<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: SOLR Tracker SSLHandshakeException in Alfresco Forum</title>
    <link>https://connect.hyland.com/t5/alfresco-forum/solr-tracker-sslhandshakeexception/m-p/4812#M2247</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Alfresco ships with its own client cert that is used by the SOLR server to authenticate requests coming from Alfresco. The log messages you are seeing indicate that something is wrong with the client certificate that Alfresco and SOLR are using.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This setup depends on Tomcat config and a keystore that, by default, resides in the alf_data directory.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Did you install using the installer?&lt;/P&gt;&lt;P&gt;Is your keystore directory where Alfresco expects?&lt;/P&gt;&lt;P&gt;Did you make any changes to Tomcat's server.xml or other Tomcat config?&lt;/P&gt;&lt;P&gt;Did you re-generate the SOLR SSL Certificate? If so, did you change the certificate's DN? If so, did you make the same change in the Tomcat config?&lt;/P&gt;&lt;P&gt;Did you make any changes to the Solr cores or their configuration (they also point to the keystore)?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Fri, 03 Feb 2017 16:31:33 GMT</pubDate>
    <dc:creator>jpotts</dc:creator>
    <dc:date>2017-02-03T16:31:33Z</dc:date>
    <item>
      <title>SOLR Tracker SSLHandshakeException</title>
      <link>https://connect.hyland.com/t5/alfresco-forum/solr-tracker-sslhandshakeexception/m-p/4811#M2246</link>
      <description>The site is up and working for 5.1.g. However, the catalina.out log is peppered with gigabytes of the following:2017-02-02 16:17:30,049 ERROR [solr.tracker.AbstractTracker] [SolrTrackerScheduler_Worker-17] Tracking failedjavax.net.ssl.SSLHandshakeException: sun.security.validator.ValidatorException:</description>
      <pubDate>Thu, 02 Feb 2017 22:22:46 GMT</pubDate>
      <guid>https://connect.hyland.com/t5/alfresco-forum/solr-tracker-sslhandshakeexception/m-p/4811#M2246</guid>
      <dc:creator>garbetsp</dc:creator>
      <dc:date>2017-02-02T22:22:46Z</dc:date>
    </item>
    <item>
      <title>Re: SOLR Tracker SSLHandshakeException</title>
      <link>https://connect.hyland.com/t5/alfresco-forum/solr-tracker-sslhandshakeexception/m-p/4812#M2247</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Alfresco ships with its own client cert that is used by the SOLR server to authenticate requests coming from Alfresco. The log messages you are seeing indicate that something is wrong with the client certificate that Alfresco and SOLR are using.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This setup depends on Tomcat config and a keystore that, by default, resides in the alf_data directory.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Did you install using the installer?&lt;/P&gt;&lt;P&gt;Is your keystore directory where Alfresco expects?&lt;/P&gt;&lt;P&gt;Did you make any changes to Tomcat's server.xml or other Tomcat config?&lt;/P&gt;&lt;P&gt;Did you re-generate the SOLR SSL Certificate? If so, did you change the certificate's DN? If so, did you make the same change in the Tomcat config?&lt;/P&gt;&lt;P&gt;Did you make any changes to the Solr cores or their configuration (they also point to the keystore)?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 03 Feb 2017 16:31:33 GMT</pubDate>
      <guid>https://connect.hyland.com/t5/alfresco-forum/solr-tracker-sslhandshakeexception/m-p/4812#M2247</guid>
      <dc:creator>jpotts</dc:creator>
      <dc:date>2017-02-03T16:31:33Z</dc:date>
    </item>
    <item>
      <title>Re: SOLR Tracker SSLHandshakeException</title>
      <link>https://connect.hyland.com/t5/alfresco-forum/solr-tracker-sslhandshakeexception/m-p/4813#M2248</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P style="color: #727174; background-color: #ffffff; border: 0px;"&gt;&amp;gt; Did you install using the installer?&amp;nbsp;&lt;/P&gt;&lt;P style="color: #727174; background-color: #ffffff; border: 0px;"&gt;Yes&lt;/P&gt;&lt;P style="color: #727174; background-color: #ffffff; border: 0px;"&gt;&amp;gt; Is your keystore directory where Alfresco expects?&lt;/P&gt;&lt;P style="color: #727174; background-color: #ffffff; border: 0px;"&gt;Yes&lt;/P&gt;&lt;P style="color: #727174; background-color: #ffffff; border: 0px;"&gt;&amp;gt; Did you make any changes to Tomcat's server.xml or other Tomcat config?&lt;/P&gt;&lt;P style="color: #727174; background-color: #ffffff; border: 0px;"&gt;Yes, I installed my own keystore with my own SSL certification issued by a provided we're required to use. Further, I set it up to use 8443 for connections which was also required by our organization's network team. I noticed that SOLR used 8443, but that was via localhost.&lt;/P&gt;&lt;P style="color: #727174; background-color: #ffffff; border: 0px;"&gt;&amp;gt; Did you re-generate the SOLR SSL Certificate? If so, did you change the certificate's DN? If so, did you make the same change in the Tomcat config?&lt;/P&gt;&lt;P style="color: #727174; background-color: #ffffff; border: 0px;"&gt;I did not.&lt;/P&gt;&lt;P style="color: #727174; background-color: #ffffff; border: 0px;"&gt;&amp;gt; Did you make any changes to the Solr cores or their configuration (they also point to the keystore)?&lt;/P&gt;&lt;P style="color: #727174; background-color: #ffffff; border: 0px;"&gt;No&lt;/P&gt;&lt;P style="color: #727174; background-color: #ffffff; border: 0px;"&gt;&lt;/P&gt;&lt;P style="color: #727174; background-color: #ffffff; border: 0px;"&gt;Can I just take the existing Alfresco keystore and add my cert to that?&amp;nbsp;I think this is the root of the problem.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 03 Feb 2017 17:12:15 GMT</pubDate>
      <guid>https://connect.hyland.com/t5/alfresco-forum/solr-tracker-sslhandshakeexception/m-p/4813#M2248</guid>
      <dc:creator>garbetsp</dc:creator>
      <dc:date>2017-02-03T17:12:15Z</dc:date>
    </item>
    <item>
      <title>Re: SOLR Tracker SSLHandshakeException</title>
      <link>https://connect.hyland.com/t5/alfresco-forum/solr-tracker-sslhandshakeexception/m-p/4814#M2249</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;You could try adding your cert to the keystore. Far better would be to create a new Connector that is listening on 443 and use that for external connections hitting the server, or even better would be to install an HTTP server with mod_ajp and use that to handle SSL, which is the best and most common practice.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If you are going to use your own cert for SOLR, you have to edit tomcat-users.xml and set the cert DN.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You should also look at this doc which talks about how SOLR security is set up: &lt;A class="link-titled" href="http://docs.alfresco.com/5.0/concepts/solrsecurity-intro.html" title="http://docs.alfresco.com/5.0/concepts/solrsecurity-intro.html" rel="nofollow noopener noreferrer"&gt;Solr 4 security | Alfresco Documentation&lt;/A&gt;&amp;nbsp;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 03 Feb 2017 17:43:44 GMT</pubDate>
      <guid>https://connect.hyland.com/t5/alfresco-forum/solr-tracker-sslhandshakeexception/m-p/4814#M2249</guid>
      <dc:creator>jpotts</dc:creator>
      <dc:date>2017-02-03T17:43:44Z</dc:date>
    </item>
    <item>
      <title>Re: SOLR Tracker SSLHandshakeException</title>
      <link>https://connect.hyland.com/t5/alfresco-forum/solr-tracker-sslhandshakeexception/m-p/4815#M2250</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I ripped all certs out of Alfresco config and put Nginx in front of it. That was a lot smoother and cleaner.&amp;nbsp;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 06 Feb 2017 16:54:37 GMT</pubDate>
      <guid>https://connect.hyland.com/t5/alfresco-forum/solr-tracker-sslhandshakeexception/m-p/4815#M2250</guid>
      <dc:creator>garbetsp</dc:creator>
      <dc:date>2017-02-06T16:54:37Z</dc:date>
    </item>
  </channel>
</rss>

