cas 配置https改为ip而不是使用域名

一月 04 2017

cas注销时地址是https,提示Error is [ No subject alternative names present]


网上很多文章说要使用CAS单点登录必须要配置域名, cas server是不能通过ip访问的,这实际上是错误的,这和cas无关,目前可以通过java 1.7来生成证书,需要JDK1.7,因为需要-ext参数 


keytool -genkey -alias cas41key -keyalg RSA -keysize 1024 -keypass 123456 -storepass 123456  -dname "CN=,OU=csoa,O=csoa,L=FZ,ST=FZ,C=CN" -ext san=ip:   -validity 3600  -keystore /home/nloa/bak/cas41.keystore

RFC 2818 (Section 3.1)

If a subjectAltName extension of type dNSName is present, that MUST be used as the identity. Otherwise, the (most specific) Common Name field in the Subject field of the certificate MUST be used. Although the use of the Common Name is existing practice, it is deprecated and Certification Authorities are encouraged to use the dNSName instead.


In some cases, the URI is specified as an IP address rather than a hostname. In this case, the iPAddress subjectAltName must be present in the certificate and must exactly match the IP in the URI.

jdk1.7,查阅keytool参数文档,keytool可以使用-ext 或者 -ext san=ip: 来包括Subject Alternative Name (SAN,主题备用名称)

具体配置文档 CAS文档.docx

在2017/01/04 11:48上被李立泓创建