Shibboleth v3 - Session HA Questions
prasanna cg
prasannacgin at yahoo.in
Wed Jul 1 21:23:57 UTC 2020
Hi Scott,
I use the following command to try creating those two file outside the IDP-HOME directory and get the error as below. Am I missing something ?
# /opt/shibboleth-idp/bin/seckeygen.sh --storefile /tmp/sealer.jks --storepass xxxx --versionfile /tmp/sealer.kver --alias secret
Exception in thread "main" java.io.IOException: Keystore was tampered with, or password was incorrect
at com.sun.crypto.provider.JceKeyStore.engineLoad(JceKeyStore.java:879)
at java.security.KeyStore.load(KeyStore.java:1445)
at net.shibboleth.utilities.java.support.security.BasicKeystoreKeyStrategyTool.changeKey(BasicKeystoreKeyStrategyTool.java:150)
at net.shibboleth.utilities.java.support.security.BasicKeystoreKeyStrategyTool.main(BasicKeystoreKeyStrategyTool.java:227)
Caused by: java.security.UnrecoverableKeyException: Password verification failed
... 4 more
> On Jul 1, 2020, at 5:18 PM, Cantor, Scott <cantor.2 at osu.edu> wrote:
>
> On 7/1/20, 5:17 PM, "users on behalf of prasanna cg" <users-bounces at shibboleth.net on behalf of prasannacgin at yahoo.in> wrote:
>
>> No, that command doesn't create a new keystore. It only adds a new encryption key to the existing keystore.
>
> Seeing as I just ran it successfully to create new files, that's simply not true.
>
> -- Scott
>
>
> --
> For Consortium Member technical support, see https://wiki.shibboleth.net/confluence/x/coFAAg
> To unsubscribe from this list send an email to users-unsubscribe at shibboleth.net
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://shibboleth.net/pipermail/users/attachments/20200701/9a2dcb0d/attachment.htm>
More information about the users
mailing list