0
votes

I have WSO2 API manager deployed in AWS EC2 instance. I have purchased a SSL certificate via sslforfree.com. I tried to import it via keytool command. But its not working and throwing error. It gives me

KrbException: Cannot locate default realm

How can I associate this certificate with the API Manager? I don't have a domain name for WSO2 and I access it via IP address. Is it possible for have CA signed certificate in this case?

In case if I want a domain name for this EC2, how can I have one?

2
could you post the keytool command you've used? there's not reason that the keytool woudn't import the keypair and certificate and as well the keytool is not related to the kerberos - gusto2

2 Answers

0
votes

You can import the certificate inside Carbon. Log into <your_server>:9443/carbon as admin. After that go on Main -> Manage -> Keystores -> List

If you're still using the default settings you'll have the wso2carbon.jks entry here. Click on Import cert, chose your cert file and click on Import. Your certificate should be working after this.

0
votes

there are several topics in this question:

I tried to import it via keytool command.But its not working and throwing error.It gives me KrbException: Cannot locate default realm

The keytool gives you this exception? It would be useful to provide the keytool command you've used. There's not reason for that exception.

please not that the certificate CN must be the same as the fqdn (domain name) of the server (how your browser access it).

How can I associate this certificate with the API Manager?

There are two options.

  1. Import the keypair (private key and certificate chain) into a keystore and configure the APIM to use the keystore (in the repository/conf/tomcat/catalina-server.xml)

  2. Have a reverse proxy server (Apache HTTP, NGinx), and configure the SSL on that proxy server. This is my favorite approach .

See: https://docs.wso2.com/display/AM210/Adding+a+Reverse+Proxy+Server

Then you have control over who/where can access the carbon console, store and publisher.

I don't have a domain name for WSO2 and I access it via IP address. Is it possible for have CA signed certificate in this case?

Certificate authorities don't provide IP based certificate, as they can validate ownership/control of a domain name, but not of the IP address.

You can create (and made trusted) your own CA and certificate (good for PoC, DEV environment, ..) but in long run you'll need a trusted certificate on a hostname.

In case if i want a domain name for this EC2 , how can i have one ?

You can always buy one :D For start - when having EC2 instance with a dynamic IP address, you may use some dynamic dns service (e.g. https://ydns.io/ , just search for more if you wish)