SkipJack Configuration

Preparation

SkipJack certificate is trusted by Equifax. In Java 1.3.x and older the standard java cartcerts file doesn't include Equifax public certificates and therefore Parallels H-Sphere returns 'Connect error, untrusted server cert chain' when trying to connect to the merchant gateway. Therefore Equifax certificates should be imported into cacerts file.

So, if you have Java 1.3 and older, you have the following solutions:

A. If you have got the default java cacerts file and you have never changed it, you can simply replace it with the cacerts file offered by Parallels:

/usr/java/<java home>/jre/lib/security/cacerts

B. If you need to keep your cacerts file, you can fix this problem using the keytool feature available in the standard Java installation:

  1. Download equifax.crt.cer file:

    wget http://download.hsphere.parallels.com/shiv/files/merchants/equifax.crt.cer

  2. Place equifax.crt.cer in the /usr/java/jdk1.3.1/jre/lib/security/ directory
  3. As root, allow read/write access to the /usr/java/jdk1.3.1/jre/lib/security/cacerts file

    chmod 666 /usr/java/jdk1.3.1/jre/lib/security/cacerts

  4. Log in as the cpanel user:

    su -l cpanel

  5. Go to the /usr/java/jdk1.3.1/jre/lib/security/ directory:

    cd /usr/java/jdk1.3.1/jre/lib/security/

  6. Run the following command:

    keytool -import -alias equifax -file equifax.crt.cer -keystore cacerts

  7. When prompted, enter the password (the default password is: changeit)
  8. When asked to trust the certificate, enter: yes
  9. As root, change permissions back on the /usr/java/jdk1.3.1/jre/lib/security/cacerts file:

    chmod 444 /usr/java/jdk1.3.1/jre/lib/security/cacerts

C. Upgrade Java to 1.4 by following our documentation in Sysadmin Guide.

Note: If your certificate is already imported into cacerts, but Java still generates 'Connect error, untrusted server cert chain', please check the connection to your payment server from your control panel server by running the following command from the control panel server console to check connection:
telnet [server.name] [port]

Configuration

  1. Select SkipJack in the Add New Gateway box.
  2. Click the Add button.
  3. Fill out the form that appears:

  4. Click Submit Query