05-30-2013 02:31 AM
05-30-2013 06:33 AM
05-30-2013 10:17 AM
<Connector port="8443" protocol="org.apache.coyote.http11.Http11Protocol" SSLEnabled="true"
maxThreads="150" scheme="https" keystoreFile="C:\Alfresco/alf_data/keystore/ssl.keystore" keystorePass="<pass>" keystoreType="JCEKS"
secure="true" connectionTimeout="240000" truststoreFile="C:\Alfresco/alf_data/keystore/ssl.truststore" truststorePass="<pass>" truststoreType="JCEKS"
clientAuth="false" sslProtocol="TLS" allowUnsafeLegacyRenegotiation="true" maxSavePostSize="-1" />
<Connector port="443" protocol="org.apache.coyote.http11.Http11Protocol" SSLEnabled="true"
maxThreads="150" scheme="https" keystoreFile="C:\Alfresco\java\bin\rapidssl.jks" keystorePass="<pass>" keystoreType="JKS" secure="true"
clientAuth="false" sslProtocol="TLS" />
05-31-2013 10:47 AM
06-05-2013 10:16 AM
<Connector port="443" protocol="org.apache.coyote.http11.Http11Protocol" SSLEnabled="true"
maxThreads="150" scheme="https" keystoreFile="C:\Alfresco\java\bin\rapidssl.jks" keystorePass="<rapidsslpass>" keystoreType="JKS" secure="true" truststoreFile="C:\Alfresco/alf_data/keystore/ssl.truststore" truststorePass="<alfrescopass>" truststoreType="JCEKS"
clientAuth="false" sslProtocol="TLS" />
06-10-2013 03:37 AM
org.apache.catalina.authenticator.level = FINEST
in tomcat/conf/logging.properties should result in log output in Tomcat logs about SSL client certificate authentication between SOLR and Repository (SOLR => Repository is the interesting use case here). Setting -Djavax.net.debug=all
in JAVA_OPTS of Tomcat will start to generate an insane amount of log output of the low-level SSL handshake / communication, which can be mined for clues (I once had similar problems with SOLR => Repository tracking and found that - due to some misconfiguration in JAVA_OPTS - the truststores of the SOLR client were not loaded correctly.06-12-2013 07:15 PM
63.87.61.77 - - [12/Jun/2013:16:07:14 -0700] "GET /share/feedservice/components/dashlets/activities/list?format=atomfeed&mode=user&site=&dateFilter=7&userFilter=all&activityFilter= HTTP/1.1" 401 -
127.0.0.1 - - [12/Jun/2013:16:03:15 -0700] "GET /alfresco/s/api/people/admin/preferences?alf_ticket=TICKET_1bc44e5ef623f64f8895d012724687b35b3a46d6 HTTP/1.1" 200 2154
127.0.0.1 - - [12/Jun/2013:16:03:15 -0700] "GET /alfresco/s/api/sites/filetransfer?alf_ticket=TICKET_1bc44e5ef623f64f8895d012724687b35b3a46d6 HTTP/1.1" 200 478
127.0.0.1 - - [12/Jun/2013:16:03:15 -0700] "GET /share/page/site/filetransfer/search?t=async.log HTTP/1.1" 200 36653
127.0.0.1 - CN=Alfresco Repository, OU=Unknown, O=Alfresco Software Ltd., L=Maidenhead, ST=UK, C=GB [12/Jun/2013:16:03:16 -0700] "POST /solr/alfresco/afts?wt=json&fl=DBID%2Cscore&rows=502&df=keywords&start=0&locale=en_US&fq=%7B%21afts%7DAUTHORITY_FILTER_FROM_JSON&fq=%7B%21afts%7DTENANT_FILTER_FROM_JSON HTTP/1.1" 200 103
127.0.0.1 - - [12/Jun/2013:16:03:16 -0700] "GET /alfresco/s/slingshot/search?site=filetransfer&term=async.log&tag=&maxResults=251&sort=&query=&repo=false&rootNode=alfresco%3A%2F%2Fcompany%2Fhome&alf_ticket=TICKET_1bc44e5ef623f64f8895d012724687b35b3a46d6 HTTP/1.1" 200 36
127.0.0.1 - - [12/Jun/2013:16:03:16 -0700] "GET /share/proxy/alfresco/slingshot/search?site=filetransfer&term=async.log&tag=&maxResults=251&sort=&query=&repo=false&rootNode=alfresco%3A%2F%2Fcompany%2Fhome HTTP/1.1" 200 25
127.0.0.1 - - [12/Jun/2013:16:03:16 -0700] "POST /alfresco/s/api/sites/query?alf_ticket=TICKET_1bc44e5ef623f64f8895d012724687b35b3a46d6 HTTP/1.1" 200 2380
127.0.0.1 - - [12/Jun/2013:16:03:16 -0700] "GET /share/service/modules/header/sites?htmlid=global_x002e_header_x0023_default-app_sites&favsites=%7B%22testtetestset%22%3Atrue%2C%22ats621%22%3Atrue%2C%22testsitesec%22%3Atrue%2C%22mail%22%3Atrue%2C%22swsdp%22%3Atrue%2C%22ats621bau%22%3Atrue%2C%22testsite%22%3Atrue%2C%22logs%22%3Atrue%2C%22filetransfer%22%3Atrue%7D&siteId=filetransfer HTTP/1.1" 200 2440
06-16-2013 10:58 AM
06-24-2013 06:50 PM
server {
listen 80;
server_name mydomain.net;
server_name *.mydomain.net;
rewrite ^/$ https://mydomain.net/;
location / {
root C:/alfresco/tomcat/webapps/share/;
proxy_pass http://localhost:8080;
proxy_set_header X-Real-IP $remote_addr;
proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;
proxy_set_header host $host;
proxy_set_header X-Forwarded-Server $host;
proxy_set_header X-Forwarded-Proto $scheme;
add_header Front-End-Https on;
proxy_redirect off;
}
}
server {
listen 443;
server_name mydomain.net;
server_name *.mydomain.net;
ssl on;
ssl_certificate C:/nginx/conf/mydomain_net-bundle.crt;
ssl_certificate_key C:/nginx/conf/myserver.key;
rewrite ^/$ /share;
location / {
root C:/alfresco/tomcat/webapps/share/;
proxy_pass https://localhost:8443;
proxy_set_header X-Real-IP $remote_addr;
proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;
proxy_set_header host $host;
proxy_set_header X-Forwarded-Server $host;
proxy_set_header X-Forwarded-Proto $scheme;
add_header Front-End-Https on;
proxy_redirect off;
}
}
Tags
Find what you came for
We want to make your experience in Hyland Connect as valuable as possible, so we put together some helpful links.