Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people, just like you, are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
Solved

Alternatives to OpenSSL for ActiveMQ

Posted on 2014-04-13
9
415 Views
Last Modified: 2014-04-15
Can we use another SSL package other than OpenSSL.  

If so, is OpenSSL the default
0
Comment
Question by:Anthony Lucia
  • 5
  • 4
9 Comments
 
LVL 62

Accepted Solution

by:
gheist earned 500 total points
ID: 39998711
OpenSSL is not used by java application servers.
Please detail on what server software concerns you... (Press request attention and use form there so that moderators can re-shuffle topic areas)
If you are worried about heartbleed - just upgrade, confirm that vuln is addressed  and regenerate your ssl keys (your CA knows and will help)
0
 
LVL 62

Expert Comment

by:gheist
ID: 39999568
ActiveMQ uses jetty servlet engine, which, unlike tomcat has no chance of loading openssl libraries ever (and even on tomcat loading native SSL library is something between rocket science and eating swords)
0
 

Author Comment

by:Anthony Lucia
ID: 39999773
That seems good.

Where does ActiveMQ get their SSL from, what package
0
Portable, direct connect server access

The ATEN CV211 connects a laptop directly to any server allowing you instant access to perform data maintenance and local operations, for quick troubleshooting, updating, service and repair.

 

Author Comment

by:Anthony Lucia
ID: 39999784
This page:

https://activemq.apache.org/cms/openssl-support.html

seems to suggest you can use Openssl

Is Openssl an optional package ?
0
 
LVL 62

Expert Comment

by:gheist
ID: 39999923
JCE/JCA (the toolkit included in java)
If it is too slow you can try bouncycastle ssl (one that android uses) before jumping on native openssl but otherwise you are safe if you patched java in last 2 montsh for non-crypto issues.

OpenSSL is used by 2/3 of all websites in the world. Now it is safe, you can install CPP module after you patch OpenSSL to speed up encryption (though bouncycastle may be faster in some settings, or at least cleaner by not calling JNI)
run "openssl version" - if it says anything else than 1.0.1 you might have happily jumped past the problems.

OpenSSL is not used by java, there is optional library that enables your java server to use it. As much as java is concerned presence of openssl or any other native SSL toolkit (like NSS or gnutls, which had their drop dead bugs in recent months, but no publicity because they are not used by high profile sites ever) is irrelevant.

e.g OpenSSH is omnipresent in UNIX etc, it uses openssl, but in mode that does not pass the code path of vulnerable extension.

What system you run your java on?
0
 

Author Comment

by:Anthony Lucia
ID: 40000354
Trying to run ActiveMQ on Linux.

What version of SSL will that configuration use

and why does this page say that OpenSSL is an option

https://activemq.apache.org/cms/openssl-support.html

Thanks
0
 
LVL 62

Expert Comment

by:gheist
ID: 40000478
Because it is an option, not a standard feature....

cat /proc/PID/maps

and see yourself if libcrypto.so.* is loaded or not.
0
 

Author Comment

by:Anthony Lucia
ID: 40001531
I did the following

root@clnt1 apache-activemq-5.9.0]# ls
activemq-all-5.9.0.jar  data      lib      README.txt  webapps-demo
bin                     docs      LICENSE  tmp
conf                    examples  NOTICE   webapps
[root@clnt1 apache-activemq-5.9.0]#
[root@clnt1 apache-activemq-5.9.0]#
[root@clnt1 apache-activemq-5.9.0]# cat /proc/PID/maps
cat: /proc/PID/maps: No such file or directory
[root@clnt1 apache-activemq-5.9.0]#

Open in new window



What is the default SSL on ActiveMQ ?
Thanks
0
 
LVL 62

Expert Comment

by:gheist
ID: 40002290
PID should be numeric process ID of your application server.
What openssl version is installed on your system?

Please refer to first word in previous answer
0

Featured Post

Easy, flexible multimedia distribution & control

Coming soon!  Ideal for large-scale A/V applications, ATEN's VM3200 Modular Matrix Switch is an all-in-one solution that simplifies video wall integration. Easily customize display layouts to see what you want, how you want it in 4k.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Suggested Solutions

Title # Comments Views Activity
java bean related info 28 643
Problem to refer to codes 10 122
Tried setting java proxy; Fiddler still not capturing traffic 27 296
getSandwich  java challenge 22 105
-Xmx and -Xms are the two JVM options often used to tune JVM heap size.   Here are some common mistakes made when using them:   Assume BigApp is a java class file for the below examples. 1.         Missing m, M, g or G at the end …
This exercise is about for the following scenario: Dmgr and One node with 2 application server. Each application server contains it owns application. Application server name as follows server1 contains app1 server2 contains app1 Prereq…
Although Jacob Bernoulli (1654-1705) has been credited as the creator of "Binomial Distribution Table", Gottfried Leibniz (1646-1716) did his dissertation on the subject in 1666; Leibniz you may recall is the co-inventor of "Calculus" and beat Isaac…

808 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question