<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Best practize to configure Alfresco behind a webproxy in Alfresco Forum</title>
    <link>https://connect.hyland.com/t5/alfresco-forum/best-practize-to-configure-alfresco-behind-a-webproxy/m-p/114925#M31909</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;can someone give me some hints how to configure Alfresco behind a webproxy (Watchguard)?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;The communication between alfresco tomcat and webproxy should be non encrypted to improve performance.&lt;/LI&gt;&lt;LI&gt;The communication between client and webproxy is secured by SSL.&lt;/LI&gt;&lt;LI&gt;On the webproxy I have enabled TLS/SSL offload, port 80 and port 443 are redirected to port 8080 on the tomcat which is not encrypted.&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;Trying to change the filename or the description, when I use SSL in my broweser results in the following error log:&lt;/P&gt;&lt;BLOCKQUOTE class="jive_macro_quote jive-quote jive_text_macro"&gt;&lt;P&gt;2019-09-05 09:16:18,089 INFO&amp;nbsp; [org.springframework.extensions.webscripts.servlet.CSRFFilter] [http-nio-8080-exec-44] Possible CSRF attack noted when asserting referer header 'https://files.*/share/page/site/management/document-details?nodeRef=workspace://SpacesStore/03ee7d34-94d6-49d4-92c6-f15131398eea'. Request: POST /share/proxy/alfresco/slingshot/doclib/activity&lt;BR /&gt;2019-09-05 09:16:18,089 ERROR [org.alfresco.web.site] [http-nio-8080-exec-44] javax.servlet.ServletException: Possible CSRF attack noted when asserting referer header 'https://files.*share/page/site/management/document-details?nodeRef=workspace://SpacesStore/03ee7d34-94d6-49d4-92c6-f15131398eea'. Request: POST /share/proxy/alfresco/slingshot/doclib/activity, FAILED TEST: Assert referer POST /share/proxy/alfresco/slingshot/doclib/activity :: referer: 'https://&lt;/P&gt;&lt;/BLOCKQUOTE&gt;&lt;P&gt;Performing the same operation if I do not use SSL in the browser succeeds. I understand the error message, but I do not know how to change the configuration that I do not need to use https on the tomcat if using ssl when connecting to the webproxy.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;Florian&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Thu, 05 Sep 2019 07:36:19 GMT</pubDate>
    <dc:creator>nettania</dc:creator>
    <dc:date>2019-09-05T07:36:19Z</dc:date>
    <item>
      <title>Best practize to configure Alfresco behind a webproxy</title>
      <link>https://connect.hyland.com/t5/alfresco-forum/best-practize-to-configure-alfresco-behind-a-webproxy/m-p/114925#M31909</link>
      <description>Hi,can someone give me some hints how to configure Alfresco behind a webproxy (Watchguard)?The communication between alfresco tomcat and webproxy should be non encrypted to improve performance.The communication between client and webproxy is secured by SSL.On the webproxy I have enabled TLS/SSL offl</description>
      <pubDate>Thu, 05 Sep 2019 07:36:19 GMT</pubDate>
      <guid>https://connect.hyland.com/t5/alfresco-forum/best-practize-to-configure-alfresco-behind-a-webproxy/m-p/114925#M31909</guid>
      <dc:creator>nettania</dc:creator>
      <dc:date>2019-09-05T07:36:19Z</dc:date>
    </item>
    <item>
      <title>Re: Best practize to configure Alfresco behind a webproxy</title>
      <link>https://connect.hyland.com/t5/alfresco-forum/best-practize-to-configure-alfresco-behind-a-webproxy/m-p/114926#M31910</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Florian,&lt;/P&gt;&lt;P&gt;I don't have experience with Watchguard but there are some points which are more or less generic:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;tomcat needs to know the hostname (&lt;CODE class=""&gt;proxyName&lt;/CODE&gt;), port (&lt;CODE class=""&gt;proxyPort&lt;/CODE&gt;) and protocol the end user called you could&lt;UL&gt;&lt;LI&gt;pass protocol and host in header variables to be mapped on tomcat in tomcat you could use RemoteIpValve to automatically map IP, host and protocol&lt;/LI&gt;&lt;LI&gt;hard code protocol, host, port by defining multiple tomcat connectors setting scheme, proxyPort in the connector attributes&lt;/LI&gt;&lt;/UL&gt;&lt;/LI&gt;&lt;LI&gt;in alfresco-global.properties the value of share.host will be whitelisted in the Alfresco Share "CSRF Token Filter". Please read &lt;A class="link-titled" href="https://docs.alfresco.com/6.1/concepts/csrf-policy.html" title="https://docs.alfresco.com/6.1/concepts/csrf-policy.html" rel="nofollow noopener noreferrer"&gt;Cross-Site Request Forgery (CSRF) filters for Share | Alfresco Documentation&lt;/A&gt; to understand how to configure/change the behavior of that filter.&lt;/LI&gt;&lt;/UL&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 05 Sep 2019 08:26:48 GMT</pubDate>
      <guid>https://connect.hyland.com/t5/alfresco-forum/best-practize-to-configure-alfresco-behind-a-webproxy/m-p/114926#M31910</guid>
      <dc:creator>heiko_robert</dc:creator>
      <dc:date>2019-09-05T08:26:48Z</dc:date>
    </item>
  </channel>
</rss>

