Use of SSL Certificate Custom Java Action

0
Hello everyone,We use a truststore and a keystore certificate (.pfx) in our Mendix application to establish an SSL/TLS handshake with an external system.Currently, we have a custom Java action that loads both certificate files from the local file system, configures the SSL context, and performs the SSL handshake.Now that our application has been deployed to Mendix Cloud, we would like to understand the recommended approach to achieve an SSL/mTLS handshake.Option 1: Upload certificates through Mendix CloudUpload the certificates via Environment → Network → Certificates.If we use this approach, how can we access the certificates from our custom Java action? Is it possible to retrieve the file path of the certificates so that it can be used in the Java action?Option 2: Alternative approachIs there a recommended Mendix Cloud approach for using client certificates in custom Java code?Should the SSL configuration be handled differently?
asked
2 answers
0

see Mendix Community - Question Details

answered
0

Hi Aishwarya,


If the .pfx is a client certificate used for mTLS, I would not try to access the uploaded certificate through a file path from your custom Java Action.

In Mendix Cloud, client certificates are managed by the platform. You can upload the .pfx/.p12 under:


Environment → Network → Outgoing Connections Certificates → Add Client Certificate

Mendix stores the certificate securely, and the application does not get a normal filesystem path to the uploaded certificate that you can read with FileInputStream.

So this approach from the local setup:


new FileInputStream("C:\\certs\\client.pfx")

should not be carried over to Mendix Cloud.


Recommended approach

If the external service is being called through a normal Mendix Call REST Service / Call Web Service action, configure the client certificate in Mendix Cloud and associate it with the service.

For example:

Mendix Cloud
   |
   +-- Network
        |
        +-- Outgoing Connections Certificates
             |
             +-- client.pfx
             |
             +-- Pin to:
                   my-service.example.com

For REST calls, Mendix allows you to specify a Client certificate identifier on the Call REST Service action and configure the corresponding certificate usage in Mendix Cloud.


But there is an important difference in your case

You're using a custom Java Action that creates its own SSLContext and performs the SSL handshake.


In that case, simply uploading the certificate to Mendix Cloud will not automatically make the .pfx available to your Java code. The standard Mendix certificate configuration is intended to be used by Mendix's HTTP/Web Service client infrastructure.


So you have two choices:

Option 1 — Preferred:

If possible, replace the custom Java HTTP/SSL implementation with Mendix's Call REST Service / Call Web Service action and let Mendix Cloud handle the client certificate.


Option 2 — Keep the custom Java Action:

Then the certificate must be made available to the Java code through a mechanism supported by your deployment architecture. You should not assume that the certificate uploaded under Environment → Network → Certificates has a readable filesystem path. Mendix Cloud explicitly manages ClientCertificates and ClientCertificatePasswords itself and does not expose those runtime settings for user configuration.


For a custom Java implementation that absolutely requires direct access to the PKCS12 keystore, I'd recommend checking with Mendix Support/Expert Services for the supported approach rather than trying to access internal certificate storage.

So, in short:

Local development
.pfx file → Java Action → SSLContext

is fine.

But in Mendix Cloud:

Uploaded .pfx
      ↓
Mendix Cloud certificate management
      ↓
Mendix REST/Web Service client
      ↓
mTLS

is the supported pattern.


Also, the current Mendix documentation confirms that PKCS12 (.pfx / .p12) containing the private key is the supported format for outgoing client certificates.


I would therefore not try to retrieve the .pfx path from Mendix Cloud. If the custom Java Action is mandatory, the key question is how to redesign that Java call so it uses the platform-managed certificate rather than reading the keystore itself.

answered