[ https://issues.apache.org/jira/browse/SOLR-14357?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=17068405#comment-17068405 ]
Bernd Wahlen edited comment on SOLR-14357 at 3/27/20, 8:14 AM: --------------------------------------------------------------- {code:java} qeep-restapi.2020-03-23.log.xz: ... 56 more qeep-restapi.2020-03-23.log.xz:Caused by: java.lang.IllegalArgumentException: Error in security property. Constraint unknown: c2tnb191v1 qeep-restapi.2020-03-23.log.xz: at sun.security.util.DisabledAlgorithmConstraints$Constraints.<init>(DisabledAlgorithmConstraints.java:381) ~[?:?] qeep-restapi.2020-03-23.log.xz: at sun.security.util.DisabledAlgorithmConstraints.<init>(DisabledAlgorithmConstraints.java:121) ~[?:?] qeep-restapi.2020-03-23.log.xz: at sun.security.ssl.SSLAlgorithmConstraints.<clinit>(SSLAlgorithmConstraints.java:45) ~[?:?] qeep-restapi.2020-03-23.log.xz: at sun.security.ssl.ProtocolVersion.<init>(ProtocolVersion.java:158) ~[?:?] qeep-restapi.2020-03-23.log.xz: at sun.security.ssl.ProtocolVersion.<clinit>(ProtocolVersion.java:41) ~[?:?] qeep-restapi.2020-03-23.log.xz: at sun.security.ssl.SSLContextImpl$AbstractTLSContext.<clinit>(SSLContextImpl.java:539) ~[?:?] qeep-restapi.2020-03-23.log.xz: at java.lang.Class.forName0(Native Method) ~[?:?] qeep-restapi.2020-03-23.log.xz: at java.lang.Class.forName(Class.java:340) ~[?:?] qeep-restapi.2020-03-23.log.xz: at java.security.Provider$Service.getImplClass(Provider.java:1844) ~[?:?] qeep-restapi.2020-03-23.log.xz: at java.security.Provider$Service.newInstance(Provider.java:1820) ~[?:?] qeep-restapi.2020-03-23.log.xz: at sun.security.jca.GetInstance.getInstance(GetInstance.java:236) ~[?:?] qeep-restapi.2020-03-23.log.xz: at sun.security.jca.GetInstance.getInstance(GetInstance.java:164) ~[?:?] qeep-restapi.2020-03-23.log.xz: at javax.net.ssl.SSLContext.getInstance(SSLContext.java:184) ~[?:?] qeep-restapi.2020-03-23.log.xz: at javax.net.ssl.SSLContext.getDefault(SSLContext.java:110) ~[?:?] qeep-restapi.2020-03-23.log.xz: at javax.net.ssl.SSLSocketFactory.getDefault(SSLSocketFactory.java:83) ~[?:?] qeep-restapi.2020-03-23.log.xz: at org.apache.http.conn.ssl.SSLConnectionSocketFactory.getSystemSocketFactory(SSLConnectionSocketFactory.java:222) ~[httpclient-4.5.10.jar:4.5.10] qeep-restapi.2020-03-23.log.xz: at org.apache.solr.client.solrj.impl.HttpClientUtil$DefaultSchemaRegistryProvider.getSchemaRegistry(HttpClientUtil.java:235) ~[solr-solrj-8.4.1.jar:8.4.1 832bf13dd9187095831caf69783179d41059d013 - ishan - 2020-01-10 13:40:30] qeep-restapi.2020-03-23.log.xz: at org.apache.solr.client.solrj.impl.HttpClientUtil.createPoolingConnectionManager(HttpClientUtil.java:260) ~[solr-solrj-8.4.1.jar:8.4.1 832bf13dd9187095831caf69783179d41059d013 - ishan - 2020-01-10 13:40:30] qeep-restapi.2020-03-23.log.xz: at org.apache.solr.client.solrj.impl.HttpClientUtil.createClient(HttpClientUtil.java:255) ~[solr-solrj-8.4.1.jar:8.4.1 832bf13dd9187095831caf69783179d41059d013 - ishan - 2020-01-10 13:40:30] qeep-restapi.2020-03-23.log.xz: at org.apache.solr.client.solrj.impl.CloudSolrClient.<init>(CloudSolrClient.java:101) ~[solr-solrj-8.4.1.jar:8.4.1 832bf13dd9187095831caf69783179d41059d013 - ishan - 2020-01-10 13:40:30] qeep-restapi.2020-03-23.log.xz: at org.apache.solr.client.solrj.impl.CloudSolrClient$Builder.build(CloudSolrClient.java:473) ~[solr-solrj-8.4.1.jar:8.4.1 832bf13dd9187095831caf69783179d41059d013 - ishan - 2020-01-10 13:40:30] {code} was (Author: bwahlen): {code:java} EASE.jar:5.2.4.RELEASE] qeep-restapi.2020-03-23.log.xz: ... 56 more qeep-restapi.2020-03-23.log.xz:Caused by: java.lang.IllegalArgumentException: Error in security property. Constraint unknown: c2tnb191v1 qeep-restapi.2020-03-23.log.xz: at sun.security.util.DisabledAlgorithmConstraints$Constraints.<init>(DisabledAlgorithmConstraints.java:381) ~[?:?] qeep-restapi.2020-03-23.log.xz: at sun.security.util.DisabledAlgorithmConstraints.<init>(DisabledAlgorithmConstraints.java:121) ~[?:?] qeep-restapi.2020-03-23.log.xz: at sun.security.ssl.SSLAlgorithmConstraints.<clinit>(SSLAlgorithmConstraints.java:45) ~[?:?] qeep-restapi.2020-03-23.log.xz: at sun.security.ssl.ProtocolVersion.<init>(ProtocolVersion.java:158) ~[?:?] qeep-restapi.2020-03-23.log.xz: at sun.security.ssl.ProtocolVersion.<clinit>(ProtocolVersion.java:41) ~[?:?] qeep-restapi.2020-03-23.log.xz: at sun.security.ssl.SSLContextImpl$AbstractTLSContext.<clinit>(SSLContextImpl.java:539) ~[?:?] qeep-restapi.2020-03-23.log.xz: at java.lang.Class.forName0(Native Method) ~[?:?] qeep-restapi.2020-03-23.log.xz: at java.lang.Class.forName(Class.java:340) ~[?:?] qeep-restapi.2020-03-23.log.xz: at java.security.Provider$Service.getImplClass(Provider.java:1844) ~[?:?] qeep-restapi.2020-03-23.log.xz: at java.security.Provider$Service.newInstance(Provider.java:1820) ~[?:?] qeep-restapi.2020-03-23.log.xz: at sun.security.jca.GetInstance.getInstance(GetInstance.java:236) ~[?:?] qeep-restapi.2020-03-23.log.xz: at sun.security.jca.GetInstance.getInstance(GetInstance.java:164) ~[?:?] qeep-restapi.2020-03-23.log.xz: at javax.net.ssl.SSLContext.getInstance(SSLContext.java:184) ~[?:?] qeep-restapi.2020-03-23.log.xz: at javax.net.ssl.SSLContext.getDefault(SSLContext.java:110) ~[?:?] qeep-restapi.2020-03-23.log.xz: at javax.net.ssl.SSLSocketFactory.getDefault(SSLSocketFactory.java:83) ~[?:?] qeep-restapi.2020-03-23.log.xz: at org.apache.http.conn.ssl.SSLConnectionSocketFactory.getSystemSocketFactory(SSLConnectionSocketFactory.java:222) ~[httpclient-4.5.10.jar:4.5.10] qeep-restapi.2020-03-23.log.xz: at org.apache.solr.client.solrj.impl.HttpClientUtil$DefaultSchemaRegistryProvider.getSchemaRegistry(HttpClientUtil.java:235) ~[solr-solrj-8.4.1.jar:8.4.1 832bf13dd9187095831caf69783179d41059d013 - ishan - 2020-01-10 13:40:30] qeep-restapi.2020-03-23.log.xz: at org.apache.solr.client.solrj.impl.HttpClientUtil.createPoolingConnectionManager(HttpClientUtil.java:260) ~[solr-solrj-8.4.1.jar:8.4.1 832bf13dd9187095831caf69783179d41059d013 - ishan - 2020-01-10 13:40:30] qeep-restapi.2020-03-23.log.xz: at org.apache.solr.client.solrj.impl.HttpClientUtil.createClient(HttpClientUtil.java:255) ~[solr-solrj-8.4.1.jar:8.4.1 832bf13dd9187095831caf69783179d41059d013 - ishan - 2020-01-10 13:40:30] qeep-restapi.2020-03-23.log.xz: at org.apache.solr.client.solrj.impl.CloudSolrClient.<init>(CloudSolrClient.java:101) ~[solr-solrj-8.4.1.jar:8.4.1 832bf13dd9187095831caf69783179d41059d013 - ishan - 2020-01-10 13:40:30] qeep-restapi.2020-03-23.log.xz: at org.apache.solr.client.solrj.impl.CloudSolrClient$Builder.build(CloudSolrClient.java:473) ~[solr-solrj-8.4.1.jar:8.4.1 832bf13dd9187095831caf69783179d41059d013 - ishan - 2020-01-10 13:40:30] {code} > solrj: using insecure namedCurves > --------------------------------- > > Key: SOLR-14357 > URL: https://issues.apache.org/jira/browse/SOLR-14357 > Project: Solr > Issue Type: Bug > Security Level: Public(Default Security Level. Issues are Public) > Reporter: Bernd Wahlen > Priority: Major > > i tried to run our our backend with solrj 8.4.1 on jdk14 and get the > following error: > Caused by: java.lang.IllegalArgumentException: Error in security property. > Constraint unknown: c2tnb191v1 > after i removed all the X9.62 algoriths from the property > jdk.disabled.namedCurves in > /usr/lib/jvm/java-14-openjdk-14.0.0.36-1.rolling.el7.x86_64/conf/security/java.security > everything is running. > This does not happend on staging (i think because of only 1 solr node - not > using lb client). > We do not set or change any ssl settings in solr.in.sh. > I don't know how to fix that (default config?, apache client settings?), but > i think using insecure algorithms may be a security risk and not only a > jdk14 issue. -- This message was sent by Atlassian Jira (v8.3.4#803005) --------------------------------------------------------------------- To unsubscribe, e-mail: issues-unsubscr...@lucene.apache.org For additional commands, e-mail: issues-h...@lucene.apache.org