Skip to content

Commit e46513a

Browse files
committed
Update ria-dev configuration to use cdoc2-keyserver.dev.riaint.ee server and a new certificate
1 parent 69dbdd7 commit e46513a

File tree

7 files changed

+29
-8
lines changed

7 files changed

+29
-8
lines changed

cdoc2-cli/config/ria-dev/README.md

Lines changed: 4 additions & 4 deletions
Original file line numberDiff line numberDiff line change
@@ -2,10 +2,10 @@
22
This directory contains cdoc2-cli config for RIA-dev servers
33

44
TLS (POST)
5-
https://cdoc2-keyserver-01.dev.riaint.ee:8443
5+
https://cdoc2-keyserver.dev.riaint.ee:8443
66

77
mTLS (GET)
8-
https://cdoc2-keyserver-01.dev.riaint.ee:8444
8+
https://cdoc2-keyserver.dev.riaint.ee:8444
99

1010
## Id-card
1111
Run from cdoc2-cli directory
@@ -26,11 +26,11 @@ Client certificate must be trusted by server
2626

2727
### Encrypt
2828
```
29-
java -jar target/cdoc2-cli-*.jar create --server=config/ria-dev/ria-dev_pkcs12.properties -f /tmp/ria2.cdoc -p keys/cdoc2client_pub.pem README.md
29+
java -jar target/cdoc2-cli-*.jar create --server=config/ria-dev/ria-dev_pkcs12.properties -f /tmp/ria_p12.cdoc -p keys/cdoc2client_pub.pem README.md
3030
```
3131

3232
### Decrypt
3333

3434
```
35-
java -jar target/cdoc2-cli-*.jar decrypt --server=config/ria-dev/ria-dev_pkcs12.properties -f /tmp/ria2.cdoc -k keys/cdoc2client.pem
35+
java -jar target/cdoc2-cli-*.jar decrypt --server=config/ria-dev/ria-dev_pkcs12.properties -p12 keys/cdoc2client.p12:passwd -f /tmp/ria_p12.cdoc -o /tmp
3636
```
-705 Bytes
Binary file not shown.
32 Bytes
Binary file not shown.
Lines changed: 1 addition & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1 @@
1+
keytool -import -trustcacerts -file tls-issuer.crt.pem -alias klass3-ria_2018_ecc_g3 -storepass passwd -keystore clienttruststore_ria-dev.jks

cdoc2-cli/config/ria-dev/ria-dev.properties

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -1,7 +1,7 @@
11
# ria-dev, mutual TLS establishment with private key from id-cards (for reading key-capsule from the server)
22
cdoc2.client.server.id=ria-dev
3-
cdoc2.client.server.base-url.post=https://cdoc2-keyserver-01.dev.riaint.ee:8443
4-
cdoc2.client.server.base-url.get=https://cdoc2-keyserver-01.dev.riaint.ee:8444
3+
cdoc2.client.server.base-url.post=https://cdoc2-keyserver.dev.riaint.ee:8443
4+
cdoc2.client.server.base-url.get=https://cdoc2-keyserver.dev.riaint.ee:8444
55

66
# trusted certificates by client
77
cdoc2.client.ssl.trust-store.type=JKS

cdoc2-cli/config/ria-dev/ria-dev_pkcs12.properties

Lines changed: 5 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -1,9 +1,12 @@
11
# ria-dev, mutual TLS establishment with private key from PKCS12 store (for reading key-capsule from the server)
22
# public key part of servers trusted certs. See cdoc2-server/cdoc2-server/keys/README.md
33
cdoc2.client.server.id=ria-dev
4-
cdoc2.client.server.base-url.post=https://cdoc2-keyserver-01.dev.riaint.ee:8443
5-
cdoc2.client.server.base-url.get=https://cdoc2-keyserver-01.dev.riaint.ee:8444
4+
cdoc2.client.server.base-url.post=https://cdoc2-keyserver.dev.riaint.ee:8443
5+
cdoc2.client.server.base-url.get=https://cdoc2-keyserver.dev.riaint.ee:8444
66

7+
cdoc2.client.server.debug=true
8+
cdoc2.client.server.connect-timeout=1000
9+
cdoc2.client.server.read-timeout=1000
710

811
# trusted certificates by client
912
cdoc2.client.ssl.trust-store.type=JKS
Lines changed: 17 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,17 @@
1+
-----BEGIN CERTIFICATE-----
2+
MIICvTCCAmOgAwIBAgIIEwktMxn8tjIwCgYIKoZIzj0EAwQwcTELMAkGA1UEBhMC
3+
RUUxJTAjBgNVBAoMHEluZm9ybWF0aW9uIFN5c3RlbSBBdXRob3JpdHkxIDAeBgNV
4+
BAMMF1JJQSBST09UIENBIDIwMTggRUNDIEcyMRkwFwYJKoZIhvcNAQkBFgpwa2lA
5+
cmlhLmVlMB4XDTIwMDgxODEwMDU1M1oXDTM4MDkyMDIwNDIxOFowdjELMAkGA1UE
6+
BhMCRUUxJTAjBgNVBAoMHEluZm9ybWF0aW9uIFN5c3RlbSBBdXRob3JpdHkxHzAd
7+
BgNVBAsMFkNlcnRpZmljYXRpb24gU2VydmljZXMxHzAdBgNVBAMMFktMQVNTMy1S
8+
SUEgMjAxOCBFQ0MgRzMwWTATBgcqhkjOPQIBBggqhkjOPQMBBwNCAAT3VfEDD3qs
9+
NO5cTGmJHeUdgWKMVOKwFunKmUf5fx82waWthh/XgcZXBxg6wMpc05x/wsVjhEtz
10+
q4Ll6UeFwiJDo4HfMIHcMBIGA1UdEwEB/wQIMAYBAf8CAQAwHwYDVR0jBBgwFoAU
11+
UCFh01APe/+6Mb/XVsMuezIYCEIwdgYIKwYBBQUHAQEEajBoMEMGCCsGAQUFBzAC
12+
hjdodHRwOi8vd3d3LnJpYS5lZS9jZXJ0cy9SSUFfUk9PVF9DQV8yMDE4X0VDQ19H
13+
Mi5kZXIuY3J0MCEGCCsGAQUFBzABhhVodHRwOi8vb2NzcC5yaWEuZWUvQ0EwHQYD
14+
VR0OBBYEFFcaZmPOL66vUw4v7g888ZdZ3c7EMA4GA1UdDwEB/wQEAwIBxjAKBggq
15+
hkjOPQQDBANIADBFAiEAipQ0yy53GLNbYFuMyxSHBKmEchGxZojuxsV62rS7C/gC
16+
IF7PshKqti26zdo/0JuwYXIohUdiSpbIPTcZgU1Su9Wo
17+
-----END CERTIFICATE-----

0 commit comments

Comments
 (0)