<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Alfresco 5,0 -&amp;gt; 201605: Sorl4 SSL 403 Errors in Alfresco Archive</title>
    <link>https://connect.hyland.com/t5/alfresco-archive/alfresco-5-0-gt-201605-sorl4-ssl-403-errors/m-p/307632#M260762</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;SPAN&gt;Hi all,&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;We have upgraded from Alfresco 5.0 community edition to Alfresco201605. Everything, except secure communication with Solr4, is working. There appears to be a problem with X509 filter in solr4. The browsers and clients do not appear to send the client certs as far as we can tell.&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;I have done the following:&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;1) Copied our existing and working ssl.keystore and ssl.truststore to alf_data/keystore along with password property files&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;2) Copied our existing and working ssl.rep.client.keystore, ssl.repo.client.truststore to our two cores, archive and workspace along with password property files,&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;3) Ensured /etc/tomcat/tomcat-users.xml has the correct users entries for client certs&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;4) When starting tomcat we get 403 solr errors - as below&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;5) We have tried running the generate_keystore.sh script, modified with our setting, and get the same error result.&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;5) We imported he browser.p12 certificate into firefox and chromium and visited the :8443/solr4. We get the untrusted cert warning, which we accept, but then we get a 403 error from the X509 filter &lt;img id="smileysad" class="emoticon emoticon-smileysad" src="https://connect.hyland.com/i/smilies/16x16_smiley-sad.png" alt="Smiley Sad" title="Smiley Sad" /&gt;&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;6) If I create a test war file, assign the "repository" and "repoclient" role to the war and add a security constraint for client certs to web.xml we get prompted to accept our client cert when we visit the test site and we successfully gain access. Thereafter we are able to access the solr4 admin page successfully.&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;I have browsed the AlfrescoX509ServletFilter and X509ServletFilterBase code at: &lt;/SPAN&gt;&lt;A href="https://github.com/Alfresco/community-edition/blob/70f90384d2745fbc0c1d1be2aaa01cab40c47f34/projects/web-client/source/java/org/alfresco/web/app/servlet/AlfrescoX509ServletFilter.java" rel="nofollow noopener noreferrer"&gt;https://github.com/Alfresco/community-edition/blob/70f90384d2745fbc0c1d1be2aaa01cab40c47f34/projects/web-client/source/java/org/alfresco/web/app/servlet/AlfrescoX509ServletFilter.java&lt;/A&gt;&lt;SPAN&gt; as far as I can see X509ServletFilterBase simply retrieves a request attribute javax.servlet.request.X509Certificate to get the cert in the code. So it seems that the client is unaware that it needs to send the cert? Just guessing here - but this is as far as our investigation has taken us.&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;Any ideas? &lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;Java&lt;img id="smileysurprised" class="emoticon emoticon-smileysurprised" src="https://connect.hyland.com/i/smilies/16x16_smiley-surprised.png" alt="Smiley Surprised" title="Smiley Surprised" /&gt;penjdk version "1.8.0_91"&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;Tomcat: 7.0.68-1&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;&amp;lt;blockcode&amp;gt;ERROR [solr.tracker.AbstractTracker] [SolrTrackerScheduler_Worker-10] Model tracking failed&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt; org.alfresco.error.AlfrescoRuntimeException: 07200907 GetModelsDiff return status is 403&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;at org.alfresco.solr.client.SOLRAPIClient.getModelsDiff(SOLRAPIClient.java:1157)&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;at org.alfresco.solr.tracker.ModelTracker.trackModelsImpl(ModelTracker.java:249)&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;at org.alfresco.solr.tracker.ModelTracker.trackModels(ModelTracker.java:207)&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;at org.alfresco.solr.tracker.ModelTracker.ensureFirstModelSync(ModelTracker.java:229)&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;at org.alfresco.solr.component.EnsureModelsComponent.prepare(EnsureModelsComponent.java:80)&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;at org.apache.solr.handler.component.AlfrescoSearchHandler.handleRequestBody(AlfrescoSearchHandler.java:283)&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;at org.apache.solr.handler.RequestHandlerBase.handleRequest(RequestHandlerBase.java:135)&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;at org.alfresco.solr.Cloud.getResponse(Cloud.java:159)&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;at org.alfresco.solr.Cloud.getSolrDocumentList(Cloud.java:143)&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;at org.alfresco.solr.SolrInformationServer.getDocsWithUncleanContent(SolrInformationServer.java:715)&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;at org.alfresco.solr.tracker.ContentTracker.doTrack(ContentTracker.java:74)&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;at org.alfresco.solr.tracker.AbstractTracker.track(AbstractTracker.java:185)&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;at org.alfresco.solr.tracker.TrackerJob.execute(TrackerJob.java:47)&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;at org.quartz.core.JobRunShell.run(JobRunShell.java:216)&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;at org.quartz.simpl.SimpleThreadPool$WorkerThread.run(SimpleThreadPool.java:563)&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;&amp;lt;/blockcode&amp;gt;&lt;/SPAN&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Sat, 20 Aug 2016 20:55:52 GMT</pubDate>
    <dc:creator>mxc</dc:creator>
    <dc:date>2016-08-20T20:55:52Z</dc:date>
    <item>
      <title>Alfresco 5,0 -&gt; 201605: Sorl4 SSL 403 Errors</title>
      <link>https://connect.hyland.com/t5/alfresco-archive/alfresco-5-0-gt-201605-sorl4-ssl-403-errors/m-p/307632#M260762</link>
      <description>Hi all,We have upgraded from Alfresco 5.0 community edition to Alfresco201605. Everything, except secure communication with Solr4, is working. There appears to be a problem with X509 filter in solr4. The browsers and clients do not appear to send the client certs as far as we can tell.I have done th</description>
      <pubDate>Sat, 20 Aug 2016 20:55:52 GMT</pubDate>
      <guid>https://connect.hyland.com/t5/alfresco-archive/alfresco-5-0-gt-201605-sorl4-ssl-403-errors/m-p/307632#M260762</guid>
      <dc:creator>mxc</dc:creator>
      <dc:date>2016-08-20T20:55:52Z</dc:date>
    </item>
    <item>
      <title>Re: Alfresco 5,0 -&gt; 201605: Sorl4 SSL 403 Errors</title>
      <link>https://connect.hyland.com/t5/alfresco-archive/alfresco-5-0-gt-201605-sorl4-ssl-403-errors/m-p/307633#M260763</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;SPAN&gt;Found the problem. It seems the syntax for the coyote connector in server.xml has changed. Needed to add 'allowUnsafeLegacyRenegotiation="true"' to the declaration so the full connector stanza looks like this:&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;&amp;lt;blockcode&amp;gt;&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;&amp;nbsp;&amp;nbsp; &amp;lt;Connector port="8443" URIEncoding="UTF-8" protocol="org.apache.coyote.http11.Http11Protocol" SSLEnabled="true"&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; maxThreads="150" scheme="https" keystoreFile="/usr/local/alfresco/alf_data/keystore/ssl.keystore" keystorePass="kT9X6oe68t" keystoreType="JCEKS"&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt; secure="true" connectionTimeout="240000" truststoreFile="/usr/lcoal/alfresco/alf_data/keystore/ssl.truststore" truststorePass="kT9X6oe68t" truststoreType="JCEKS"&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; clientAuth="want" sslProtocol="TLS" allowUnsafeLegacyRenegotiation="true" maxHttpHeaderSize="32768" maxSavePostSize="-1" /&amp;gt;&amp;nbsp; &lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;&amp;lt;/blockcode&amp;gt;&lt;/SPAN&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 21 Aug 2016 10:49:00 GMT</pubDate>
      <guid>https://connect.hyland.com/t5/alfresco-archive/alfresco-5-0-gt-201605-sorl4-ssl-403-errors/m-p/307633#M260763</guid>
      <dc:creator>mxc</dc:creator>
      <dc:date>2016-08-21T10:49:00Z</dc:date>
    </item>
  </channel>
</rss>

