<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic SSL acceleration + NO unencrypted access = broken CMIS in Alfresco Archive</title>
    <link>https://connect.hyland.com/t5/alfresco-archive/ssl-acceleration-no-unencrypted-access-broken-cmis/m-p/248984#M202114</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;SPAN&gt;A brief description of our setup:&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;Clustered RHEL environment, consisting of 2 Alfresco boxes.&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;NO unencrypted (8080) traffic is allowed. Only open port into the Alfresco cluster is 443.&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;1) Application layer sends CMIS traffic to SSL accelerator on 443&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;2) Traffic is decrypted by the accelerator and forwarded to the Load Balancer on 8080.&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;3) Load Balancer distributes the traffic to one of the Alfresco boxes on 8080.&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;4) Since Alfresco is getting the messages unencrypted, it stores &lt;/SPAN&gt;&lt;A href="http://ourdomain/alfresco/service/cmis/s/workspace:SpacesStore/i/41ba7c1c-93a4-4bd1-9855-f07ab18b7c11" rel="nofollow noopener noreferrer"&gt;http://ourdomain/alfresco/service/cmis/s/workspace&lt;img id="smileyfrustrated" class="emoticon emoticon-smileyfrustrated" src="https://connect.hyland.com/i/smilies/16x16_smiley-frustrated.png" alt="Smiley Frustrated" title="Smiley Frustrated" /&gt;pacesStore/i/41ba7c1c-93a4-4bd1-9855-f07ab18b7c11&lt;/A&gt;&lt;SPAN&gt; for the doc.&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;5) Some operations (get &amp;amp; post) seem to work if we change "http" to https" in our code, but deletes fail.&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;So the question is, can Alfresco be configured to store "https" instead of "http" as the URI for a doc, even though it is received unencrypted? This way we would not need to try to change it ourselves and perhaps the rest of the CMIS functionality would work.&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;I'm guessing we are not the first team trying to use SSL in a clustered environment with SSL accelerators, so someone should have figured this one out.&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;Related symptom:&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;We can not use "&lt;/SPAN&gt;&lt;A href="https://ourdomain/alfresco" rel="nofollow noopener noreferrer"&gt;https://ourdomain/alfresco&lt;/A&gt;&lt;SPAN&gt;" to get onto the system. This results in a "The connection has timed out" message. Using "&lt;/SPAN&gt;&lt;A href="https://ourdomain/alfresco/faces/jsp/login.jsp" rel="nofollow noopener noreferrer"&gt;https://ourdomain/alfresco/faces/jsp/login.jsp&lt;/A&gt;&lt;SPAN&gt;" does allow us to log in.&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;Not that searching the forums on "SSL acceleration" yielded no results.&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;Thanks for having a look,&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;Paul P&lt;/SPAN&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Thu, 23 Jun 2011 22:44:14 GMT</pubDate>
    <dc:creator>paul_price</dc:creator>
    <dc:date>2011-06-23T22:44:14Z</dc:date>
    <item>
      <title>SSL acceleration + NO unencrypted access = broken CMIS</title>
      <link>https://connect.hyland.com/t5/alfresco-archive/ssl-acceleration-no-unencrypted-access-broken-cmis/m-p/248984#M202114</link>
      <description>A brief description of our setup:Clustered RHEL environment, consisting of 2 Alfresco boxes.NO unencrypted (8080) traffic is allowed. Only open port into the Alfresco cluster is 443.1) Application layer sends CMIS traffic to SSL accelerator on 4432) Traffic is decrypted by the accelerator and forwar</description>
      <pubDate>Thu, 23 Jun 2011 22:44:14 GMT</pubDate>
      <guid>https://connect.hyland.com/t5/alfresco-archive/ssl-acceleration-no-unencrypted-access-broken-cmis/m-p/248984#M202114</guid>
      <dc:creator>paul_price</dc:creator>
      <dc:date>2011-06-23T22:44:14Z</dc:date>
    </item>
    <item>
      <title>Re: SSL acceleration + NO unencrypted access = broken CMIS</title>
      <link>https://connect.hyland.com/t5/alfresco-archive/ssl-acceleration-no-unencrypted-access-broken-cmis/m-p/248985#M202115</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;SPAN&gt;Hi Paul,&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;That sounds like a proxy scenario. Have a look at the connector configuration in the Tomcat server.xml. Add the attributes proxyName, proxyPort, scheme and maybe secure with appropriate values (see [1]).&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;Florian&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;[1] &lt;/SPAN&gt;&lt;A href="http://tomcat.apache.org/tomcat-6.0-doc/config/http.html#Proxy%20Support" rel="nofollow noopener noreferrer"&gt;http://tomcat.apache.org/tomcat-6.0-doc/config/http.html#Proxy%20Support&lt;/A&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 23 Jun 2011 23:17:24 GMT</pubDate>
      <guid>https://connect.hyland.com/t5/alfresco-archive/ssl-acceleration-no-unencrypted-access-broken-cmis/m-p/248985#M202115</guid>
      <dc:creator>fmui</dc:creator>
      <dc:date>2011-06-23T23:17:24Z</dc:date>
    </item>
  </channel>
</rss>

