[ 
https://issues.apache.org/jira/browse/SOLR-14357?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=17100542#comment-17100542
 ] 

Bernd Wahlen edited comment on SOLR-14357 at 5/11/20, 8:56 AM:
---------------------------------------------------------------

Update:
after i updated to AdoptOpenJDK (build 14.0.1+7) and my patched java.security 
file was overwritten with the jdk default accidentally, it still works without 
the error above. But i updated some other things in the meantime (mainly centos 
7.7->7.8 and solrj to 8.5.1). I will try to investigate how to reproduce later.

I think negotiation of algorithm fails only in specific jvm/solrj combinations.

not working:  server: jdk 11.0.6+solr 8.4.1, client jdk 14.0.0+solrj 8.4.1
working: server jdk 11.0.7+solr8.4.1, client jdk: 14.0.1+solrj8.5.1
working: server: jdk11.0.7+solr8.5.1, client jdk 14.0.1+solrj 8.5.1
working: server jdk 14.0.1+solr8.5.1, client jdk 14.0.1+solrj 8.5.1

I think not relevant anymore, because with the latest version of each jdk and 
the latest solrj Problem did not occur anymore.


was (Author: bwahlen):
Update:
after i updated to AdoptOpenJDK (build 14.0.1+7) and my patched java.security 
file was overwritten with the jdk default accidentally, it still works without 
the error above. But i updated some other things in the meantime (mainly centos 
7.7->7.8 and solrj to 8.5.1). I will try to investigate how to reproduce later.

I think negotiation of algorithm fails only in specific jvm/solrj combinations.

not working:  server: jdk 11.0.6+solr 8.4.1, client jdk 14.0.0+solrj 8.4.1
working: server jdk 11.0.7+solr8.4.1, client jdk: 14.0.1+solrj8.5.1
working: server: jdk11.0.7+solr8.5.1, client jdk 14.0.1+solrj 8.5.1
working: server jdk 14.0.1+solr8.5.1, client jdk 14.0.1+solrj 8.5.1


> solrj: using insecure namedCurves
> ---------------------------------
>
>                 Key: SOLR-14357
>                 URL: https://issues.apache.org/jira/browse/SOLR-14357
>             Project: Solr
>          Issue Type: Bug
>      Security Level: Public(Default Security Level. Issues are Public) 
>            Reporter: Bernd Wahlen
>            Priority: Major
>
> i tried to run our our backend with solrj 8.4.1 on jdk14 and get the 
> following error:
> Caused by: java.lang.IllegalArgumentException: Error in security property. 
> Constraint unknown: c2tnb191v1
> after i removed all the X9.62 algoriths from the property 
> jdk.disabled.namedCurves in
> /usr/lib/jvm/java-14-openjdk-14.0.0.36-1.rolling.el7.x86_64/conf/security/java.security
> everything is running.
> This does not happend on staging (i think because of only 1 solr node - not 
> using lb client).
> We do not set or change any ssl settings in solr.in.sh.
> I don't know how to fix that (default config?, apache client settings?), but 
> i think using insecure algorithms may be  a security risk and not only a 
> jdk14 issue.



--
This message was sent by Atlassian Jira
(v8.3.4#803005)

---------------------------------------------------------------------
To unsubscribe, e-mail: issues-unsubscr...@lucene.apache.org
For additional commands, e-mail: issues-h...@lucene.apache.org

Reply via email to