Adam, which conf directory, source or felix? If Matterhorn is running without a security configuration, that's a blocker, but based on Sean's findings, I don't think you removed the right file.
Josh On Fri, Feb 25, 2011 at 10:00 PM, Adam Hochman <[email protected]>wrote: > fwiw, I removed the security.xml from the conf directory and was still able > to access the UI and process a workflow successfully. > > > On 2/25/11 8:59 AM, Josh Holtzman wrote: > >> Hi Sean, >> Matterhorn requires that a security filter be registered with the >> HttpService, which is what's running Jetty and handling HTTP requests. >> There's no security filter registered, so you get a "Requests are not >> permitted" entry in the logs and the client gets a 401. The idea here >> is that it's better to deny access to the app entirely if there's a >> problem finding the security configuration, rather than allowing full >> access to everything. >> >> It looks like there's a problem with the JVM's crypto libraries: >> >> Caused by: java.lang.SecurityException: Cannot set up certs for trusted >> CAs >> at javax.crypto.SunJCE_b.<clinit>(DashoA13*..) >> ... 27 more >> Caused by: java.lang.SecurityException: Cannot locate policy or framework >> files! >> at javax.crypto.SunJCE_b.i(DashoA13*..) >> at javax.crypto.SunJCE_b.g(DashoA13*..) >> at javax.crypto.SunJCE_b$1.run(DashoA13*..) >> at java.security.AccessController.doPrivileged(Native Method) >> >> I've never seen this problem with Matterhorn, so you may need to do >> some research on this exception and play with the system to see what's >> going on. Please keep us posted! >> >> Thanks, >> Josh >> >> On Fri, Feb 25, 2011 at 5:26 PM, Sean Hennessee<[email protected]> wrote: >> >>> Can anyone help me with this issue? I'm new to Matterhorn and not that >>> familiar with Java, but I do have a fair amount of experience with Linux >>> and >>> other server programs. >>> >>> We're basically only testing the administrative video upload feature and >>> not >>> the automatic recording of a classroom. We already have classroom >>> recording >>> implemented using other tools. >>> >>> I had Matterhorn running and working until recently when it crashed back >>> to >>> a linux prompt. Now when I start it, I get these error messages at the >>> console and all of the web pages present a >>> "HTTP ERROR 401 Problem accessing /. Reason: UNAUTHORIZED Powered by >>> Jetty://" >>> >>> A full ./bin/start.sh startup console log and opencast.log can be seen >>> here >>> until Mar 25, 2011: >>> http://pastebin.com/tE7xHgDB >>> >>> 08:02:03 INFO (RestPublisher:90) - Registered REST endpoint at >>> /ingest/rest >>> 08:02:12 WARN (SharedHttpContext:92) - Requests are not permitted >>> without a >>> registered matterhorn security filter. >>> 08:02:12 WARN (TrustedHttpClientImpl:217) - URI >>> >>> http://matterhorn1.es.uci.edu:8080/capture-admin/rest/agents/demo_capture_agent >>> does not support digest authentication >>> 08:02:12 WARN (SharedHttpContext:92) - Requests are not permitted >>> without a >>> registered matterhorn security filter. >>> 08:02:12 INFO (AgentStateJob:166) - State push to >>> >>> http://matterhorn1.es.uci.edu:8080/capture-admin/rest/agents/demo_capture_agent >>> failed with code 401. >>> 08:02:12 WARN (SharedHttpContext:92) - Requests are not permitted >>> without a >>> registered matterhorn security filter. >>> 08:02:12 WARN (TrustedHttpClientImpl:217) - URI >>> >>> http://matterhorn1.es.uci.edu:8080/capture-admin/rest/agents/demo_capture_agent/capabilities >>> does not support digest authentication >>> 08:02:12 WARN (SharedHttpContext:92) - Requests are not permitted >>> without a >>> registered matterhorn security filter. >>> 08:02:12 INFO (AgentCapabilitiesJob:95) - Capabilities push to >>> >>> http://matterhorn1.es.uci.edu:8080/capture-admin/rest/agents/demo_capture_agent/capabilities >>> failed with code 401. >>> 08:02:22 WARN (SharedHttpContext:92) - Requests are not permitted >>> without a >>> registered matterhorn security filter. >>> 08:02:22 WARN (TrustedHttpClientImpl:217) - URI >>> >>> http://matterhorn1.es.uci.edu:8080/capture-admin/rest/agents/demo_capture_agent >>> does not support digest authentication >>> 08:02:22 WARN (SharedHttpContext:92) - Requests are not permitted >>> without a >>> registered matterhorn security filter. >>> 08:02:22 INFO (AgentStateJob:166) - State push to >>> >>> http://matterhorn1.es.uci.edu:8080/capture-admin/rest/agents/demo_capture_agent >>> failed with code 401. >>> 08:02:22 WARN (SharedHttpContext:92) - Requests are not permitted >>> without a >>> registered matterhorn security filter. >>> 08:02:22 WARN (TrustedHttpClientImpl:217) - URI >>> >>> http://matterhorn1.es.uci.edu:8080/capture-admin/rest/agents/demo_capture_agent/capabilities >>> does not support digest authentication >>> 08:02:22 WARN (SharedHttpContext:92) - Requests are not permitted >>> without a >>> registered matterhorn security filter. >>> 08:02:22 INFO (AgentCapabilitiesJob:95) - Capabilities push to >>> >>> http://matterhorn1.es.uci.edu:8080/capture-admin/rest/agents/demo_capture_agent/capabilities >>> failed with code 401. >>> >>> Here is my config file: >>> org.osgi.service.http.port=8080 >>> org.osgi.service.http.secure.enabled=false >>> org.ops4j.pax.web.session.timeout = 30 >>> org.opencastproject.server.url=http://matterhorn1.es.uci.edu:8080 >>> org.opencastproject.admin.ui.url=http://matterhorn1.es.uci.edu:8080 >>> org.opencastproject.engage.ui.url=http://matterhorn1.es.uci.edu:8080 >>> org.opencastproject.storage.dir=/opt/matterhorn/felix/opencast >>> >>> org.opencastproject.security.config=/opt/matterhorn/felix/conf/security.xml >>> org.opencastproject.security.digest.user=matterhorn_system_account >>> org.opencastproject.security.digest.pass=CHANGE_ME >>> >>> org.opencastproject.download.directory=${org.opencastproject.storage.dir}/downloads >>> ddl-generation=true >>> inbox.threads = 1 >>> composer.threads = 1 >>> videosegmenter.threads = 1 >>> textanalyzer.threads = 1 >>> >>> org.opencastproject.file.repo.path=${org.opencastproject.storage.dir}/files >>> org.opencastproject.workspace.rootdir = >>> ${org.opencastproject.storage.dir}/workspace >>> org.opencastproject.workflow.default.definition = full >>> archive.threads = 1 >>> felix.auto.deploy.action=install,start,update >>> felix.auto.start.1= \ >>> file:lib/org.osgi.compendium-4.2.0.jar \ >>> file:lib/org.apache.felix.configadmin-1.2.4.jar \ >>> file:lib/pax-confman-propsloader-0.2.1.jar \ >>> file:lib/pax-logging-api-1.5.0.jar \ >>> file:lib/pax-logging-service-1.5.0.jar \ >>> file:lib/org.apache.felix.scr-1.4.0.jar \ >>> file:lib/org.apache.felix.eventadmin-1.2.2.jar \ >>> file:lib/org.apache.felix.fileinstall-3.0.0.jar \ >>> file:lib/org.apache.felix.metatype-1.0.4.jar \ >>> felix.auto.start.2= \ >>> file:lib/geronimo-annotation_1.0_spec-1.1.1.jar \ >>> file:lib/geronimo-activation_1.1_spec-1.1.jar \ >>> file:lib/geronimo-jpa_2.0_spec-1.1.jar \ >>> file:lib/geronimo-jta_1.1_spec-1.1.1.jar \ >>> file:lib/geronimo-javamail_1.4_spec-1.7.1.jar \ >>> file:lib/geronimo-ws-metadata_2.0_spec-1.1.2.jar \ >>> file:lib/geronimo-j2ee-connector_1.5_spec-2.0.0.jar \ >>> file:lib/geronimo-j2ee-management_1.1_spec-1.0.1.jar \ >>> file:lib/org.apache.servicemix.specs.jaxb-api-2.1-1.3.0.jar \ >>> file:lib/org.apache.servicemix.specs.jaxws-api-2.1-1.3.0.jar \ >>> file:lib/org.apache.servicemix.specs.saaj-api-1.3-1.3.0.jar \ >>> file:lib/org.apache.servicemix.specs.stax-api-1.0-1.3.0.jar \ >>> file:lib/org.apache.servicemix.specs.jsr311-api-1.1-1.5.0.jar \ >>> felix.auto.start.3= \ >>> file:lib/commons-fileupload-1.2.1.jar \ >>> file:lib/commons-io-1.4.jar \ >>> file:lib/commons-lang-2.4.jar \ >>> file:lib/commons-codec-1.4.jar \ >>> file:lib/commons-pool-1.5.3.jar \ >>> file:lib/commons-collections-3.2.1.jar \ >>> file:lib/joda-time-1.6.jar \ >>> file:lib/jettison-1.1.jar \ >>> file:lib/org.apache.servicemix.bundles.jaxb-impl-2.1.6_1.jar \ >>> file:lib/org.apache.servicemix.bundles.quartz-1.6.6_1.jar \ >>> file:lib/org.apache.servicemix.bundles.woodstox-3.2.7_1.jar \ >>> file:lib/org.apache.servicemix.bundles.wsdl4j-1.6.1_1.jar \ >>> file:lib/org.apache.servicemix.bundles.neethi-2.0.4_1.jar \ >>> file:lib/org.apache.servicemix.bundles.xmlschema-1.4.3_1.jar \ >>> file:lib/org.apache.servicemix.bundles.xmlresolver-1.2_1.jar \ >>> file:lib/org.apache.servicemix.bundles.commons-httpclient-3.1_4.jar \ >>> file:lib/org.apache.servicemix.bundles.asm-2.2.3_1.jar \ >>> file:lib/com.springsource.org.apache.commons.beanutils-1.7.0.jar \ >>> file:lib/com.springsource.org.apache.lucene-2.4.1.jar \ >>> file:lib/tika-bundle-0.7.jar \ >>> file:lib/org.eclipse.persistence.core-2.0.2.jar \ >>> file:lib/org.eclipse.persistence.jpa-2.0.2.jar \ >>> file:lib/org.eclipse.persistence.asm-2.0.2.jar \ >>> file:lib/org.eclipse.persistence.antlr-2.0.2.jar \ >>> file:lib/com.springsource.org.aopalliance-1.0.0.jar \ >>> file:lib/org.springframework.osgi.io-1.2.1.jar \ >>> file:lib/org.springframework.osgi.core-1.2.1.jar \ >>> file:lib/org.springframework.osgi.extender-1.2.1.jar \ >>> file:lib/com.springsource.org.openid4java-0.9.5.jar \ >>> file:lib/com.springsource.org.cyberneko.html-1.9.13.jar \ >>> file:lib/org.springframework.asm-3.0.2.RELEASE.jar \ >>> file:lib/org.springframework.web-3.0.2.RELEASE.jar \ >>> file:lib/org.springframework.aop-3.0.2.RELEASE.jar \ >>> file:lib/org.springframework.core-3.0.2.RELEASE.jar \ >>> file:lib/org.springframework.beans-3.0.2.RELEASE.jar \ >>> file:lib/org.springframework.expression-3.0.2.RELEASE.jar \ >>> file:lib/org.springframework.transaction-3.0.2.RELEASE.jar \ >>> file:lib/org.springframework.context-3.0.2.RELEASE.jar \ >>> file:lib/org.springframework.context.support-3.0.2.RELEASE.jar \ >>> file:lib/org.springframework.security.core-3.0.2.RELEASE.jar \ >>> file:lib/org.springframework.security.config-3.0.2.RELEASE.jar \ >>> file:lib/org.springframework.security.web-3.0.2.RELEASE.jar \ >>> file:lib/org.springframework.security.openid-3.0.2.RELEASE.jar \ >>> file:lib/spring-security-cas-client-3.0.2.RELEASE.jar \ >>> file:lib/com.springsource.org.jasig.cas.client-3.1.8.jar \ >>> file:lib/com.springsource.org.opensaml-1.1.0.jar \ >>> file:lib/com.springsource.org.jdom-1.0.0.jar \ >>> file:lib/com.springsource.org.ognl-2.7.3.jar \ >>> file:lib/com.springsource.javassist-3.9.0.GA.jar \ >>> file:lib/httpcore-osgi-4.0.1.jar \ >>> file:lib/httpclient-osgi-4.0.1.jar \ >>> file:lib/cxf-bundle-minimal-2.2.9.jar \ >>> file:lib/org.apache.servicemix.bundles.xmlsec-1.3.0_1.jar \ >>> file:lib/org.apache.servicemix.bundles.wss4j-1.5.4_1.jar \ >>> file:lib/org.apache.servicemix.bundles.xerces-2.9.1_3.jar \ >>> felix.auto.start.4= \ >>> file:lib/pax-web-jetty-bundle-0.7.2.jar \ >>> org.osgi.framework.startlevel.beginning=5 >>> felix.startlevel.bundle=5 >>> felix.log.level=1 >>> obr.repository.url=http://felix.apache.org/obr/releases.xml >>> testMode=true >>> >>> >>> Peace, >>> Sean >>> -- >>> >>> Sean Hennessee >>> Central Computing Support >>> Office of Information Technology >>> UC Irvine >>> >>> ... . .- -. / .... . -. -. . ... ... . . >>> _______________________________________________ >>> Matterhorn mailing list >>> [email protected] >>> http://lists.opencastproject.org/mailman/listinfo/matterhorn >>> >>> >>> To unsubscribe please email >>> [email protected] >>> _______________________________________________ >>> >>> _______________________________________________ >> Matterhorn mailing list >> [email protected] >> http://lists.opencastproject.org/mailman/listinfo/matterhorn >> >> >> To unsubscribe please email >> [email protected] >> _______________________________________________ >> > _______________________________________________ > Matterhorn mailing list > [email protected] > http://lists.opencastproject.org/mailman/listinfo/matterhorn > > > To unsubscribe please email > [email protected] > _______________________________________________ >
_______________________________________________ Matterhorn mailing list [email protected] http://lists.opencastproject.org/mailman/listinfo/matterhorn To unsubscribe please email [email protected] _______________________________________________
