# certificates & Java

**URL:** <https://forum.servoy.com/t/certificates-java/12196>\
**Category:** Classic Servoy\
**Created:** [May 17, 2010, 12:57pm UTC](https://forum.servoy.com/t/certificates-java/12196 "2010-05-17T12:57:10Z")\
**Posts on this page:** 20\
**Page:** 1

<div class="post-metadata">

**Author:** ![Harjo](https://yyz2.discourse-cdn.com/flex010/user_avatar/forum.servoy.com/harjo/32/4873_2.png) [@Harjo](https://forum.servoy.com/u/Harjo)\
**Post date:** [May 17, 2010, 12:57pm UTC](https://forum.servoy.com/t/certificates-java/12196/1 "2010-05-17T12:57:10Z")

</div>

Oke,

we are about to deploy to 5.1.2. We have installed now also all the 3th party plugins with signed certificates.  
But we have to go to 5 screens??? (And later maybe more…)

Servoy B.V. - we have to click: TRUST, because it cannot be verified, jnlp is not signed  
Trapman Marcellinus (IT2BE) - we have to click: INSTALL  
iTech Professionals, Inc. (ServoyGuy) - we have to click: INSTALL  
D.r Maison & Partner GmbH - we have to click: INSTALL  
Direct ICT (couple of self signed jars, jasper plugin 3.0, sintpro scanner plugin) - we have to click TRUST  
Patrick Talbot Open Source Developer - we have to click INSTALL.

I know this is only once, but does every customer of us, need to do this?? ![:(]( "Sad")  
Is this something than can be optimized?? ![:?]( "Confused")  
we realize that for every new plugin-developer (with his own certificate) we get an extra screen… This can’t be true right?

---

<div class="post-metadata">

**Author:** ![ptalbot](https://yyz2.discourse-cdn.com/flex010/user_avatar/forum.servoy.com/ptalbot/32/4952_2.png) [@ptalbot](https://forum.servoy.com/u/ptalbot)\
**Post date:** [May 17, 2010, 1:14pm UTC](https://forum.servoy.com/t/certificates-java/12196/2 "2010-05-17T13:14:09Z")

</div>

You can thank Oracle for this!  
And unfortunately there’s nothing here that can be optimized ![:cry:]( "Crying or Very sad")

---

<div class="post-metadata">

**Author:** ![Harjo](https://yyz2.discourse-cdn.com/flex010/user_avatar/forum.servoy.com/harjo/32/4873_2.png) [@Harjo](https://forum.servoy.com/u/Harjo)\
**Post date:** [May 17, 2010, 1:50pm UTC](https://forum.servoy.com/t/certificates-java/12196/3 "2010-05-17T13:50:57Z")

</div>

Servoy, can you tell something about this? will or can there be things optimized? (or in future releases?)

---

<div class="post-metadata">

**Author:** ![jcompagner](https://yyz2.discourse-cdn.com/flex010/user_avatar/forum.servoy.com/jcompagner/32/4889_2.png) [@jcompagner](https://forum.servoy.com/u/jcompagner)\
**Post date:** [May 18, 2010, 6:09am UTC](https://forum.servoy.com/t/certificates-java/12196/4 "2010-05-18T06:09:24Z")

</div>

no that is out of our hands.  
Its webstart/java asking all these questions.

Or you have to sign everything yourself (as a customer) with the same certificate.  
Then you only will get it once.

---

<div class="post-metadata">

**Author:** ![Harjo](https://yyz2.discourse-cdn.com/flex010/user_avatar/forum.servoy.com/harjo/32/4873_2.png) [@Harjo](https://forum.servoy.com/u/Harjo)\
**Post date:** [May 18, 2010, 6:16am UTC](https://forum.servoy.com/t/certificates-java/12196/5 "2010-05-18T06:16:24Z")

</div>

Oke, I was also thinking in that direction.  
But how can this be done easily? We get all the jars now, (Servoy AND 3th party plugins) signed allready.  
How do we remove the the existing certificates? and most of all, can we do that, without breaking something??

Is this something, that the signtester.jar could do?

---

<div class="post-metadata">

**Author:** ![wvitpr](https://avatars.discourse-cdn.com/v4/letter/w/e0b2c6/32.png) [@wvitpr](https://forum.servoy.com/u/wvitpr)\
**Post date:** [May 18, 2010, 6:18am UTC](https://forum.servoy.com/t/certificates-java/12196/6 "2010-05-18T06:18:12Z")

</div>

Hi,

> Or you have to sign everything yourself (as a customer) with the same certificate.  
> Then you only will get it once.

How would you go about doing the above ?

---

<div class="post-metadata">

**Author:** ![IT2Be](https://avatars.discourse-cdn.com/v4/letter/i/dc4da7/32.png) [@IT2Be](https://forum.servoy.com/u/IT2Be)\
**Post date:** [May 18, 2010, 6:35am UTC](https://forum.servoy.com/t/certificates-java/12196/7 "2010-05-18T06:35:21Z")

</div>

> wvitpr:  
> Hi,
> 
> > Or you have to sign everything yourself (as a customer) with the same certificate.  
> > Then you only will get it once.
> 
> How would you go about doing the above ?

Read the sticky on the top in iServoy and read to the wiki pages.

> Harjo:  
> Oke, I was also thinking in that direction.  
> But how can this be done easily? We get all the jars now, (Servoy AND 3th party plugins) signed allready.  
> How do we remove the the existing certificates? and most of all, can we do that, without breaking something??
> 
> Is this something, that the signtester.jar could do?

It was something I wanted to advice you at first as well but there is no guarantee that it will not break a jar.  
Our jars won’t break but there are a couple of jars that will.  
Apart from that it is debatable if it is allowed to replace a signature…

---

<div class="post-metadata">

**Author:** ![jcompagner](https://yyz2.discourse-cdn.com/flex010/user_avatar/forum.servoy.com/jcompagner/32/4889_2.png) [@jcompagner](https://forum.servoy.com/u/jcompagner)\
**Post date:** [May 18, 2010, 6:43am UTC](https://forum.servoy.com/t/certificates-java/12196/8 "2010-05-18T06:43:36Z")

</div>

i think with the current java version (\>6\_u14) you can double sign the jars.  
(else you really have to remove it from the jar itself in the meta-inf dir)  
So if double signing works, you could try to sign all the jars in the application\_server dir with your own certificate.  
Just loop over all the jars in a script and execute jarsigner of the jdk for all the jars.

---

<div class="post-metadata">

**Author:** ![Harjo](https://yyz2.discourse-cdn.com/flex010/user_avatar/forum.servoy.com/harjo/32/4873_2.png) [@Harjo](https://forum.servoy.com/u/Harjo)\
**Post date:** [May 18, 2010, 7:07am UTC](https://forum.servoy.com/t/certificates-java/12196/9 "2010-05-18T07:07:06Z")

</div>

> jcompagner:  
> Just loop over all the jars in a script and execute jarsigner of the jdk for all the jars.

yeah, I’m an expert in that! ![:lol:]( "Laughing") ![:lol:]( "Laughing")

So nothing to expect from Servoy to ease things up?

---

<div class="post-metadata">

**Author:** ![jcarlos](https://avatars.discourse-cdn.com/v4/letter/j/46a35a/32.png) [@jcarlos](https://forum.servoy.com/u/jcarlos)\
**Post date:** [May 18, 2010, 7:43pm UTC](https://forum.servoy.com/t/certificates-java/12196/10 "2010-05-18T19:43:11Z")

</div>

I guess that we should start building for the browsers only. Good bye smarty client!

Can any of the super heroes in Servoy write and script that would do what Compagner suggested above?

---

<div class="post-metadata">

**Author:** ![ROCLASI](https://yyz2.discourse-cdn.com/flex010/user_avatar/forum.servoy.com/roclasi/32/4371_2.png) [@ROCLASI](https://forum.servoy.com/u/ROCLASI)\
**Post date:** [May 18, 2010, 8:00pm UTC](https://forum.servoy.com/t/certificates-java/12196/11 "2010-05-18T20:00:00Z")

</div>

Hi Johan,

> jcompagner:  
> Just loop over all the jars in a script and execute jarsigner of the jdk for all the jars.

Any syntax, example scripts, etc for us ?

---

<div class="post-metadata">

**Author:** ![Harjo](https://yyz2.discourse-cdn.com/flex010/user_avatar/forum.servoy.com/harjo/32/4873_2.png) [@Harjo](https://forum.servoy.com/u/Harjo)\
**Post date:** [May 18, 2010, 8:01pm UTC](https://forum.servoy.com/t/certificates-java/12196/12 "2010-05-18T20:01:33Z")

</div>

oke, seams I’m not the only one, struggling with this. ![:D]( "Very Happy")  
(And also not liking the multiple certificate windows)

---

<div class="post-metadata">

**Author:** ![Harjo](https://yyz2.discourse-cdn.com/flex010/user_avatar/forum.servoy.com/harjo/32/4873_2.png) [@Harjo](https://forum.servoy.com/u/Harjo)\
**Post date:** [May 18, 2010, 8:45pm UTC](https://forum.servoy.com/t/certificates-java/12196/13 "2010-05-18T20:45:00Z")

</div>

oke, surfing the internet, I found this: [http://mojo.codehaus.org/webstart/webst … en-plugin/](http://mojo.codehaus.org/webstart/webstart-maven-plugin/)

auto signing?  
Maybe someone of Servoy could take a look of this…

---

<div class="post-metadata">

**Author:** ![sbutler](https://yyz2.discourse-cdn.com/flex010/user_avatar/forum.servoy.com/sbutler/32/4393_2.png) [@sbutler](https://forum.servoy.com/u/sbutler)\
**Post date:** [May 18, 2010, 9:56pm UTC](https://forum.servoy.com/t/certificates-java/12196/14 "2010-05-18T21:56:38Z")

</div>

If you don’t like all of the dialogs, you can just unzip the jars, remove the signing stuff from the meta-inf directory, then rezip into the jar file, and then sign all of them with your own certificate. Then you just get one extra dialog.

---

<div class="post-metadata">

**Author:** ![ROCLASI](https://yyz2.discourse-cdn.com/flex010/user_avatar/forum.servoy.com/roclasi/32/4371_2.png) [@ROCLASI](https://forum.servoy.com/u/ROCLASI)\
**Post date:** [May 18, 2010, 9:58pm UTC](https://forum.servoy.com/t/certificates-java/12196/15 "2010-05-18T21:58:20Z")

</div>

_just_ ? For most Servoy developers there is no ‘just do this’ in this case.

---

<div class="post-metadata">

**Author:** ![sbutler](https://yyz2.discourse-cdn.com/flex010/user_avatar/forum.servoy.com/sbutler/32/4393_2.png) [@sbutler](https://forum.servoy.com/u/sbutler)\
**Post date:** [May 18, 2010, 10:16pm UTC](https://forum.servoy.com/t/certificates-java/12196/16 "2010-05-18T22:16:09Z")

</div>

1. First unzip the jar. Place it in its own folder so it is easy to work with. Open terminal or some command line and navigate to where you placed the plugin jar. Run this command

```auto
jar -xvf pluginname.jar

```

1. Then remove the signing stuff from when it was previously signed. You should see 2 files in the META-INF folder after you ran the previous command. One ends in “.RSA” and the other in “.SF”. Remove both of the files

2. Zip the jar back up. First remove the previous pluginname.jar from the folder so it doesn’t get zipped into itself. Then run this command (again inside of the directory where it was previously unzipped)

```auto
jar -cf pluginname.jar *

```

1. Now you have pluginname.jar that is unsigned. Next resign with your own certificate. Step-by-step instructions at my site: [http://www.servoyguy.com/knowledge\_base … \_and\_beans](http://www.servoyguy.com/knowledge_base/deployment/how_do_i_sign_my_servoy_plugins_and_beans)

The place I found to purchase my certificate was only $99 per year, and cheaper when you buy multi-year.

---

<div class="post-metadata">

**Author:** ![jcarlos](https://avatars.discourse-cdn.com/v4/letter/j/46a35a/32.png) [@jcarlos](https://forum.servoy.com/u/jcarlos)\
**Post date:** [May 18, 2010, 10:18pm UTC](https://forum.servoy.com/t/certificates-java/12196/17 "2010-05-18T22:18:48Z")

</div>

WOW. Thanks!

I think we should have a protocol or code of good practice that recognizes the owner or ‘creator’ of the original jars. Any idea on how this new single certificate should reflect the various original owners?

---

<div class="post-metadata">

**Author:** ![sbutler](https://yyz2.discourse-cdn.com/flex010/user_avatar/forum.servoy.com/sbutler/32/4393_2.png) [@sbutler](https://forum.servoy.com/u/sbutler)\
**Post date:** [May 18, 2010, 10:26pm UTC](https://forum.servoy.com/t/certificates-java/12196/18 "2010-05-18T22:26:29Z")

</div>

The JNLP files still show who the original owner is (will be displayed as the JARS download). However the SSL Cert will determine what shows up in the dialog when the user is asked to accept the security, etc. So, by signing someone else’s plugin, you’re essentially vouching for the developer to tell your users that the code is safe to run.

---

<div class="post-metadata">

**Author:** ![Harjo](https://yyz2.discourse-cdn.com/flex010/user_avatar/forum.servoy.com/harjo/32/4873_2.png) [@Harjo](https://forum.servoy.com/u/Harjo)\
**Post date:** [May 19, 2010, 7:20am UTC](https://forum.servoy.com/t/certificates-java/12196/19 "2010-05-19T07:20:53Z")

</div>

Scott, thanks for your reply & explanation, but  
we are talking about 201 jar files (every jar I could find under application\_server) ![:shock:]( "Shocked")  
AND with every update of Servoy or 3th party plugin/bean, you have to do it again, all by hand… ![:?]( "Confused")

This is undoable IMHO…

---

<div class="post-metadata">

**Author:** ![michel](https://avatars.discourse-cdn.com/v4/letter/m/ea666f/32.png) [@michel](https://forum.servoy.com/u/michel)\
**Post date:** [May 19, 2010, 7:52am UTC](https://forum.servoy.com/t/certificates-java/12196/20 "2010-05-19T07:52:35Z")

</div>

Maybe this ant-macro can do the job [http://frank.neatstep.com/node/29](http://frank.neatstep.com/node/29).

If so, we can also make an ant-macro that does the signing with our own certificate. Then we could to this from within eclipse and it would be a piece of cake…

[Next page](https://forum.servoy.com/t/certificates-java/12196.md?page=2)
