Glassfish 5 Server默认HTTPS失效及连接显示不安全问题求助
Hey there! Glad you got the initial HTTPS access working—let’s tackle that annoying security warning next. The root cause here is almost always the self-signed certificate that GlassFish uses by default: browsers don’t trust these because they aren’t issued by a recognized, trusted Certificate Authority (CA). Here’s how to fix it, with options for quick local development and more formal setups:
Quick Fix: Trust GlassFish’s Default Self-Signed Certificate
This is the fastest way for local testing:
Export the GlassFish certificate
Open a terminal, navigate to your GlassFish domain’s config folder (usuallyglassfish/domains/domain1/config), then run this command (default keystore password ischangeit):keytool -export -alias s1as -keystore keystore.jks -file glassfish-local.cerImport the certificate into your browser
Every browser handles this a bit differently, but the general steps are:- Open your browser’s settings, find the "Certificates" or "Privacy & Security" section for managing trusted certificates.
- Import the
glassfish-local.cerfile you just created. - When prompted, mark the certificate as trusted for identity verification (this tells your browser to trust connections using this certificate).
Restart your browser and re-test
After importing, close and reopen your browser, then visithttps://localhost:8181—the warning should be gone.
More Formal Setup: Create Your Own Local CA (For Better Security Practices)
If you want to mimic a production-like setup (great for learning), you can create your own local Certificate Authority, sign GlassFish’s server certificate with it, then trust your CA in the browser:
- Create your local CA keystore
Follow the prompts to fill in details (for local use, you can use dummy info like "Local CA" for the organization).keytool -genkeypair -alias my-local-ca -keyalg RSA -keysize 2048 -keystore my-ca.jks -validity 3650 - Export your CA certificate
keytool -export -alias my-local-ca -keystore my-ca.jks -file my-local-ca.cer - Prepare GlassFish’s server certificate request
First, delete the defaults1asalias if you want a fresh start (optional but clean):
Then generate a new server keypair:keytool -delete -alias s1as -keystore keystore.jks
When prompted, make sure the "Common Name" matches the domain you’re using (for localhost, usekeytool -genkeypair -alias s1as -keyalg RSA -keysize 2048 -keystore keystore.jks -validity 3650localhost). - Generate a certificate signing request (CSR)
keytool -certreq -alias s1as -keystore keystore.jks -file server-csr.csr - Sign the server certificate with your local CA
keytool -gencert -alias my-local-ca -keystore my-ca.jks -infile server-csr.csr -outfile server-signed.cer -validity 3650 - Import certificates into GlassFish’s keystore
First import your CA certificate (so GlassFish trusts it):
Then import the signed server certificate:keytool -import -alias my-local-ca -keystore keystore.jks -file my-local-ca.cerkeytool -import -alias s1as -keystore keystore.jks -file server-signed.cer - Trust your local CA in the browser
Import themy-local-ca.cerfile into your browser’s trusted certificates (same steps as the quick fix). Now any certificate signed by your local CA will be trusted by your browser.
Double-Check GlassFish’s HTTPS Listener Config
Just to be sure, verify your HTTPS listener is using the correct settings in the GlassFish admin console (port 4848):
- Navigate to Configurations > server-config > Network Config > Network Listeners > http-listener-2
- Under the SSL tab:
- Confirm the Keystore File path points to
keystore.jks(your domain’s config folder) - Verify the Keystore Password is
changeit(or whatever you set) - Ensure the Certificate Alias is
s1as - Enable modern TLS versions (TLS 1.2 or 1.3) and disable outdated protocols like SSL 3.0
- Confirm the Keystore File path points to
After making any changes, restart GlassFish to apply them.
内容的提问来源于stack exchange,提问作者user3808269

