<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Open LDAP with SSL/TLS and Alfresco 4.0.c in Alfresco Archive</title>
    <link>https://connect.hyland.com/t5/alfresco-archive/open-ldap-with-ssl-tls-and-alfresco-4-0-c/m-p/265995#M219125</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;SPAN&gt;Does Alfresco work properly without LDAP configuration ? I'm not 100% sure your problem is LDAP related.&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;Have you tried specifying your keystore in JAVA_OPTS environment variable ??? If you have a vanilla tomcat installed probably editing catalina.sh (or catalina.bat in windows) and adding "-Djavax.net.ssl.trustStore=/etc/java/keystore" and/or "-Djavax.net.ssl.keyStore=/etc/java/keystore" options to JAVA_OPTS should point tomcat to the right keystore.&lt;/SPAN&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Tue, 17 Jul 2012 14:46:53 GMT</pubDate>
    <dc:creator>iblanco</dc:creator>
    <dc:date>2012-07-17T14:46:53Z</dc:date>
    <item>
      <title>Open LDAP with SSL/TLS and Alfresco 4.0.c</title>
      <link>https://connect.hyland.com/t5/alfresco-archive/open-ldap-with-ssl-tls-and-alfresco-4-0-c/m-p/265992#M219122</link>
      <description>Hi , I tried configuring Open LDAP with SSL/TLS with Alfresco 4.0.c and getting exception :My Configurations are as below :I have added below line in alfresco-global.properties fileauthentication.chain=alfrescoNtlm1:alfrescoNtlm,ldap1:ldap‍Created folder structure as below and copied files from subs</description>
      <pubDate>Fri, 13 Jul 2012 15:11:53 GMT</pubDate>
      <guid>https://connect.hyland.com/t5/alfresco-archive/open-ldap-with-ssl-tls-and-alfresco-4-0-c/m-p/265992#M219122</guid>
      <dc:creator>ashwini</dc:creator>
      <dc:date>2012-07-13T15:11:53Z</dc:date>
    </item>
    <item>
      <title>Re: Open LDAP with SSL/TLS and Alfresco 4.0.c</title>
      <link>https://connect.hyland.com/t5/alfresco-archive/open-ldap-with-ssl-tls-and-alfresco-4-0-c/m-p/265993#M219123</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;SPAN&gt;Does the keystore exist ? It looks like a problem not with Alfresco but with Java. You must make sure that the Java running tomcat does validate the certificate send by your LDAP server or configure JVM to ignore invalid Certificates. But it seems your problem is previous. &lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;I know is not the direct solution for your problem but hope it points you to the right direction to check.&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;Bye.&lt;/SPAN&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 14 Jul 2012 18:27:53 GMT</pubDate>
      <guid>https://connect.hyland.com/t5/alfresco-archive/open-ldap-with-ssl-tls-and-alfresco-4-0-c/m-p/265993#M219123</guid>
      <dc:creator>iblanco</dc:creator>
      <dc:date>2012-07-14T18:27:53Z</dc:date>
    </item>
    <item>
      <title>Re: Open LDAP with SSL/TLS and Alfresco 4.0.c</title>
      <link>https://connect.hyland.com/t5/alfresco-archive/open-ldap-with-ssl-tls-and-alfresco-4-0-c/m-p/265994#M219124</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;SPAN&gt;Hello ,&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;I think you are right, when I checked connection using certificate its successful as shown below&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;PRE class="language-none line-numbers"&gt;&lt;CODE&gt;alfadmin@alfresc-VM:~$ java -Djavax.net.ssl.trustStore=/etc/java/keystore SSLPoke email.datamatics.eu 636&lt;BR /&gt;Successfully connected&lt;BR /&gt;alfadmin@alfresc-VM:~$ &lt;BR /&gt;&lt;SPAN class="line-numbers-rows"&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/CODE&gt;&lt;/PRE&gt;&lt;BR /&gt;&lt;SPAN&gt;Could you please tell me how can I check, weather certificates get validated by tomcat or not ?&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;Regards,&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;Ashwini&lt;/SPAN&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 17 Jul 2012 13:48:39 GMT</pubDate>
      <guid>https://connect.hyland.com/t5/alfresco-archive/open-ldap-with-ssl-tls-and-alfresco-4-0-c/m-p/265994#M219124</guid>
      <dc:creator>ashwini</dc:creator>
      <dc:date>2012-07-17T13:48:39Z</dc:date>
    </item>
    <item>
      <title>Re: Open LDAP with SSL/TLS and Alfresco 4.0.c</title>
      <link>https://connect.hyland.com/t5/alfresco-archive/open-ldap-with-ssl-tls-and-alfresco-4-0-c/m-p/265995#M219125</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;SPAN&gt;Does Alfresco work properly without LDAP configuration ? I'm not 100% sure your problem is LDAP related.&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;Have you tried specifying your keystore in JAVA_OPTS environment variable ??? If you have a vanilla tomcat installed probably editing catalina.sh (or catalina.bat in windows) and adding "-Djavax.net.ssl.trustStore=/etc/java/keystore" and/or "-Djavax.net.ssl.keyStore=/etc/java/keystore" options to JAVA_OPTS should point tomcat to the right keystore.&lt;/SPAN&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 17 Jul 2012 14:46:53 GMT</pubDate>
      <guid>https://connect.hyland.com/t5/alfresco-archive/open-ldap-with-ssl-tls-and-alfresco-4-0-c/m-p/265995#M219125</guid>
      <dc:creator>iblanco</dc:creator>
      <dc:date>2012-07-17T14:46:53Z</dc:date>
    </item>
    <item>
      <title>Re: Open LDAP with SSL/TLS and Alfresco 4.0.c</title>
      <link>https://connect.hyland.com/t5/alfresco-archive/open-ldap-with-ssl-tls-and-alfresco-4-0-c/m-p/265996#M219126</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;SPAN&gt;Yes,Alfresco works perfectly without LDAP configuration. &lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;And ya I have edited catalina.sh and specified keystore in JAVA_OPTS environment variable as below :&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;PRE class="language-none line-numbers"&gt;&lt;CODE&gt;JAVA_OPTS="$JAVA_OPTS -Djavax.net.ssl.trustStore=/etc/java/keystore"&lt;SPAN class="line-numbers-rows"&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/CODE&gt;&lt;/PRE&gt;&lt;BR /&gt;&lt;SPAN&gt;but nothing changed .. same exceptions .&lt;/SPAN&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 17 Jul 2012 15:22:06 GMT</pubDate>
      <guid>https://connect.hyland.com/t5/alfresco-archive/open-ldap-with-ssl-tls-and-alfresco-4-0-c/m-p/265996#M219126</guid>
      <dc:creator>ashwini</dc:creator>
      <dc:date>2012-07-17T15:22:06Z</dc:date>
    </item>
    <item>
      <title>Re: Open LDAP with SSL/TLS and Alfresco 4.0.c</title>
      <link>https://connect.hyland.com/t5/alfresco-archive/open-ldap-with-ssl-tls-and-alfresco-4-0-c/m-p/265997#M219127</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;SPAN&gt;Alfresco runs on https (tomcat has been configured for SSL),When I disabled my https , then I was able connect to Open ldaps with the same configuration. But when I enable https again I gets exception as below :&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;PRE class="language-none line-numbers"&gt;&lt;CODE&gt;SEVERE: Failed to load keystore type pkcs12 with path /etc/java/keystorePkcs12 due to DerInputStream.getLength(): lengthTag=109, too big.&lt;BR /&gt;java.io.IOException: DerInputStream.getLength(): lengthTag=109, too big.&lt;SPAN class="line-numbers-rows"&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/CODE&gt;&lt;/PRE&gt;&lt;BR /&gt;&lt;SPAN&gt;same exception I found when I tried to convert keystore manually from jks to pkcs12 type&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;I have generated keystore as below : &lt;/SPAN&gt;&lt;BR /&gt;&lt;PRE class="language-none line-numbers"&gt;&lt;CODE&gt;sudo keytool -import -alias domain -keystore /etc/java/keystore -file /home/alfadmin/Desktop/xyz.der&lt;SPAN class="line-numbers-rows"&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/CODE&gt;&lt;/PRE&gt;&lt;BR /&gt;&lt;SPAN&gt;Checked type for generated keystore &lt;/SPAN&gt;&lt;BR /&gt;&lt;PRE class="language-none line-numbers"&gt;&lt;CODE&gt;keytool -list -keystore /etc/java/keystore&lt;SPAN class="line-numbers-rows"&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/CODE&gt;&lt;/PRE&gt;&lt;SPAN&gt;which showed me keystore type as jks.&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;keystore.type=jks set in &lt;/SPAN&gt;&lt;STRONG&gt;java.security . &lt;/STRONG&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;I have configured server.xml for https as below:&lt;/SPAN&gt;&lt;BR /&gt;&lt;PRE class="language-none line-numbers"&gt;&lt;CODE&gt;&amp;lt;Connector port="333" protocol="HTTP/1.1" SSLEnabled="true"&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; maxThreads="150" scheme="https" secure="true"&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; clientAuth="false" sslProtocol="TLS"&amp;nbsp; &lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;nbsp;&amp;nbsp;&amp;nbsp; keystoreType="pkcs12" keystoreFile="/etc/keystore/sss.p12"&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;keystorePass= "htgkilnsg" /&amp;gt; &lt;BR /&gt;&lt;SPAN class="line-numbers-rows"&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/CODE&gt;&lt;/PRE&gt;&lt;SPAN&gt; &lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;Here I noticed&amp;nbsp; &lt;/SPAN&gt;&lt;STRONG&gt;keystoreType="pkcs12"&lt;/STRONG&gt;&lt;SPAN&gt;.&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;Is this the reason why java tries to convert the keystore type from jks to pkcs12.&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;has anybody configured&amp;nbsp; Open Ldap with ssl on alfresco running on https ?&lt;/SPAN&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 19 Jul 2012 08:41:51 GMT</pubDate>
      <guid>https://connect.hyland.com/t5/alfresco-archive/open-ldap-with-ssl-tls-and-alfresco-4-0-c/m-p/265997#M219127</guid>
      <dc:creator>ashwini</dc:creator>
      <dc:date>2012-07-19T08:41:51Z</dc:date>
    </item>
    <item>
      <title>Re: Open LDAP with SSL/TLS and Alfresco 4.0.c</title>
      <link>https://connect.hyland.com/t5/alfresco-archive/open-ldap-with-ssl-tls-and-alfresco-4-0-c/m-p/265998#M219128</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;SPAN&gt;Finally I have figured out the problem. &lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;After importing both certificates (one for tomcat SSL and another for ldaps ) together in single keystore file , problem is resolved.&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;Now ldap over SSL is integrated with alfresco ( tomcat with https ).&lt;/SPAN&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 01 Aug 2012 08:09:10 GMT</pubDate>
      <guid>https://connect.hyland.com/t5/alfresco-archive/open-ldap-with-ssl-tls-and-alfresco-4-0-c/m-p/265998#M219128</guid>
      <dc:creator>ashwini</dc:creator>
      <dc:date>2012-08-01T08:09:10Z</dc:date>
    </item>
  </channel>
</rss>

