.der-file -keystore %KEYSTORE_LOC%\trusted.certs -storepass "" -noprompt

Show whether it is really added:
keytool -list -keystore %KEYSTORE_LOC%\trusted.certs -storepass ""
ebs12appltop, Nov 1, 2013, trustedCertEntry,
Certificate fingerprint (SHA1): 6B:28:5C:28:A6:D1:5A:32:EE:E7:47:37:DB:B1:EB:BB:8C:4D:46:AD

(4) Turn off the certificate revocation check, and launch the form, and accept the warning.

Do a list of certificate of the keystore trusted.certs and you will find the original alias has changed:
keytool -list -keystore %KEYSTORE_LOC%\trusted.certs -storepass ""
deploymentusercert$tsflag$loc=http//papaya.symplik.com:8020java.util.random@19b0d0, Nov 1, 2013, trustedCertEntry,
Certificate fingerprint (SHA1): 6B:28:5C:28:A6:D1:5A:32:EE:E7:47:37:DB:B1:EB:BB:8C:4D:46:AD

Turn the certificate revocation check in Java Control Panel on again.

So, the key to make the User-Trusted Certificate not being checked for revocation is to use a connect ALIAS NAME, in a format of:

deploymentusercert$tsflag$loc=[url]:[port]

I found out the last part (java.util.random@xxxx) is not really needed.

What it means is that instead of using an arbitrary alias name in step (3), you need to to use a proper alias name to import this certificate:
keytool -import -alias "deploymentusercert$tsflag$loc=http//papaya.symplik.com:8020" 
-keystore %KEYSTORE_LOC%\trusted.certs -storepass "" noprompt


So, to do the mass deployment of self-signed certificate to client machines, you can:
- Replace the files trusted.cacerts and trusted.certs in employees desktop, as you prepared in step (2) and (4), or
- Prepare a batch file to run the keytool commands, which fetch the certificate files from somewhere from the corporate LAN.  This method will able to preserve any certificates added in client JRE before this deployment.









Saturday, November 2, 2013

Get Rid of Applet Security Warning when Using Self-Signed Certificate in EBS (Part II)


If your EBS 11i or R12 environment does not have patch 17309237 applied, you will see this warning when you start any Forms:
Reason: JAR file manifest does not contain the Permission attribute.

You check the box of "I accept the risk..." and click Run, you could see the error "FRM-92095: Oracle JInitiator version too low. Please install version 1.1.8.2 or higher"

Reason: You need to patch your IAS to version 10.1.2.3 (through patch 5983622), and patch 14825718 for numerous bug fixes -- which requires OPatch 1.0.0.0.63 or higher, and OUI must be 10.1.
So you probably need to apply 6640838 (to Oracle Home 10.1.2) which upgrade OUI to 10.1, and then unzip patch 6880880_10100_[OS].zip to this Oracle Home directory.

A quick workaround is to change the java.vendor system property value back to it's original owner: Sun Microsystems Inc.  This property value has changed to "Oracle Corporation" since JRE 7.

To achieve this change, you can open the Java Control Panel -> Java -> View -> User Tab
Add a Runtime Parameter: -Djava.vendor="Sun Microsystems Inc."


Or even simpler way is to add a system variable JAVA_TOOL_OPTIONS and the value is
-Djava.vendor="Sun Microsystems Inc."



After you'd apply the patch 17309237 and using self-signed certificate, you will see another warning:
Reason: UNKNOWN Publisher, i.e. The JRE does not know the CA which signed these JAR files.

You can continue to work if you check the "I accept..." box, but this warning will show up EVERY TIME when you start the form.

Obtain the cacert.pem file (in-house CA root certificate) from C:\OpenSSL\CA and import it to your desktop JRE under Certificate type "Signer CA":

Start the Form again you will see the warning but the content is slightly different:
Reason: The Publisher is recognized, but the JRE cannot find out whether this certificate has been revoked or not (through Certificate Revocation list CRL or Online Certificate Status Protocol OCSP).  

Again,. you can continue to work if you check the "I accept..." box, but this warning will show up EVERY TIME when you start the form.

Change the JRE setting to stop checking certificate revocation

Start the Form again, and finally you get a "one-click-away-everything-done' warning:


After the Form is opened successfully, you can go back to the Java control panel, and you will see that this certificate has been added to Trust Certificate.  It is done automatically when you check the "Do not show this again..." warning message dialog box.


Finally, you can set the Certificate Revocation security settings back to the originally values:

If you open the Form again, no more warning will be shown even you set the checking back.  Hurray !!

Get Rid of Applet Security Warning when Using Self-Signed Certificate in EBS (Part I)

Since the outbreak of Java Applet security issue around January 2013, this fiasco ended in October that Oracle finally provided a stable and acceptable JRE version (according to those Mozilla developers) to make those security experts feel happy, and now it is Java SE 7u45.

In short, the changes make the Java Applet more difficult to run malicious code by giving never-ending stop signs and warnings if the Jar files are not properly signed.  In light of these changes, Oracle released the long-waiting patch 17191279 to resolve this issue, as mentioned in Metalink doc 1591073.1 "Enhanced Jar Signing for Oracle E-Business Suite".

If your company is willing to pay the ransom to Verisign, Thawte or other Certificate Authorities, those security warning will be gone smoothly.  However, if you plan to use self-signed certificate, please follow this blog and I'll go through a step-by-step approach to settle this, without paying a dime to these CAs.

All the steps are tested in the environment of Oracle EBS R12.1.x  under Windows OS.  If you're using Unix/Linux environment, the steps are essentially the same.  These steps can also be applied to 11i environment.

Part I - Apply patch 17191279
This patch requires you to run the adgrants.sql script (follows the readme file in the patch) before patching. If you encounter error in one of the AD worker and the process hangs in the middle, you can:
-   open SQL*Plus, connect as APPS, run the SQL
  create context AD_JAR using AD_JAR;
- run adctrl to restart the failed worker.

Part II - Setup your own CA
(1) Download OpenSSL 0.9.8h for Windows from Sourceforge, and unzip it under C:\OpenSSL. Even though it is independent of Oracle EBS stuff, I recommend that you put it in APPLTOP server.

(2) Open a Command Prompt
C:\> cd OpenSSL
C:\OpenSSL> mkdir CA
C:\OpenSSL> copy share\openssl.cnf CA\openssl.conf
C:\OpenSSL> cd CA
C:\OpenSSL> mkdir certs
C:\OpenSSL> mkdir crl
C:\OpenSSL> mkdir newcerts
C:\OpenSSL> mkdir private
C:\OpenSSL\CA>set PATH=C:\OpenSSL\bin;%PATH%
C:\OpenSSL\CA>set OPENSSL_CONF=c:\OpenSSL\CA\openssl.conf
C:\OpenSSL\CA>echo off
echo >index.txt
echo 01>serial
echo on
C:\OpenSSL\CA>
DO NOT close this command prompt....

(3) Edit C:\OpenSSL\CA\openssl.conf

Change the dir property to what we set in our environment
[ CA_default ]
dir = ./demoCA # Where everything is kept
certs = $dir/certs # Where the issued certs are kept

[ CA_default ]
dir = C:\\OpenSSL\\CA # Where everything is kept
certs = $dir/certs # Where the issued certs are kept

Change the policy to allow signing all certificates 
# For the CA policy
[ policy_match ]
countryName = match
stateOrProvinceName = match
organizationName = match
organizationalUnitName = optional
commonName = supplied
emailAddress = optional

# For the CA policy
[ policy_match ]
countryName = optional
stateOrProvinceName = optional
organizationName = optional
organizationalUnitName = optional
commonName = optional
emailAddress = optional

Go back to the command prompt in step (2)...

(4)  Create your own Certificate Authority
C:\OpenSSL\CA>openssl genrsa -des3 -out private\cakey.pem 4096
Loading 'screen' into random state - done
Generating RSA private key, 4096 bit long modulus
.............................................................++
.............................................++
e is 65537 (0x10001)
Enter pass phrase for server.key: (password)
Verifying - Enter pass phrase for server.key: (password)

C:\OpenSSL\CA>openssl req -new -x509 -days 3650 -key private\cakey.pem -out cacert.pem -config openssl.conf
Enter pass phrase for cakey.pem:
Loading 'screen' into random state - done
You are about to be asked to enter information that will be incorporated
into your certificate request.
What you are about to enter is what is called a Distinguished Name or a DN.
There are quite a few fields but you can leave some blank
For some fields there will be a default value,
If you enter '.', the field will be left blank.
-----
Country Name (2 letter code) []:CA
State or Province Name (full name) []:Ontario
Locality Name (eg, city) []:Toronto
Organization Name (eg, company) []:SYMPLiK Technologies
Organizational Unit Name (eg, section) []:Information Technology
Common Name (eg, your websiteÆs domain name) []: SYMPLiK Certificate Authority
Email Address []:

You can check the content of this certificate file by
C:\OpenSSL\CA>openssl x509 -noout -text -in cacert.pem

(5) Add CA certificate to JRE in APPL_TOP
First, find out where is the JRE datastore located in APPL_TOP:
echo $OA_JRE_TOP\lib\security\cacerts
c:\oracle\apps\tech_st\10.1.3\appsutil\jdk\jre\lib\security\cacerts

Copy file CA certificate to APPL_TOP (if different locations), and add this CA certificate to keystore:
C:\OpenSSL\CA>c:\oracle\apps\tech_st\10.1.3\appsutil\jdk\jre\bin\keytool.exe ^
-import -alias symplik -file cacert.pem -trustcacerts -v -keystore ^
c:\oracle\apps\tech_st\10.1.3\appsutil\jdk\jre\lib\security\cacerts
Enter keystore password: (changeit)
Owner: OU=Information Technology, O=SYMPLiK Technologies, L=Toronto ST=Ontario, C=CA
Issuer: OU=Information Technology O=SYMPLiK Technologies, L=v, ST=Ontario, C=CA
Serial number: c7d2e988a015eb6a
Valid from: Wed Oct 30 11:02:26 CST 2013 until: Sat Oct 28 11:02:26 CST 2023
Certificate fingerprints:
         MD5:  AF:26:AE:7A:9D:68:89:06:E8:90:30:6E:EE:6A:EC:62
         SHA1: 22:66:25:B1:AA:1C:C7:EA:01:BF:4C:EB:F6:04:80:BE:0D:6A:1B:86
         Signature algorithm name: SHA1withRSA
         Version: 1
Trust this certificate? [no]:  yes
Certificate was added to keystore
[Storing c:\oracle\apps\tech_st\10.1.3\appsutil\jdk\jre\lib\security\cacerts]

Double check whether this key alias has been added:
C:\OpenSSL\CA>c:\oracle\apps\tech_st\10.1.3\appsutil\jdk\jre\bin\keytool.exe \
-list -keystore \
c:\oracle\apps\tech_st\10.1.3\appsutil\jdk\jre\lib\security\cacerts 
....
symplik, Oct 30, 2013, trustedCertEntry,
Certificate fingerprint (MD5): AF:26:AE:7A:9D:68:89:06:E8:90:30:6E:EE:6A:EC:62
....

(6) Open another command prompt which has set the APPL_TOP environment.  
(6.1) Initialize the keystore
C:> cd %APPL_TOP%\admin
C:\oracle\apps\apps_st\appl\admin>adjkey -initialize -keysize 4096

                     Copyright (c) 2002 Oracle Corporation
                        Redwood Shores, California, USA

                             AD Java Key Generation

                                 Version 12.0.0

NOTE: You may not use this utility for custom development
      unless you have written permission from Oracle Corporation.

Reading product information from file...

Reading language and territory information from file...

Reading language information from applUS.txt ...

Enter the APPS username: apps

Enter the APPS password:

Successfully created javaVersionFile.

adjkey will now create a signing entity for you.

Enter the Name of your Company (used for both CN and
ORGANIZATION NAME) [CN/ORGANIZATION NAME] : SYMPLiK Technologies

Enter the department or group that will use the certificate [ORGANIZATION UNIT] : Finance

Enter the full name of the city where your organization's
head office is located [LOCALITY] :  Toronto

Enter the full name of the State, Province or County where
your organization's head office is located [STATE] :  Ontario

Enter the two-letter ISO abbreviation for your country
(for example, US for the United States) [COUNTRY] : CA
Enter keystore password:  Re-enter new password: Enter key password for
        (RETURN if same as keystore password):  Re-enter new password:
keytool -genkey -alias VCPDEMO_papaya -keyalg RSA -keysize  4096 -keystore c:\oracle\apps\apps_st\appl\admin\adkeystore.dat -validity 14600 -dname " CN=SYMPLiK Technologies, OU=Finance, O=SYMPLiK Technologies, L=Toronto, S=Ontario, C=CA"

The above Java program completed successfully.
Your digital signature has been created successfully and
imported into the keystore database. This signature
will now be used to sign Applications JAR files whenever
they are patched.

  IMPORTANT: If you have multiple web servers, you must copy
  files to each of the remaining web servers on your site.
  See the documentation reference for more information.

adjkey is complete.

(6.2) Generate client certificate
C:\oracle\apps\apps_st\appl\admin>adjkey -certreq -file adkeystore.csr

                     Copyright (c) 2002 Oracle Corporation
                        Redwood Shores, California, USA

                             AD Java Key Generation

                                 Version 12.0.0

NOTE: You may not use this utility for custom development
      unless you have written permission from Oracle Corporation.

Reading product information from file...

Reading language and territory information from file...

Reading language information from applUS.txt ...

Enter the APPS username: apps

Enter the APPS password:

Successfully created javaVersionFile.
Enter keystore password:  Enter key password for
keytool -certreq -file adkeystore.csr -keystore c:\oracle\apps\apps_st\appl\admin\adkeystore.dat -alias VCPDEMO_papaya

The above Java program completed successfully.

adjkey is complete.

(7) Sign the client certificate by your CA

(7.1) Copy client certificate adkeystore.csr to OpenSSL directory C:\OpenSSL\CA

(7.2) Do the signing
C:\OpenSSL\CA>openssl ca -in adkeystore.csr -out adkeystore.crt
Using configuration from c:\OpenSSL\CA\openssl.conf
Loading 'screen' into random state - done
Enter pass phrase for C:\OpenSSL\CA\private\cakey.pem:
Check that the request matches the signature
Signature ok
The Subject's Distinguished Name is as follows
countryName           :PRINTABLE:'CA'
stateOrProvinceName   :PRINTABLE:'Ontario'
localityName          :PRINTABLE:'Toronto'
organizationName      :PRINTABLE:'SYMPLiK Technologies'
organizationalUnitName:PRINTABLE:'FINANCE'
commonName            :PRINTABLE:'SYMPLiK Technologies'
Certificate is to be certified until Oct 28 03:21:06 2023 GMT (3650 days)
Sign the certificate? [y/n]:y

1 out of 1 certificate requests certified, commit? [y/n]y
Write out database with 1 new entries
Data Base Updated

if you got error:
failed to update database
TXT_DB error number 2

It's because the same /C/ST/O/OU/CN combination exists.
Change the 'unique_subject = no' in openssl.conf
remove index.attr and rerun

(7.3) Convert the signed certificate to DER format
C:\OpenSSL\CA>openssl x509 -outform der -in adkeystore.crt -out adkeystore.der

(7.4) Copy DER-formatted certificate to %APPL_TOP%\admin directory

(8) Add the DER-formatted certificate to keystore
C:\oracle\apps\apps_st\appl\admin>adjkey -import -file adkeystore.der -trustcacerts

                     Copyright (c) 2002 Oracle Corporation
                        Redwood Shores, California, USA

                             AD Java Key Generation

                                 Version 12.0.0

NOTE: You may not use this utility for custom development
      unless you have written permission from Oracle Corporation.

Reading product information from file...

Reading language and territory information from file...

Reading language information from applUS.txt ...

Enter the APPS username: apps

Enter the APPS password:

Successfully created javaVersionFile.
Enter keystore password:  Enter key password for Certificate reply was installed in keystore

keytool -import -file adkeystore.der -trustcacerts -keystore c:\oracle\apps\apps_st\appl\admin\adkeystore.dat -alias VCPDEMO_papaya

The above Java program completed successfully.

adjkey is complete.

(9) Run adadmin and force regenerate all JAR files (R12: 1 > 4 > yes / 11i: 1 > 5 > yes)

Sunday, October 13, 2013

A simple way to display a long-waiting servlet

I came across a situation that I needed to write a servlet which ran some SQL statements, got some data from web services, compiled all the data in a XML files, and transferred files from one place to another, and finally update the status and others back to database.  All actions had to be done in one-pass, and it was invoked by end-user through a web page.

It's a pretty typical scenario that one needs to have a servlet running and show the messages like "please wait", "do not interrupt", "transaction in process", etc.  How to do it ? The trick is that the servlet itself does not show that message, it's the DIV layer in the parent page.

(1) Create a page in JSP, servlet, or html which contains a DIV with known ID (loader) and has an animated gif (/images/ajax-loader.gif) in it. You can generate one of this image from this link or this link.

(2) Write your long-running servlet (LongServlet), and register it in the web xml. This servlet writes a Javascript block at the end that will hide the DIV block in the parent page.

(3) Put the servlet as a iFrame in the html created in (1).
So, when the parent page is landed, it shows the DIV layer with the animated gif and message which says something is running. The iframe, which is indeed the servlet, keep running for a while but it is not visible until it is done. When the servlet process stops, the Javascript will hide the parent DIV layer and content of the servlet will be shown. You can put a link in the servlet likes
<a href="#" onclick="top.window.location.href='yourURL';">Click here to proceed</a>
and it will allow user to quit the page after the process has finished.

Example code for long-running servlet
public class LongServlet extends HttpServlet {
  public void init(ServletConfig config) throws ServletException {
    super.init(config);
    ....
  }
  public void doGet(HttpServletRequest request, HttpServletResponse response) 
     throws ServletException, IOException {

     PrintWriter out = response.getWriter();
     response.setContentType("text/html; charset=UTF-8");
     response.setHeader("Cache-Control","no-cache"); //HTTP 1.1
     response.setHeader("Pragma","no-cache"); //HTTP 1.0
     response.setDateHeader ("Expires", 0); //prevents caching at the proxy server
     out.println("<html><head/><body bgcolor='Azure' text='LightSlateGray'>");
     out.println("Start running process...<br/>");
     .... 
     out.println("Process done.");
     out.println("<script type='text/javascript'>" +
               "window.parent.document.getElementById('loader').style.visibility='hidden';" +
                  "</script>");
     out.println("</body></html>"); 
  }
}

Example html page which hold the servlet as iframe
<html>
<head>
  <title>Fetch Summary</title>
  <meta http-equiv="Content-Type" content="text/html; charset=utf-8" />
  <meta http-equiv="Pragma" content="no-cache" /><meta http-equiv="Expires" content="-1" /><meta http-equiv="Cache-Control" content="no-cache" />
  <style type="text/css">
  #loader { background:url(/images/ajax-loader.gif) no-repeat center center; height:66px; width:66px; top: 300px; left: 200px;}
  #header { font-size:14px;color:brown;font-weight:bold;}
  </style>
</html>
<body>
<div id="loader"></div>
<div id="header">Running something long and big, please wait...</div>
<iframe src="/servlets/LongServlet" height="600" width="500" scrolling="yes" frameborder="1"></iframe>
</body>
</html>