<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Instalasi EJBCA 6.10.1.2 pada Centos 7 - GoBlog</title>
	<atom:link href="https://blog.goreinnamah.com/blog/tag/instalasi-ejbca-6-10-1-2-pada-centos-7/feed/" rel="self" type="application/rss+xml" />
	<link>https://blog.goreinnamah.com</link>
	<description>LOG ALL LOGS</description>
	<lastBuildDate>Mon, 02 Dec 2019 08:26:35 +0000</lastBuildDate>
	<language>en-US</language>
	<sy:updatePeriod>
	hourly	</sy:updatePeriod>
	<sy:updateFrequency>
	1	</sy:updateFrequency>
	

<image>
	<url>https://blog.goreinnamah.com/wp-content/uploads/2017/01/cropped-1-150x150.jpg</url>
	<title>Instalasi EJBCA 6.10.1.2 pada Centos 7 - GoBlog</title>
	<link>https://blog.goreinnamah.com</link>
	<width>32</width>
	<height>32</height>
</image> 
	<item>
		<title>Instalasi EJBCA 6.10.1.2 dengan HSM Luna 7 pada CentOS 7</title>
		<link>https://blog.goreinnamah.com/blog/2018/03/26/instalasi-ejbca-6-10-1-2/</link>
					<comments>https://blog.goreinnamah.com/blog/2018/03/26/instalasi-ejbca-6-10-1-2/#comments</comments>
		
		<dc:creator><![CDATA[Darius Go Reinnamah]]></dc:creator>
		<pubDate>Mon, 26 Mar 2018 11:33:58 +0000</pubDate>
				<category><![CDATA[Information Technology]]></category>
		<category><![CDATA[EJBCA 6.10.1.2]]></category>
		<category><![CDATA[Instalasi EJBCA 6.10.1.2]]></category>
		<category><![CDATA[Instalasi EJBCA 6.10.1.2 dan Wildfly 10 pada Centos 7]]></category>
		<category><![CDATA[Instalasi EJBCA 6.10.1.2 pada Centos 7]]></category>
		<guid isPermaLink="false">http://blog.goreinnamah.com/?p=2064</guid>

					<description><![CDATA[<p>Setelah sukses membahas cara menghubungkan EJBCA 6.3.1.1 yang berjalan di atas CentOS 7 dengan HSM PCIE di postingan ini, sekarang[...]</p>
<p>The post <a href="https://blog.goreinnamah.com/blog/2018/03/26/instalasi-ejbca-6-10-1-2/">Instalasi EJBCA 6.10.1.2 dengan HSM Luna 7 pada CentOS 7</a> first appeared on <a href="https://blog.goreinnamah.com">GoBlog</a>.</p>]]></description>
										<content:encoded><![CDATA[<p style="text-align: justify;">Setelah sukses membahas cara menghubungkan EJBCA 6.3.1.1 yang berjalan di atas CentOS 7 dengan HSM PCIE di <a href="http://blog.goreinnamah.com/blog/2017/12/01/instalasi-ejbca-6-3-1-1-dengan-hsm-luna-pcie-pada-centos-7/"><strong>postingan ini</strong></a>, sekarang saya mau membagikan cara untuk melakukan instalasi EJBCA 6.10.1.2 di atas CentOS 7 yang terhubung dengan HSM Luna 7.</p>
<p style="text-align: justify;">Sejak versi EJBCA di atas versi 6.4.0, kita tidak lagi bisa menggunakan JBoss 7.1.1 sebagai web-servernya dan OpenJDK-7 sebagai Java Environment-nya. Sebagai gantinya, kita bisa menggunakan WildFly 10.0.0 dan juga OpenJDK-8.</p>
<p style="text-align: justify;">Berikut ini beberapa hal yang perlu kalian persiapkan untuk mencoba tutorial kali ini:</p>
<h3 style="text-align: justify;"><strong>Alat dan Bahan</strong></h3>
<ol style="text-align: justify;">
<li>EJBCA 6.10.1.2 → Download <a href="https://excellmedia.dl.sourceforge.net/project/ejbca/ejbca6/ejbca_6_10_0/ejbca_ce_6_10_1_2.zip"><strong>DI SINI</strong></a></li>
<li>WildFly 10.0.0. Final → Download <a href="http://download.jboss.org/wildfly/10.0.0.Final/wildfly-10.0.0.Final.zip"><strong>DI SINI</strong></a></li>
<li>Software Client &amp; SDK Safenet HSM v7.0.0 → Download <strong><a href="https://www.dropbox.com/s/9shwbk3dpr17adc/610-013144-003_SW_CLIENT_SDK_SAFENET_HSM_V7.0.0-956_LINUX.zip?dl=0">DI SINI</a></strong></li>
<li>MariaDB 10.2 (Stable) → Cara install <a href="https://downloads.mariadb.org/mariadb/repositories/#mirror=poliwangi&amp;distro=CentOS&amp;distro_release=centos7-amd64--centos7&amp;version=10.2"><strong>DI SINI</strong></a></li>
<li>MariaDB Java Client 2.1.0 → Download <a href="http://central.maven.org/maven2/org/mariadb/jdbc/mariadb-java-client/2.1.0/mariadb-java-client-2.1.0.jar"><strong>DI SINI</strong></a></li>
<li>OpenJDK 8</li>
<li>JCE Policy 8 → Download <a href="http://download.oracle.com/otn-pub/java/jce/8/jce_policy-8.zip?AuthParam=1521531388_8329e84a9d4f3bdefb8c877c2832cccc"><strong>DI SINI</strong></a></li>
</ol>
<h3 style="text-align: justify;"><strong>Spek Server yang Digunakan</strong></h3>
<ol style="text-align: justify;">
<li style="text-align: justify;">RAM = 2 GB</li>
<li style="text-align: justify;">CPUs = 4</li>
<li style="text-align: justify;">Harddisk = 50 GB</li>
</ol>
<h3 style="text-align: justify;">IP Server</h3>
<ul style="text-align: justify;">
<li>CentOS 7 : 192.168.1.12</li>
<li>HSM LUNA 7: 192.168.1.2</li>
</ul>
<h2 style="text-align: justify;"><strong>Tahap Awal</strong></h2>
<h3 style="text-align: justify;"><strong>NTLs &amp; Membuat partisi pada HSM</strong></h3>
<p style="text-align: justify;">Sebelum masuk ke dalam EJBCA 6.10.1.2, terlebih dahulu kita harus menghubungkan CentOS 7 dengan HSM Luna 7 melalui <strong><em>Network Trust Links. </em></strong>Untuk menciptakan koneksi tersebut, Silahkan liat tutorialnya <a href="http://blog.goreinnamah.com/blog/2018/03/02/hsm-luna-7-dan-centos-7-dengan-ntl/"><strong>DI SINI</strong></a>.</p>
<h3 style="text-align: justify;"><strong>Konfigurasi SafeNet Chrystoki</strong></h3>
<p style="text-align: justify;">Untuk menghubungkan HSM dengan OS, terlebih dahulu kita harus mengubah sedikit konfigurasi yang ada pada <strong>/etc/Chrystoki.conf </strong>agar nantinya Luna 7 dapat berkomunikasi dengan OS.</p>
<p style="text-align: justify;">Beberapa hal yang perlu diubah adalah:</p>
<ul style="text-align: justify;">
<li>Library LibUNIX64 untuk Chrystoki2 dan libshim</li>
<li>Penambahan Application Instance</li>
<li>Penambahan OneBaseSlotId</li>
</ul>
<p style="text-align: justify;">Ubah file <strong>/etc/Chrystoki.conf </strong>dan tambahkan konfigurasi berikut:</p>
<pre><span style="color: #ff0000;"><strong>Chrystoki2 = {</strong></span>
<span style="color: #ff0000;"><strong>LibUNIX64 =/usr/safenet/lunaclient/lib/libCryptoki2_64.so ;</strong></span>
<span style="color: #ff0000;"><strong>}
</strong></span>
<span style="color: #ff0000;"><strong>Shim2 = {</strong></span>
<span style="color: #ff0000;"><strong>LibUNIX64 =/usr/safenet/lunaclient/lib/libshim.so;</strong></span>
<span style="color: #ff0000;"><strong>}
</strong></span>
<span style="color: #ff0000;"><strong>Misc = {</strong></span> 
<span style="color: #ff0000;"><strong>ApplicationInstance=SA5_COMPATIBILITY;</strong></span>
<span style="color: #ff0000;"><strong>FunctionBindLevel=2;</strong></span> 
<span style="color: #ff0000;"><strong>ProtectedAuthenticationPathFlagStatus = 1;</strong></span>
<span style="color: #ff0000;"><strong>}</strong></span></pre>
<p style="text-align: justify;">Di bagian paling bawah, tambahkan:</p>
<pre><span style="color: #ff0000;"><strong>}</strong></span>
<span style="color: #ff0000;"><strong>Presentation = {</strong></span>
<span style="color: #ff0000;"><strong>OneBaseSlotId =1;</strong></span>
<span style="color: #ff0000;"><strong>}</strong></span></pre>
<figure id="attachment_2099" aria-describedby="caption-attachment-2099" style="width: 660px" class="wp-caption aligncenter"><img fetchpriority="high" decoding="async" class="size-full wp-image-2099" src="http://blog.goreinnamah.com/wp-content/uploads/2018/03/23-Chrystoki-conf.png" alt="" width="660" height="562" srcset="https://blog.goreinnamah.com/wp-content/uploads/2018/03/23-Chrystoki-conf.png 660w, https://blog.goreinnamah.com/wp-content/uploads/2018/03/23-Chrystoki-conf-300x255.png 300w" sizes="(max-width: 660px) 100vw, 660px" /><figcaption id="caption-attachment-2099" class="wp-caption-text">Perubahan pada /etc/Chrystoki conf</figcaption></figure>
<h3 style="text-align: justify;"><strong>Pengaturan FQDN</strong></h3>
<p style="text-align: justify;">Pertama kali yang dilakukan adalah Setting FQDN-nya terlebih dahulu, caranya:</p>
<pre><span style="color: #ff0000;"><strong>vi /etc/hosts</strong></span></pre>
<figure id="attachment_2087" aria-describedby="caption-attachment-2087" style="width: 293px" class="wp-caption aligncenter"><img decoding="async" class="size-full wp-image-2087" src="http://blog.goreinnamah.com/wp-content/uploads/2018/03/Screenshot-from-2018-03-22-16-55-27.png" alt="" width="293" height="36" /><figcaption id="caption-attachment-2087" class="wp-caption-text">setting FQDN</figcaption></figure>
<h3 style="text-align: justify;"><strong>Konfigurasi Firewall</strong></h3>
<p style="text-align: justify;">EJBCA 6.10.1.2 menggunakan port 8080, 8442, 8443 untuk servis CA. Yang lainnya merupakan port internal (3306 untuk MySQL, 9990 untuk JBoss Admin, dll). Kita tidak perlu mengubah port tersebut pada aplikasi EJBCA 6.10.1.2 nya secara langsung.</p>
<p style="text-align: justify;">Jika kita mau menggunakan port standar yang digunakan WEB, silahkan atur Port Forwarding pada iptables. Kita bisa melakukannya dengan cara:</p>
<pre><span style="color: #ff0000;"><strong>vi /etc/sysconfig/iptables</strong></span></pre>
<p style="text-align: justify;">kemudian masukkan:</p>
<h4 style="text-align: justify;">#### Start Iptables ####</h4>
<p style="text-align: justify;">*<strong>filter</strong><br />
<strong>:INPUT ACCEPT [0:0]</strong><br />
<strong>:FORWARD ACCEPT [0:0]</strong><br />
<strong>:OUTPUT ACCEPT [34:14652]</strong><br />
<strong>-A INPUT -p tcp -m tcp –dport 8008 -j ACCEPT<br />
</strong><strong>-A INPUT -p tcp -m tcp &#8211;dport 4447 -j ACCEPT</strong><br />
<strong>-A INPUT -m state –state RELATED,ESTABLISHED -j ACCEPT</strong><br />
<strong>-A INPUT -p icmp -j ACCEPT</strong><br />
<strong>-A INPUT -i lo -j ACCEPT</strong><br />
<strong>-A INPUT -i eth0 -p tcp -m state –state NEW -m tcp –dport 8080 -m mark –mark 0x64 -j ACCEPT</strong><br />
<strong>-A INPUT -p tcp -m state –state NEW -m tcp –dport 80 -j ACCEPT</strong><br />
<strong>-A INPUT -p tcp -m state –state NEW -m tcp –dport 8080 -j ACCEPT</strong><br />
<strong>-A INPUT -p tcp -m state –state NEW -m tcp –dport 8443 -j ACCEPT</strong><br />
<strong>-A INPUT -p tcp -m state –state NEW -m tcp –dport 8442 -j ACCEPT</strong><br />
<strong>-A INPUT -p tcp -m state –state NEW -m tcp –dport 443 -j ACCEPT</strong><br />
<strong>-A INPUT -p tcp -m state –state NEW -m tcp –dport 22 -j ACCEPT</strong><br />
<strong>-A INPUT -j REJECT –reject-with icmp-host-prohibited</strong><br />
<strong>-A FORWARD -j REJECT –reject-with icmp-host-prohibited</strong><br />
<strong>COMMIT</strong></p>
<p style="text-align: justify;"><strong>*nat</strong><br />
<strong>:PREROUTING ACCEPT [1928198:538190860]</strong><br />
<strong>:POSTROUTING ACCEPT [239877:14576705]</strong><br />
<strong>:OUTPUT ACCEPT [239877:14576705]</strong><br />
<strong>-A PREROUTING -i eth0 -p tcp -m tcp –dport 80 -m mark –mark 0x64 -j DNAT –to-destination :8080</strong><br />
<strong>COMMIT</strong></p>
<p style="text-align: justify;"><strong>*mangle</strong><br />
<strong>:PREROUTING ACCEPT [5793867:3540661671]</strong><br />
<strong>:INPUT ACCEPT [5504145:3514609021]</strong><br />
<strong>:FORWARD ACCEPT [0:0]</strong><br />
<strong>:OUTPUT ACCEPT [4546890:3055306048]</strong><br />
<strong>:POSTROUTING ACCEPT [4546890:3055306048]</strong><br />
<strong>-A PREROUTING -i eth0 -p tcp -m tcp –dport 80 -j MARK –set-xmark 0x64/0xffffffff</strong><br />
<strong>COMMIT</strong></p>
<figure id="attachment_1576" aria-describedby="caption-attachment-1576" style="width: 893px" class="wp-caption aligncenter"><img decoding="async" class="size-full wp-image-1576" src="http://blog.goreinnamah.com/wp-content/uploads/2017/11/500.png" alt="" width="893" height="637" srcset="https://blog.goreinnamah.com/wp-content/uploads/2017/11/500.png 893w, https://blog.goreinnamah.com/wp-content/uploads/2017/11/500-300x214.png 300w, https://blog.goreinnamah.com/wp-content/uploads/2017/11/500-768x548.png 768w" sizes="(max-width: 893px) 100vw, 893px" /><figcaption id="caption-attachment-1576" class="wp-caption-text">Konfigurasi IPTables</figcaption></figure>
<p style="text-align: justify;"> Setelah melakuan konfigurasi, untuk mengaktifkan iptables tersebut maka lakukan perintah berikut:</p>
<pre><span style="color: #ff0000;"><strong>sh -c 'iptables-restore -t &lt; /etc/sysconfig/iptables'</strong></span></pre>
<h3 style="text-align: justify;">Instalasi beberapa paket</h3>
<p style="text-align: justify;">Seperti namanya <strong>EJBCA (Enterprise Java Bean Certification Authority)</strong>, maka kita membutuhkan java agar software ini dapat <em>running</em>. Versi OpenJDK yang harus diinstal adalah versi 8. Caranya:</p>
<pre><span style="color: #ff0000;"><strong>yum -y install java-1.8.0-openjdk java-1.8.0-openjdk-devel</strong></span></pre>
<figure id="attachment_2090" aria-describedby="caption-attachment-2090" style="width: 1095px" class="wp-caption aligncenter"><img loading="lazy" decoding="async" class="size-full wp-image-2090" src="http://blog.goreinnamah.com/wp-content/uploads/2018/03/1-install-java8.png" alt="" width="1095" height="618" srcset="https://blog.goreinnamah.com/wp-content/uploads/2018/03/1-install-java8.png 1095w, https://blog.goreinnamah.com/wp-content/uploads/2018/03/1-install-java8-300x169.png 300w, https://blog.goreinnamah.com/wp-content/uploads/2018/03/1-install-java8-768x433.png 768w, https://blog.goreinnamah.com/wp-content/uploads/2018/03/1-install-java8-1024x578.png 1024w" sizes="auto, (max-width: 1095px) 100vw, 1095px" /><figcaption id="caption-attachment-2090" class="wp-caption-text">Instalasi OpenJDK 8</figcaption></figure>
<p style="text-align: justify;">Setelah selesai melakukan instalasi <strong>openjdk-8</strong>, tahapan selanjutnya adalah memilih <strong>java-1.8.0</strong> tadi sebagai <em>default. </em>Caranya:</p>
<pre><span style="color: #ff0000;"><strong>alternatives --config java</strong></span></pre>
<figure id="attachment_2091" aria-describedby="caption-attachment-2091" style="width: 851px" class="wp-caption aligncenter"><img loading="lazy" decoding="async" class="size-full wp-image-2091" src="http://blog.goreinnamah.com/wp-content/uploads/2018/03/2-pilih-java.png" alt="" width="851" height="231" srcset="https://blog.goreinnamah.com/wp-content/uploads/2018/03/2-pilih-java.png 851w, https://blog.goreinnamah.com/wp-content/uploads/2018/03/2-pilih-java-300x81.png 300w, https://blog.goreinnamah.com/wp-content/uploads/2018/03/2-pilih-java-768x208.png 768w" sizes="auto, (max-width: 851px) 100vw, 851px" /><figcaption id="caption-attachment-2091" class="wp-caption-text">Memeriksa versi java yang digunakan</figcaption></figure>
<p style="text-align: justify;">dan untuk lebih memastikan agar kita tidak salah memilih versi java yang akan kita gunakan, jalankan perintah:</p>
<pre><span style="color: #ff0000;"><strong>java -version</strong></span></pre>
<p style="text-align: justify;">Setelah itu, kita akan sedikit me-<em>replace</em> beberapa file yang ada di <strong>/usr/lib/jvm/java-1.8.0-openjdk/jre/lib/security. </strong>2 file yang harus di <em>replace </em>adalah <strong>local_policy.jar </strong>dan <strong>US_export_policy.jar.</strong></p>
<p style="text-align: justify;">Bagaimana cara me-<em>replace-</em>nya?</p>
<ol style="text-align: justify;">
<li>Download JCE pada link yang sudah saya sertakan di atas.</li>
<li>Setelah berhasil di download, ekstrak file tersebut dan kamu akan menemukan sebuah folder bernama <strong>jce_policy-8. </strong>Cara ekstraknya adalah seperti berikut:
<pre><span style="color: #ff0000;"><b>cd /home/user/Downloads
unzip jce_policy-8.zip</b></span></pre>
</li>
<li>Setelah berhasil di ekstrak, copy-kan 2 file yang sudah saya sebutkan di atas ke dalam folder <strong>/usr/lib/jvm/java-1.8.0-openjdk/jre/lib/security. </strong>Caranya:
<pre><span style="color: #ff0000;"><strong>cp jce_policy-8/UnlimitedJCEPolicyJDK8/local_policy.jar</strong> </span><strong><span style="color: #ff0000;">/usr/lib/jvm/java-1.8.0-openjdk/jre/lib/security</span>
<span style="color: #ff0000;">cp jce_policy-8/UnlimitedJCEPolicyJDK8/US_export_policy.jar /usr/lib/jvm/java-1.8.0-openjdk/jre/lib/security</span>
</strong></pre>
</li>
</ol>
<p style="text-align: justify;">Berikutnya kita akan meng-install beberapa paket tambahan yaitu <strong>ant, ant-antlr</strong>, dan <strong>unzip</strong>. Caranya:</p>
<pre><span style="color: #ff0000;"><strong>yum install ant ant-antlr unzip</strong></span></pre>
<figure id="attachment_1581" aria-describedby="caption-attachment-1581" style="width: 772px" class="wp-caption aligncenter"><img loading="lazy" decoding="async" class="size-full wp-image-1581" src="http://blog.goreinnamah.com/wp-content/uploads/2017/11/502.png" alt="" width="772" height="321" srcset="https://blog.goreinnamah.com/wp-content/uploads/2017/11/502.png 772w, https://blog.goreinnamah.com/wp-content/uploads/2017/11/502-300x125.png 300w, https://blog.goreinnamah.com/wp-content/uploads/2017/11/502-768x319.png 768w" sizes="auto, (max-width: 772px) 100vw, 772px" /><figcaption id="caption-attachment-1581" class="wp-caption-text">instalasi ant ant-antlr unzip</figcaption></figure>
<h3 style="text-align: justify;"><strong>Instalasi dan Konfigurasi MariaDB</strong></h3>
<p style="text-align: justify;">Tahap berikutnya kita harus melakukan instalasi <em>database</em> kemudian konfigurasi. Konfigurasi yang saya lakukan disini hanyalah konfigurasi biasa tanpa <em>s</em><em>ecurity </em>yang cukup baik (hanya untuk keperluan percobaan). Untuk kalian yang ingin mengimplementasikannya di production, pastikan mengamankan direktori mysql dan meng-<em>update </em><strong>/etc/mysql/my.cnf</strong> sebelum menjalankan service database. Konfigurasi ini juga menggunakan <strong>utf-8 encoding</strong> yang menjadi syarat dari EJBCA 6.10.1.2. Mari kita mulai instalasinya terlebih dahulu:</p>
<p style="text-align: justify;">Untuk melakukan instalasi mariaDB 10.2 (stable) pada CentOS 7. Tambahkan dulu repositorinya dengan cara:</p>
<pre><strong><code><span style="color: #ff0000;">#</span></code><span style="color: #ff0000;"> MariaDB 10.2 CentOS repository list - created 2017-11-24 07:32 UTC <code>#</code> <a style="color: #ff0000;" href="http://downloads.mariadb.org/mariadb/repositories/">http://downloads.mariadb.org/mariadb/repositories/</a> </span></strong><span style="color: #ff0000;"> <strong>[mariadb] </strong> <strong>name = MariaDB </strong> <strong>baseurl = <a style="color: #ff0000;" href="http://yum.mariadb.org/10.2/centos7-amd64">http://yum.mariadb.org/10.2/centos7-amd64</a> </strong> <strong>gpgkey= <a style="color: #ff0000;" href="https://yum.mariadb.org/RPM-GPG-KEY-MariaDB">https://yum.mariadb.org/RPM-GPG-KEY-MariaDB</a> </strong> <strong>gpgcheck=1</strong></span></pre>
<p style="text-align: justify;">Setelah itu update paket CentOS dan install MariaDB 10.2. Caranya:</p>
<pre><span style="color: #ff0000;"><strong>yum update</strong>
<strong>yum install MariaDB-server MariaDB-client</strong></span></pre>
<p style="text-align: justify;">Setelah MariaDB selesai terinstal, tahap selanjutnya adalah mengubah beberapa konfigurasi yang ada pada <em>my.cnf.</em> Salah satunya adalah menambahkan <em><strong>binlog_format=row</strong>. </em>Kalau menggunakan MariaDB, kemungkinan servicenya menolak untuk berjalan karena InnoDB tidak bisa memproses log binary-nya. Tambahkan <em>binlog_format=row </em>seperti konfigurasi di bawah untuk memecahkan masalah tersebut. Tambahkan juga beberapa item lain yang belum ada di <em>my.cnf  </em>kalian ya.</p>
<pre><span style="color: #ff0000;"><strong>vi /etc/mysql/my.cnf</strong></span></pre>
<pre><strong>[client]
 port                    = 3306
 socket                  = /var/run/mysqld/mysqld.sock
 default-character-set   = utf8

[mysqld]
 user                    = mysql
 socket                  = /var/run/mysqld/mysqld.sock
 port                    = 3306
 basedir                 = /usr
 datadir                 = /var/lib/mysql
 tmpdir                  = /tmp
 lc_messages_dir         = /usr/share/mysql
 lc_messages             = en_US
 skip-external-locking

#UTF-8
 character-set-server    = utf8
 collation-server        = utf8_unicode_ci
 init-connect            = 'SET NAMES utf8'

bind-address             = 127.0.0.1
#Binary Logging
 log_bin                 = /var/log/mysql/mariadb-bin
 log_bin_index           = /var/log/mysql/mariadb-bin.index
 binlog_format           = ROW
 expire_logs_days        = 10
 max_binlog_size         = 100M
 server-id               = 1
 slow_query_log_file     = /var/log/mysql/mariadb-slow.log
 long_query_time         = 10</strong></pre>
<p style="text-align: justify;">Setelah beres, jangan lupa untuk mengubah kepemilikan my.cnf tersebut menjadi milik mysql. caranya:</p>
<pre><span style="color: #ff0000;"><strong>sudo chown mysql:mysql /etc/mysql/my.cnf</strong></span></pre>
<p style="text-align: justify;">Pada konfigurasi <em>my.cnf </em>di atas, kita memasukkan lokasi untuk meletakkan log. Untuk mengamankan log tersebut (karena log tersebut mengandung data sertifikat kita), maka kita harus mengatur izin yang terbatas soal siapa yang bisa mengaksesnya. Caranya:</p>
<pre><span style="color: #ff0000;"><strong>chown -R mysql:mysql /var/log/mysql
chmod -R 750 /var/log/mysql/</strong></span></pre>
<p style="text-align: justify;">Setelah MariaDB terinstall dan konfigurasi dilakukan, tahap selanjutnya adalah me-<em>restart service</em> database dan membuat <em>database</em> untuk EJBCA 6.10.1.2 dan juga sebuah user untuk mengakses <em>database</em> EJBCA 6.10.1.2 tersebut (jangan menggunakan user root untuk EJBCA 6.10.1.2 dalam mengakses <em>database</em>-nya). Caranya:</p>
<pre><span style="color: #ff0000;"><strong>service mysql restart</strong></span></pre>
<pre><span style="color: #ff0000;"><strong>mysql -u root -p
create database &lt;nama_db&gt; </strong><strong>CHARACTER SET utf8 COLLATE utf8_general_ci;</strong></span></pre>
<pre><span style="color: #ff0000;"><strong>; grant all privileges on &lt;nama_db&gt;.* to '&lt;user&gt;'@'&lt;ip&gt;' identified by '&lt;password&gt;'; flush privileges; exit</strong></span></pre>
<figure id="attachment_1458" aria-describedby="caption-attachment-1458" style="width: 1560px" class="wp-caption alignnone"><img loading="lazy" decoding="async" class="size-full wp-image-1458" src="http://blog.goreinnamah.com/wp-content/uploads/2017/10/13.png" alt="" width="1560" height="939" srcset="https://blog.goreinnamah.com/wp-content/uploads/2017/10/13.png 1560w, https://blog.goreinnamah.com/wp-content/uploads/2017/10/13-300x181.png 300w, https://blog.goreinnamah.com/wp-content/uploads/2017/10/13-768x462.png 768w, https://blog.goreinnamah.com/wp-content/uploads/2017/10/13-1024x616.png 1024w" sizes="auto, (max-width: 1560px) 100vw, 1560px" /><figcaption id="caption-attachment-1458" class="wp-caption-text">Create db untuk EJBCA 6.10.1.2 dan user untuk mengaksesnya</figcaption></figure>
<p style="text-align: justify;">Kalau sudah, lakukan verifikasi dengan cara login dengan menggunakan user yang baru saja kita buat tadi dan test aksesnya. Caranya:</p>
<pre><span style="color: #ff0000;"><strong>mysql -u &lt;user_db&gt; -p
use &lt;db_ejbca&gt;;
show grants for '&lt;user_db&gt;@'&lt;ip&gt;';
exit</strong></span></pre>
<figure id="attachment_1459" aria-describedby="caption-attachment-1459" style="width: 1555px" class="wp-caption alignnone"><img loading="lazy" decoding="async" class="size-full wp-image-1459" src="http://blog.goreinnamah.com/wp-content/uploads/2017/10/14.png" alt="" width="1555" height="747" srcset="https://blog.goreinnamah.com/wp-content/uploads/2017/10/14.png 1555w, https://blog.goreinnamah.com/wp-content/uploads/2017/10/14-300x144.png 300w, https://blog.goreinnamah.com/wp-content/uploads/2017/10/14-768x369.png 768w, https://blog.goreinnamah.com/wp-content/uploads/2017/10/14-1024x492.png 1024w" sizes="auto, (max-width: 1555px) 100vw, 1555px" /><figcaption id="caption-attachment-1459" class="wp-caption-text">test user yang baru dibuat untuk database EJBCA 6.10.1.2</figcaption></figure>
<p style="text-align: justify;">Pada bagian akhir, restart service database tersebut dengan perintah:</p>
<pre><span style="color: #ff0000;"><strong>service mysql restart</strong></span></pre>
<h5 style="text-align: justify;"><span style="color: #ff0000;">*Jika kita tidak mengatur charset menjadi utf8, EJBCA 6.10.1.2 kemungkinan tidak akan bisa berjalan karena ada limitasi index jika menggunakan charset &#8216;utf8mb4&#8217; pada beberapa konfigurasi MariaDB/MySQL. Hasilnya hal tersebut akan memberikan error berupa &#8216;Specified key was too long; max key length is 767 bytes&#8217;.</span></h5>
<h3 style="text-align: justify;"><strong>Membuat Struktur Direktori</strong></h3>
<p style="text-align: justify;">Sekarang kita akan membuat struktur direktori dari aplikasi itu sendiri. Saya memutuskan untuk meletakkan aplikasi-aplikasi yang saya butuhkan pada <strong>/opt</strong>. Secara default, Semua dokumentasi EJBCA mengasumsikan kita melakukan instalasi pada home direktori. Namun saya lebih senang untuk menggunakan simbolik link agar lebih mudah.</p>
<ul style="text-align: justify;">
<li><strong>/opt </strong>saya gunakan untuk meletakkan semua file sehingga kita bisa dengan mudah menghapusnya dan memulai lagi dari awal.</li>
<li>Download WildFly 10.0.0 dan EJBCA 6.10.1.2 dengan wget (link ada di “alat &amp; bahan”) dan letakkan pada <strong>/opt</strong>.</li>
</ul>
<p style="text-align: justify;">Setelah semua file terdownload (dalam bentuk zip), lalu ekstrak dan buat beberapa link sebagai <em>shortcut</em> untuk menuju folder tersebut. Caranya:</p>
<pre><span style="color: #ff0000;"><strong>sudo unzip wildfly-10.0.0.Final.zip
sudo unzip ejbca_ce_6_10_1_2.zip
sudo ln -s /opt/ejbca_ce_6_10_1_2 ejbca
sudo ln -s /opt/wildfly-10.0.0.0.Final jboss</strong></span></pre>
<figure id="attachment_2094" aria-describedby="caption-attachment-2094" style="width: 455px" class="wp-caption aligncenter"><img loading="lazy" decoding="async" class="size-full wp-image-2094" src="http://blog.goreinnamah.com/wp-content/uploads/2018/03/4-link.png" alt="" width="455" height="56" srcset="https://blog.goreinnamah.com/wp-content/uploads/2018/03/4-link.png 455w, https://blog.goreinnamah.com/wp-content/uploads/2018/03/4-link-300x37.png 300w" sizes="auto, (max-width: 455px) 100vw, 455px" /><figcaption id="caption-attachment-2094" class="wp-caption-text">Membuat Link</figcaption></figure>
<p style="text-align: justify;">lalu masukkan perintah berikut:</p>
<pre><span style="color: #ff0000;"><strong>export JAVA_HOME=/usr/lib/jvm/java-1.8.0-openjdk/
</strong><strong>export PATH=$JAVA_HOME/bin:$PATH
</strong><strong>export JBOSS_HOME=/opt/jboss
</strong><strong>export PATH=$PATH:$JBOSS_HOME/bin:$PATH
</strong><strong>export APPSRV_HOME=/opt/jboss
</strong><strong>export PATH=$JBOSS_HOME/bin:$PATH
</strong><strong>export EJBCA_HOME=/opt/ejbca
</strong><strong>export PATH=$EJBCA_HOME/bin:$PATH
</strong><strong>export CLASSPATH=$JAVA_HOME/jre/lib/ext:$CLASSPATH</strong></span></pre>
<figure id="attachment_2095" aria-describedby="caption-attachment-2095" style="width: 483px" class="wp-caption aligncenter"><img loading="lazy" decoding="async" class="size-full wp-image-2095" src="http://blog.goreinnamah.com/wp-content/uploads/2018/03/3-export-java.png" alt="" width="483" height="153" srcset="https://blog.goreinnamah.com/wp-content/uploads/2018/03/3-export-java.png 483w, https://blog.goreinnamah.com/wp-content/uploads/2018/03/3-export-java-300x95.png 300w" sizes="auto, (max-width: 483px) 100vw, 483px" /><figcaption id="caption-attachment-2095" class="wp-caption-text">Export</figcaption></figure>
<h3 style="text-align: justify;"><strong>Menambahkan Akun User untuk OS</strong></h3>
<p style="text-align: justify;">Sekarang kita akan membuat akun untuk service ejbca. Ada 2 akun yang akan dibuat di sini, yang pertama akun sistem dengan nama <strong>jboss </strong>dan yang kedua adalah akun <strong>ejbca </strong>untuk keperluan administratif setelah server ini dibuat.</p>
<p style="text-align: justify;">Sangat penting <strong>jboss </strong>memiliki <strong>/bin/bash </strong>dalam sebuah<strong> <em>shell </em></strong>dan sebuah <strong>/opt/jboss </strong>sebagai <em>home directory.<br />
</em></p>
<pre><span style="color: #ff0000;"><strong>useradd ­s /bin/bash -­r -­d /opt/jboss ­-M -­U jboss</strong>
<strong>useradd -­m -­U -­G jboss,wheel ejbca</strong></span></pre>
<h3 style="text-align: justify;"><strong>Instalasi Wildfly 10.0.0.Final</strong></h3>
<p style="text-align: justify;">Untuk meng-<em>compile </em>EJBCA 6.10.1.2, terlebih dahulu kita harus menginstall Wildfly versi 10.0.0.Final <strong>(OpenJDK 8 diperlukan di sini)</strong>.</p>
<p style="text-align: justify;">Wildfly sedikit berbeda dengan JBoss. Untuk Wildfly, <em>deploy</em> dan <em>install</em> tidak secara otomatis membuat <em>application server </em>kita terkonfigurasi. Oleh sebab itu, kita perlu melakukan beberapa konfigurasi terlebih dahulu.</p>
<h3 style="text-align: justify;"><strong>Menambahkan Database Driver ke dalam Wildfly</strong></h3>
<p style="text-align: justify;">Kita akan melakukan <em>hot-deploying </em>pada penambahan driver database kali ini yaitu dengan memasukkannya secara langsung ke dalam direktori <em>deployment. Driver</em> tersebut akan diambil dan di deploy secara otomatis ketika Wildfly dijalankan.</p>
<p style="text-align: justify;">Untuk mempermudah, kita akan <em>meng-copy</em> file <em>driver</em> tersebut dan mengubah namanya menjadi baru, tanpa ada <em>embel-embel </em>versi drivernya. Caranya:</p>
<pre><span style="color: #ff0000;"><strong>cp mariadb-java-client-2.1.0.jar /opt/jboss/standalone/deployments/mariadb-java-client.jar
ls</strong></span></pre>
<figure id="attachment_2101" aria-describedby="caption-attachment-2101" style="width: 763px" class="wp-caption alignnone"><img loading="lazy" decoding="async" class="size-full wp-image-2101" src="http://blog.goreinnamah.com/wp-content/uploads/2018/03/5-mariadb-driver.png" alt="" width="763" height="62" srcset="https://blog.goreinnamah.com/wp-content/uploads/2018/03/5-mariadb-driver.png 763w, https://blog.goreinnamah.com/wp-content/uploads/2018/03/5-mariadb-driver-300x24.png 300w" sizes="auto, (max-width: 763px) 100vw, 763px" /><figcaption id="caption-attachment-2101" class="wp-caption-text">mariadb driver</figcaption></figure>
<ul style="text-align: justify;">
<li><strong>/opt/jboss/</strong> merupakan sebuah link yang saya buat untuk <strong>/opt/wildfly-10.0.0.final</strong></li>
<li><em>Link driver database</em> sudah saya sertakan di awal tutorial.<em> </em></li>
</ul>
<h3 style="text-align: justify;"><strong>Konfigurasi Wildfly Instance (Standalone)</strong></h3>
<p style="text-align: justify;">Pertama, kita akan melakukan konfigurasi Instance yang nanti akan digunakan oleh EJBCA 6.10.1.2. Namanya “<strong>standalone”</strong>, dan hadir secara default dalam Wildfly 10.0.0.Final</p>
<p style="text-align: justify;">Pada direktori <strong>/opt/jboss/bin</strong> terdapat sebuah script yang bernama <strong>standalone.sh</strong> yang merupakan titik utama dari <strong>Wildfly</strong>. Script ini memberi referensi pada sebuah file konfigurasi yang terletak pada folder yang sama bernama <strong>standalone.conf</strong>. Kita tidak akan memodifikasi script startup-nya, tapi kita perlu untuk memodifikasi file konfigurasinya.</p>
<p style="text-align: justify;">Sebagai langkah awal, kita akan mem-backup file konfigurasi defaultnya terlebih dahulu. Caranya:</p>
<pre><span style="color: #ff0000;"><strong>cd /opt/jboss/bin
cp standalone.conf standalone.conf.bak</strong></span></pre>
<figure id="attachment_2102" aria-describedby="caption-attachment-2102" style="width: 624px" class="wp-caption aligncenter"><img loading="lazy" decoding="async" class="size-full wp-image-2102" src="http://blog.goreinnamah.com/wp-content/uploads/2018/03/6-standalone-conf.png" alt="" width="624" height="36" srcset="https://blog.goreinnamah.com/wp-content/uploads/2018/03/6-standalone-conf.png 624w, https://blog.goreinnamah.com/wp-content/uploads/2018/03/6-standalone-conf-300x17.png 300w, https://blog.goreinnamah.com/wp-content/uploads/2018/03/6-standalone-conf-600x36.png 600w" sizes="auto, (max-width: 624px) 100vw, 624px" /><figcaption id="caption-attachment-2102" class="wp-caption-text">copy standalone conf</figcaption></figure>
<p style="text-align: justify;">File konfigurasi tersebut juga berisi satu set option JVM yang nantinya akan kita ubah sedikit. Ini bukanlah perubahan yang wajib, tapi perubahan tersebut dapat mengalokasikan memori lebih pada JVM.</p>
<ul style="text-align: justify;">
<li>Ada beberapa entri yang dinonaktifkan, namun yang penting di sini adalah <strong>JAVA_HOME</strong> dan <strong>JAVA_OPTS</strong>.</li>
</ul>
<p style="text-align: justify;">Secara <em>default, </em>direktori JAVA_HOME belum di <em>set </em>dan JAVA_OPTS hanya mengizinkan penggunaan memori sebesar 512Mib. Ubah kedua parameter tersebut menjadi seperti berikut:</p>
<pre><span style="color: #ff0000;"><strong>vi standalone.conf</strong></span></pre>
<pre><span style="color: #ff0000;"><strong>JAVA_HOME=/usr/lib/jvm/java-1.8.0-openjdk
JAVA_OPTS="-Xms2048m -Xmx2048m -Djava.net.preferIPv4Stack=true"</strong></span></pre>
<figure id="attachment_2103" aria-describedby="caption-attachment-2103" style="width: 831px" class="wp-caption aligncenter"><img loading="lazy" decoding="async" class="size-full wp-image-2103" src="http://blog.goreinnamah.com/wp-content/uploads/2018/03/7-standalone-ubah.png" alt="" width="831" height="455" srcset="https://blog.goreinnamah.com/wp-content/uploads/2018/03/7-standalone-ubah.png 831w, https://blog.goreinnamah.com/wp-content/uploads/2018/03/7-standalone-ubah-300x164.png 300w, https://blog.goreinnamah.com/wp-content/uploads/2018/03/7-standalone-ubah-768x421.png 768w" sizes="auto, (max-width: 831px) 100vw, 831px" /><figcaption id="caption-attachment-2103" class="wp-caption-text">Perubahan pada standalone.conf</figcaption></figure>
<h3 style="text-align: justify;">Starting Wildfly</h3>
<p style="text-align: justify;">Beberapa <em>tweak</em> harus kita lakukan setelah Wildfly berjalan. Karena beberapa perintah di atas ada yang dijalankan sebagai <strong>root</strong>, kita akan membuat user <strong>jboss</strong> menjadi owner dari folder wildfly yang sudah kita extract.</p>
<ul style="text-align: justify;">
<li>Jangan jalankan perintah “<strong>chown -R root:root /opt/jboss</strong>” – kita ingin agar <strong>root</strong> tetap menjadi pemilik dari Symbolic link.</li>
</ul>
<p style="text-align: justify;">Maka jalankan perintah berikut:</p>
<pre><span style="color: #ff0000;"><strong>chown -R jboss:jboss /opt/wildfly-10.0.0.Final</strong></span></pre>
<p style="text-align: justify;">Sekarang dengan user jboss, kita akan mengeksekusi file <strong>standalone.sh</strong> yang berada pada folder jboss. Langkah-langkahnya adalah sebagai berikut:</p>
<pre><span style="color: #ff0000;"><strong>cd /opt/jboss/bin
nohup ./standalone.sh -b 0.0.0.0 -bmanagement=0.0.0.0 &amp;</strong></span></pre>
<figure id="attachment_2104" aria-describedby="caption-attachment-2104" style="width: 660px" class="wp-caption aligncenter"><img loading="lazy" decoding="async" class="size-full wp-image-2104" src="http://blog.goreinnamah.com/wp-content/uploads/2018/03/8-1-nohup.png" alt="" width="660" height="81" srcset="https://blog.goreinnamah.com/wp-content/uploads/2018/03/8-1-nohup.png 660w, https://blog.goreinnamah.com/wp-content/uploads/2018/03/8-1-nohup-300x37.png 300w" sizes="auto, (max-width: 660px) 100vw, 660px" /><figcaption id="caption-attachment-2104" class="wp-caption-text">Menjalankan service wildfly</figcaption></figure>
<ul style="text-align: justify;">
<li>“&amp;” digunakan agar jboss tetap berjalan saat kita keluar dari terminal.</li>
<li>“-b” adalah opsi untuk menentukan jboss.bind.address.</li>
<li>“0.0.0.0” berarti dapat diakses dari IP manapun.</li>
</ul>
<figure id="attachment_2105" aria-describedby="caption-attachment-2105" style="width: 1564px" class="wp-caption aligncenter"><img loading="lazy" decoding="async" class="size-full wp-image-2105" src="http://blog.goreinnamah.com/wp-content/uploads/2018/03/9-wildfly-started.png" alt="" width="1564" height="227" srcset="https://blog.goreinnamah.com/wp-content/uploads/2018/03/9-wildfly-started.png 1564w, https://blog.goreinnamah.com/wp-content/uploads/2018/03/9-wildfly-started-300x44.png 300w, https://blog.goreinnamah.com/wp-content/uploads/2018/03/9-wildfly-started-768x111.png 768w, https://blog.goreinnamah.com/wp-content/uploads/2018/03/9-wildfly-started-1024x149.png 1024w" sizes="auto, (max-width: 1564px) 100vw, 1564px" /><figcaption id="caption-attachment-2105" class="wp-caption-text">bukti pada file nohup yang mengatakan kalau wildfly sudah berjalan</figcaption></figure>
<p style="text-align: justify;">dari log diatas dapat dihasilkan beberapa poin, yaitu:</p>
<ul style="text-align: justify;">
<li>JBoss Admin Page dapat diakses dari IP manapun melalui browser.</li>
<li>alamat default URL untuk JBoss Admin tersebut adalah <strong>http://&lt;ip atau domain&gt;:9990/console/App.html</strong></li>
<li>Ketika kita melihat proses ini pada log  → <strong>“started xxx of xxx services”  </strong>, maka JBoss sudah berjalan.</li>
</ul>
<h3 style="text-align: justify;"><strong>Konfigurasi User Admin untuk Wildfly Web</strong></h3>
<p style="text-align: justify;">apabila kita mengakses <strong>console Wildfly via web</strong> pada tahap ini melalui <strong>http://&lt;ip atau domain&gt;:9990 </strong>maka yang tampil adalah seperti berikut:</p>
<figure id="attachment_2318" aria-describedby="caption-attachment-2318" style="width: 1243px" class="wp-caption aligncenter"><img loading="lazy" decoding="async" class="size-full wp-image-2318" src="http://blog.goreinnamah.com/wp-content/uploads/2018/03/3-2.png" alt="" width="1243" height="988" srcset="https://blog.goreinnamah.com/wp-content/uploads/2018/03/3-2.png 1243w, https://blog.goreinnamah.com/wp-content/uploads/2018/03/3-2-300x238.png 300w, https://blog.goreinnamah.com/wp-content/uploads/2018/03/3-2-768x610.png 768w, https://blog.goreinnamah.com/wp-content/uploads/2018/03/3-2-1024x814.png 1024w" sizes="auto, (max-width: 1243px) 100vw, 1243px" /><figcaption id="caption-attachment-2318" class="wp-caption-text">Jboss console via web tapi masih belum memiliki admin</figcaption></figure>
<p style="text-align: justify;">Hal itu disebabkan oleh belum adanya admin User yang dibuat untuk mengakses console tersebut. Untuk itu kita perlu membuatnya. Caranya:</p>
<pre><span style="color: #ff0000;"><strong>cd /opt/jboss/bin
sh add-user.sh</strong></span></pre>
<p style="text-align: justify;">Maka akan muncul pertanyaan seperti berikut:</p>
<pre><span style="color: #ff0000;"><strong>What type of user do you wish to add?</strong></span>
<span style="color: #ff0000;"><strong> a) Management User (mgmt-users.properties)</strong></span>
<span style="color: #ff0000;"><strong> b) Application User (application-users.properties)</strong></span>
<span style="color: #ff0000;"><strong>(a):</strong></span>

<span style="color: #ff0000;"><strong>Enter the details of the new user to add.</strong></span>
<span style="color: #ff0000;"><strong>Using realm 'ManagementRealm' as discovered from the existing property files.</strong></span>
<span style="color: #ff0000;"><strong>Username : xxxx</strong></span>
<span style="color: #ff0000;"><strong>Password recommendations are listed below. To modify these restrictions edit the add-user.properties configuration file.</strong></span>
<span style="color: #ff0000;"><strong> - The password should be different from the username</strong></span>
<span style="color: #ff0000;"><strong> - The password should not be one of the following restricted values {root, admin, administrator}</strong></span>
<span style="color: #ff0000;"><strong> - The password should contain at least 8 characters, 1 alphabetic character(s), 1 digit(s), 1 non-alphanumeric symbol(s)</strong></span>
<span style="color: #ff0000;"><strong>Password :</strong></span>
<span style="color: #ff0000;"><strong>WFLYDM0101: Password should have at least 1 digit.</strong></span>
<span style="color: #ff0000;"><strong>Are you sure you want to use the password entered yes/no? yes</strong></span>
<span style="color: #ff0000;"><strong>Re-enter Password :</strong></span>
<span style="color: #ff0000;"><strong>What groups do you want this user to belong to? (Please enter a comma separated list, or leave blank for none)[ ]:</strong></span>
<span style="color: #ff0000;"><strong>About to add user 'jadmin' for realm 'ManagementRealm'</strong></span>
<span style="color: #ff0000;"><strong>Is this correct yes/no? yes</strong></span>
<span style="color: #ff0000;"><strong>Added user 'xxxx' to file '/opt/wildfly-10.0.0.Final/standalone/configuration/mgmt-users.properties'</strong></span>
<span style="color: #ff0000;"><strong>Added user 'xxxx' to file '/opt/wildfly-10.0.0.Final/domain/configuration/mgmt-users.properties'</strong></span>
<span style="color: #ff0000;"><strong>Added user 'xxxx' with groups to file '/opt/wildfly-10.0.0.Final/standalone/configuration/mgmt-groups.properties'</strong></span>
<span style="color: #ff0000;"><strong>Added user 'xxxx' with groups to file '/opt/wildfly-10.0.0.Final/domain/configuration/mgmt-groups.properties'</strong></span>
<span style="color: #ff0000;"><strong>Is this new user going to be used for one AS process to connect to another AS process?</strong></span>
<span style="color: #ff0000;"><strong>e.g. for a slave host controller connecting to the master or for a Remoting connection for server to server EJB calls.</strong></span>
<span style="color: #ff0000;"><strong>yes/no? no</strong></span></pre>
<ul style="text-align: justify;">
<li>“What type of user do you wish to add?”<b> → </b>isi dengan “a”</li>
<li>“Realm” <b>→</b> enter saja.</li>
<li>“username” <b>→</b> Isi dengan username yang kalian mau.</li>
<li>“Password” <b>→</b> Isi dengan password yang kalian mau.</li>
<li>“Re-Enter Password” <b>→</b> Ulangi kembali dengan password yang sama.</li>
<li>“is this correct” <b>→</b> pilih “yes”</li>
<li>“is this new user going to …..” <b>→</b> pilih “no”</li>
</ul>
<p style="text-align: justify;">Pada saat ini seharusnya kita sudah bisa mengakses interface dari <strong>Wildfly Web Console</strong> dan mengganti beberapa item. Namun pada saat ini kita belum perlu untuk mengganti apapun:</p>
<ul style="text-align: justify;">
<li>Ini adalah user spesifik untuk JBoss yang tidak digunakan dimanapun.</li>
<li>Ini adalah tahapan yang bagus untuk mengambil snapshot vm.</li>
</ul>
<p style="text-align: justify;">Sekarang mari kita coba user tersebut. caranya masuk ke browser dan ketikkan <strong>http://&lt;ip atau domain&gt;:9990/console/App.html. </strong>Maka akan muncul tampilan seperti berikut:</p>
<figure id="attachment_2319" aria-describedby="caption-attachment-2319" style="width: 894px" class="wp-caption aligncenter"><img loading="lazy" decoding="async" class="size-full wp-image-2319" src="http://blog.goreinnamah.com/wp-content/uploads/2018/03/4-2.png" alt="" width="894" height="284" srcset="https://blog.goreinnamah.com/wp-content/uploads/2018/03/4-2.png 894w, https://blog.goreinnamah.com/wp-content/uploads/2018/03/4-2-300x95.png 300w, https://blog.goreinnamah.com/wp-content/uploads/2018/03/4-2-768x244.png 768w" sizes="auto, (max-width: 894px) 100vw, 894px" /><figcaption id="caption-attachment-2319" class="wp-caption-text">Wildfly web console</figcaption></figure>
<p style="text-align: justify;">Masukkan username dan password sesuai dengan yang baru saja kita input. Apabila benar maka akan muncul tampilan seperti berikut:</p>
<figure id="attachment_2320" aria-describedby="caption-attachment-2320" style="width: 1446px" class="wp-caption aligncenter"><img loading="lazy" decoding="async" class="size-full wp-image-2320" src="http://blog.goreinnamah.com/wp-content/uploads/2018/03/5-2.png" alt="" width="1446" height="856" srcset="https://blog.goreinnamah.com/wp-content/uploads/2018/03/5-2.png 1446w, https://blog.goreinnamah.com/wp-content/uploads/2018/03/5-2-300x178.png 300w, https://blog.goreinnamah.com/wp-content/uploads/2018/03/5-2-768x455.png 768w, https://blog.goreinnamah.com/wp-content/uploads/2018/03/5-2-1024x606.png 1024w" sizes="auto, (max-width: 1446px) 100vw, 1446px" /><figcaption id="caption-attachment-2320" class="wp-caption-text">Wildfly web login</figcaption></figure>
<h3 style="text-align: justify;"><strong>Menambahkan Data Source</strong></h3>
<p style="text-align: justify;">Sekarang <em>service</em> Wildfly sudah berjalan, kini kita bisa menambahkan data source. Kita akan melakukan ini melalui CLI-nya JBoss, yang akan mengupdate konfigurasi yang berada pada file <strong>Standalone.xml</strong>. Sebelum melakukan perubahan maka ada baiknya kita membackup konfigurasi awal terlebih dahulu. Caranya (masih dengan user jboss):</p>
<pre><span style="color: #ff0000;"><strong>cd /opt/jboss/standalone/configuration
cp standalone.xml standalone.xml.bak</strong></span></pre>
<p style="text-align: justify;">Sekarang kita akan menuju JBoss CLI dan melakukan beberapa perubahan. Caranya:</p>
<pre><span style="color: #ff0000;"><strong>cd /opt/jboss/bin
sh jboss-cli.sh
connect</strong></span></pre>
<p style="text-align: justify;">Lalu jalankan perintah berikut:</p>
<pre class="code"><span style="color: #ff0000;"><strong>data-source add --name=ejbcads --driver-name="mariadb-java-client.jar" --connection-url="jdbc:mysql://127.0.0.1:3306/ejbca" --jndi-name="java:/EjbcaDS" --use-ccm=true --driver-class="org.mariadb.jdbc.Driver" --user-name="<span style="color: #000000;">ejbca</span>" --password="<span style="color: #000000;">ejbca</span>" --validate-on-match=true --background-validation=false --prepared-statements-cache-size=50 --share-prepared-statements=true --min-pool-size=5 --max-pool-size=150 --pool-prefill=true --transaction-isolation=TRANSACTION_READ_COMMITTED --check-valid-connection-sql="select 1;"</strong></span>
<span style="color: #ff0000;"><strong>:reload</strong></span></pre>
<p style="text-align: justify;">Setelah perintah tersebut dieksekusi maka hasil keluarannya adalah “<strong>Success</strong>” (seperti pada gambar di bawah).</p>
<figure id="attachment_2243" aria-describedby="caption-attachment-2243" style="width: 1904px" class="wp-caption aligncenter"><img loading="lazy" decoding="async" class="size-full wp-image-2243" src="http://blog.goreinnamah.com/wp-content/uploads/2018/03/10-1.png" alt="" width="1904" height="201" srcset="https://blog.goreinnamah.com/wp-content/uploads/2018/03/10-1.png 1904w, https://blog.goreinnamah.com/wp-content/uploads/2018/03/10-1-300x32.png 300w, https://blog.goreinnamah.com/wp-content/uploads/2018/03/10-1-768x81.png 768w, https://blog.goreinnamah.com/wp-content/uploads/2018/03/10-1-1024x108.png 1024w" sizes="auto, (max-width: 1904px) 100vw, 1904px" /><figcaption id="caption-attachment-2243" class="wp-caption-text">sukses menambahkan datasource</figcaption></figure>
<p style="text-align: justify;">Hal yang kita lakukan pada CLI ini mendefinisikan driver mariadb dan koneksi yang ada pada <strong>/opt/jboss/standalone/configuration/standalone.xml</strong>, kemudian me-reload JBoss.</p>
<p style="text-align: justify;">Hasilnya akan terlihat pada <strong>standalone.xml</strong> seperti gambar berikut:</p>
<figure id="attachment_2115" aria-describedby="caption-attachment-2115" style="width: 582px" class="wp-caption aligncenter"><img loading="lazy" decoding="async" class="size-full wp-image-2115" src="http://blog.goreinnamah.com/wp-content/uploads/2018/03/17-1.png" alt="" width="582" height="212" srcset="https://blog.goreinnamah.com/wp-content/uploads/2018/03/17-1.png 582w, https://blog.goreinnamah.com/wp-content/uploads/2018/03/17-1-300x109.png 300w" sizes="auto, (max-width: 582px) 100vw, 582px" /><figcaption id="caption-attachment-2115" class="wp-caption-text">konfigurasi ini akan kalian temukan di standalone.xml</figcaption></figure>
<p style="text-align: justify;">Sebagai bukti lagi kalau <em>connector</em> tersebut sudah masuk, kita akan melihat pada log yang tertera di file <strong>nohup.out</strong> yang ada pada folder <strong>/opt/jboss/bin</strong>. Namun sebelumnya kita harus me-restart service wildfly yang sedang berjalan. Caranya:</p>
<pre><span style="color: #ff0000;"><strong>cd /opt/jboss/bin
ps -ax | grep jboss
kill &lt;nomor pada ps-ax&gt;
nohup ./standalone.sh -b 0.0.0.0 -bmanagement=0.0.0.0 &amp;
tail -100f nohup.out</strong></span></pre>
<p style="text-align: justify;">Ketika kalian menemukan <strong>mariadb.jdbc.driver, </strong>maka datasource tersebut sudah dapat dipastikan masuk.</p>
<h3 style="text-align: justify;"><strong>Datasource Password</strong></h3>
<p style="text-align: justify;">Untuk mengamankan password yang ada pada <strong>ejbcads </strong>di atas agar tidak <strong>plain text </strong>pada saat ditampilkan di <strong>/opt/jboss/standalone/configuration/standalone.xml </strong>(Guna meningkatkan keamanan sistem), Jalankan perintah berikut:</p>
<ul>
<li>Ganti <strong>PASSWORDLO </strong>dengan password database di atas.</li>
</ul>
<pre style="text-align: justify;"><span style="color: #ff0000;"><strong>java -cp /opt/jboss/modules/system/layers/base/org/picketbox/main/picketbox-4.9.4.Final.jar:/opt/jboss/modules/system/layers/base/org/jboss/logging/main/jboss-logging-3.3.0.Final.jar:$CLASSPATH org.picketbox.datasource.security.SecureIdentityLoginModule <span style="color: #000000;">PASSWORDLO</span></strong></span></pre>
<figure id="attachment_2449" aria-describedby="caption-attachment-2449" style="width: 719px" class="wp-caption aligncenter"><img loading="lazy" decoding="async" class="wp-image-2449 size-full" src="http://blog.goreinnamah.com/wp-content/uploads/2018/03/4-3.png" alt="" width="719" height="114" srcset="https://blog.goreinnamah.com/wp-content/uploads/2018/03/4-3.png 719w, https://blog.goreinnamah.com/wp-content/uploads/2018/03/4-3-300x48.png 300w" sizes="auto, (max-width: 719px) 100vw, 719px" /><figcaption id="caption-attachment-2449" class="wp-caption-text">Mendapatkan encoded password</figcaption></figure>
<ul>
<li>copy dan paste <strong>encoded password </strong>di atas ke file <strong>standalone.xml:</strong></li>
</ul>
<pre><span style="color: #ff0000;"><strong>vi /opt/jboss/standalone/configuration/standalone.xml</strong></span></pre>
<ul>
<li>Paste segmen berikut pada segmen <strong>security-domains </strong>(dengan mengganti <strong>PASSWORDLO_ENC </strong>menjadi <strong>encoded password </strong>yang kita dapatkan dari perintah di atas dan <strong>USERLO </strong>dengan user untuk terkoneksi ke database)</li>
</ul>
<pre><span style="color: #ff0000;"><strong>&lt;security-domain name="EjbcaDsEncryptedPassword"&gt;</strong></span>
<span style="color: #ff0000;"><strong> &lt;authentication&gt;</strong></span>
<span style="color: #ff0000;"><strong> &lt;login-module code="SecureIdentity" flag="required"&gt;</strong></span>
<span style="color: #ff0000;"><strong> &lt;module-option name="username" value="<span style="color: #000000;">USERLO</span>"/&gt;</strong></span>
<span style="color: #ff0000;"><strong> &lt;module-option name="password" value="<span style="color: #000000;">PASSWORDLO_ENC</span>"/&gt;</strong></span>
<span style="color: #ff0000;"><strong> &lt;/login-module&gt;</strong></span>
<span style="color: #ff0000;"><strong> &lt;/authentication&gt;</strong></span>
<span style="color: #ff0000;"><strong>&lt;/security-domain&gt;</strong></span></pre>
<figure id="attachment_2452" aria-describedby="caption-attachment-2452" style="width: 881px" class="wp-caption aligncenter"><img loading="lazy" decoding="async" class="wp-image-2452 size-full" src="http://blog.goreinnamah.com/wp-content/uploads/2018/03/5-1-1.png" alt="" width="881" height="200" srcset="https://blog.goreinnamah.com/wp-content/uploads/2018/03/5-1-1.png 881w, https://blog.goreinnamah.com/wp-content/uploads/2018/03/5-1-1-300x68.png 300w, https://blog.goreinnamah.com/wp-content/uploads/2018/03/5-1-1-768x174.png 768w" sizes="auto, (max-width: 881px) 100vw, 881px" /><figcaption id="caption-attachment-2452" class="wp-caption-text">Penambahan Security Domain</figcaption></figure>
<ul>
<li>Lihat bagian <strong>EjbcaDs datasource </strong>dan ganti segmen <strong>security </strong>(dimana <strong>PASSWORDLO </strong>adalah password lama dalam bentuk <strong>plain text</strong>):</li>
</ul>
<pre><strong><span style="color: #ff0000;">&lt;security&gt;</span></strong>
<strong><span style="color: #ff0000;"> &lt;user-name&gt;<span style="color: #000000;">USERLO</span>&lt;/user-name&gt;</span></strong>
<strong><span style="color: #ff0000;"> &lt;password&gt;<span style="color: #000000;">PASSWORDLO</span>&lt;/password&gt;</span></strong>
<strong><span style="color: #ff0000;">&lt;/security&gt;</span></strong></pre>
<ul>
<li>Dengan bentuk berikut:</li>
</ul>
<pre><strong><span style="color: #ff0000;">&lt;security&gt;</span></strong>
<strong><span style="color: #ff0000;"> &lt;security-domain&gt;EjbcaDsEncryptedPassword&lt;/security-domain&gt;</span></strong>
<strong><span style="color: #ff0000;">&lt;/security&gt;</span></strong></pre>
<p>Restart kembali JBOSS</p>
<pre><span style="color: #ff0000;"><strong>cd /opt/jboss/bin 
ps -ax | grep jboss kill &lt;nomor pada ps-ax&gt; 
nohup ./standalone.sh -b 0.0.0.0 -bmanagement=0.0.0.0 &amp; 
tail -100f nohup.out</strong></span></pre>
<h3 style="text-align: justify;"><strong>Konfigurasi WildFly Remoting</strong></h3>
<p style="text-align: justify;">EJBCA 6.10.1.2 perlu menggunakan <strong>JBOSS Remoting</strong> untuk <strong>EJBCA CLI</strong> agar bisa bekerja. Nah, kita akan mengkonfigurasi JBOSS Remoting tersebut. Kita akan menggunakan port yang berbeda dan memulainya dengan menghapus konfigurasi yang dulu pernah ada. Caranya:</p>
<pre class="code"><span style="color: #ff0000;"><strong>cd /opt/jboss/bin
sh jboss-cli.sh 
connect</strong></span></pre>
<pre class="code"><span style="color: #ff0000;"><strong>/subsystem=remoting/http-connector=http-remoting-connector:remove
/subsystem=remoting/http-connector=http-remoting-connector:add(connector-ref="remoting",security-realm="ApplicationRealm")
/socket-binding-group=standard-sockets/socket-binding=remoting:add(port="4447")
/subsystem=undertow/server=default-server/http-listener=remoting:add(socket-binding=remoting)
:reload</strong></span></pre>
<div class="subsubsection" style="text-align: justify;">
<p>Tunggu sampai proses reload selesai dengan cara mengecek log yang ada pada <strong>nohup.out, </strong>baru kemudian lanjutkan ke proses berikutnya</p>
<h3><strong>Konfigurasi Logging</strong></h3>
<p>Untuk mengkonfigurasi <em>log </em>yang ada pada Wildfly, Kita harus bisa mengganti log secara dinamis. Pada contoh ini <strong>DEBUG </strong>akan diaktifkan</p>
<pre class="code"><strong><span style="color: #ff0000;">cd /opt/jboss/bin
sh jboss-cli.sh 
connect</span></strong></pre>
<pre class="code"><span style="color: #ff0000;"><strong>/subsystem=logging/logger=org.ejbca:add
/subsystem=logging/logger=org.ejbca:write-attribute(name=level, value=DEBUG)
/subsystem=logging/logger=org.cesecore:add
/subsystem=logging/logger=org.cesecore:write-attribute(name=level, value=DEBUG)</strong></span></pre>
<figure id="attachment_2116" aria-describedby="caption-attachment-2116" style="width: 780px" class="wp-caption alignnone"><img loading="lazy" decoding="async" class="size-full wp-image-2116" src="http://blog.goreinnamah.com/wp-content/uploads/2018/03/18-enable-logging-wildfly.png" alt="" width="780" height="230" srcset="https://blog.goreinnamah.com/wp-content/uploads/2018/03/18-enable-logging-wildfly.png 780w, https://blog.goreinnamah.com/wp-content/uploads/2018/03/18-enable-logging-wildfly-300x88.png 300w, https://blog.goreinnamah.com/wp-content/uploads/2018/03/18-enable-logging-wildfly-768x226.png 768w" sizes="auto, (max-width: 780px) 100vw, 780px" /><figcaption id="caption-attachment-2116" class="wp-caption-text">enable logging</figcaption></figure>
<h3><strong>Konfigurasi PKCS11 Provider pada EJBCA 6.10.1.2</strong></h3>
<p>Untuk melakukan <em>setup </em>pada PKCS11 di server ini, lakukan beberapa langkah berikut pada terminal:</p>
<ol>
<li>Buat file konfigurasi Luna dengan konten di bawah:<br />
<span style="color: #ff0000;"><strong># vi $JAVA_HOME/jre/lib/security/luna.cfg</strong></span><br />
dan masukkan perintah berikut:</li>
</ol>
</div>
<pre><span style="color: #ff0000;"><strong>#SafeNet Luna </strong></span>
<span style="color: #ff0000;"><strong>name = Luna </strong></span>
<span style="color: #ff0000;"><strong>library = /usr/safenet/lunaclient/lib/libCryptoki2_64.so </strong></span>
<span style="color: #ff0000;"><strong>description = Luna config </strong></span>
<span style="color: #ff0000;"><strong>slot = 1 </strong></span>
<span style="color: #ff0000;"><strong>attributes(*, CKO_PUBLIC_KEY, *) = {</strong></span>
<span style="color: #ff0000;"><strong> CKA_TOKEN = false</strong></span>
<span style="color: #ff0000;"><strong> CKA_ENCRYPT = true</strong></span>
<span style="color: #ff0000;"><strong> CKA_VERIFY = true</strong></span>
<span style="color: #ff0000;"><strong> CKA_WRAP = true</strong></span>
<span style="color: #ff0000;"><strong>}</strong></span>
<span style="color: #ff0000;"><strong>attributes(*, CKO_PRIVATE_KEY, *) = {</strong></span>
<span style="color: #ff0000;"><strong> CKA_TOKEN = true</strong></span>
<span style="color: #ff0000;"><strong> CKA_PRIVATE = true</strong></span>
<span style="color: #ff0000;"><strong> CKA_SENSITIVE = true</strong></span>
<span style="color: #ff0000;"><strong> CKA_EXTRACTABLE = false</strong></span>
<span style="color: #ff0000;"><strong> CKA_DECRYPT = true</strong></span>
<span style="color: #ff0000;"><strong> CKA_SIGN = true</strong></span>
<span style="color: #ff0000;"><strong> CKA_UNWRAP = true</strong></span>
<span style="color: #ff0000;"><strong> CKA_DERIVE = false</strong></span>
<span style="color: #ff0000;"><strong>}</strong></span>
<span style="color: #ff0000;"><strong>disabledMechanisms = {</strong></span>
<span style="color: #ff0000;"><strong> CKM_SHA1_RSA_PKCS</strong></span>
<span style="color: #ff0000;"><strong> CKM_SHA256_RSA_PKCS</strong></span>
<span style="color: #ff0000;"><strong> CKM_SHA384_RSA_PKCS</strong></span>
<span style="color: #ff0000;"><strong> CKM_SHA512_RSA_PKCS</strong></span>
<span style="color: #ff0000;"><strong> CKM_MD2_RSA_PKCS</strong></span>
<span style="color: #ff0000;"><strong> CKM_MD5_RSA_PKCS</strong></span>
<span style="color: #ff0000;"><strong> CKM_DSA_SHA1</strong></span>
<span style="color: #ff0000;"><strong> CKM_ECDSA_SHA1</strong></span>
<span style="color: #ff0000;"><strong>}</strong></span></pre>
<figure id="attachment_2186" aria-describedby="caption-attachment-2186" style="width: 441px" class="wp-caption aligncenter"><img loading="lazy" decoding="async" class="size-full wp-image-2186" src="http://blog.goreinnamah.com/wp-content/uploads/2018/03/24-lunacfg.png" alt="" width="441" height="478" srcset="https://blog.goreinnamah.com/wp-content/uploads/2018/03/24-lunacfg.png 441w, https://blog.goreinnamah.com/wp-content/uploads/2018/03/24-lunacfg-277x300.png 277w" sizes="auto, (max-width: 441px) 100vw, 441px" /><figcaption id="caption-attachment-2186" class="wp-caption-text">luna.cfg</figcaption></figure>
<ul style="text-align: justify;">
<li>Modifikasi file <strong>java.security </strong>untuk memasukkan PKCS11. Buka file <strong>java.security </strong>dan lakukan perubahan berikut:<br />
<strong>Untuk Java 8:<br />
# vi $JAVA_HOME/jre/lib/security/java.security<br />
</strong></li>
</ul>
<pre><span style="color: #ff0000;"><strong>security.provider.1=sun.security.provider.Sun</strong></span>
<span style="color: #ff0000;"><strong>security.provider.2=sun.security.rsa.SunRsaSign</strong></span>
<span style="color: #ff0000;"><strong>security.provider.3=sun.security.ec.SunEC</strong></span>
<span style="color: #ff0000;"><strong>security.provider.4=com.sun.net.ssl.internal.ssl.Provider</strong></span>
<span style="color: #ff0000;"><strong>security.provider.5=com.sun.crypto.provider.SunJCE</strong></span>
<span style="color: #ff0000;"><strong>security.provider.6=sun.security.jgss.SunProvider</strong></span>
<span style="color: #ff0000;"><strong>security.provider.7=com.sun.security.sasl.Provider</strong></span>
<span style="color: #ff0000;"><strong>security.provider.8=org.jcp.xml.dsig.internal.dom.XMLDSigRI</strong></span>
<span style="color: #ff0000;"><strong>security.provider.9=sun.security.smartcardio.SunPCSC</strong></span>
<span style="color: #ff0000;"><strong>security.provider.10=sun.security.pkcs11.SunPKCS11 /usr/lib/jvm/java-1.8.0-openjdk/jre/lib/security/luna.cfg</strong></span></pre>
<figure id="attachment_2185" aria-describedby="caption-attachment-2185" style="width: 784px" class="wp-caption aligncenter"><img loading="lazy" decoding="async" class="size-full wp-image-2185" src="http://blog.goreinnamah.com/wp-content/uploads/2018/03/25-java-security.png" alt="" width="784" height="208" srcset="https://blog.goreinnamah.com/wp-content/uploads/2018/03/25-java-security.png 784w, https://blog.goreinnamah.com/wp-content/uploads/2018/03/25-java-security-300x80.png 300w, https://blog.goreinnamah.com/wp-content/uploads/2018/03/25-java-security-768x204.png 768w" sizes="auto, (max-width: 784px) 100vw, 784px" /><figcaption id="caption-attachment-2185" class="wp-caption-text">java.security</figcaption></figure>
<h3 style="text-align: justify;"><strong>Generate Keys Untuk EJBCA 6.10.1.2</strong></h3>
<p style="text-align: justify;">Tool yang berada pada <strong>$EJBCA_HOME/dist/clientToolBox/ejbcaClientToolBox.sh </strong>digunakan untuk administratif dan men-generate keys. Lakukan beberapa langkah berikut untuk men-generate keys pada SafeNet Luna HSM dengan menggunakan PKCS11:</p>
<pre><strong><span style="color: #ff0000;">cd $EJBCA_HOME
ant clientToolBox
cd dist/clientToolBox/
sh ejbcaClientToolBox.sh PKCS11HSMKeyTool generate /usr/safenet/lunaclient/lib/libCryptoki2_64.so 2048 signKey 1
sh ejbcaClientToolBox.sh PKCS11HSMKeyTool generate /usr/safenet/lunaclient/lib/libCryptoki2_64.so 2048 defaultKey 1
sh ejbcaClientToolBox.sh PKCS11HSMKeyTool generate /usr/safenet/lunaclient/lib/libCryptoki2_64.so 2048 testKey 1</span></strong></pre>
<figure id="attachment_2171" aria-describedby="caption-attachment-2171" style="width: 1308px" class="wp-caption aligncenter"><img loading="lazy" decoding="async" class="size-full wp-image-2171" src="http://blog.goreinnamah.com/wp-content/uploads/2018/03/20-signKey.png" alt="" width="1308" height="350" srcset="https://blog.goreinnamah.com/wp-content/uploads/2018/03/20-signKey.png 1308w, https://blog.goreinnamah.com/wp-content/uploads/2018/03/20-signKey-300x80.png 300w, https://blog.goreinnamah.com/wp-content/uploads/2018/03/20-signKey-768x206.png 768w, https://blog.goreinnamah.com/wp-content/uploads/2018/03/20-signKey-1024x274.png 1024w" sizes="auto, (max-width: 1308px) 100vw, 1308px" /><figcaption id="caption-attachment-2171" class="wp-caption-text">Membuat signKey pada HSM</figcaption></figure>
<figure id="attachment_2172" aria-describedby="caption-attachment-2172" style="width: 1309px" class="wp-caption aligncenter"><img loading="lazy" decoding="async" class="size-full wp-image-2172" src="http://blog.goreinnamah.com/wp-content/uploads/2018/03/21-DefaultKey.png" alt="" width="1309" height="355" srcset="https://blog.goreinnamah.com/wp-content/uploads/2018/03/21-DefaultKey.png 1309w, https://blog.goreinnamah.com/wp-content/uploads/2018/03/21-DefaultKey-300x81.png 300w, https://blog.goreinnamah.com/wp-content/uploads/2018/03/21-DefaultKey-768x208.png 768w, https://blog.goreinnamah.com/wp-content/uploads/2018/03/21-DefaultKey-1024x278.png 1024w" sizes="auto, (max-width: 1309px) 100vw, 1309px" /><figcaption id="caption-attachment-2172" class="wp-caption-text">Membuat defaultKey pada HSM</figcaption></figure>
<figure id="attachment_2173" aria-describedby="caption-attachment-2173" style="width: 1317px" class="wp-caption aligncenter"><img loading="lazy" decoding="async" class="size-full wp-image-2173" src="http://blog.goreinnamah.com/wp-content/uploads/2018/03/22-testKey.png" alt="" width="1317" height="351" srcset="https://blog.goreinnamah.com/wp-content/uploads/2018/03/22-testKey.png 1317w, https://blog.goreinnamah.com/wp-content/uploads/2018/03/22-testKey-300x80.png 300w, https://blog.goreinnamah.com/wp-content/uploads/2018/03/22-testKey-768x205.png 768w, https://blog.goreinnamah.com/wp-content/uploads/2018/03/22-testKey-1024x273.png 1024w" sizes="auto, (max-width: 1317px) 100vw, 1317px" /><figcaption id="caption-attachment-2173" class="wp-caption-text">Membuat testKey pada HSM</figcaption></figure>
<p style="text-align: justify;">Ketika mengeksekusi setiap perintah di atas, maka kita akan diminta untuk memasukkan password dari token hitam yang sudah kita set sebelumnya di tahapan awal. Masukkan Password dari partisi SafeNet Luna HSM dan tunggu hingga keys ter-generate. Kunci-kunci ini yang akan digunakan untuk membuat inisial Admin CA, ROOT CA, dan Server CA.</p>
<h1 style="text-align: justify;"><strong>Instalasi EJBCA 6.10.1.2</strong></h1>
<p style="text-align: justify;">Sebelum kita melanjutkan, kalian perlu tahu bahwa konfigurasi awal EJBCA 6.10.1.2 dapat dibagi kedalam beberapa bagian yaitu:</p>
<ul style="text-align: justify;">
<li>file-file <strong>.properties</strong> yang ada dalam folder <strong>/opt/ejbca/conf</strong></li>
<li>file keystore awal yang terdapat pada folder <strong>/opt/ejbca/p12</strong></li>
<li>config JBoss di <strong>standalone.xml</strong></li>
</ul>
<p style="text-align: justify;">Kalian juga perlu tahu bahwa beberapa aturan umum untuk bekerja dengan konfigurasi EJBCA 6.10.1.2, diantaranya:</p>
<ul style="text-align: justify;">
<li>Pertama, anggap bahwa tidak akan ada konfigurasi yang berubah selama proses deploy dan hanya file <strong>ejbca.ear</strong> yang tersentuh dalam aksi kali ini.</li>
<li>Database mariaDB akan terisi secara otomatis saat pertama kali kita melakukan proses deploy, tapi sebaliknya tidak akan tersentuh oleh script <strong>ant</strong> apapun.</li>
<li>Database tidak akan menyimpan data konfigurasi apapun, tetapi akan berpengaruh jika ada perubahan pada konfigurasi yang kita buat.</li>
<li>Perintah <strong>ant.install</strong> mencoba untuk membuat file keystore setiap kali perintah tersebut dijalankan, meskipun file-file tersebut ada.</li>
<li>porsi dari <strong>standalone.xml</strong> dapat diubah baik oleh <strong>ant build</strong> atau <strong>ant install</strong>, tetapi hal tersebut hanya menanggapi perubahan yang kita buat pada file <strong>*.properties.</strong></li>
<li>Setelah instalasi awal selesai, <strong>ant</strong> tidak akan mengubah <strong>standalone.xml</strong> kecuali  kita telah mengubah sebuah file <strong>.properties</strong>.</li>
</ul>
<h3 style="text-align: justify;"><strong>File Properties pada EJBCA 6.10.1.2</strong></h3>
<p style="text-align: justify;">EJBCA 6.10.1.2 menggunakan text biasa pada file “<strong>.properties</strong>” untuk konfigurasi utamanya. File-file ini akan menjadi rujukan ketika kita meng-compile <strong>ejbca.ear</strong> dengan perintah <strong>ant</strong>, dan tidak menjadi referensi oleh aplikasi yang sedang berjalan.</p>
<ul style="text-align: justify;">
<li>file <strong>install.properties</strong> hanya digunakan ketika menjalankan perintah <strong>ant install</strong>, dan bukan saat menjalankan <strong>ant deployear.</strong></li>
<li>Beberapa file sebenarnya berisi paremeter yang menyediakan parsing <em>runtime</em> dari variabel-variabel pada file properties tersebut, tetapi fungsi ini di non-aktifkan secara default.</li>
</ul>
<p style="text-align: justify;">Pertama, EJBCA memiliki beberapa contoh dari semua file properties yang ada pada direktori <strong>/opt/ejbca/conf</strong>. Yang kita butuhkan adalah:</p>
<p style="text-align: justify;">
<table id="tablepress-12" class="tablepress tablepress-id-12">
<thead>
<tr class="row-1">
	<th class="column-1"> Properties</th><th class="column-2">Penjelasan</th>
</tr>
</thead>
<tbody class="row-striping row-hover">
<tr class="row-2">
	<td class="column-1">catoken.properties</td><td class="column-2">mendefinisikan nama key, password dan alias untuk HSM. file ini digunakan ketika menambahkan HSM ketika melakukan 'ant install'</td>
</tr>
<tr class="row-3">
	<td class="column-1">certstore.properties</td><td class="column-2">mendefinisikan variabel penyimpanan sertifikat</td>
</tr>
<tr class="row-4">
	<td class="column-1">cesecore.properties</td><td class="column-2">mendefinisikan variabel core security engine</td>
</tr>
<tr class="row-5">
	<td class="column-1">crlstore.properties</td><td class="column-2">mendefinisikan variabel penyimpanan CRL</td>
</tr>
<tr class="row-6">
	<td class="column-1">database.properties</td><td class="column-2">mendefinisikan bagaimana EJBCA akan mengakses database<br />
</td>
</tr>
<tr class="row-7">
	<td class="column-1">extendedkeyusage.properties</td><td class="column-2">mendefinisikan oid dan nama dari oid tersebut</td>
</tr>
<tr class="row-8">
	<td class="column-1">ejbca.properties</td><td class="column-2">mendefinisikan variabel basic untuk EJBCA itu sendiri</td>
</tr>
<tr class="row-9">
	<td class="column-1">install.properties</td><td class="column-2">digunakan oleh "ant install" selama instalasi</td>
</tr>
<tr class="row-10">
	<td class="column-1">mail.properties</td><td class="column-2">mendefinisikan bagaiman EJBCA SMTP connector akan berfungsi</td>
</tr>
<tr class="row-11">
	<td class="column-1">ocsp.properties</td><td class="column-2">mendefinisikan bagaimana OCSP itu akan bekerja</td>
</tr>
<tr class="row-12">
	<td class="column-1">va.properties</td><td class="column-2">mendefinisikan bagaimana validation authority akan bekerja</td>
</tr>
<tr class="row-13">
	<td class="column-1">va-publisher.properties</td><td class="column-2">mendefinisikan bagaimana validation authority akan mengakses database</td>
</tr>
<tr class="row-14">
	<td class="column-1">web.properties</td><td class="column-2">mendefinisikan variabel untuk web interface EJBCA</td>
</tr>
</tbody>
</table>
<!-- #tablepress-12 from cache --></p>
<p style="text-align: justify;">Ada beberapa file <strong>jndi.*</strong> dalam folder conf tersebut. Mereka dibutuhkan, namun tidak akan diotak-atik lebih jauh, dan bisa diabaikan saja. Ada juga 2 folder lainnya yaitu <strong>logdevices</strong> dan <strong>plugins</strong>, yang bisa diabaikan juga.</p>
<p style="text-align: justify;">Pertama, kita akan membuat direktori baru yang disebut <strong>/opt/ejbca/conf/sample</strong> dan memindahkan semua file <strong>.sample</strong> ke dalam folder tersebut untuk tujuan backup. Caranya:</p>
<pre><span style="color: #ff0000;"><strong>cd /opt/ejbca/conf
</strong><strong>mkdir sample
</strong><strong>mv *.sample sample/</strong></span></pre>
<p style="text-align: justify;">Lalu kemudian kita akan meng-copy beberapa file yang dibutuhkan ke direktori utamanya. Caranya:</p>
<pre><span style="color: #ff0000;"><strong>cp sample/certstore.properties.sample certstore.properties
</strong><strong>cp sample/catoken.properties.sample catoken.properties</strong>
<strong>cp sample/cesecore.properties.sample cesecore.properties</strong>
<strong>cp sample/crlstore.properties.sample crlstore.properties</strong>
<strong>cp sample/database.properties.sample database.properties</strong>
<strong>cp sample/ejbca.properties.sample ejbca.properties</strong>
<strong>cp sample/install.properties.sample install.properties</strong>
<strong>cp sample/mail.properties.sample mail.properties</strong>
<strong>cp sample/web.properties.sample web.properties
</strong></span></pre>
<p style="text-align: justify;">Kita akan mengkonfigurasi file-file ini kemudian menguji coba instalasinya sebelum melakukan tindakan. Dengan hanya file di atas tersebut maka EJBCA 6.10.1.2 akan beroperasi tanpa <strong>Validation Authority</strong>.</p>
<p style="text-align: justify;">Mari kita mulai:</p>
<h3 style="text-align: justify;"><span style="color: #00ccff;"><strong>catoken.properties</strong></span></h3>
<p style="text-align: justify;"><strong>#### Start catoken.properties ###</strong></p>
<p style="text-align: justify;"><strong># Ini merupakan kombinasi dari CA dan CryptoToken Properties yang nanti ada di Admin-GUI</strong></p>
<p style="text-align: justify;"><strong># Common for all HSM are:</strong><br />
<strong># * certSignKey &#8211; the key to be used when signing certificates, can be RSA or ECDSA.</strong><br />
<strong># * crlSignKey &#8211; the key to be used when signing CLSs, can be RSA or ECDSA.</strong><br />
<strong># * keyEncryptKey &#8211; the key to be used for key encryption and decryption, this must be an RSA key.</strong><br />
<strong># * testKey &#8211; the key to be used by HSM status checks, can be RSA or ECDSA.</strong><br />
<strong># * hardTokenEncrypt &#8211; the key to be used for hardtoken encryption and decryption. PUK will be decrypted by this key.</strong><br />
<strong># * defaultKey &#8211; the key to be used when no other key is defined for a purpose. If this is the only definition then this key will be used for all purposes.</strong><br />
<strong>#</strong></p>
<p style="text-align: justify;"><strong># Utimaco HSM Crypto Token example:</strong><br />
<strong>#sharedLibrary /opt/utimaco/p11/libcs2_pkcs11.so</strong><br />
<strong>#slotLabelType=SLOT_NUMBER</strong><br />
<strong>#slotLabelValue=1</strong></p>
<p style="text-align: justify;"><span style="color: #ff0000;"><strong>sharedLibrary /usr/safenet/lunaclient/lib/libCryptoki2_64.so <span style="color: #000000;">#library dari safenet</span></strong></span><br />
<span style="color: #ff0000;"><strong>slotLabelType=SLOT_NUMBER</strong></span><br />
<span style="color: #ff0000;"><strong>slotLabelValue=1 <span style="color: #000000;">#slot partisi yang digunakan</span></strong></span><br />
<span style="color: #ff0000;"><strong>pin=P@ssw0rd <span style="color: #000000;">#password yang di set pada partisi</span></strong></span></p>
<p style="text-align: justify;"><strong># CA key configuration</strong><br />
<strong>#defaultKey defaultRoot</strong><br />
<strong>#certSignKey signRoot</strong><br />
<strong>#crlSignKey signRoot</strong><br />
<strong>#testKey testRoot</strong></p>
<p style="text-align: justify;"><span style="color: #ff0000;"><strong>defaultKey defaultKey</strong></span><br />
<span style="color: #ff0000;"><strong>certSignKey signKey</strong></span><br />
<span style="color: #ff0000;"><strong>crlSignKey signKey</strong></span><br />
<span style="color: #ff0000;"><strong>testKey testKey</strong></span></p>
<h4 style="text-align: justify;"><strong>### End catoken.properties ###</strong></h4>
<h3 style="text-align: justify;"><span style="color: #00ccff;"><strong>certstore.properties</strong></span></h3>
<p style="text-align: justify;"><strong>### Start certstore.properties ###</strong></p>
<p style="text-align: justify;"><strong># ———— RFC 4387 Certificate store configuration ———————</strong><br />
<span style="color: #ff0000;"><strong>certstore.enabled=true</strong></span></p>
<p style="text-align: justify;"><strong># This is the web directory that the web interface for the cert store will use. </strong></p>
<p style="text-align: justify;"><strong># This is an unused alternate location</strong><br />
<span style="color: #ff0000;"><strong>certstore.contextroot=/ejbca/publicweb/certificates</strong></span></p>
<h4 style="text-align: justify;"><b>### End certstore.properties ###</b></h4>
<figure id="attachment_158" aria-describedby="caption-attachment-158" style="width: 831px" class="wp-caption aligncenter"><img loading="lazy" decoding="async" class="size-full wp-image-158" src="http://blog.goreinnamah.com/wp-content/uploads/2017/01/54-certstore-properties.png" alt="" width="831" height="174" srcset="https://blog.goreinnamah.com/wp-content/uploads/2017/01/54-certstore-properties.png 831w, https://blog.goreinnamah.com/wp-content/uploads/2017/01/54-certstore-properties-300x63.png 300w, https://blog.goreinnamah.com/wp-content/uploads/2017/01/54-certstore-properties-768x161.png 768w" sizes="auto, (max-width: 831px) 100vw, 831px" /><figcaption id="caption-attachment-158" class="wp-caption-text">certstore.properties</figcaption></figure>
<div class="subsubsection" style="text-align: justify;">
<h3><span style="color: #00ccff;"><strong>cesecore.properties</strong></span></h3>
<p><strong>### Start cesecore.properties ###</strong></p>
<p><span style="color: #ff0000;"><strong>allow.external-dynamic.configuration=true</strong></span></p>
<p><span style="color: #ff0000;"><strong>ca.keystorepass=!secret! <span style="color: #000000;">#ganti dengan yang kamu inginkan</span></strong></span></p>
<p><strong>#ca.rngalgorithm=SHA1PRNG</strong><br />
<span style="color: #ff0000;"><strong>ca.serialnumberoctetsize=8</strong></span></p>
<p><span style="color: #ff0000;"><strong>ca.toolateexpiredate=80000000<br />
</strong><strong>certificate.validityoffset=-10m</strong></span><br />
<strong>#ca.toolateexpiredate=2038-01-19 03:14:08+00:00</strong></p>
<p><strong>#ca.doPermitExtractablePrivateKeys=true</strong></p>
<p><strong>#forbidden.characters = \n\r;!\u0000%`?$~</strong><br />
<strong>#intresources.preferredlanguage=EN</strong><br />
<strong>#intresources.secondarylanguage=SE</strong></p>
<p><strong>#These variables will enable explicit logging. You can turn them off later</strong><br />
<span style="color: #ff0000;"><strong>securityeventsaudit.implementation.X=org.cesecore.audit.impl.log4j.Log4jDevice</strong></span><br />
<span style="color: #ff0000;"> <strong>securityeventsaudit.implementation.X=org.cesecore.audit.impl.integrityprotected.IntegrityProtectedDevice</strong></span></p>
<p><strong>#securityeventsaudit.implementation.0=null</strong><br />
<strong>#securityeventsaudit.implementation.1=null</strong></p>
<p><strong>#securityeventsaudit.exporter.X=org.cesecore.audit.impl.AuditExporterDummy (default)</strong><br />
<strong>#securityeventsaudit.exporter.X=org.cesecore.audit.impl.AuditExportCsv</strong><br />
<strong>#securityeventsaudit.exporter.X=org.cesecore.audit.impl.AuditExporterXml</strong><br />
<strong>#securityeventsaudit.deviceproperty.X.key.subkey=value</strong></p>
<p><strong># More log config below </strong><br />
<span style="color: #ff0000;"><strong>securityeventsaudit.implementation.0=org.cesecore.audit.impl.log4j.Log4jDevice</strong></span><br />
<span style="color: #ff0000;"><strong>securityeventsaudit.implementation.1=org.cesecore.audit.impl.integrityprotected.IntegrityProtectedDevice</strong></span><br />
<span style="color: #ff0000;"> <strong>securityeventsaudit.exporter.1=org.cesecore.audit.impl.AuditExporterXml</strong></span></p>
<p><strong>#securityeventsaudit.deviceproperty.1.export.dir=/tmp/</strong><br />
<strong>#securityeventsaudit.deviceproperty.1.export.fetchsize=1000</strong><br />
<strong>#securityeventsaudit.deviceproperty.1.validate.fetchsize=1000</strong></p>
<p><strong>#ecdsa.implicitlyca.q=883423532389192164791648750360308885314476597252960362792450860609699839</strong><br />
<strong>#ecdsa.implicitlyca.a=7fffffffffffffffffffffff7fffffffffff8000000000007ffffffffffc</strong><br />
<strong>#ecdsa.implicitlyca.b=6b016c3bdcf18941d0d654921475ca71a9db2fb27d1d37796185c2942c0a</strong><br />
<strong>#ecdsa.implicitlyca.g=020ffa963cdca8816ccc33b8642bedf905c3d358573d3f27fbbd3b3cb9aaaf</strong><br />
<strong>#ecdsa.implicitlyca.n=883423532389192164791648750360308884807550341691627752275345424702807307</strong></p>
<p><strong>### End cesecore.properties ###</strong></p>
<figure id="attachment_160" aria-describedby="caption-attachment-160" style="width: 853px" class="wp-caption aligncenter"><img loading="lazy" decoding="async" class="size-full wp-image-160" src="http://blog.goreinnamah.com/wp-content/uploads/2017/01/56-cesesore-properties-2.png" alt="" width="853" height="94" srcset="https://blog.goreinnamah.com/wp-content/uploads/2017/01/56-cesesore-properties-2.png 853w, https://blog.goreinnamah.com/wp-content/uploads/2017/01/56-cesesore-properties-2-300x33.png 300w, https://blog.goreinnamah.com/wp-content/uploads/2017/01/56-cesesore-properties-2-768x85.png 768w" sizes="auto, (max-width: 853px) 100vw, 853px" /><figcaption id="caption-attachment-160" class="wp-caption-text">cesecore.properties 2</figcaption></figure>
<figure id="attachment_159" aria-describedby="caption-attachment-159" style="width: 479px" class="wp-caption aligncenter"><img loading="lazy" decoding="async" class="size-full wp-image-159" src="http://blog.goreinnamah.com/wp-content/uploads/2017/01/55-cesesore-properties-1.png" alt="" width="479" height="42" srcset="https://blog.goreinnamah.com/wp-content/uploads/2017/01/55-cesesore-properties-1.png 479w, https://blog.goreinnamah.com/wp-content/uploads/2017/01/55-cesesore-properties-1-300x26.png 300w" sizes="auto, (max-width: 479px) 100vw, 479px" /><figcaption id="caption-attachment-159" class="wp-caption-text">cesecore.properties 1</figcaption></figure>
<h3><span style="color: #00ccff;"><strong>crlstore.properties</strong></span></h3>
<p><strong>### Start crlstore.properties ###</strong></p>
<p><strong># This is all very similar to certstore.properties</strong><br />
<strong># ———— RFC 4387 CRL store configuration ———————</strong><br />
<span style="color: #ff0000;"><strong>crlstore.enabled=true</strong></span><br />
<strong>#crlstore.contextroot=/crls</strong><br />
<span style="color: #ff0000;"><strong>crlstore.contextroot=/ejbca/publicweb/crls</strong></span></p>
<p><strong>### End crlstore.properties ###</strong></p>
<figure id="attachment_161" aria-describedby="caption-attachment-161" style="width: 818px" class="wp-caption aligncenter"><img loading="lazy" decoding="async" class="size-full wp-image-161" src="http://blog.goreinnamah.com/wp-content/uploads/2017/01/57-crlstore-properties.png" alt="" width="818" height="174" srcset="https://blog.goreinnamah.com/wp-content/uploads/2017/01/57-crlstore-properties.png 818w, https://blog.goreinnamah.com/wp-content/uploads/2017/01/57-crlstore-properties-300x64.png 300w, https://blog.goreinnamah.com/wp-content/uploads/2017/01/57-crlstore-properties-768x163.png 768w" sizes="auto, (max-width: 818px) 100vw, 818px" /><figcaption id="caption-attachment-161" class="wp-caption-text">crlstore.properties</figcaption></figure>
<h3><span style="color: #00ccff;"><strong>database.properties</strong></span></h3>
<p><strong>### Start database.properties ###</strong></p>
<p><strong># ————- Database configuration ————————</strong></p>
<p><strong>#This variable is used in our standalone.xml &lt;datasource&gt; stanza</strong><br />
<span style="color: #ff0000;"><strong>datasource.jndi-name=EjbcaDS</strong></span></p>
<p><strong># This is the TYPE of db, not the NAME OF the db</strong><br />
<span style="color: #ff0000;"><strong>database.name=mysql</strong></span></p>
<p><strong># Be sure to use utf-8</strong><br />
<span style="color: #ff0000;"><strong>database.url=jdbc:mysql://127.0.0.1:3306/&lt;nama_db&gt;?characterEncoding=UTF-8  </strong></span><br />
<span style="color: #ff0000;"><strong>database.driver=org.mariadb.jdbc.Driver</strong></span></p>
<p><strong>#username mysql yang sudah kamu buat:<br />
</strong><span style="color: #ff0000;"><strong>database.username=ejbcadbuser</strong></span></p>
<p><strong># password mysql yang sudah kamu buat: </strong><br />
<span style="color: #ff0000;"><strong>database.password=pumpkin</strong></span></p>
<p><strong>#### End database.properties ###</strong></p>
<figure id="attachment_166" aria-describedby="caption-attachment-166" style="width: 463px" class="wp-caption aligncenter"><img loading="lazy" decoding="async" class="size-full wp-image-166" src="http://blog.goreinnamah.com/wp-content/uploads/2017/01/58-database-properties-1.png" alt="" width="463" height="244" srcset="https://blog.goreinnamah.com/wp-content/uploads/2017/01/58-database-properties-1.png 463w, https://blog.goreinnamah.com/wp-content/uploads/2017/01/58-database-properties-1-300x158.png 300w" sizes="auto, (max-width: 463px) 100vw, 463px" /><figcaption id="caption-attachment-166" class="wp-caption-text">database.properties 1</figcaption></figure>
<figure id="attachment_167" aria-describedby="caption-attachment-167" style="width: 699px" class="wp-caption aligncenter"><img loading="lazy" decoding="async" class="size-full wp-image-167" src="http://blog.goreinnamah.com/wp-content/uploads/2017/01/59-database-properties-2.png" alt="" width="699" height="359" srcset="https://blog.goreinnamah.com/wp-content/uploads/2017/01/59-database-properties-2.png 699w, https://blog.goreinnamah.com/wp-content/uploads/2017/01/59-database-properties-2-300x154.png 300w" sizes="auto, (max-width: 699px) 100vw, 699px" /><figcaption id="caption-attachment-167" class="wp-caption-text">database.properties 2</figcaption></figure>
<figure id="attachment_170" aria-describedby="caption-attachment-170" style="width: 430px" class="wp-caption aligncenter"><img loading="lazy" decoding="async" class="size-full wp-image-170" src="http://blog.goreinnamah.com/wp-content/uploads/2017/01/1-5.png" alt="" width="430" height="181" srcset="https://blog.goreinnamah.com/wp-content/uploads/2017/01/1-5.png 430w, https://blog.goreinnamah.com/wp-content/uploads/2017/01/1-5-300x126.png 300w" sizes="auto, (max-width: 430px) 100vw, 430px" /><figcaption id="caption-attachment-170" class="wp-caption-text">database.properties 3</figcaption></figure>
<h3><span style="color: #00ccff;"><strong>ejbca.properties</strong></span></h3>
<p><strong>###Start ejbca.properties ###</strong></p>
<p><strong># The next two variables are very important… </strong><br />
<span style="color: #ff0000;"><strong>appserver.home=/opt/jboss</strong></span><br />
<span style="color: #ff0000;"> <strong>appserver.type=jboss</strong></span></p>
<p><strong># Initially, we will set this to false. Once the install is complete, we change</strong><br />
<strong># this to true.</strong><br />
<strong>#ejbca.productionmode=true</strong><br />
<span style="color: #ff0000;"><strong>ejbca.productionmode=false</strong></span></p>
<p><span style="color: #ff0000;"><strong>allow.external-dynamic.configuration=true</strong></span></p>
<p><strong># Don’t set these!</strong><br />
<strong>#ca.xkmskeystorepass=</strong><br />
<strong>#ca.cmskeystorepass=</strong></p>
<p><span style="color: #ff0000;"><strong>approval.defaultrequestvalidity=28800</strong></span><br />
<span style="color: #ff0000;"> <strong>approval.defaultapprovalvalidity=28800</strong></span><br />
<strong>#approval.excludedClasses=org.ejbca.extra.caservice.ExtRACAServiceWorker</strong><br />
<strong>#approval.excludedClasses=org.ejbca.core.protocol.cmp.CmpMessageDispatcherSessionBean</strong><br />
<strong>#approval.excludedClasses=org.ejbca.core.protocol.cmp.RevocationMessageHandler</strong><br />
<strong>#approval.excludedClasses=</strong></p>
<p><span style="color: #ff0000;"><strong>healthcheck.amountfreemem=32</strong></span><br />
<span style="color: #ff0000;"><strong>healthcheck.dbquery=Select 1 From CertificateData where fingerprint=’XX’</strong></span><br />
<span style="color: #ff0000;"><strong>healthcheck.authorizedips=127.0.0.1</strong></span><br />
<span style="color: #ff0000;"><strong>healthcheck.catokensigntest=true</strong></span><br />
<span style="color: #ff0000;"> <strong>healthcheck.publisherconnections=true</strong></span><br />
<strong>#healthcheck.maintenancefile=~/maintenance.properties</strong><br />
<strong>#healthcheck.maintenancepropertyname=DOWN_FOR_MAINTENANCE</strong><br />
<span style="color: #ff0000;"><strong>healthcheck.okmessage=ALLOK</strong></span><br />
<span style="color: #ff0000;"> <strong>healthcheck.sendservererror=true</strong></span><br />
<strong>#healthcheck.customerrormessage=EJBCANOTOK</strong></p>
<p><strong># It’s important to change this to 8:</strong><br />
<span style="color: #ff0000;"><strong>ejbca.passwordlogrounds=8</strong></span></p>
<p><strong>#——————- CLI settings ————-</strong><br />
<span style="color: #ff0000;"><strong>ejbca.cli.defaultusername=apaaja</strong></span><br />
<span style="color: #ff0000;"> <strong>ejbca.cli.defaultpassword=bebaspokoknya</strong></span></p>
<p><strong>### End ejbca.properties ###</strong></p>
<figure id="attachment_172" aria-describedby="caption-attachment-172" style="width: 486px" class="wp-caption aligncenter"><img loading="lazy" decoding="async" class="size-full wp-image-172" src="http://blog.goreinnamah.com/wp-content/uploads/2017/01/61-ejbca-properties-1.png" alt="" width="486" height="365" srcset="https://blog.goreinnamah.com/wp-content/uploads/2017/01/61-ejbca-properties-1.png 486w, https://blog.goreinnamah.com/wp-content/uploads/2017/01/61-ejbca-properties-1-300x225.png 300w" sizes="auto, (max-width: 486px) 100vw, 486px" /><figcaption id="caption-attachment-172" class="wp-caption-text">ejbca.properties 1</figcaption></figure>
<figure id="attachment_173" aria-describedby="caption-attachment-173" style="width: 782px" class="wp-caption aligncenter"><img loading="lazy" decoding="async" class="size-full wp-image-173" src="http://blog.goreinnamah.com/wp-content/uploads/2017/01/62-ejbca-properties-2.png" alt="" width="782" height="170" srcset="https://blog.goreinnamah.com/wp-content/uploads/2017/01/62-ejbca-properties-2.png 782w, https://blog.goreinnamah.com/wp-content/uploads/2017/01/62-ejbca-properties-2-300x65.png 300w, https://blog.goreinnamah.com/wp-content/uploads/2017/01/62-ejbca-properties-2-768x167.png 768w" sizes="auto, (max-width: 782px) 100vw, 782px" /><figcaption id="caption-attachment-173" class="wp-caption-text">ejbca.properties 2</figcaption></figure>
<figure id="attachment_174" aria-describedby="caption-attachment-174" style="width: 852px" class="wp-caption aligncenter"><img loading="lazy" decoding="async" class="size-full wp-image-174" src="http://blog.goreinnamah.com/wp-content/uploads/2017/01/63-ejbca-properties-3.png" alt="" width="852" height="506" srcset="https://blog.goreinnamah.com/wp-content/uploads/2017/01/63-ejbca-properties-3.png 852w, https://blog.goreinnamah.com/wp-content/uploads/2017/01/63-ejbca-properties-3-300x178.png 300w, https://blog.goreinnamah.com/wp-content/uploads/2017/01/63-ejbca-properties-3-768x456.png 768w" sizes="auto, (max-width: 852px) 100vw, 852px" /><figcaption id="caption-attachment-174" class="wp-caption-text">ejbca.properties 3</figcaption></figure>
<figure id="attachment_175" aria-describedby="caption-attachment-175" style="width: 728px" class="wp-caption aligncenter"><img loading="lazy" decoding="async" class="size-full wp-image-175" src="http://blog.goreinnamah.com/wp-content/uploads/2017/01/64-ejbca-properties-4.png" alt="" width="728" height="270" srcset="https://blog.goreinnamah.com/wp-content/uploads/2017/01/64-ejbca-properties-4.png 728w, https://blog.goreinnamah.com/wp-content/uploads/2017/01/64-ejbca-properties-4-300x111.png 300w" sizes="auto, (max-width: 728px) 100vw, 728px" /><figcaption id="caption-attachment-175" class="wp-caption-text">ejbca.properties 4</figcaption></figure>
<figure id="attachment_176" aria-describedby="caption-attachment-176" style="width: 850px" class="wp-caption aligncenter"><img loading="lazy" decoding="async" class="size-full wp-image-176" src="http://blog.goreinnamah.com/wp-content/uploads/2017/01/65-ejbca-properties-5.png" alt="" width="850" height="140" srcset="https://blog.goreinnamah.com/wp-content/uploads/2017/01/65-ejbca-properties-5.png 850w, https://blog.goreinnamah.com/wp-content/uploads/2017/01/65-ejbca-properties-5-300x49.png 300w, https://blog.goreinnamah.com/wp-content/uploads/2017/01/65-ejbca-properties-5-768x126.png 768w" sizes="auto, (max-width: 850px) 100vw, 850px" /><figcaption id="caption-attachment-176" class="wp-caption-text">ejbca.properties 5</figcaption></figure>
<h3><span style="color: #00ccff;"><strong>install.properties</strong></span></h3>
<p><strong>### This file is essentially an “answer file” used when running the “ant install” command.</strong><br />
<strong>### The variables listed here are *not* used by ejbca while it is running.</strong></p>
<p><strong>### Start install.properties ###</strong></p>
<p><strong># In every case that “CA” is mentioned in this file, it refers to the “management” CA ONLY.</strong></p>
<p><strong># This will be the initial name of the management CA instance</strong><br />
<strong># ejbca will use this for administration purpose, not your production CAs</strong><br />
<strong># Note that the CN given here is NOT the FQDN of your CA!</strong><br />
<strong># Why does this matter? This certificate will be temporarily installed </strong><br />
<strong># on your browser as a trusted root CA, but will not be communicated </strong><br />
<strong># with.</strong><br />
<span style="color: #ff0000;"><strong>ca.name=mgmtca</strong></span><br />
<span style="color: #ff0000;"> <strong>ca.dn=CN=mgmtca,O=Your Company,C=ID</strong></span></p>
<p><strong># The token type the administrative CA will use.</strong><br />
<span style="color: #ff0000;"><strong>ca.tokentype=org.cesecore.keys.token.PKCS11CryptoToken</strong></span></p>
<p><strong>#Password for the administrative CA token. Masukkan sama dengan pin pada catoken.properties</strong><br />
<span style="color: #ff0000;"><strong>ca.tokenpassword=P@ssw0rd <span style="color: #000000;">#sama seperti password yang kamu masukkan di catoken.properties</span></strong></span></p>
<p><strong># This is the path to a “catoken.properties” file that will be created when ‘ant</strong><br />
<strong># install’ is run. It will contain encryption parameters used by the mgmt CA.</strong><br />
<strong># It is only used with hard encryption tokens, and can be ignored if your certs</strong><br />
<strong># will be stored in the ejbca database (which is were we will be putting them.)</strong></p>
<p><strong># Configuration file were you define key name, password and key alias for the HSM</strong><br />
<span style="color: #ff0000;"><strong>ca.tokenproperties=/opt/ejbca/conf/catoken.properties</strong></span></p>
<p><strong># THIS IS IMPORTANT</strong><br />
<strong># You can assume that ejbca cannot use EC algorithms for the management CA.</strong><br />
<strong># This does not mean that ejbca cannot issue certificates that use EC.</strong><br />
<strong># It just means that the management CA will use RSA for internal purposes.</strong><br />
<strong># The reason for this limitation is that the various EC algorithms are</strong><br />
<strong># not equally supported by the various java flavors that could be used.</strong><br />
<strong># More importantly, ejbca does not include any sort of logic to identify</strong><br />
<strong># the version of java you are using to limit or correct your options.</strong><br />
<strong># Choosing an unsupported algorithm here leads to a corrupt installation.</strong><br />
<strong># This can waste a great amount of time, so just avoid EC. </strong><br />
<strong># You can use EC later with the actual production CAs you define.</strong></p>
<p><strong># Keyspec for RSA keys is size of RSA keys (1024, 2048, 4096, 8192).</strong><br />
<span style="color: #ff0000;"><strong>ca.keyspec=2048</strong></span></p>
<p><strong># The keytype for the administrative CA, can be RSA, ECDSA or DSA</strong><br />
<span style="color: #ff0000;"><strong>ca.keytype=RSA</strong></span></p>
<p><strong># Even though SHA1 is still largely in use as a certificate hashing</strong><br />
<strong># algorithm, I *strongly* suggest that you go with SHA256WithRSA.</strong><br />
<strong># Also, please note that the “with/With” in the hash names is indeed case-sensitive. </strong><br />
<strong># Stay classy, Oracle.</strong></p>
<p><strong># SHA1WithRSA, SHA1withECDSA, SHA256WithRSA, SHA256withECDSA.</strong><br />
<span style="color: #ff0000;"><strong>ca.signaturealgorithm=SHA256WithRSA</strong></span></p>
<p><strong># I set a CA validity of 10 years (including the leap years, rain man)</strong><br />
<span style="color: #ff0000;"><strong>ca.validity=5650</strong></span><br />
<span style="color: #ff0000;"><strong>ca.policy=null</strong></span><br />
<span style="color: #ff0000;"><strong>ca.certificateprofile=ROOTCA</strong></span></p>
<p><strong>### End install.properties ###</strong></p>
<figure id="attachment_1622" aria-describedby="caption-attachment-1622" style="width: 905px" class="wp-caption aligncenter"><img loading="lazy" decoding="async" class="size-full wp-image-1622" src="http://blog.goreinnamah.com/wp-content/uploads/2017/12/Screenshot-from-2017-12-01-15-09-26.png" alt="" width="905" height="456" srcset="https://blog.goreinnamah.com/wp-content/uploads/2017/12/Screenshot-from-2017-12-01-15-09-26.png 905w, https://blog.goreinnamah.com/wp-content/uploads/2017/12/Screenshot-from-2017-12-01-15-09-26-300x151.png 300w, https://blog.goreinnamah.com/wp-content/uploads/2017/12/Screenshot-from-2017-12-01-15-09-26-768x387.png 768w" sizes="auto, (max-width: 905px) 100vw, 905px" /><figcaption id="caption-attachment-1622" class="wp-caption-text">install.properties1</figcaption></figure>
<figure id="attachment_214" aria-describedby="caption-attachment-214" style="width: 853px" class="wp-caption aligncenter"><img loading="lazy" decoding="async" class="size-full wp-image-214" src="http://blog.goreinnamah.com/wp-content/uploads/2017/01/67-install-properties-2.png" alt="" width="853" height="475" srcset="https://blog.goreinnamah.com/wp-content/uploads/2017/01/67-install-properties-2.png 853w, https://blog.goreinnamah.com/wp-content/uploads/2017/01/67-install-properties-2-300x167.png 300w, https://blog.goreinnamah.com/wp-content/uploads/2017/01/67-install-properties-2-768x428.png 768w" sizes="auto, (max-width: 853px) 100vw, 853px" /><figcaption id="caption-attachment-214" class="wp-caption-text">install.properties 2</figcaption></figure>
<h3><span style="color: #00ccff;"><strong>web.properties</strong></span></h3>
<p><strong>### Start web.properties ###</strong></p>
<p><strong># The key to this portion of the config is understanding that this file affects</strong><br />
<strong># the certificate used by the ejbca admin webpage. In install.properties, we</strong><br />
<strong># defined variables for the management CA root certificate. But that certificate</strong><br />
<strong># is not used for session TLS. The management CA issues a separate “server</strong><br />
<strong># certificate” for that purpose that is defined here.</strong></p>
<p><strong># ———— Web GUI configuration ———————</strong><br />
<strong># Can not be set to false, commented away means that web will be configured.</strong><br />
<strong>#web.noconfigure=true</strong></p>
<p><strong># Can not be set to false, commented away means that web will be configured.</strong><br />
<strong># web.nosslconfigure=true</strong></p>
<p><span style="color: #ff0000;"><strong>java.trustpassword=gantiapaaja</strong></span></p>
<p><span style="color: #ff0000;"><strong>superadmin.cn=superadmin</strong></span><br />
<span style="color: #ff0000;"><strong>superadmin.dn=CN=${superadmin.cn},O=Your Company,C=ID</strong></span></p>
<p><span style="color: #ff0000;"><strong>superadmin.password=ejbca</strong></span></p>
<p><span style="color: #ff0000;"><strong>superadmin.batch=true</strong></span></p>
<p><strong># You do not need to set this password!</strong><br />
<strong>#httpsserver.password=serverpwd</strong></p>
<p><span style="color: #ff0000;"><strong>httpsserver.hostname=rootca.domainlo.net</strong></span></p>
<p><span style="color: #ff0000;"><strong>httpsserver.dn=CN=${httpsserver.hostname},O=Your Company,C=ID</strong></span></p>
<p><strong># This is the port that will host the unencrypted Ejbca Public Web page.</strong><br />
<strong># Note that this will be used the CRL and OSCP URLs, although it will be NATted to port 80 by our firewall rules.</strong></p>
<p><span style="color: #ff0000;"><strong>httpserver.pubhttp=8080</strong></span></p>
<p><strong># This is the port that will host the encrypted Ejbca Public Web page, *without* client certificate authentication.</strong><br />
<span style="color: #ff0000;"><strong>httpserver.pubhttps=8442</strong></span></p>
<p><strong># This is the port that will host the encrypted Ejbca Public Web page,</strong><br />
<strong># as well as the Administration page. Accessing content hosted on</strong><br />
<strong># this port requires client certificate authentication.</strong></p>
<p><strong># Note that the Ejbca Public Web page link to the administration</strong><br />
<strong># page will try to include this port in the URL, regardless of any</strong><br />
<strong># port redirection you may be using. This will fixed at the end of</strong><br />
<strong># the how-to.</strong></p>
<p><span style="color: #ff0000;"><strong>httpserver.privhttps=8443</strong></span></p>
<p><strong># Trying to use port 443 will not work here, as it is a “privileged” port.</strong><br />
<strong>#httpserver.external.privhttps=443</strong></p>
<p><strong>#Don’t set these up unless you use an apache proxy for port translation</strong></p>
<p><strong>#httpserver.external.fqdn=</strong><br />
<strong>#httpserver.external.fqdn=${httpsserver.hostname}</strong></p>
<p><strong>#httpsserver.bindaddress.pubhttp=0.0.0.0</strong><br />
<strong>#httpsserver.bindaddress.pubhttps=0.0.0.0</strong><br />
<strong>#httpsserver.bindaddress.privhttps=0.0.0.0</strong></p>
<p><strong># Who let the Swedes in here?</strong><br />
<strong>#web.availablelanguages=EN,DE,ES,FR,IT,JA,PT,SE,UA,ZH,BS</strong></p>
<p><span style="color: #ff0000;"><strong>web.availablelanguages=EN,DE,ES,FR,IT,JA,PT,UA,ZH,BS</strong></span><br />
<span style="color: #ff0000;"> <strong>web.contentencoding=UTF-8</strong></span></p>
<p><strong># Well, this doesn’t sound like a good idea. </strong><br />
<strong>#hardtoken.diplaysensitiveinfo=true</strong></p>
<p><strong>#web.docbaseuri=disabled</strong><br />
<strong>#web.docbaseuri=internal</strong><br />
<strong>#web.docbaseuri=http://www.ejbca.org</strong></p>
<p><strong>#web.reqcertindb=true</strong></p>
<p><span style="color: #ff0000;"><strong>web.selfreg.enabled=false</strong></span><br />
<span style="color: #ff0000;"><strong>web.selfreg.defaultcerttype=1</strong></span><br />
<span style="color: #ff0000;"> <strong>web.selfreg.certtypes.1.description=User certificate</strong></span><br />
<span style="color: #ff0000;"> <strong>web.selfreg.certtypes.1.eeprofile=SOMEPROFILE</strong></span><br />
<span style="color: #ff0000;"> <strong>web.selfreg.certtypes.1.certprofile=ENDUSER</strong></span><br />
<strong>#web.selfreg.certtypes.1.usernamemapping=CN</strong><br />
<span style="color: #ff0000;"><strong>web.renewalenabled=false</strong></span><br />
<strong>#web.manualclasspathsenabled=true</strong></p>
<p><strong>#web.errorpage.notification=An exception has occurred.</strong><br />
<span style="color: #ff0000;"><strong>web.errorpage.notification=ZOMG PWND!!!!!!!!!!</strong></span></p>
<p><strong># This setting is good for a lab environment. Don’t use this in production.</strong><br />
<span style="color: #ff0000;"><strong>web.errorpage.stacktrace=true</strong></span></p>
<p><strong>#web.enableproxiedauth=true</strong><br />
<span style="color: #ff0000;"><strong>web.log.adminremoteip=true</strong></span><br />
<strong>#web.log.adminforwardedip=true</strong></p>
<p><strong>#### End web.properties ###</strong></p>
<figure id="attachment_180" aria-describedby="caption-attachment-180" style="width: 854px" class="wp-caption aligncenter"><img loading="lazy" decoding="async" class="size-full wp-image-180" src="http://blog.goreinnamah.com/wp-content/uploads/2017/01/68-web-properties-1.png" alt="" width="854" height="507" srcset="https://blog.goreinnamah.com/wp-content/uploads/2017/01/68-web-properties-1.png 854w, https://blog.goreinnamah.com/wp-content/uploads/2017/01/68-web-properties-1-300x178.png 300w, https://blog.goreinnamah.com/wp-content/uploads/2017/01/68-web-properties-1-768x456.png 768w" sizes="auto, (max-width: 854px) 100vw, 854px" /><figcaption id="caption-attachment-180" class="wp-caption-text">web.properties 1</figcaption></figure>
<figure id="attachment_183" aria-describedby="caption-attachment-183" style="width: 854px" class="wp-caption aligncenter"><img loading="lazy" decoding="async" class="size-full wp-image-183" src="http://blog.goreinnamah.com/wp-content/uploads/2017/01/62-ejbca-properties-2-1.png" alt="" width="854" height="239" srcset="https://blog.goreinnamah.com/wp-content/uploads/2017/01/62-ejbca-properties-2-1.png 854w, https://blog.goreinnamah.com/wp-content/uploads/2017/01/62-ejbca-properties-2-1-300x84.png 300w, https://blog.goreinnamah.com/wp-content/uploads/2017/01/62-ejbca-properties-2-1-768x215.png 768w" sizes="auto, (max-width: 854px) 100vw, 854px" /><figcaption id="caption-attachment-183" class="wp-caption-text">web.properties 2</figcaption></figure>
<figure id="attachment_185" aria-describedby="caption-attachment-185" style="width: 852px" class="wp-caption aligncenter"><img loading="lazy" decoding="async" class="size-full wp-image-185" src="http://blog.goreinnamah.com/wp-content/uploads/2017/01/70-web-properties-3.png" alt="" width="852" height="139" srcset="https://blog.goreinnamah.com/wp-content/uploads/2017/01/70-web-properties-3.png 852w, https://blog.goreinnamah.com/wp-content/uploads/2017/01/70-web-properties-3-300x49.png 300w, https://blog.goreinnamah.com/wp-content/uploads/2017/01/70-web-properties-3-768x125.png 768w" sizes="auto, (max-width: 852px) 100vw, 852px" /><figcaption id="caption-attachment-185" class="wp-caption-text">web.properties 3</figcaption></figure>
<figure id="attachment_186" aria-describedby="caption-attachment-186" style="width: 786px" class="wp-caption aligncenter"><img loading="lazy" decoding="async" class="size-full wp-image-186" src="http://blog.goreinnamah.com/wp-content/uploads/2017/01/71-web-properties-4.png" alt="" width="786" height="324" srcset="https://blog.goreinnamah.com/wp-content/uploads/2017/01/71-web-properties-4.png 786w, https://blog.goreinnamah.com/wp-content/uploads/2017/01/71-web-properties-4-300x124.png 300w, https://blog.goreinnamah.com/wp-content/uploads/2017/01/71-web-properties-4-768x317.png 768w" sizes="auto, (max-width: 786px) 100vw, 786px" /><figcaption id="caption-attachment-186" class="wp-caption-text">web.properties 4</figcaption></figure>
<figure id="attachment_187" aria-describedby="caption-attachment-187" style="width: 853px" class="wp-caption aligncenter"><img loading="lazy" decoding="async" class="size-full wp-image-187" src="http://blog.goreinnamah.com/wp-content/uploads/2017/01/72-web-properties-5.png" alt="" width="853" height="410" srcset="https://blog.goreinnamah.com/wp-content/uploads/2017/01/72-web-properties-5.png 853w, https://blog.goreinnamah.com/wp-content/uploads/2017/01/72-web-properties-5-300x144.png 300w, https://blog.goreinnamah.com/wp-content/uploads/2017/01/72-web-properties-5-768x369.png 768w" sizes="auto, (max-width: 853px) 100vw, 853px" /><figcaption id="caption-attachment-187" class="wp-caption-text">web.properties 5</figcaption></figure>
<h3>Deploy EJBCA 6.10.1.2</h3>
<p>Sekarang kita sudah punya file properties yang sudah dimodifikasi. Kita bisa memulai untuk <em>build </em>dan <em>deploy </em>EJBCA ke Wildfly, tanpa menyentuh konfigurasi konfigurasi Wildfly, dengan menjalankan perintah EJBCA.</p>
<p>Sebelum menjalankan perintah <em>deployear, </em>jangan lupa untuk mengarahkan <em><strong>application server</strong> </em>pada <strong>APPSRV_HOME </strong>dan konfigur database pada <strong>conf/database.properties.</strong></p>
<p>Jalankan perintah ini pada <em>command prompt </em>di <strong>EJBCA_HOME</strong></p>
<pre><span style="color: #ff0000;"><strong>chown ­R jboss:jboss /opt/wildfly-10.0.0</strong>
<strong>chown ­R jboss:jboss /opt/ejbca_ce_6_10_1_2
</strong><strong>cd /opt/ejbca
ant deployear</strong></span></pre>
<ul>
<li>Kalian harus selalu menjalankan <strong>ant</strong> dari folder <strong>/opt/ejbca</strong>, tempat dimana <strong>build.xml </strong>berada. kita bisa saja menggunakan path menuju folder ejbca tersebut ketika mengeksekusi perintah <strong>ant</strong>, namun lebih mudah apabila kita pindah langsung ke folder <strong>/opt/ejbca</strong>.</li>
<li>dan yang terakhir, Wildfly harus terlebih dahulu berjalan sebelum kita menjalankan perintah <strong>ant</strong>.</li>
</ul>
<p>Deployment yang kita lakukan menarik informasi dari file konfigurasi, menggunakan informasi tersebut untuk meng-compile file <strong>ejbca.ear</strong>, kemudian mendorong wildfly untuk men-deploy-nya. Karena ini deployment pertama, <strong>ant</strong> juga melakukan hal berikut:</p>
<ul>
<li>Menambahkan konfigurasi mail ejbca ke file standalone.xml</li>
<li>menambahkan ejbca datasource ke file standalone.xml</li>
<li>membuat tabel pada database dengan skema awal</li>
</ul>
<p>Periksa Wildfly console atau log yang ada untuk memastikan tidak ada error yang terjadi pada saat proses deploy.</p>
<h3><strong>Run Install</strong></h3>
<p>setelah proses <strong>deployear </strong>berjalan mulus tanpa ada masalah, sekarang adalah waktunya melakukan <strong>run install. </strong>Caranya:</p>
<pre><span style="color: #ff0000;"><strong>ant runinstall</strong></span></pre>
<figure id="attachment_2187" aria-describedby="caption-attachment-2187" style="width: 475px" class="wp-caption aligncenter"><img loading="lazy" decoding="async" class="size-full wp-image-2187" src="http://blog.goreinnamah.com/wp-content/uploads/2018/03/27-runinstall.png" alt="" width="475" height="115" srcset="https://blog.goreinnamah.com/wp-content/uploads/2018/03/27-runinstall.png 475w, https://blog.goreinnamah.com/wp-content/uploads/2018/03/27-runinstall-300x73.png 300w" sizes="auto, (max-width: 475px) 100vw, 475px" /><figcaption id="caption-attachment-2187" class="wp-caption-text">proses runinstall berjalan lancar</figcaption></figure>
<h3><strong>Deploy TLS Keystore ke dalam WildFLy</strong></h3>
<p>Setelah install, TLS keystores telah berhasil dibuat. Jalankan perintah berikut untuk meng-<em>copy </em><em>keystore </em>tersebut ke <strong>wildfly_home/standarlone/config/keystore.</strong></p>
</div>
<pre class="code"><span style="color: #ff0000;"><strong>ant deploy-keystore</strong></span></pre>
<figure id="attachment_2188" aria-describedby="caption-attachment-2188" style="width: 549px" class="wp-caption aligncenter"><img loading="lazy" decoding="async" class="size-full wp-image-2188" src="http://blog.goreinnamah.com/wp-content/uploads/2018/03/28-deploy-keystore.png" alt="" width="549" height="712" srcset="https://blog.goreinnamah.com/wp-content/uploads/2018/03/28-deploy-keystore.png 549w, https://blog.goreinnamah.com/wp-content/uploads/2018/03/28-deploy-keystore-231x300.png 231w" sizes="auto, (max-width: 549px) 100vw, 549px" /><figcaption id="caption-attachment-2188" class="wp-caption-text">deploy-keystore</figcaption></figure>
<h3 style="text-align: justify;"><strong>Menghapus TLS dan Konfigurasi HTTP yang Sudah Ada</strong></h3>
<p style="text-align: justify;">Jalankan perintah berikut pada <strong>JBOSS CLI </strong>untuk menhapus konfigurasi TLS dan HTTP yang sudah ada (hanya untuk keamanan).</p>
<pre class="code"><span style="color: #ff0000;"><strong>/subsystem=undertow/server=default-server/http-listener=default:remove
/subsystem=undertow/server=default-server/https-listener=https:remove
/socket-binding-group=standard-sockets/socket-binding=http:remove
/socket-binding-group=standard-sockets/socket-binding=https:remove
:reload</strong></span></pre>
<figure id="attachment_2189" aria-describedby="caption-attachment-2189" style="width: 725px" class="wp-caption aligncenter"><img loading="lazy" decoding="async" class="size-full wp-image-2189" src="http://blog.goreinnamah.com/wp-content/uploads/2018/03/29-remove-tls-and-http-conf.png" alt="" width="725" height="651" srcset="https://blog.goreinnamah.com/wp-content/uploads/2018/03/29-remove-tls-and-http-conf.png 725w, https://blog.goreinnamah.com/wp-content/uploads/2018/03/29-remove-tls-and-http-conf-300x269.png 300w" sizes="auto, (max-width: 725px) 100vw, 725px" /><figcaption id="caption-attachment-2189" class="wp-caption-text">remove tls and http conf</figcaption></figure>
<p style="text-align: justify;">Tunggu proses <em>reload </em>hingga benar-benar selesai dengan memeriksa <em>log server </em>sebelum melanjutkan ke proses selanjutnya.</p>
<p style="text-align: justify;"><strong><span style="color: #000000;">Konfigure TLS</span></strong></p>
<p style="text-align: justify;">Jalankan perintah berikut pada <strong>JBOSS CLI</strong> (jboss-cli.sh -c) untuk mengatur konfigurasi TLS.</p>
<p style="text-align: justify;">Tambahkan <em>interfaces, </em>gunakan 0.0.0.0 agar bisa diakses dari luar:</p>
<pre class="code"><span style="color: #ff0000;"><strong>/interface=http:add(inet-address="0.0.0.0")
/interface=httpspub:add(inet-address="0.0.0.0")
/interface=httpspriv:add(inet-address="0.0.0.0")
/socket-binding-group=standard-sockets/socket-binding=http:add(port="8080",interface="http")
/subsystem=undertow/server=default-server/http-listener=http:add(socket-binding=http)
/subsystem=undertow/server=default-server/http-listener=http:write-attribute(name=redirect-socket, value="httpspriv")
:reload</strong></span></pre>
<figure id="attachment_2190" aria-describedby="caption-attachment-2190" style="width: 1046px" class="wp-caption aligncenter"><img loading="lazy" decoding="async" class="size-full wp-image-2190" src="http://blog.goreinnamah.com/wp-content/uploads/2018/03/30-configure-TLS.png" alt="" width="1046" height="365" srcset="https://blog.goreinnamah.com/wp-content/uploads/2018/03/30-configure-TLS.png 1046w, https://blog.goreinnamah.com/wp-content/uploads/2018/03/30-configure-TLS-300x105.png 300w, https://blog.goreinnamah.com/wp-content/uploads/2018/03/30-configure-TLS-768x268.png 768w, https://blog.goreinnamah.com/wp-content/uploads/2018/03/30-configure-TLS-1024x357.png 1024w" sizes="auto, (max-width: 1046px) 100vw, 1046px" /><figcaption id="caption-attachment-2190" class="wp-caption-text">configure TLS</figcaption></figure>
<p style="text-align: justify;">Tunggu proses <em>reload </em>hingga benar-benar selesai dengan memeriksa <em>log server </em>sebelum melanjutkan ke proses selanjutnya.</p>
<p style="text-align: justify;"><strong>Konfigur <em>identities </em>dan <em>socket bindings:</em></strong></p>
<p style="text-align: justify;"><em>update </em><em>keystore alias </em>agar cocok dengan <strong>httpsserver.hostname </strong>yang ada pada <strong>web.properties. </strong>Jangan lupa juga untuk <em>update </em><strong>keystore-password </strong>untuk <strong>keystore.jks </strong>agar cocok dengan <strong>httpsserver.password </strong>dan <strong>keystore-password </strong>untuk <strong>trustore.jks </strong>agar cocok dengan <strong>java.trustore </strong>pada <strong>web.properties:</strong></p>
<h5 style="text-align: justify;"> <span style="color: #ff0000;">*pastikan kalau password pada sesi ini sesuai. Kalau tidak, maka proses akan gagal. Untuk kalian yang melakukannya pada <em>production, </em>password harus benar-benar diganti ke password yang sesuai.</span></h5>
<pre class="code"><span style="color: #ff0000;"><strong>/core-service=management/security-realm=SSLRealm:add()
/core-service=management/security-realm=SSLRealm/server-identity=ssl:add(keystore-path="${jboss.server.config.dir}/keystore/keystore.jks", keystore-password="<span style="color: #000000;">serverpwd</span>", alias="<span style="color: #000000;">localhost</span>")
/core-service=management/security-realm=SSLRealm/authentication=truststore:add(keystore-path="${jboss.server.config.dir}/keystore/truststore.jks", keystore-password="<span style="color: #000000;">changeit</span>")
/socket-binding-group=standard-sockets/socket-binding=httpspriv:add(port="8443",interface="httpspriv")
/socket-binding-group=standard-sockets/socket-binding=httpspub:add(port="8442", interface="httpspub")</strong></span></pre>
<figure id="attachment_2192" aria-describedby="caption-attachment-2192" style="width: 1596px" class="wp-caption alignnone"><img loading="lazy" decoding="async" class="size-full wp-image-2192" src="http://blog.goreinnamah.com/wp-content/uploads/2018/03/31.png" alt="" width="1596" height="442" srcset="https://blog.goreinnamah.com/wp-content/uploads/2018/03/31.png 1596w, https://blog.goreinnamah.com/wp-content/uploads/2018/03/31-300x83.png 300w, https://blog.goreinnamah.com/wp-content/uploads/2018/03/31-768x213.png 768w, https://blog.goreinnamah.com/wp-content/uploads/2018/03/31-1024x284.png 1024w" sizes="auto, (max-width: 1596px) 100vw, 1596px" /><figcaption id="caption-attachment-2192" class="wp-caption-text">Update Keystore</figcaption></figure>
<p style="text-align: justify;">Restart Wildfly sampai benar-benar berjalan kembali. Periksa log untuk benar-benar memastikannya</p>
<p style="text-align: justify;">Setelah me-<em>restart </em>Wildfly, sekarang jalankan perintah berikut:</p>
<pre class="code"><span style="color: #ff0000;"><strong>/subsystem=undertow/server=default-server/https-listener=httpspriv:add(socket-binding=httpspriv, security-realm="SSLRealm", verify-client=REQUIRED)
/subsystem=undertow/server=default-server/https-listener=httpspriv:write-attribute(name=max-parameters, value="2048")
/subsystem=undertow/server=default-server/https-listener=httpspub:add(socket-binding=httpspub, security-realm="SSLRealm")
/subsystem=undertow/server=default-server/https-listener=httpspub:write-attribute(name=max-parameters, value="2048")
:reload</strong></span></pre>
<figure id="attachment_2193" aria-describedby="caption-attachment-2193" style="width: 1248px" class="wp-caption aligncenter"><img loading="lazy" decoding="async" class="size-full wp-image-2193" src="http://blog.goreinnamah.com/wp-content/uploads/2018/03/32-restart-appserver.png" alt="" width="1248" height="455" srcset="https://blog.goreinnamah.com/wp-content/uploads/2018/03/32-restart-appserver.png 1248w, https://blog.goreinnamah.com/wp-content/uploads/2018/03/32-restart-appserver-300x109.png 300w, https://blog.goreinnamah.com/wp-content/uploads/2018/03/32-restart-appserver-768x280.png 768w, https://blog.goreinnamah.com/wp-content/uploads/2018/03/32-restart-appserver-1024x373.png 1024w" sizes="auto, (max-width: 1248px) 100vw, 1248px" /><figcaption id="caption-attachment-2193" class="wp-caption-text">Jalankan setelah restart appserver</figcaption></figure>
<p style="text-align: justify;">Untuk finalisasi, jalankan perintah berikut:</p>
<pre class="code"><span style="color: #ff0000;"><strong>/system-property=org.apache.tomcat.util.buf.UDecoder.ALLOW_ENCODED_SLASH:add(value=true)
/system-property=org.apache.catalina.connector.CoyoteAdapter.ALLOW_BACKSLASH:add(value=true)
/system-property=org.apache.catalina.connector.URI_ENCODING:add(value="UTF-8")
/system-property=org.apache.catalina.connector.USE_BODY_ENCODING_FOR_QUERY_STRING:add(value=true)
/subsystem=webservices:write-attribute(name=wsdl-host, value=jbossws.undefined.host)
/subsystem=webservices:write-attribute(name=modify-wsdl-address, value=true)
:reload</strong></span></pre>
<figure id="attachment_2194" aria-describedby="caption-attachment-2194" style="width: 905px" class="wp-caption aligncenter"><img loading="lazy" decoding="async" class="size-full wp-image-2194" src="http://blog.goreinnamah.com/wp-content/uploads/2018/03/33-last.png" alt="" width="905" height="410" srcset="https://blog.goreinnamah.com/wp-content/uploads/2018/03/33-last.png 905w, https://blog.goreinnamah.com/wp-content/uploads/2018/03/33-last-300x136.png 300w, https://blog.goreinnamah.com/wp-content/uploads/2018/03/33-last-768x348.png 768w" sizes="auto, (max-width: 905px) 100vw, 905px" /><figcaption id="caption-attachment-2194" class="wp-caption-text">konfigurasi akhir</figcaption></figure>
<h5 style="text-align: justify;"><span style="color: #ff0000;"><strong>*Jika kamu menggunakan OCSP GET request, maka pengaturan URI Encoding dan mengizinkan encoding untuk query dan backslash sangat diperlukan.</strong></span></h5>
<h3 style="text-align: justify;"><strong>Lebih Detail soal Ant</strong></h3>
<p style="text-align: justify;">Kenapa kita melakukan ant deploy sebelum melakukan ant install? ada dua alasannya:</p>
<ul style="text-align: justify;">
<li>untuk menguji file <strong>ejbca.ear</strong> sukses di-compile dari apa yang sudah kita bangun sejauh ini. Menjalankan <strong>ant deploy</strong> sambil membaca log memberikan kita sebuah kesempatan untuk memperbaiki kesalahan sebelum lanjut ke tahap selanjutnya. Setelah instalasi komplit, akan jauh lebih sulit untuk memperbaiki kesalahan-kesalahan yang terjadi pada konfigurasi.</li>
<li>yang lebih penting lagi, file <strong>ejbca.ear</strong> haruslah ada sebelum file <strong>install</strong> dapat dieksekusi.</li>
</ul>
<p style="text-align: justify;">Memang perlu meluangkan waktu sedikit untuk menggambarkan dengan lebih detil apa saja yang dilakukan oleh beragam perintah ant dan belajar beberapa hal yang baru. Mempelajari ant akan sangat berguna ketika memperbaiki beberapa kendala yang terjadi saat instalasi.</p>
<ul style="text-align: justify;">
<li>Seperti yang kita tau, skrip <strong>ant deploy</strong> membuat beberapa file sementara yang digunakan untuk meng-compile <strong>ejbca.ear</strong>, meng-compile <strong>ejbca.ear,</strong> dan kemudian mendorong jboss untuk mendeploy-nya. Ada dua fungsi yang berbeda di sini yaitu:<br />
pertama, <strong>ant</strong> menjalankan <strong>build</strong> yang melakukan persiapan dan kompilasi.<br />
kedua, <strong>ant</strong> menggunakan jboss <strong>jee.deploy</strong> untuk melakukan transfer ke jboss.</li>
<li>proses <strong>build</strong> dapat dipanggil dengan menggunakan perintah <strong>ant build</strong>. namun perintah <strong>ant deploy</strong>menjalankan keduanya, build dan deploy.</li>
<li>skrip <strong>ant install</strong> mengambil file konfigurasi kita, menggunakan informasi tersebut untuk menciptakan konfigurasi yang lebih jauh lagi (seperti file keystore), dan meng-copy file-file baru tersebut ke lokasi-lokasi yang lebih tepat. Bermacam perubahan pada jboss juga dibuat oleh skrip ini. dan full deployment harus dijalankan secara manual setelah instalasi selesai.<br />
Sebuah skrip terpisah untuk instalasi dibutuhkan untuk memisahkan hal yang dilakukan hanya sekali (seperti mengenerate keystore) dari hal yang dilakukan berulang-ulang saat deployment. Kita tidak perlu membangun ulang setiap kali kita ingin deploy.</li>
<li>perintah <strong>ant clean</strong> akan menghapus file-file temporary (sementara) yang dihasilkan saat deployment sebelumnya yang mungkin secara tidak sengaja masih ada atau tertinggal. Menghapus file-file temporary tersebut dapat membantu memecahkan error-error yang muncul saat deployment.</li>
<li>jika kalian tetap menerima error selama deployment setelah melakukan <strong>ant clean</strong>, kalian boleh mencoba sebuah perintah yng sudah usang: <strong>ant bootstrap</strong>. Secara teori, semua fungsi ant bootstrap sekarang dijalankan oleh <strong>ant deploy</strong>.</li>
</ul>
<p style="text-align: justify;">Semua perintah harus dieksekusi oleh user <strong>jboss</strong>.</p>
<h3 style="text-align: justify;"><strong>Keystore</strong></h3>
<p style="text-align: justify;">Keystore menyimpan sertifikat yang digunakan oleh EJBCA 6.10.1.2 untuk mengamankan web portal, tidak lebih. Keberadaan mereka selama instalasi membuat mereka sangat penting, tetapi mereka memiliki sedikit relevansi dengan fungsi “Certificate Authority” dari EJBCA 6.10.1.2.</p>
<ul style="text-align: justify;">
<li>Mereka <strong>tidak</strong> digunakan untuk menyimpan kunci dan sertifikat yang dihasilkan oleh EJBCA setelah aplikasi ini live di production –  informasi tersebut disimpan di dalam database.</li>
<li>pada sebuah instalasi yang terdistribusi, mereka mempunyai peran penting dalam autentikasi lintas server (cross-server).</li>
</ul>
<p style="text-align: justify;">ketika skrip install berjalan, skrip tersebut akan melakukan bermacam operasi sampai akhirnya membawa kita untuk memasukkan beberapa password yang digunakan untuk file-file keystore. File-file keystore tersebut berada di <strong>/opt/ejbca/p12</strong> dan mereka adalah:</p>
<ul style="text-align: justify;">
<li><strong>tomcat. jks</strong> → Menyimpan sertifikat yang digunakan jboss untuk mengamankan web portal EJBCA 6.10.1.2 dengan TLS.</li>
<li><strong>trustore.jks</strong> → menyimpan sebuah copy dari key root CA yang mengeluarkan sertifikat TLS.</li>
</ul>
<p style="text-align: justify;">Setelah pembuatan, file-file ini di-copy oleh script install tersebut ke <strong>/opt/jboss/standalone/configuration/keystore</strong>, dan file <strong>tomcat.jks</strong> di rename menjadi <strong>keystore.jks</strong>di direktori baru.</p>
<p style="text-align: justify;">Penting untuk dimengerti bahwa ketika <strong>ant</strong> membuat keystore di <strong>/opt/ejbca/p12</strong>, jboss menggunakan keystore yang berada pada <strong>/opt/jboss/standalone/configuration/keystore</strong> untuk TLS.</p>
<ul style="text-align: justify;">
<li>file <strong>superadmin.p12</strong> yang berisi sertifikat klien yang digunakan untuk mengautentikasi akun administrator juga berada di <strong>/opt/ejbca/p12</strong>. file ini tidak di copy ke direktori jboss seperti keystore lainnya.</li>
</ul>
<p style="text-align: justify;">Java tool yang digunakan untuk mengatur keystore disebut <strong>keytool</strong>, dan (saat instalasi) keytool tersebut dipanggil oleh sebuah link pada <strong>/usr/bin</strong>. Melalui alternatives, link ini diarahkan ke <strong>/usr/lib/jvm/java-1.8.0-openjdk-amd64/bin/keytool</strong>. Untuk mencegah terjadinya beberapa masalah yang mungkin muncul (karena menggunakan enkripsi EC), gunakan enkripsi RSA untuk keystore kita. seperti contoh di atas.</p>
<p style="text-align: justify;">Seperti telah disebutkan tadi, <strong>ant install</strong> menghasilkan copy awal dari keystore yang didasarkan pada konfigurasi kita di <strong>install.properties</strong> dan <strong>web.properties</strong>. Tergantung dari bagaimana kita mengkonfigurasi file-file tersebut, kalau kita banyak mengisi informasi pada kedua file tersebut, maka kita tidak akan diminta untuk menginput lagi pada saat <strong>ant install</strong> dijalankan.</p>
<h3 style="text-align: justify;">Pengujian</h3>
<p style="text-align: justify;">Untuk membuktikan apakah instalasi sudah berjalan dengan benar, caranya adalah masuk ke browser dan ketikkan alamat berikut:</p>
<pre><strong><span style="color: #ff0000;">http://&lt;ip atau domain&gt;:8080</span></strong></pre>
<p style="text-align: justify;">Maka akan muncul halaman berikut:</p>
<figure id="attachment_2197" aria-describedby="caption-attachment-2197" style="width: 1440px" class="wp-caption alignnone"><img loading="lazy" decoding="async" class="size-full wp-image-2197" src="http://blog.goreinnamah.com/wp-content/uploads/2018/03/34-wildfly.png" alt="" width="1440" height="710" srcset="https://blog.goreinnamah.com/wp-content/uploads/2018/03/34-wildfly.png 1440w, https://blog.goreinnamah.com/wp-content/uploads/2018/03/34-wildfly-300x148.png 300w, https://blog.goreinnamah.com/wp-content/uploads/2018/03/34-wildfly-768x379.png 768w, https://blog.goreinnamah.com/wp-content/uploads/2018/03/34-wildfly-1024x505.png 1024w" sizes="auto, (max-width: 1440px) 100vw, 1440px" /><figcaption id="caption-attachment-2197" class="wp-caption-text">wildfly jalan</figcaption></figure>
<p style="text-align: justify;">dan untuk masuk ke halaman EJBCA-nya, tambahkan <strong>/ejbca</strong> setelah port tersebut. maka akan tampil halaman berikut:</p>
<figure id="attachment_2198" aria-describedby="caption-attachment-2198" style="width: 1652px" class="wp-caption aligncenter"><img loading="lazy" decoding="async" class="size-full wp-image-2198" src="http://blog.goreinnamah.com/wp-content/uploads/2018/03/37-ejbca-running.png" alt="" width="1652" height="723" srcset="https://blog.goreinnamah.com/wp-content/uploads/2018/03/37-ejbca-running.png 1652w, https://blog.goreinnamah.com/wp-content/uploads/2018/03/37-ejbca-running-300x131.png 300w, https://blog.goreinnamah.com/wp-content/uploads/2018/03/37-ejbca-running-768x336.png 768w, https://blog.goreinnamah.com/wp-content/uploads/2018/03/37-ejbca-running-1024x448.png 1024w" sizes="auto, (max-width: 1652px) 100vw, 1652px" /><figcaption id="caption-attachment-2198" class="wp-caption-text">halaman utama EJBCA 6.10.1.2</figcaption></figure>
<figure id="attachment_2199" aria-describedby="caption-attachment-2199" style="width: 1799px" class="wp-caption alignnone"><img loading="lazy" decoding="async" class="size-full wp-image-2199" src="http://blog.goreinnamah.com/wp-content/uploads/2018/03/38-running.png" alt="" width="1799" height="55" srcset="https://blog.goreinnamah.com/wp-content/uploads/2018/03/38-running.png 1799w, https://blog.goreinnamah.com/wp-content/uploads/2018/03/38-running-300x9.png 300w, https://blog.goreinnamah.com/wp-content/uploads/2018/03/38-running-768x23.png 768w, https://blog.goreinnamah.com/wp-content/uploads/2018/03/38-running-1024x31.png 1024w" sizes="auto, (max-width: 1799px) 100vw, 1799px" /><figcaption id="caption-attachment-2199" class="wp-caption-text">tampilan pada log</figcaption></figure>
<h2 style="text-align: justify;">Notes:</h2>
<p style="text-align: justify;">Tulisan ini merupakan hasil pengujian dari blog <strong><a href="http://ejbcacentos.blogspot.co.id/">ejbcacentos</a></strong> dengan melakukan beberapa modifikasi sesuai dengan kebutuhan dan juga mengambil beberapa konfigurasi dari <a href="https://www.ejbca.org/docs/installation.html#WildFly%2010%20/%20JBoss%20EAP%207"><strong>SINI</strong></a>.</p><p>The post <a href="https://blog.goreinnamah.com/blog/2018/03/26/instalasi-ejbca-6-10-1-2/">Instalasi EJBCA 6.10.1.2 dengan HSM Luna 7 pada CentOS 7</a> first appeared on <a href="https://blog.goreinnamah.com">GoBlog</a>.</p>]]></content:encoded>
					
					<wfw:commentRss>https://blog.goreinnamah.com/blog/2018/03/26/instalasi-ejbca-6-10-1-2/feed/</wfw:commentRss>
			<slash:comments>7</slash:comments>
		
		
			</item>
	</channel>
</rss>

<!--
Performance optimized by W3 Total Cache. Learn more: https://www.boldgrid.com/w3-total-cache/?utm_source=w3tc&utm_medium=footer_comment&utm_campaign=free_plugin

Object Caching 0/255 objects using Memcached
Page Caching using Disk: Enhanced 
Database Caching using Memcached (Request-wide modification query)

Served from: blog.goreinnamah.com @ 2026-10-07 08:54:20 by W3 Total Cache
-->