Gemalto 2FA windows logon

Posted on: 21 September 2020 | 8:13 am

Generate a Certificate Signing Request (CSR) File for Cisco ASA

To generate a certificate signing request (CSR) for Cisco ASA 5510, perform the following steps: Step 1:  Generate a key pair 1.    Within ASDM, click Configuration > Device Management 2.    Click Certificate Management > Identity Certificates > Add > Add a new identity certificate 3.    For the Key Pair, click New > Enter new key pair name 4.    Enter a unique key pair name for the certificate 5.    Select the key size as 2048 6.    To complete the generation of the key pair, click Generate Now Step 2: Generate a certificate signing request (CSR) file 1.    To enter certificate information, click Select 2.    From the drop-down list, select the following attributes > enter value > click Add Note: The following fields are required: C (Country), St (State), L (Locality), O (Organization Name), OU (Organizational Unit), CN (Common Name) 3.    Once the appropriate values are added, click OK > Advanced 4.    In the FQDN field, enter the FQDN that will be used to access the device from the Internet: NOTE - If enrolling for a Subject Alternative Name certificate leave this field blank. Note: This value should be same FQDN you used for the Common Name (CN) 5.    Click OK >  Add Certificate > Browse 6.    Choose a location where to save the request file

Posted on: 19 June 2019 | 11:55 am

Most Imp .Java Keytool Commands

      Generate a Java keystore and key pair:             keytool -genkey -alias mydomain -keyalg RSA -keystore keystore.jks -keysize 2048     Generate a certificate signing request (CSR) for an existing Java keystore:              keytool -certreq -alias mydomain -keystore keystore.jks -file mydomain.csr     Generate a keystore and self-signed certificate:            keytool -genkey -keyalg RSA -alias selfsigned -keystore keystore.jks -storepass password -validity 360 -keysize 2048       Certificate import commands in keystore: Import a root CA certificate to an existing Java keystore:                keytool -import -trustcacerts -alias root -file root.crt -keystore keystore.jks            Import a intermediate CA certificate to an existing Java keystore:               keytool -import -trustcacerts -alias intermediate -file intermediate.crt -keystore keystore.jks Import a signed SSL primary certificate to an existing Java keystore:                 keytool -import -trustcacerts -alias mydomain -file mydomain.crt -keystore keystore.jks     Java Keytool Commands for Conversion:              If you need to change the type of keystore. PFX keystore to JKS keystore: keytool -importkeystore -srckeystore mypfxfile.pfx -srcstoretype pkcs12 -destkeystore newjkskeystore.jks -deststoretype JKS JKS keystore to PFX keystore: keytool -importkeystore -srckeystore myjksfile.jks -srcstoretype JKS -deststoretype PKCS12 -destkeystore newpfxkeystore.pfx     Other Java Keytool Commands: Delete a certificate from a Java Keytool keystore: keytool -delete -alias mydomain -keystore keystore.jks Change a Java keystore password: keytool -storepasswd -new newstorepass -keystore keystore.jks Export a certificate from a keystore: keytool -export -alias mydomain -file mydomain.crt -keystore keystore.jks List Trusted CA Certs: keytool -list -v -keystore $JAVA_HOME/jre/lib/security/cacerts Import New CA into Trusted Certs: keytool -import -trustcacerts -file /path/to/ca/ca.pem -alias mydomain -keystore $JAVA_HOME/jre/lib/security/cacerts

Posted on: 19 June 2019 | 11:51 am

Most OpenSSL Commands

      Convert PEM to DER:        openssl x509 -outform der -in certificate.pem -out certificate.der        Convert DER to PEM:        openssl x509 -inform der -in certificate.der -out certificate.pem        Convert PEM/CRT to P7B:        openssl crl2pkcs7 -nocrl -certfile certificate.crt -out certificate.p7b -certfile CACert.crt        Convert P7B to PEM/CRT:        openssl pkcs7 -print_certs -in certificate.p7b -out certificate.crt         Convert PEM/CRT & Private Key to PFX/P12:        openssl pkcs12 -export -out certificate.pfx -inkey privateKey.key -in certificate.crt -certfile CACert.crt         Convert P7B to PFX:         openssl pkcs12 -export -in certificate.cer -inkey privateKey.key -out certificate.pfx -certfile CACert.cer         Convert PFX to PEM/CRT and Private Key                  openssl pkcs12 -in certificate.pfx -out certificate.crt -nodes              OpenSSL command to remove private key password                                               Or           To convert simple private to   RSA   private.key         openssl rsa -in file.key -out newfile.key         openssl command print out md5 checksums of the certificate and key         openssl x509 -noout -modulus -in server.crt| openssl md5                 openssl rsa -noout -modulus -in server.key| openssl md5    

Posted on: 19 June 2019 | 11:47 am

Installing SSL Certificate on Zimbra

Using the CLI ·         1. Get the certificate from ssl authority in crt/txt format, or sometimes like a zip file. ·         2. Place the Certificate on your Zimbra mailbox server. You should receive below files: o    Root.crt o    Intermediate.crt o    My_Domain_com.crt files Note the root and intermediate files may have different names depends of the SSL Certificate, like DigiCert etc. Note 2 all the below commands should be run as zimbra user starting ZCS 8.7 and above, and as a root user in ZCS 8.6 and below. ·         3. Cat the CA certs to form a single CA certificate chain file  cat Root.crt Intermediate.crt > /tmp/commercial_ca.crt ·         4. Place the SSL certificate in /tmp/commercial.crt.  cp my_domain_com.crt /tmp/commercial.crt ·         5. Copy private key file (which is generate at a time of CSR generation) on below path and rename it  commercial.key  . /opt/Zimbra/ssl/Zimbra/commercial/commercial.key ·         6. Check that your SSL certificate, your private key and the Intermediate CA are OK, this step is important and you should not continue if you receive an error here: /opt/zimbra/bin/zmcertmgr verifycrt comm /opt/zimbra/ssl/zimbra/commercial/commercial.key /tmp/commercial.crt /tmp/commercial_ca.crt ** Verifying /tmp/commercial.crt against /opt/zimbra/ssl/zimbra/commercial/commercial.key Certificate (/tmp/commercial.crt) and private key (/opt/zimbra/ssl/zimbra/commercial/commercial.key) match. Valid Certificate: /tmp/commercial.crt: OK ·         7. Deploy the commercial certificate with zmcertmgr as the Zimbra user. /opt/zimbra/bin/zmcertmgr deploycrt comm /tmp/commercial.crt /tmp/commercial_ca.crt ** Verifying /tmp/commercial.crt against /opt/zimbra/ssl/zimbra/commercial/commercial.key Certificate (/tmp/commercial.crt) and private key (/opt/zimbra/ssl/zimbra/commercial/commercial.key) match. Valid Certificate: /tmp/commercial.crt: OK ** Copying /tmp/commercial.crt to /opt/zimbra/ssl/zimbra/commercial/commercial.crt ** Appending ca chain /tmp/commercial_ca.crt to /opt/zimbra/ssl/zimbra/commercial/commercial.crt ** Importing certificate /opt/zimbra/ssl/zimbra/commercial/commercial_ca.crt to CACERTS as zcs-user-commercial_ca...done. ** NOTE: mailboxd must be restarted in order to use the imported certificate. ** Saving server config key zimbraSSLCertificate...done. ** Saving server config key zimbraSSLPrivateKey...done. ** Installing mta certificate and key...done. ** Installing slapd certificate and key...done. ** Installing proxy certificate and key...done. ** Creating pkcs12 file /opt/zimbra/ssl/zimbra/jetty.pkcs12...done. ** Creating keystore file /opt/zimbra/mailboxd/etc/keystore...done. ** Installing CA to /opt/zimbra/conf/ca...done. ·         8. Restart the Zimbra Services zmcontrol restart

Posted on: 19 June 2019 | 11:25 am

            SSL Configuring step for IBM Http Server  Creating new SSL digital Certificate using iKeyman: For the certificate you can use either a certificate that is signed by a certificate authority or you can also use a self-signed certificate.  Before creating a new certificate, you need to create a certificate store or Key Database. start the iKeyman utility: /IHS root/bin/ikeyman.sh From the Menu Bar select Key Database File > New. Choose the key database type as CMS Enter a file name for the new Key Database file you are creating Enter a Location for the location where you want to store the .kdb file Click OK After saving the key database file to the location specified, you are prompted to enter a password. This is the password that will be used to open the key database file in iKeyman in the future. make sure checkbox Stash the password to a file is enabled. this saves the encrypted password file as a .sth file in the same directory as the key database file. Now Click OK Your Key Database file is Ready. Now let's create a certificate request. I am using this URL for my site sslsupport.blogspot.com First, Open the KDB using ikeyman. This will show the key database contents. Click on the “down arrow” to the right, to display a list of three choices. Select Personal Certificate Requests and click New Now, a new window will pop up. here you need to input details about the certificate and your organization. Options: Key Size= 2048 for 256bit and 512bit Common Name= SiteName, [This is the name that the CA will register] Organization= Company Name Enter the name of a file in which to store the certificate request = This is the file (.arm) that will contain your request Once you save the file (.arm) you are done with creating the request You must now choose a CA and send them a “Certificate Request” Once the CA has signed your certificate, generally they send you back the signed certificate through email. Take the information provided in the CAs email and copy it to a text file (notepad) and save it as IHS_Root/SSL/CertRcvd.arm Open the KDB file and choose Personal Certificates from the drop-down options [ check image3 for how-to] From the Personal Certificates section, click Receive, a pop-up window will come Input the required data. Like  certificate name and location and click OK Preparing IHS for SSL: Open the httpd.conf file for editing and modify it to implement the following: For the host_name.domain, use the virtual host IP address or fully qualified domain name. Typically, port 443 is used for HTTPS protocol. The timeout values are given in seconds. Your values might be different. Sample httpd.conf file for a UNIX computer:     LoadModule ibm_ssl_module libexec/mod_ibm_ssl.soAddModule mod_ibm_ssl.cListen 443 <VirtualHost host_name.domain:443>ServerName host_name.domainSSLServerCert certificate nameDocumentRoot “IHS_Root\docs”SSLEnableSSLClientAuth none<\VirtualHost> SSLDisableKeyfile “path_to_keyfile_created”SSLV2Timeout 100SSLV3Timeout 1000 Restart IBM HTTP Server for the changes take effect. Example SSL virtualhost : <VirtualHost xxx.xxx.xx.xx:443>ServerName test.comSSLEnableSSLClientAuth NoneSSLServerCert mywebsite<Directory “/home/www/website”>Options IndexesAllowOverride Noneorder allow,denyallow from all</Directory>DocumentRoot “/home/www/website”</VirtualHost>

Posted on: 12 February 2019 | 12:59 pm

FortiGate firewall ssl installation step

Step 1: Downloading your SSL Certificate & its Intermediate CA  Certificate: If you had the option of server type during enrollment and selected Other you will receive a x509/.cer/.crt/.pem version of your certificate within the email. Alternately you can access your Certificate User Portal by the supplied link in the email to pick up the x509 version of your certificate. Copy the SSL certificate and make sure to copy the —–BEGIN CERTIFICATE—– and —–END CERTIFICATE—– header and footer Ensure there are no white spaces, extra line breaks or additional characters. Use a plain text editor such as Notepad, paste the content of the certificate and save it with extension .crt If your intermediate CA certificate for your product is not in the body of the email you can access your Intermediate CA also in a link within that email. Copy and paste the contents of your Intermediate CA into its own Notepad file and save it with a .crt extension also. Note: Some CAs may require two intermediates for best compatibility. These two are to be copied within their own corresponding .crt files and installed one at a time in a repeated process for intermediate installation. Step 2: Importing your SSL Certificate: Log into your FortiGate System. Browse to System > Certificates. Select Import > Local Certificate. Browse to the location and path of your SSL certificate. Click OK. The status of the certificate should change from PENDING to OK Step 3: Importing your Intermediate CA: Browse to System > Certificates. Select Import > CA Certificate. Browse to the location and path of your Intermediate CA certificate. Click OK. Your Intermediate CA should be under the CA Certificate section of the certificates list. Step 4: Configuring your FortiGate VPN to use the new SSL certificate: Browse to VPN > SSL > Settings. In the Connection Settings section under the Server Certificate drop down select your new SSL certificate. Click ApplyYou have configured the Foritgate VPN to use the new SSL certificate.

Posted on: 10 July 2018 | 1:10 am

Tomcat Server SSL Installation

Tomcat SSL Installation Instructions Download your certificate files from your certificate authority and save them to the same directory as the keystore that you created during the CSR creation process. The certificate will only work with the same keystore that you initially created the CSR with. The certificates must be installed to your keystore in the correct order. Install the Root Certificate file: Every time you install a certificate to the keystore you must enter the keystore password that you chose when you generated it. Enter the following command to install the Root certificate file: keytool -import  -trustcacerts -keystore tomcat.jks -storepass changeit -alias root -file root.cer  Install the Intermediate Certificate file: If your certificate authority provided an intermediate certificate file, you will need to install it here by typing the following command: keytool -import  -trustcacerts -keystore tomcat.jks -storepass changeit -alias intermediate  -file intermediate.cer If successful, you will see "Certificate was added to keystore". Install the Primary Certificate file: Type the following command to install the Primary certificate file (for your domain name): keytool -import  -trustcacerts -keystore tomcat.jks -storepass changeit -alias tomcat -file servercertificate.cer  If successful, you will see "Certificate reply was installed in keystore". You now have all the certificates installed to the keystore file. You just need to configure your server to use the keystore file. Note:- when given api error then use this protocol      “protocol="org.apache.coyote.http11.Http11NioProtocol” Note:- if you have a pfx file then use this command to make.jks Convert PFX to keystore.jks Keytool  -importkeystore -srckeystore uatwebsrv1.pfx -srcstoretype pkcs12 -destkeystore uatwebsrv1.jks  -deststoretype  JKS Configuring your SSL Connector Tomcat will first need an SSL Connector configured before it can accept secure connections. 1.    Open the Tomcat server.xml file in a text editor (this is usually located in the conf folder of your Tomcat's home directory). 2.    Find the connector that will be secured with the new keystore and uncomment it if necessary (it is usually a connector with port 443 or 8443 like the example below). 3.    Specify the correct keystore filename and password in your connector configuration. When you are done your connector should look something like this: <Connector port="443" protocol="HTTP/1.1" maxThreads="150" scheme="https" secure="true" SSLEnabled="true" keystoreFile="conf/tomcat.jks" keystorePass="changeit" clientAuth="false" SSLProtocol="TLSv1+TLSv1.1+TLSv1.2" ciphers="TLS_ECDHE_RSA_WITH_AES_256_CBC_SHA384, TLS_RSA_WITH_AES_256_CBC_SHA256, TLS_ECDHE_RSA_WITH_AES_256_CBC_SHA, TLS_RSA_WITH_AES_256_CBC_SHA, TLS_ECDHE_RSA_WITH_3DES_EDE_CBC_SHA, TLS_RSA_WITH_3DES_EDE_CBC_SHA, TLS_ECDHE_RSA_WITH_AES_128_CBC_SHA256, TLS_RSA_WITH_AES_128_CBC_SHA256, TLS_ECDHE_RSA_WITH_AES_128_CBC_SHA, TLS_RSA_WITH_AES_128_CBC_SHA" /> Note: If you are using version 7 of Tomcat you will need to change "keypass" to "keystorePass". 4.    Save your changes to the server.xml file. 5.    Restart Tomcat.

Posted on: 2 June 2018 | 5:44 am

Apache server ssl installation

                             Apache server ssl installation step 1. copy your domain certificate and intermediate certificates to a folder on the server with the private key like /etc/sslcert/ssl.crt 2. Edit your Apache configuration to reference these files. The exact configuration file you will edit will depend on your version of Apache, your OS platform, and/or the method used to install Apache. In Apache 1.3, you will most likely edit the main httpd.conf file. In Apache 2.x, you will most likely edit the ssl.conf file. 4. Now open ssl.conf  file  on this location  /etc/httpd/conf.d For example:- Note:-  check below  ssl configuration  in ssl.conf file.    LoadModule ssl_module modules/mod_ssl.so     Listen 443     <VirtualHost _default_:443>     #   Server Certificate:   SSLCertificateFile /etc/ssl/certs/mysitename.crt      #   Server Private Key:   SSLCertificateKeyFile /etc/ssl/certs/mysitename.key    #   Server Certificate Chain:   SSLCertificateChainFile /etc/ssl/certs/ca-bundle.crt 6 .Change the names of the files and paths to match your certificate files: SSLCertificateFile should be your primary certificate file for your domain name. SSLCertificateKeyFile should be the key file generated when you created the CSR. SSLCertificateChainFile should be the intermediate certificate file (if any) that was supplied by your certificate authority             7. Save the changes and exit the text editor. 8.        8.  Restart Apache services.

Posted on: 2 June 2018 | 5:23 am