<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Tork Wrench &#187; jre</title>
	<atom:link href="http://www.torkwrench.com/tag/jre/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.torkwrench.com</link>
	<description>Things I learnt today, working on IBM Lotus Web Content Management.</description>
	<lastBuildDate>Tue, 17 Aug 2010 06:50:47 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.0.1</generator>
		<item>
		<title>The security certificate &#8220;America Online Root Certification Authority 2&#8243; has a public key of length greater than 2048 bit.</title>
		<link>http://www.torkwrench.com/2009/10/15/the-security-certificate-america-online-root-certification-authority-2-has-a-public-key-of-length-greater-than-2048-bit/</link>
		<comments>http://www.torkwrench.com/2009/10/15/the-security-certificate-america-online-root-certification-authority-2-has-a-public-key-of-length-greater-than-2048-bit/#comments</comments>
		<pubDate>Wed, 14 Oct 2009 14:05:33 +0000</pubDate>
		<dc:creator>Graham</dc:creator>
				<category><![CDATA[random]]></category>
		<category><![CDATA[citrix]]></category>
		<category><![CDATA[java]]></category>
		<category><![CDATA[jre]]></category>
		<category><![CDATA[metaframe]]></category>
		<category><![CDATA[security]]></category>

		<guid isPermaLink="false">http://www.torkwrench.com/?p=155</guid>
		<description><![CDATA[I&#8217;m doing a bit of work for a client and they run this crazy Citrix Metaframe thing, which I&#8217;ve heard of but never used before. It&#8217;s like a remote access tool / website wrapped in java applets and special clients &#8230; <a href="http://www.torkwrench.com/2009/10/15/the-security-certificate-america-online-root-certification-authority-2-has-a-public-key-of-length-greater-than-2048-bit/">Continue reading <span class="meta-nav">&#8594;</span></a>]]></description>
			<content:encoded><![CDATA[<p>I&#8217;m doing a bit of work for a client and they run this crazy Citrix Metaframe thing, which I&#8217;ve heard of but never used before. It&#8217;s like a remote access tool / website wrapped in java applets and special clients and all sorts of other whizbangerry.</p>
<p>But I had a problem connecting to it. It would load a java applet and then Java would die when initializing with the following error. I&#8217;m running the latest Sun Java 6 u16.</p>
<div class="codecolorer-container text dawn" style="overflow:auto;white-space:nowrap;border:1px solid #9F9F9F;width:435px;"><div class="text codecolorer" style="padding:5px;font:normal 12px/1.4em Monaco, Lucida Console, monospace;white-space:nowrap">A local security certificate could not be loaded. (error code: 7)<br />
&nbsp; &nbsp; at com.citrix.sdk.security.ssl.ConnectionModel.addCACertificate(ConnectionModel.java)<br />
&nbsp; &nbsp; at sun.reflect.NativeMethodAccessorImpl.invoke0(Native Method)<br />
&nbsp; &nbsp; at sun.reflect.NativeMethodAccessorImpl.invoke(NativeMethodAccessorImpl.java:39)<br />
&nbsp; &nbsp; at sun.reflect.DelegatingMethodAccessorImpl.invoke(DelegatingMethodAccessorImpl.java:25)<br />
&nbsp; &nbsp; at java.lang.reflect.Method.invoke(Method.java:597)<br />
&nbsp; &nbsp; at com.citrix.client.io.net.ip.m.h(Unknown Source)<br />
&nbsp; &nbsp; at com.citrix.client.io.net.ip.proxy.i.(Unknown Source)<br />
&nbsp; &nbsp; at com.citrix.client.io.net.ip.g.a(Unknown Source)<br />
&nbsp; &nbsp; at com.citrix.client.io.net.ip.o.a(Unknown Source)<br />
&nbsp; &nbsp; at com.citrix.client.module.td.tcp.TCPTransportDriver.t(Unknown Source)<br />
&nbsp; &nbsp; at com.citrix.client.module.td.TransportDriver.run(Unknown Source)<br />
&nbsp; &nbsp; at java.lang.Thread.run(Thread.java:619)<br />
Caused by: The SSL cryptography library failed. The security certificate &quot;America Online Root Certification Authority 2&quot; has a public key of length greater than 2048 bit.<br />
&nbsp; &nbsp; at com.citrix.sdk.security.certificate.X509CertificateLoader.loadCertificates(X509CertificateLoader.java)</div></div>
<p>It&#8217;s about identical to this <a href="https://answers.launchpad.net/ubuntu/+question/48682">unsolved post</a> at Ubuntu launchpad too. The certificates for a simple client JRE are stored in the cacerts file which lives in jre/lib/security/cacerts . It looks as if the root certificate for AOL is too long or recently updated or something and it&#8217;s not playing nicely with MetaFrame. So somehow we have to ditch that root cert. It would only really be a problem if we are unlucky enough to have our certificate signed by that root CA.</p>
<p>I assumed that MetaFrame worked on older jres and that the problem is that I am using a brand new one. So luckily Sun keep an archive of old JDKs and JREs <a href="http://java.sun.com/products/archive/">here.</a> So it is quite simple, download an install an old JRE (I got 5u1) and rip the cacerts file out of there and dump it into your new JRE&#8217;s directory and try it again. Worked like a charm for me. You probably don&#8217;t want to do this permanently (I guess they updated the cacerts file for a reason?) but if you really need to log into MetaFrame, it&#8217;ll do.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.torkwrench.com/2009/10/15/the-security-certificate-america-online-root-certification-authority-2-has-a-public-key-of-length-greater-than-2048-bit/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
	</channel>
</rss>
