<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Default generated SSL Certificate contains 'invalid address' in Alfresco Archive</title>
    <link>https://connect.hyland.com/t5/alfresco-archive/default-generated-ssl-certificate-contains-invalid-address/m-p/293887#M247017</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;SPAN&gt;Hi,&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;I've tried to put together a working installation of Alfresco based on the documentation and it appears to be working now, more or less.&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;The issue which I have encountered is related to the self-generated SSL certificates which were automatically set up by the installation script.&amp;nbsp; I understand that these certificates are self-generated and I have, of course, already added both the CA and the site certificates to Windows Trusted Root Certificate store.&amp;nbsp; However, I am still received an error messages about an invalid certificate when I try logging into the site through a web browser – and more importantly (to me, at least) – the Windows 7 WebDAV client fails to connect.&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;The error message that I am receiving is:&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;IE: Mismatched Address. The security certificate presented for this website was issued for a different website's address&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;Chrome:&amp;nbsp; &amp;lt;strong&amp;gt;This is probably not the site you are looking for!&amp;lt;/strong&amp;gt;&amp;nbsp; You attempted to reach xxx.xxxx.xx (my FQDN), but instead you actually reached a server identifying itself as &amp;lt;strong&amp;gt;Alfresco Repository&amp;lt;/strong&amp;gt;&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;Viewing the certificate information, I see that the certificate was:&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;&amp;lt;strong&amp;gt;Issued to:&amp;lt;/strong&amp;gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Alfresco Repository&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;&amp;lt;strong&amp;gt;Issued by:&amp;lt;/strong&amp;gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Alfresco CA&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;All of my DNS settings appear to be correct.&amp;nbsp; The actual 'hostname' on the server matches the CNAME entry in DNS.&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;I've tried Googling this for more information, but I have been unable to find anything helpful.&amp;nbsp; Most of what I have found is either about incorporating 3rd-party certificates (not interested – personal website), or about setting up the keystores with the default information.&amp;nbsp; Indeed, I see from that wiki page that it explicitly says to use "Alfresco Repository" in the CN for the certificate.&amp;nbsp; This appears to be the source of the troubles, but I'm a little hesitant to regenerate these certificates and end up ruining this installation.&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;Has anyone encountered and resolved a similar issue?&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;Thanks and your help is much appreciated.&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;Shmuel&lt;/SPAN&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Thu, 01 May 2014 16:37:53 GMT</pubDate>
    <dc:creator>shmuel_levine</dc:creator>
    <dc:date>2014-05-01T16:37:53Z</dc:date>
    <item>
      <title>Default generated SSL Certificate contains 'invalid address'</title>
      <link>https://connect.hyland.com/t5/alfresco-archive/default-generated-ssl-certificate-contains-invalid-address/m-p/293887#M247017</link>
      <description>Hi,I've tried to put together a working installation of Alfresco based on the documentation and it appears to be working now, more or less.The issue which I have encountered is related to the self-generated SSL certificates which were automatically set up by the installation script.&amp;nbsp; I understand th</description>
      <pubDate>Thu, 01 May 2014 16:37:53 GMT</pubDate>
      <guid>https://connect.hyland.com/t5/alfresco-archive/default-generated-ssl-certificate-contains-invalid-address/m-p/293887#M247017</guid>
      <dc:creator>shmuel_levine</dc:creator>
      <dc:date>2014-05-01T16:37:53Z</dc:date>
    </item>
    <item>
      <title>Re: Default generated SSL Certificate contains 'invalid address'</title>
      <link>https://connect.hyland.com/t5/alfresco-archive/default-generated-ssl-certificate-contains-invalid-address/m-p/293888#M247018</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;SPAN&gt;Hello,&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;if you want to have a valid SSL certificate for your specific DNS / host name, you absolutely have to regenerate the certificates specific to your environment. The default certificates are basically just for evaluation installations and not meant to be used in production. Anyone of your users could just get the Repository certificate from the Alfresco downloads, access your SOLR server and thus be able to research a large part of your content without content permissions stopping them in any way.&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;Regards&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;Axel&lt;/SPAN&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 02 May 2014 08:05:28 GMT</pubDate>
      <guid>https://connect.hyland.com/t5/alfresco-archive/default-generated-ssl-certificate-contains-invalid-address/m-p/293888#M247018</guid>
      <dc:creator>afaust</dc:creator>
      <dc:date>2014-05-02T08:05:28Z</dc:date>
    </item>
    <item>
      <title>Re: Default generated SSL Certificate contains 'invalid address'</title>
      <link>https://connect.hyland.com/t5/alfresco-archive/default-generated-ssl-certificate-contains-invalid-address/m-p/293889#M247019</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;SPAN&gt;Axel,&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;Thanks for your response. &lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;I found a script to generate new keystores and in there, I replaced the installation folder and also changed the CN to match my FQDN. There was a slight unexpected change to the CA certificate as a result, but insignificant. &lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;In any case, that seems to have done the trick. I am now able to connect both with 3rd-party webdav clients as well as with the Windows7 built-in client.&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;Thanks for your help.&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;Shmuel&lt;/SPAN&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 02 May 2014 13:20:44 GMT</pubDate>
      <guid>https://connect.hyland.com/t5/alfresco-archive/default-generated-ssl-certificate-contains-invalid-address/m-p/293889#M247019</guid>
      <dc:creator>shmuel_levine</dc:creator>
      <dc:date>2014-05-02T13:20:44Z</dc:date>
    </item>
  </channel>
</rss>

