<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic How to enable an additional certificate ? in Alfresco Archive</title>
    <link>https://connect.hyland.com/t5/alfresco-archive/how-to-enable-an-additional-certificate/m-p/302465#M255595</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;SPAN&gt;Hi,&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;We are running a vulnerability testing appliance and we have the following vulnerabilities associated with port 8443/tcp over SSL (Alfresco Tomcat) :&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;SSL Certificate - Self-Signed Certificate&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;SSL Certificate - Subject Common Name Does Not Match Server FQDN&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;SSL Certificate - Signature Verification Failed Vulnerability&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;I know what this means so I set out to generate a certificate from a trusted issuer.&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;The original keystore had :&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;keytool.exe -list -keystore …\alf_data\keystore\ssl.keystore -storetype JCEKS -storepass TheGoodPW&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;Keystore type: JCEKS&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;Keystore provider: SunJCE&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;Your keystore contains 2 entries&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;ssl.repo, Aug 10, 2012, PrivateKeyEntry,&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;Certificate fingerprint (SHA1): C7:50:C4:95:03:90:F7:5E:45:58:58:89:08:5F&lt;img id="smileyvery-happy" class="emoticon emoticon-smileyvery-happy" src="https://connect.hyland.com/i/smilies/16x16_smiley-very-happy.png" alt="Smiley Very Happy" title="Smiley Very Happy" /&gt;7:4F:1B:8C:C2:32&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;ssl.alfresco.ca, Aug 10, 2012, trustedCertEntry,&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;Certificate fingerprint (SHA1): F4:28:0B:38:FC:28:C6:53:18:CF:53:28:2A:F5:2F:40:78:15:0B:FF&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;I generated a certificate the Issuer of which is trusted by our vulnerability testing appliance : &lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;$ openssl x509 -inform DER -in …/alf_data/keystore/cert-MyCert.cer -text -noout&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;Certificate:&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; Data:&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Version: 3 (0x2)&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Serial Number:&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; …&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; Signature Algorithm: sha1WithRSAEncryption&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Issuer: CN=MyFQDN-NoProblem&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;Importing it into the keystore : &lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;keytool -v -importcert -alias MyAlias -file …\Alfresco\alf_data\keystore\MyCert.cer -storepass GoodPW -keystore D…\Alfresco\alf_data\keystore\ssl.keystore -storetype JCEKS&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;And listing its content :&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;keytool.exe -list -keystore …\alf_data\keystore\ssl.keystore -storetype JCEKS -storepass TheGoodPW&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;Your keystore contains 4 entries&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;ssl.repo, Aug 10, 2012, PrivateKeyEntry,&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;Certificate fingerprint (SHA1): C7:50:C4:95:03:90:F7:5E:45:58:58:89:08:5F&lt;img id="smileyvery-happy" class="emoticon emoticon-smileyvery-happy" src="https://connect.hyland.com/i/smilies/16x16_smiley-very-happy.png" alt="Smiley Very Happy" title="Smiley Very Happy" /&gt;7:4F:1B:8C:C2:32&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;MyCert1, Oct 29, 2013, trustedCertEntry,&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;Certificate fingerprint (SHA1): ….&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;ssl.alfresco.ca, Aug 10, 2012, trustedCertEntry,&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;Certificate fingerprint (SHA1): F4:28:0B:38:FC:28:C6:53:18:CF:53:28:2A:F5:2F:40:78:15:0B:FF&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;MyCert2, Oct 29, 2013, trustedCertEntry,&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;Certificate fingerprint (SHA1): …&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;Now, if I hit port 8443 to see what comes :&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;$ openssl s_client -connect localhost:8443&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;CONNECTED(00000003)&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;depth=1 C = GB, ST = UK, L = Maidenhead, O = Alfresco Software Ltd., CN = Alfresco CA&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;verify error:num=19:self signed certificate in certificate chain&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;verify return:0&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;—&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;Certificate chain&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt; 0 s:/C=GB/ST=UK/L=Maidenhead/O=Alfresco Software Ltd./OU=Unknown/CN=Alfresco Repository&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;&amp;nbsp;&amp;nbsp; i:/C=GB/ST=UK/L=Maidenhead/O=Alfresco Software Ltd./CN=Alfresco CA&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt; 1 s:/C=GB/ST=UK/L=Maidenhead/O=Alfresco Software Ltd./CN=Alfresco CA&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;&amp;nbsp;&amp;nbsp; i:/C=GB/ST=UK/L=Maidenhead/O=Alfresco Software Ltd./CN=Alfresco CA&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;I get only the two original certificates.&amp;nbsp; How can I get Alfresco's Tomcat to present my new certs too ?&amp;nbsp; I'm pretty sure if I can get the chain with the trusted Issuer certificate I will clear all those vulnerabilities.&amp;nbsp; What do I need to do ?&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;TIA,&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;YvesM&lt;/SPAN&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Wed, 30 Oct 2013 20:39:48 GMT</pubDate>
    <dc:creator>ymoisan</dc:creator>
    <dc:date>2013-10-30T20:39:48Z</dc:date>
    <item>
      <title>How to enable an additional certificate ?</title>
      <link>https://connect.hyland.com/t5/alfresco-archive/how-to-enable-an-additional-certificate/m-p/302465#M255595</link>
      <description>Hi,We are running a vulnerability testing appliance and we have the following vulnerabilities associated with port 8443/tcp over SSL (Alfresco Tomcat) &lt;IMG id="smileyfrustrated" class="emoticon emoticon-smileyfrustrated" src="https://migration33.stage.lithium.com/i/smilies/16x16_smiley-frustrated.png" alt="Smiley Frustrated" title="Smiley Frustrated" /&gt;SL Certificate - Self-Signed CertificateSSL Certificate - Subject Common Name Does Not Match Server FQDNSSL Certificate - Signature Verification Fa</description>
      <pubDate>Wed, 30 Oct 2013 20:39:48 GMT</pubDate>
      <guid>https://connect.hyland.com/t5/alfresco-archive/how-to-enable-an-additional-certificate/m-p/302465#M255595</guid>
      <dc:creator>ymoisan</dc:creator>
      <dc:date>2013-10-30T20:39:48Z</dc:date>
    </item>
    <item>
      <title>Re: How to enable an additional certificate ?</title>
      <link>https://connect.hyland.com/t5/alfresco-archive/how-to-enable-an-additional-certificate/m-p/302466#M255596</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;SPAN&gt;Ok now I understand the issue is between solr and Alfresco.&amp;nbsp; I don't see instructions on how to create certificates other than self-signed (and with a longer keysize than the default of 1024 used with keytool -genkeypair) and I didn't find a way to have my non self-signed cert to show up in a ssl request, so I'll ask a different question.&amp;nbsp; Since only ports 80 and 443 are open and everything else from the outsie is stopped by a firewall, can I safely dismiss the vulnerabilities found by saying it's internal communications within the Alfresco software stack that is not open to the web ?&amp;nbsp; Our vulnerability testing appliance is in our internal network and that's why it finds port 8443.&amp;nbsp; Am I missing something ?&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;TIA&lt;/SPAN&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 31 Oct 2013 14:50:44 GMT</pubDate>
      <guid>https://connect.hyland.com/t5/alfresco-archive/how-to-enable-an-additional-certificate/m-p/302466#M255596</guid>
      <dc:creator>ymoisan</dc:creator>
      <dc:date>2013-10-31T14:50:44Z</dc:date>
    </item>
    <item>
      <title>Re: How to enable an additional certificate ?</title>
      <link>https://connect.hyland.com/t5/alfresco-archive/how-to-enable-an-additional-certificate/m-p/302467#M255597</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;SPAN&gt;Added address="127.0.0.1" in the &amp;lt;Connector port="8443" …&amp;gt; object and the vulnerability applicance can't hit the port anymore.&lt;/SPAN&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 04 Nov 2013 16:44:19 GMT</pubDate>
      <guid>https://connect.hyland.com/t5/alfresco-archive/how-to-enable-an-additional-certificate/m-p/302467#M255597</guid>
      <dc:creator>ymoisan</dc:creator>
      <dc:date>2013-11-04T16:44:19Z</dc:date>
    </item>
  </channel>
</rss>

