§Configuring WS SSL
Play WS allows you to set up HTTPS completely from a configuration file, without the need to write code. It does this by layering the Java Secure Socket Extension (JSSE) with a configuration layer and with reasonable defaults.
JDK 1.8 contains an implementation of JSSE which is significantly more advanced than previous versions, and should be used if security is a priority.
NOTE: It is highly recommended (if not required) to use WS SSL with the
unlimited strength java cryptography extension. You can download the policy files from Oracle’s website at Java Cryptography Extension (JCE) Unlimited Strength Jurisdiction Policy Files 8 Download.
§Table of Contents
- Quick Start to WS SSL
- Generating X.509 Certificates
- Configuring Trust Stores and Key Stores
- Configuring Protocols
- Configuring Cipher Suites
- Configuring Certificate Validation
- Configuring Certificate Revocation
- Configuring Hostname Verification
- Example Configurations
- Using the Default SSLContext
- Debugging SSL Connections
- Loose Options
- Testing SSL
JSSE is a complex product. For convenience, the JSSE materials are provided here:
Next: Quick Start to WS SSL
Found an error in this documentation? The source code for this page can be found here. After reading the documentation guidelines, please feel free to contribute a pull request. Have questions or advice to share? Go to our community forums to start a conversation with the community.