[ 
https://issues.apache.org/jira/browse/SOLR-14357?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=17068405#comment-17068405
 ] 

Bernd Wahlen commented on SOLR-14357:
-------------------------------------


{code:java}
EASE.jar:5.2.4.RELEASE]
qeep-restapi.2020-03-23.log.xz: ... 56 more
qeep-restapi.2020-03-23.log.xz:Caused by: java.lang.IllegalArgumentException: 
Error in security property. Constraint unknown: c2tnb191v1
qeep-restapi.2020-03-23.log.xz: at 
sun.security.util.DisabledAlgorithmConstraints$Constraints.<init>(DisabledAlgorithmConstraints.java:381)
 ~[?:?]
qeep-restapi.2020-03-23.log.xz: at 
sun.security.util.DisabledAlgorithmConstraints.<init>(DisabledAlgorithmConstraints.java:121)
 ~[?:?]
qeep-restapi.2020-03-23.log.xz: at 
sun.security.ssl.SSLAlgorithmConstraints.<clinit>(SSLAlgorithmConstraints.java:45)
 ~[?:?]
qeep-restapi.2020-03-23.log.xz: at 
sun.security.ssl.ProtocolVersion.<init>(ProtocolVersion.java:158) ~[?:?]
qeep-restapi.2020-03-23.log.xz: at 
sun.security.ssl.ProtocolVersion.<clinit>(ProtocolVersion.java:41) ~[?:?]
qeep-restapi.2020-03-23.log.xz: at 
sun.security.ssl.SSLContextImpl$AbstractTLSContext.<clinit>(SSLContextImpl.java:539)
 ~[?:?]
qeep-restapi.2020-03-23.log.xz: at java.lang.Class.forName0(Native Method) 
~[?:?]
qeep-restapi.2020-03-23.log.xz: at java.lang.Class.forName(Class.java:340) 
~[?:?]
qeep-restapi.2020-03-23.log.xz: at 
java.security.Provider$Service.getImplClass(Provider.java:1844) ~[?:?]
qeep-restapi.2020-03-23.log.xz: at 
java.security.Provider$Service.newInstance(Provider.java:1820) ~[?:?]
qeep-restapi.2020-03-23.log.xz: at 
sun.security.jca.GetInstance.getInstance(GetInstance.java:236) ~[?:?]
qeep-restapi.2020-03-23.log.xz: at 
sun.security.jca.GetInstance.getInstance(GetInstance.java:164) ~[?:?]
qeep-restapi.2020-03-23.log.xz: at 
javax.net.ssl.SSLContext.getInstance(SSLContext.java:184) ~[?:?]
qeep-restapi.2020-03-23.log.xz: at 
javax.net.ssl.SSLContext.getDefault(SSLContext.java:110) ~[?:?]
qeep-restapi.2020-03-23.log.xz: at 
javax.net.ssl.SSLSocketFactory.getDefault(SSLSocketFactory.java:83) ~[?:?]
qeep-restapi.2020-03-23.log.xz: at 
org.apache.http.conn.ssl.SSLConnectionSocketFactory.getSystemSocketFactory(SSLConnectionSocketFactory.java:222)
 ~[httpclient-4.5.10.jar:4.5.10]
qeep-restapi.2020-03-23.log.xz: at 
org.apache.solr.client.solrj.impl.HttpClientUtil$DefaultSchemaRegistryProvider.getSchemaRegistry(HttpClientUtil.java:235)
 ~[solr-solrj-8.4.1.jar:8.4.1 832bf13dd9187095831caf69783179d41059d013 - ishan 
- 2020-01-10 13:40:30]
qeep-restapi.2020-03-23.log.xz: at 
org.apache.solr.client.solrj.impl.HttpClientUtil.createPoolingConnectionManager(HttpClientUtil.java:260)
 ~[solr-solrj-8.4.1.jar:8.4.1 832bf13dd9187095831caf69783179d41059d013 - ishan 
- 2020-01-10 13:40:30]
qeep-restapi.2020-03-23.log.xz: at 
org.apache.solr.client.solrj.impl.HttpClientUtil.createClient(HttpClientUtil.java:255)
 ~[solr-solrj-8.4.1.jar:8.4.1 832bf13dd9187095831caf69783179d41059d013 - ishan 
- 2020-01-10 13:40:30]
qeep-restapi.2020-03-23.log.xz: at 
org.apache.solr.client.solrj.impl.CloudSolrClient.<init>(CloudSolrClient.java:101)
 ~[solr-solrj-8.4.1.jar:8.4.1 832bf13dd9187095831caf69783179d41059d013 - ishan 
- 2020-01-10 13:40:30]
qeep-restapi.2020-03-23.log.xz: at 
org.apache.solr.client.solrj.impl.CloudSolrClient$Builder.build(CloudSolrClient.java:473)
 ~[solr-solrj-8.4.1.jar:8.4.1 832bf13dd9187095831caf69783179d41059d013 - ishan 
- 2020-01-10 13:40:30]

{code}


> solrj: using insecure namedCurves
> ---------------------------------
>
>                 Key: SOLR-14357
>                 URL: https://issues.apache.org/jira/browse/SOLR-14357
>             Project: Solr
>          Issue Type: Bug
>      Security Level: Public(Default Security Level. Issues are Public) 
>            Reporter: Bernd Wahlen
>            Priority: Major
>
> i tried to run our our backend with solrj 8.4.1 on jdk14 and get the 
> following error:
> Caused by: java.lang.IllegalArgumentException: Error in security property. 
> Constraint unknown: c2tnb191v1
> after i removed all the X9.62 algoriths from the property 
> jdk.disabled.namedCurves in
> /usr/lib/jvm/java-14-openjdk-14.0.0.36-1.rolling.el7.x86_64/conf/security/java.security
> everything is running.
> This does not happend on staging (i think because of only 1 solr node - not 
> using lb client).
> We do not set or change any ssl settings in solr.in.sh.
> I don't know how to fix that (default config?, apache client settings?), but 
> i think using insecure algorithms may be  a security risk and not only a 
> jdk14 issue.



--
This message was sent by Atlassian Jira
(v8.3.4#803005)

---------------------------------------------------------------------
To unsubscribe, e-mail: issues-unsubscr...@lucene.apache.org
For additional commands, e-mail: issues-h...@lucene.apache.org

Reply via email to