The client certificate has been generated by means of keytool with the following command: At the very beggining we hve generate the keystored used by apacheDS: keytool –genkey –keyalg “RSA” –dname “cn=localhost, ou=ApacheDS, o=ASF, c=US” –alias dem –keystore “C:\DEM\DEM.ks” –storepass secret –validity 730 and then we have generated the self signed certificate: Keytool -export –keystore “C:\DEM\DEM.ks” –alias dem -file “C:\DEM\DEM.cer” and then we have added the DEM.cer certificate to the "cacerts" trusted store of the JVM.these are the three steps adviced on the Basic User guide. Could you please take a look to the log added in my prevoius mail where is stated all the messages produced by the client and the server during the handsheking? This is to verify, looking the signature and the chain messages, what is the problem. Thank you very much for you support, but I am in trouble, because I have to delivery my SW, ad I am in terrible delay.
Regards, Pasquale Il presente messaggio e-mail e ogni suo allegato devono intendersi indirizzati esclusivamente al destinatario indicato e considerarsi dal contenuto strettamente riservato e confidenziale. Se non siete l'effettivo destinatario o avete ricevuto il messaggio e-mail per errore, siete pregati di avvertire immediatamente il mittente e di cancellare il suddetto messaggio e ogni suo allegato dal vostro sistema informatico. Qualsiasi utilizzo, diffusione, copia o archiviazione del presente messaggio da parte di chi non ne è il destinatario è strettamente proibito e può dar luogo a responsabilità di carattere civile e penale punibili ai sensi di legge. Questa e-mail ha valore legale solo se firmata digitalmente ai sensi della normativa vigente. The contents of this email message and any attachments are intended solely for the addressee(s) and contain confidential and/or privileged information. If you are not the intended recipient of this message, or if this message has been addressed to you in error, please immediately notify the sender and then delete this message and any attachments from your system. If you are not the intended recipient, you are hereby notified that any use, dissemination, copying, or storage of this message or its attachments is strictly prohibited. Unauthorized disclosure and/or use of information contained in this email message may result in civil and criminal liability. “ This e-mail has legal value according to the applicable laws only if it is digitally signed by the sender -----Messaggio originale----- Da: Emmanuel Lécharny [mailto:elecha...@gmail.com] Inviato: mercoledì 5 aprile 2017 18:39 A: Apache Directory Developers List Oggetto: Re: R: R: how to set TLS connection with ApacheDS Le 05/04/2017 à 17:25, Maiorano Pasquale a écrit : > Yes it is a self signed certificate, and i have already added the self > signed certificate to the JVM And the certificate you use on the client has been generated using the CA certificate you have stored locally ? -- Emmanuel Lecharny Symas.com directory.apache.org