<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Alfreco session  broken while using  HTTPS  in Alfresco Archive</title>
    <link>https://connect.hyland.com/t5/alfresco-archive/alfreco-session-broken-while-using-https/m-p/294776#M247906</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello&amp;nbsp; &lt;/P&gt;&lt;P&gt;Are&amp;nbsp; environment is as&amp;nbsp; follows&lt;/P&gt;&lt;P&gt;Windows&amp;nbsp; 2008&amp;nbsp; R2&amp;nbsp;&lt;/P&gt;&lt;P&gt;Apache Tomcat/7.0.53&lt;/P&gt;&lt;P style="margin: 0in 0in 10pt;"&gt;Alfresco 4.2.4 enterprise&amp;nbsp; edition&lt;/P&gt;&lt;P style="margin: 0in 0in 10pt;"&gt;The&amp;nbsp; issue&amp;nbsp; we&amp;nbsp; are&amp;nbsp; experience in alfresco&amp;nbsp; share&amp;nbsp;&amp;nbsp;is as&amp;nbsp; follows&lt;/P&gt;&lt;P style="margin: 0in 0in 10pt;"&gt;1. Authentication NTLM SSO&amp;nbsp; on&amp;nbsp; active&amp;nbsp; directory&lt;/P&gt;&lt;P style="margin: 0in 0in 10pt;"&gt;2. We&amp;nbsp; only&amp;nbsp; are&amp;nbsp; authenticating&amp;nbsp; share and&amp;nbsp; explorer&lt;/P&gt;&lt;P style="margin: 0in 0in 10pt;"&gt;3&amp;nbsp;Using&amp;nbsp; http&amp;nbsp; and&amp;nbsp; https.&lt;/P&gt;&lt;P style="margin: 0in 0in 10pt;"&gt;&lt;SPAN style="color: navy; font-size: 10pt;"&gt;what’s happening is that for some users they are randomly y being prompted to enter their user credentials through the Windows&amp;nbsp; security pop up&amp;nbsp; windows, the user enter&amp;nbsp; their active&amp;nbsp; directory&amp;nbsp; credentials but&amp;nbsp; the pop&amp;nbsp; up will continuosly appear thus not letting the user use Alfresco.&amp;nbsp; The page usually freezes and users have to close their browsers if they can as the page is “Not Responding” or reboot their computer.&amp;nbsp; Once they go back into Alfresco it will work for a while then the pop will appear again.&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="margin: 0in 0in 10pt;"&gt;&lt;SPAN style="color: navy; font-size: 10pt;"&gt;The&amp;nbsp; above&amp;nbsp; issue only occurs while&amp;nbsp; they are using&amp;nbsp; https,&amp;nbsp;his makes me think that the problem is not caused by the authentication but by the configuration of the connector in TOMCAT,&amp;nbsp;below is my&amp;nbsp; configuration,&amp;nbsp; could&amp;nbsp; you&amp;nbsp; help&amp;nbsp; me&amp;nbsp; to understand&amp;nbsp; why the&amp;nbsp; session&amp;nbsp; is&amp;nbsp; broken&amp;nbsp; and&amp;nbsp; the user&amp;nbsp; are&amp;nbsp; prompted to&amp;nbsp; enter&amp;nbsp; credential if we&amp;nbsp; set up&amp;nbsp; NTLM-SSO.&amp;nbsp; Thanks&amp;nbsp; so much&amp;nbsp; for&amp;nbsp; your help&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="margin: 0in 0in 10pt;"&gt;&lt;SPAN style="color: navy; font-size: 10pt;"&gt;&amp;lt;Connector port="8445" protocol="org.apache.coyote.http11.Http11NioProtocol" SSLEnabled="true"&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; maxthreads="400" scheme="https" secure="true"&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; keystoreFile="D:\Alfresco\alf_data\keystore\ssl.serv.keystore"&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; keystorePass="kT9X6oe68t" keystoreType="JCEKS"&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; clientAuth="false" sslProtocol="TLS" /&amp;gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Fri, 09 Dec 2016 15:42:38 GMT</pubDate>
    <dc:creator>oscar_2016</dc:creator>
    <dc:date>2016-12-09T15:42:38Z</dc:date>
    <item>
      <title>Alfreco session  broken while using  HTTPS</title>
      <link>https://connect.hyland.com/t5/alfresco-archive/alfreco-session-broken-while-using-https/m-p/294776#M247906</link>
      <description>Hello&amp;nbsp; Are&amp;nbsp; environment is as&amp;nbsp; followsWindows&amp;nbsp; 2008&amp;nbsp; R2&amp;nbsp;Apache Tomcat/7.0.53Alfresco 4.2.4 enterprise&amp;nbsp; editionThe&amp;nbsp; issue&amp;nbsp; we&amp;nbsp; are&amp;nbsp; experience in alfresco&amp;nbsp; share&amp;nbsp;&amp;nbsp;is as&amp;nbsp; follows1. Authentication NTLM SSO&amp;nbsp; on&amp;nbsp; active&amp;nbsp; directory2. We&amp;nbsp; only&amp;nbsp; are&amp;nbsp; authenticating&amp;nbsp; share and&amp;nbsp; explorer3&amp;nbsp;Using&amp;nbsp; http&amp;nbsp; and&amp;nbsp; ht</description>
      <pubDate>Fri, 09 Dec 2016 15:42:38 GMT</pubDate>
      <guid>https://connect.hyland.com/t5/alfresco-archive/alfreco-session-broken-while-using-https/m-p/294776#M247906</guid>
      <dc:creator>oscar_2016</dc:creator>
      <dc:date>2016-12-09T15:42:38Z</dc:date>
    </item>
    <item>
      <title>Re: Alfreco session  broken while using  HTTPS</title>
      <link>https://connect.hyland.com/t5/alfresco-archive/alfreco-session-broken-while-using-https/m-p/294777#M247907</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;This issue could depends on some networking issue between Alfresco and the specific user machine.&lt;/P&gt;&lt;P&gt;Have you tried to understand if these users have&amp;nbsp;the same subnet or similar constraints&amp;nbsp;compared to the other users?&lt;/P&gt;&lt;P&gt;It could be a problem related to a proxy setting but I'm not sure.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If you are using Alfresco Enterprise Edition you should have a dedicated account for creating a ticket to the Alfresco Support:&lt;/P&gt;&lt;P&gt;&lt;A class="link-titled" href="http://support.alfresco.com/" title="http://support.alfresco.com/" rel="nofollow noopener noreferrer"&gt;http://support.alfresco.com/&lt;/A&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;In this way the Alfresco Engineers will help you on this specific issue.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 16 Dec 2016 11:20:09 GMT</pubDate>
      <guid>https://connect.hyland.com/t5/alfresco-archive/alfreco-session-broken-while-using-https/m-p/294777#M247907</guid>
      <dc:creator>openpj</dc:creator>
      <dc:date>2016-12-16T11:20:09Z</dc:date>
    </item>
    <item>
      <title>Re: Alfreco session  broken while using  HTTPS</title>
      <link>https://connect.hyland.com/t5/alfresco-archive/alfreco-session-broken-while-using-https/m-p/294778#M247908</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;First&amp;nbsp; of&amp;nbsp; all,&amp;nbsp; Thanks&amp;nbsp; very much&amp;nbsp;&amp;nbsp; for&amp;nbsp; your&amp;nbsp; response;&amp;nbsp;was already starting to disappoint to see that nobody showed interest in this.&amp;nbsp;&amp;nbsp; &lt;/P&gt;&lt;P style="margin: 0in 0in 0pt;"&gt;&lt;SPAN style="color: #1f497d; font-size: medium; font-family: Calibri;"&gt;The&amp;nbsp; https&amp;nbsp; connector&amp;nbsp; configuration is ignoring the parameter&amp;nbsp; maxHttpHeaderSize, see&amp;nbsp;&amp;nbsp; what&amp;nbsp; tomcat&amp;nbsp;&amp;nbsp; documentation&amp;nbsp; says&amp;nbsp; &amp;nbsp;about&amp;nbsp;&amp;nbsp; this&amp;nbsp; parameter: &lt;/SPAN&gt;&lt;/P&gt;&lt;P style="margin: 0in 0in 0pt;"&gt;&lt;SPAN style="color: red; font-size: medium; font-family: Calibri;"&gt;The maximum size of the request and response HTTP header, specified in bytes. If not specified, this attribute is set to 8192 (8 KB).&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="margin: 0in 0in 0pt;"&gt;&lt;SPAN style="color: #1f497d; font-size: medium; font-family: Calibri;"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="margin: 0in 0in 0pt;"&gt;&lt;SPAN style="color: #1f497d; font-size: medium; font-family: Calibri;"&gt;We &amp;nbsp;are&amp;nbsp; using&amp;nbsp; NTLM SSO&amp;nbsp; again&amp;nbsp; Active&amp;nbsp; directory,&amp;nbsp; the&amp;nbsp; NTLM authentication &amp;nbsp;uses&amp;nbsp; http&amp;nbsp; headers&amp;nbsp; WWWAuthenticate and&amp;nbsp; &amp;nbsp;&amp;nbsp;Authorization (this&amp;nbsp; header could be big),&amp;nbsp; in addition there&amp;nbsp; are&amp;nbsp; other&amp;nbsp; headers&amp;nbsp; on&amp;nbsp; each&amp;nbsp; http&amp;nbsp; request and&amp;nbsp; response messages&amp;nbsp; like&amp;nbsp; session header, cookies&amp;nbsp; etc&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="margin: 0in 0in 0pt;"&gt;&lt;SPAN style="color: #1f497d; font-size: medium; font-family: Calibri;"&gt;In http or&amp;nbsp; https &amp;nbsp;&amp;nbsp;A request with too long headers is rejected&amp;nbsp; by the&amp;nbsp; webserver before it reaches a web application (alfresco&amp;nbsp; share or&amp;nbsp; alfresco) &lt;/SPAN&gt;&lt;/P&gt;&lt;P style="margin: 0in 0in 0pt;"&gt;&lt;SPAN style="color: #1f497d; font-size: medium; font-family: Calibri;"&gt;The &amp;nbsp;above means&amp;nbsp; that&amp;nbsp; randomly&amp;nbsp; the end user might&amp;nbsp; get&amp;nbsp; and&amp;nbsp; error&amp;nbsp; or&amp;nbsp; be&amp;nbsp; prompted &amp;nbsp;to enter&amp;nbsp; &amp;nbsp;credentials, &amp;nbsp;I have play&amp;nbsp; with&amp;nbsp; &amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="margin: 0in 0in 0pt;"&gt;&lt;SPAN style="color: #1f497d; font-size: medium; font-family: Calibri;"&gt;&amp;nbsp;maxHttpHeaderSize, setting&amp;nbsp; small&amp;nbsp; values and&amp;nbsp; what&amp;nbsp; I&amp;nbsp; got&amp;nbsp;&amp;nbsp; is&amp;nbsp; either&amp;nbsp; and&amp;nbsp; error Web page&amp;nbsp; cannot&amp;nbsp; be&amp;nbsp; display&amp;nbsp; (Tomcat is&amp;nbsp; rejecting the&amp;nbsp; request and&amp;nbsp; sending&amp;nbsp; HTTP&amp;nbsp; status&amp;nbsp; bad&amp;nbsp; request)&amp;nbsp; or&amp;nbsp; I am being prompted &amp;nbsp;to enter&amp;nbsp; credential &amp;nbsp;through&amp;nbsp; the&amp;nbsp; alfresco login page (this means&amp;nbsp; that the&amp;nbsp; header&amp;nbsp; size is&amp;nbsp; not&amp;nbsp; big&amp;nbsp; enough &amp;nbsp;and&amp;nbsp; &amp;nbsp;the NTLM&amp;nbsp; SSO failed).&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="margin: 0in 0in 0pt;"&gt;&lt;SPAN style="color: #1f497d; font-size: medium; font-family: Calibri;"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="margin: 0in 0in 0pt;"&gt;&lt;SPAN style="color: #1f497d; font-size: medium; font-family: Calibri;"&gt;What the end&amp;nbsp; user&amp;nbsp; are getting&amp;nbsp; is&amp;nbsp; the Windows&amp;nbsp;&amp;nbsp; security&amp;nbsp; POP up&amp;nbsp; Windows,&amp;nbsp;&amp;nbsp; this&amp;nbsp; Windows is&amp;nbsp; displays&amp;nbsp; when&amp;nbsp; Basic authentication has been&amp;nbsp; configured&amp;nbsp; for a&amp;nbsp; web&amp;nbsp; application,&amp;nbsp; this kind of&amp;nbsp; authentication is&amp;nbsp; Done my&amp;nbsp; TOMCAT&amp;nbsp; and &amp;nbsp;&amp;nbsp;is&amp;nbsp; enable&amp;nbsp; through&amp;nbsp; security&amp;nbsp; constrains &amp;nbsp;in the&amp;nbsp; web application deployment&amp;nbsp; descriptor, I have&amp;nbsp; checked&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="margin: 0in 0in 0pt;"&gt;&lt;SPAN style="color: #1f497d; font-size: medium; font-family: Calibri;"&gt;The &amp;nbsp;deployment&amp;nbsp; descriptor of&amp;nbsp; Share,&amp;nbsp; alfresco and&amp;nbsp; SOLR&amp;nbsp; and there&amp;nbsp; are &amp;nbsp;&amp;nbsp;security&amp;nbsp; constrains in&amp;nbsp; Alfresco &amp;nbsp;&amp;nbsp;&amp;nbsp;and&amp;nbsp; SOLR&amp;nbsp; but they&amp;nbsp; do not use&amp;nbsp; Basic&amp;nbsp; authentication).&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="margin: 0in 0in 0pt;"&gt;&lt;SPAN style="color: #1f497d; font-size: medium; font-family: Calibri;"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="margin: 0in 0in 0pt;"&gt;&lt;SPAN style="color: #1f497d; font-size: medium; font-family: Calibri;"&gt;Since&amp;nbsp; Anonymous&amp;nbsp; authentication&amp;nbsp; is&amp;nbsp; disable in&amp;nbsp; Tomcat, Alfresco, SOLR and&amp;nbsp; Share, it&amp;nbsp; &amp;nbsp;could be happening &amp;nbsp;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="margin: 0in 0in 0pt;"&gt;&lt;SPAN style="font-size: medium; font-family: Calibri;"&gt;&lt;SPAN style="color: #1f497d;"&gt;That &amp;nbsp;when&amp;nbsp; a &amp;nbsp;request with too long headers arrives TOMCAT is rejecting&amp;nbsp; it &amp;nbsp;before it reaches&amp;nbsp; share and silently drop connection and&amp;nbsp; from&amp;nbsp; this point&amp;nbsp; tomcat&amp;nbsp; is&amp;nbsp; switching&amp;nbsp; to basic&amp;nbsp; authentication &lt;/SPAN&gt;&lt;SPAN style="color: red;"&gt;(the&amp;nbsp; NTLM SSO is&amp;nbsp; performed&amp;nbsp; by&amp;nbsp; Alfresco&lt;/SPAN&gt;&lt;SPAN style="color: #1f497d;"&gt;)&amp;nbsp;&amp;nbsp; &amp;nbsp;&amp;nbsp;and&amp;nbsp;&amp;nbsp; reply any&amp;nbsp; request&amp;nbsp; containing &amp;nbsp;&amp;nbsp;the&amp;nbsp; header WWWAuthenticate =&amp;nbsp; basic, that&amp;nbsp; makes IE&amp;nbsp; display&amp;nbsp; the &amp;nbsp;Windows&amp;nbsp; security pop ups, then the user&amp;nbsp; enter&amp;nbsp; their&amp;nbsp; credential&amp;nbsp;&amp;nbsp;&amp;nbsp; but&amp;nbsp; Tomcat&amp;nbsp; does not&amp;nbsp; find&amp;nbsp;&amp;nbsp;&amp;nbsp; this&amp;nbsp; credential&amp;nbsp; in&amp;nbsp; the&amp;nbsp; xml&amp;nbsp; find&amp;nbsp; that is&amp;nbsp; used&amp;nbsp; for&amp;nbsp; Basic authentication and the authentication fail and&amp;nbsp; keep&amp;nbsp; asking&amp;nbsp; for&amp;nbsp; credentials.&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="margin: 0in 0in 0pt;"&gt;&lt;SPAN style="color: #1f497d; font-size: medium; font-family: Calibri;"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 16 Dec 2016 13:35:21 GMT</pubDate>
      <guid>https://connect.hyland.com/t5/alfresco-archive/alfreco-session-broken-while-using-https/m-p/294778#M247908</guid>
      <dc:creator>oscar_2016</dc:creator>
      <dc:date>2016-12-16T13:35:21Z</dc:date>
    </item>
  </channel>
</rss>

