<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Replacing self-signed certificates with Zentyal-generated certificates in Alfresco Archive</title>
    <link>https://connect.hyland.com/t5/alfresco-archive/replacing-self-signed-certificates-with-zentyal-generated/m-p/275986#M229116</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;SPAN&gt;In order to provide our staff with a consistent experience with each of the servers we run, I'm replacing self-signed certificates with those issued by our Zentyal server, which is acting as the CA. I haven't found entries in either this forum or Zentyal's that deal with this particular topic thoroughly. What I have done so far is to work (unsuccessfully) through the instructions in the following locations, which seem to be similar:&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;UL&gt;&lt;LI&gt;/opt/alfresco-4.2.c/alf_data/keystore/CreateSSLKeystores.txt&lt;/LI&gt;&lt;LI&gt;&lt;A href="http://docs.alfresco.com/4.2/index.jsp?topic=%2Fcom.alfresco.enterprise.doc%2Ftasks%2Fgenerate-repo-ssl-keystore.html" rel="nofollow noopener noreferrer"&gt;http://docs.alfresco.com/4.2/index.jsp?topic=%2Fcom.alfresco.enterprise.doc%2Ftasks%2Fgenerate-repo-ssl-keystore.html&lt;/A&gt;&lt;/LI&gt;&lt;LI&gt;&lt;A href="https://wiki.alfresco.com/wiki/Alfresco_And_SOLR#Manually_Generating_New_SSL_Keys_Signed_by_a_Certificate_Authority" rel="nofollow noopener noreferrer"&gt;https://wiki.alfresco.com/wiki/Alfresco_And_SOLR#Manually_Generating_New_SSL_Keys_Signed_by_a_Certificate_Authority&lt;/A&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;SPAN&gt;My &lt;/SPAN&gt;&lt;SPAN style="text-decoration: underline;"&gt;first&lt;/SPAN&gt;&lt;SPAN&gt; question is this: Am I even starting in the right place with the right instructions?&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;With respect to these instructions, I noticed that there are a few aliases used for the certificates in the keystores, e.g. ssl.repo, ssl.alfresco.ca, and alfresco.ca. These aliases are referred to in each of the &lt;/SPAN&gt;&lt;EM&gt;*-passwords.properties&lt;/EM&gt;&lt;SPAN&gt; files.&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;My &lt;/SPAN&gt;&lt;SPAN style="text-decoration: underline;"&gt;second&lt;/SPAN&gt;&lt;SPAN&gt; question is: Does it matter how these aliases are named? That is, are there any important references to them apart from the link between each keystore and its corresponding password properties file?&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;When the Zentyal Certification Authority is activated and configured, it creates these files:&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;UL&gt;&lt;LI&gt;ca-cert.pem&lt;/LI&gt;&lt;LI&gt;ca-public-key.pem&lt;/LI&gt;&lt;/UL&gt;&lt;SPAN&gt;And when it creates a new certificate, it generates these files:&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;UL&gt;&lt;LI&gt;Alfresco-cert.pem&lt;/LI&gt;&lt;LI&gt;Alfresco.p12&lt;/LI&gt;&lt;LI&gt;Alfresco-private-key.pem&lt;/LI&gt;&lt;LI&gt;Alfresco-public-key.pem&lt;/LI&gt;&lt;/UL&gt;&lt;SPAN&gt;When working through the instructions above, I have tried to do so both with and without the existing keystores. After failures, I have run the &lt;/SPAN&gt;&lt;EM&gt;generate_keystores.sh&lt;/EM&gt;&lt;SPAN&gt; script. Nothing seems broken, and I see no errors in the logs after restarting the server.&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;My &lt;/SPAN&gt;&lt;SPAN style="text-decoration: underline;"&gt;third&lt;/SPAN&gt;&lt;SPAN&gt; question is: If I &lt;/SPAN&gt;&lt;SPAN style="text-decoration: underline;"&gt;should&lt;/SPAN&gt;&lt;SPAN&gt; be using the above instructions, should I create new keystores and then simply replace the old ones?&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;In the instruction at the Alfresco Wiki link above, I noticed the following:&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;BLOCKQUOTE class="jive-quote"&gt;Note&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; if using Tomcat, the values for the above prompts must match those defined in the tomcat-users.xml file for the following entry: &lt;BR /&gt;&amp;lt;user username="CN=Alfresco Repository, OU=Unknown, O=Alfresco Software Ltd., L=Maidenhead, ST=UK, C=GB" roles="repository" password="null"/&amp;gt;&lt;/BLOCKQUOTE&gt;&lt;BR /&gt;&lt;SPAN&gt;My &lt;/SPAN&gt;&lt;SPAN style="text-decoration: underline;"&gt;fourth&lt;/SPAN&gt;&lt;SPAN&gt; question is: If I am following the instruction correctly, do I understand rightly that I need to modify this line to fit the values in the Zentyal-issued certificate?&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;Before I report the errors I experience, I would like to know the answers to these questions. It probably doesn't help to copy in error codes if I'm on the wrong track anyway.&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;My thanks to each of you who take the time to read this, and many more to those who respond.&lt;/SPAN&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Thu, 07 Feb 2013 13:49:21 GMT</pubDate>
    <dc:creator>dfliddle</dc:creator>
    <dc:date>2013-02-07T13:49:21Z</dc:date>
    <item>
      <title>Replacing self-signed certificates with Zentyal-generated certificates</title>
      <link>https://connect.hyland.com/t5/alfresco-archive/replacing-self-signed-certificates-with-zentyal-generated/m-p/275986#M229116</link>
      <description>In order to provide our staff with a consistent experience with each of the servers we run, I'm replacing self-signed certificates with those issued by our Zentyal server, which is acting as the CA. I haven't found entries in either this forum or Zentyal's that deal with this particular topic thorou</description>
      <pubDate>Thu, 07 Feb 2013 13:49:21 GMT</pubDate>
      <guid>https://connect.hyland.com/t5/alfresco-archive/replacing-self-signed-certificates-with-zentyal-generated/m-p/275986#M229116</guid>
      <dc:creator>dfliddle</dc:creator>
      <dc:date>2013-02-07T13:49:21Z</dc:date>
    </item>
    <item>
      <title>Re: Replacing self-signed certificates with Zentyal-generated certificates</title>
      <link>https://connect.hyland.com/t5/alfresco-archive/replacing-self-signed-certificates-with-zentyal-generated/m-p/275987#M229117</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;SPAN&gt;Hi David,&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;I would recommend not to go this way. Instead you should configure an apache in front of tomcat. This is best practice for all our installations and much, much more easy to handle. As a side effect you can harden Alfresco, create redirects and open just the URLs and requests using apache config. Tomcat should be configured to talk only to apache and SOLR.&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;Anyway you should create new certificates to prevent that everyone can read your content with the default certs who has access to tomcat. For this Alfresco allready provides scripts not to make any mistakes.&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;Of course you can use commercial certs for the tomcat ssl connector but as long you don't understand the complexity in alfresco/SOLR communication and if you're not very familiar with openssl and keystore mechanisms you shouldn't touch this. Otherwise it is very likely that at least your SOLR search will not work any more. So don't go the trappy way if there is an easy and robust one.&lt;/SPAN&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 07 Feb 2013 15:55:23 GMT</pubDate>
      <guid>https://connect.hyland.com/t5/alfresco-archive/replacing-self-signed-certificates-with-zentyal-generated/m-p/275987#M229117</guid>
      <dc:creator>heiko_robert</dc:creator>
      <dc:date>2013-02-07T15:55:23Z</dc:date>
    </item>
    <item>
      <title>Re: Replacing self-signed certificates with Zentyal-generated certificates</title>
      <link>https://connect.hyland.com/t5/alfresco-archive/replacing-self-signed-certificates-with-zentyal-generated/m-p/275988#M229118</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;SPAN&gt;Thank you for the reply, Heiko. I have seen many such recommendations for the Apache reverse proxy server, and using this technique could help simplify other services that we run. Do you know if it can handle the Alfresco IMAP component also? I have read of others attempting IMAP funneling with that and Nginx, but it's not always easy to tell how successful or satisfied they were.&lt;/SPAN&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 13 Feb 2013 13:58:18 GMT</pubDate>
      <guid>https://connect.hyland.com/t5/alfresco-archive/replacing-self-signed-certificates-with-zentyal-generated/m-p/275988#M229118</guid>
      <dc:creator>dfliddle</dc:creator>
      <dc:date>2013-02-13T13:58:18Z</dc:date>
    </item>
  </channel>
</rss>

