Adam, which conf directory, source or felix?  If Matterhorn is running
without a security configuration, that's a blocker, but based on Sean's
findings, I don't think you removed the right file.

Josh

On Fri, Feb 25, 2011 at 10:00 PM, Adam Hochman <[email protected]>wrote:

> fwiw, I removed the security.xml from the conf directory and was still able
> to access the UI and process a workflow successfully.
>
>
> On 2/25/11 8:59 AM, Josh Holtzman wrote:
>
>> Hi Sean,
>> Matterhorn requires that a security filter be registered with the
>> HttpService, which is what's running Jetty and handling HTTP requests.
>>  There's no security filter registered, so you get a "Requests are not
>> permitted" entry in the logs and the client gets a 401.  The idea here
>> is that it's better to deny access to the app entirely if there's a
>> problem finding the security configuration, rather than allowing full
>> access to everything.
>>
>> It looks like there's a problem with the JVM's crypto libraries:
>>
>> Caused by: java.lang.SecurityException: Cannot set up certs for trusted
>> CAs
>>         at javax.crypto.SunJCE_b.<clinit>(DashoA13*..)
>>         ... 27 more
>> Caused by: java.lang.SecurityException: Cannot locate policy or framework
>> files!
>>         at javax.crypto.SunJCE_b.i(DashoA13*..)
>>         at javax.crypto.SunJCE_b.g(DashoA13*..)
>>         at javax.crypto.SunJCE_b$1.run(DashoA13*..)
>>         at java.security.AccessController.doPrivileged(Native Method)
>>
>> I've never seen this problem with Matterhorn, so you may need to do
>> some research on this exception and play with the system to see what's
>> going on.  Please keep us posted!
>>
>> Thanks,
>> Josh
>>
>> On Fri, Feb 25, 2011 at 5:26 PM, Sean Hennessee<[email protected]>  wrote:
>>
>>> Can anyone help me with this issue? I'm new to Matterhorn and not that
>>> familiar with Java, but I do have a fair amount of experience with Linux
>>> and
>>> other server programs.
>>>
>>> We're basically only testing the administrative video upload feature and
>>> not
>>> the automatic recording of a classroom. We already have classroom
>>> recording
>>> implemented using other tools.
>>>
>>> I had Matterhorn running and working until recently when it crashed back
>>> to
>>> a linux prompt. Now when I start it, I get these error messages at the
>>> console and all of the web pages present a
>>> "HTTP ERROR 401 Problem accessing /. Reason: UNAUTHORIZED Powered by
>>> Jetty://"
>>>
>>> A full ./bin/start.sh startup console log and opencast.log can be seen
>>> here
>>> until Mar 25, 2011:
>>> http://pastebin.com/tE7xHgDB
>>>
>>> 08:02:03  INFO (RestPublisher:90) - Registered REST endpoint at
>>> /ingest/rest
>>> 08:02:12  WARN (SharedHttpContext:92) - Requests are not permitted
>>> without a
>>> registered matterhorn security filter.
>>> 08:02:12  WARN (TrustedHttpClientImpl:217) - URI
>>>
>>> http://matterhorn1.es.uci.edu:8080/capture-admin/rest/agents/demo_capture_agent
>>> does not support digest authentication
>>> 08:02:12  WARN (SharedHttpContext:92) - Requests are not permitted
>>> without a
>>> registered matterhorn security filter.
>>> 08:02:12  INFO (AgentStateJob:166) - State push to
>>>
>>> http://matterhorn1.es.uci.edu:8080/capture-admin/rest/agents/demo_capture_agent
>>> failed with code 401.
>>> 08:02:12  WARN (SharedHttpContext:92) - Requests are not permitted
>>> without a
>>> registered matterhorn security filter.
>>> 08:02:12  WARN (TrustedHttpClientImpl:217) - URI
>>>
>>> http://matterhorn1.es.uci.edu:8080/capture-admin/rest/agents/demo_capture_agent/capabilities
>>> does not support digest authentication
>>> 08:02:12  WARN (SharedHttpContext:92) - Requests are not permitted
>>> without a
>>> registered matterhorn security filter.
>>> 08:02:12  INFO (AgentCapabilitiesJob:95) - Capabilities push to
>>>
>>> http://matterhorn1.es.uci.edu:8080/capture-admin/rest/agents/demo_capture_agent/capabilities
>>> failed with code 401.
>>> 08:02:22  WARN (SharedHttpContext:92) - Requests are not permitted
>>> without a
>>> registered matterhorn security filter.
>>> 08:02:22  WARN (TrustedHttpClientImpl:217) - URI
>>>
>>> http://matterhorn1.es.uci.edu:8080/capture-admin/rest/agents/demo_capture_agent
>>> does not support digest authentication
>>> 08:02:22  WARN (SharedHttpContext:92) - Requests are not permitted
>>> without a
>>> registered matterhorn security filter.
>>> 08:02:22  INFO (AgentStateJob:166) - State push to
>>>
>>> http://matterhorn1.es.uci.edu:8080/capture-admin/rest/agents/demo_capture_agent
>>> failed with code 401.
>>> 08:02:22  WARN (SharedHttpContext:92) - Requests are not permitted
>>> without a
>>> registered matterhorn security filter.
>>> 08:02:22  WARN (TrustedHttpClientImpl:217) - URI
>>>
>>> http://matterhorn1.es.uci.edu:8080/capture-admin/rest/agents/demo_capture_agent/capabilities
>>> does not support digest authentication
>>> 08:02:22  WARN (SharedHttpContext:92) - Requests are not permitted
>>> without a
>>> registered matterhorn security filter.
>>> 08:02:22  INFO (AgentCapabilitiesJob:95) - Capabilities push to
>>>
>>> http://matterhorn1.es.uci.edu:8080/capture-admin/rest/agents/demo_capture_agent/capabilities
>>> failed with code 401.
>>>
>>> Here is my config file:
>>> org.osgi.service.http.port=8080
>>> org.osgi.service.http.secure.enabled=false
>>> org.ops4j.pax.web.session.timeout = 30
>>> org.opencastproject.server.url=http://matterhorn1.es.uci.edu:8080
>>> org.opencastproject.admin.ui.url=http://matterhorn1.es.uci.edu:8080
>>> org.opencastproject.engage.ui.url=http://matterhorn1.es.uci.edu:8080
>>> org.opencastproject.storage.dir=/opt/matterhorn/felix/opencast
>>>
>>> org.opencastproject.security.config=/opt/matterhorn/felix/conf/security.xml
>>> org.opencastproject.security.digest.user=matterhorn_system_account
>>> org.opencastproject.security.digest.pass=CHANGE_ME
>>>
>>> org.opencastproject.download.directory=${org.opencastproject.storage.dir}/downloads
>>> ddl-generation=true
>>> inbox.threads = 1
>>> composer.threads = 1
>>> videosegmenter.threads = 1
>>> textanalyzer.threads = 1
>>>
>>> org.opencastproject.file.repo.path=${org.opencastproject.storage.dir}/files
>>> org.opencastproject.workspace.rootdir =
>>> ${org.opencastproject.storage.dir}/workspace
>>> org.opencastproject.workflow.default.definition = full
>>> archive.threads = 1
>>> felix.auto.deploy.action=install,start,update
>>> felix.auto.start.1= \
>>>  file:lib/org.osgi.compendium-4.2.0.jar \
>>>  file:lib/org.apache.felix.configadmin-1.2.4.jar \
>>>  file:lib/pax-confman-propsloader-0.2.1.jar \
>>>  file:lib/pax-logging-api-1.5.0.jar \
>>>  file:lib/pax-logging-service-1.5.0.jar \
>>>  file:lib/org.apache.felix.scr-1.4.0.jar \
>>>  file:lib/org.apache.felix.eventadmin-1.2.2.jar \
>>>  file:lib/org.apache.felix.fileinstall-3.0.0.jar \
>>>  file:lib/org.apache.felix.metatype-1.0.4.jar \
>>> felix.auto.start.2= \
>>>  file:lib/geronimo-annotation_1.0_spec-1.1.1.jar \
>>>  file:lib/geronimo-activation_1.1_spec-1.1.jar \
>>>  file:lib/geronimo-jpa_2.0_spec-1.1.jar \
>>>  file:lib/geronimo-jta_1.1_spec-1.1.1.jar \
>>>  file:lib/geronimo-javamail_1.4_spec-1.7.1.jar \
>>>  file:lib/geronimo-ws-metadata_2.0_spec-1.1.2.jar \
>>>  file:lib/geronimo-j2ee-connector_1.5_spec-2.0.0.jar \
>>>  file:lib/geronimo-j2ee-management_1.1_spec-1.0.1.jar \
>>>  file:lib/org.apache.servicemix.specs.jaxb-api-2.1-1.3.0.jar \
>>>  file:lib/org.apache.servicemix.specs.jaxws-api-2.1-1.3.0.jar \
>>>  file:lib/org.apache.servicemix.specs.saaj-api-1.3-1.3.0.jar \
>>>  file:lib/org.apache.servicemix.specs.stax-api-1.0-1.3.0.jar \
>>>  file:lib/org.apache.servicemix.specs.jsr311-api-1.1-1.5.0.jar \
>>> felix.auto.start.3= \
>>>  file:lib/commons-fileupload-1.2.1.jar \
>>>  file:lib/commons-io-1.4.jar \
>>>  file:lib/commons-lang-2.4.jar \
>>>  file:lib/commons-codec-1.4.jar \
>>>  file:lib/commons-pool-1.5.3.jar \
>>>  file:lib/commons-collections-3.2.1.jar \
>>>  file:lib/joda-time-1.6.jar \
>>>  file:lib/jettison-1.1.jar \
>>>  file:lib/org.apache.servicemix.bundles.jaxb-impl-2.1.6_1.jar \
>>>  file:lib/org.apache.servicemix.bundles.quartz-1.6.6_1.jar \
>>>  file:lib/org.apache.servicemix.bundles.woodstox-3.2.7_1.jar \
>>>  file:lib/org.apache.servicemix.bundles.wsdl4j-1.6.1_1.jar \
>>>  file:lib/org.apache.servicemix.bundles.neethi-2.0.4_1.jar \
>>>  file:lib/org.apache.servicemix.bundles.xmlschema-1.4.3_1.jar \
>>>  file:lib/org.apache.servicemix.bundles.xmlresolver-1.2_1.jar \
>>>  file:lib/org.apache.servicemix.bundles.commons-httpclient-3.1_4.jar \
>>>  file:lib/org.apache.servicemix.bundles.asm-2.2.3_1.jar \
>>>  file:lib/com.springsource.org.apache.commons.beanutils-1.7.0.jar \
>>>  file:lib/com.springsource.org.apache.lucene-2.4.1.jar \
>>>  file:lib/tika-bundle-0.7.jar \
>>>  file:lib/org.eclipse.persistence.core-2.0.2.jar \
>>>  file:lib/org.eclipse.persistence.jpa-2.0.2.jar \
>>>  file:lib/org.eclipse.persistence.asm-2.0.2.jar \
>>>  file:lib/org.eclipse.persistence.antlr-2.0.2.jar \
>>>  file:lib/com.springsource.org.aopalliance-1.0.0.jar \
>>>  file:lib/org.springframework.osgi.io-1.2.1.jar \
>>>  file:lib/org.springframework.osgi.core-1.2.1.jar \
>>>  file:lib/org.springframework.osgi.extender-1.2.1.jar \
>>>  file:lib/com.springsource.org.openid4java-0.9.5.jar  \
>>>  file:lib/com.springsource.org.cyberneko.html-1.9.13.jar \
>>>  file:lib/org.springframework.asm-3.0.2.RELEASE.jar \
>>>  file:lib/org.springframework.web-3.0.2.RELEASE.jar \
>>>  file:lib/org.springframework.aop-3.0.2.RELEASE.jar \
>>>  file:lib/org.springframework.core-3.0.2.RELEASE.jar \
>>>  file:lib/org.springframework.beans-3.0.2.RELEASE.jar \
>>>  file:lib/org.springframework.expression-3.0.2.RELEASE.jar \
>>>  file:lib/org.springframework.transaction-3.0.2.RELEASE.jar \
>>>  file:lib/org.springframework.context-3.0.2.RELEASE.jar \
>>>  file:lib/org.springframework.context.support-3.0.2.RELEASE.jar \
>>>  file:lib/org.springframework.security.core-3.0.2.RELEASE.jar \
>>>  file:lib/org.springframework.security.config-3.0.2.RELEASE.jar \
>>>  file:lib/org.springframework.security.web-3.0.2.RELEASE.jar \
>>>  file:lib/org.springframework.security.openid-3.0.2.RELEASE.jar \
>>>  file:lib/spring-security-cas-client-3.0.2.RELEASE.jar \
>>>  file:lib/com.springsource.org.jasig.cas.client-3.1.8.jar \
>>>  file:lib/com.springsource.org.opensaml-1.1.0.jar \
>>>  file:lib/com.springsource.org.jdom-1.0.0.jar \
>>>  file:lib/com.springsource.org.ognl-2.7.3.jar \
>>>  file:lib/com.springsource.javassist-3.9.0.GA.jar \
>>>  file:lib/httpcore-osgi-4.0.1.jar \
>>>  file:lib/httpclient-osgi-4.0.1.jar \
>>>  file:lib/cxf-bundle-minimal-2.2.9.jar \
>>>  file:lib/org.apache.servicemix.bundles.xmlsec-1.3.0_1.jar \
>>>  file:lib/org.apache.servicemix.bundles.wss4j-1.5.4_1.jar \
>>>  file:lib/org.apache.servicemix.bundles.xerces-2.9.1_3.jar \
>>> felix.auto.start.4= \
>>>  file:lib/pax-web-jetty-bundle-0.7.2.jar \
>>> org.osgi.framework.startlevel.beginning=5
>>> felix.startlevel.bundle=5
>>> felix.log.level=1
>>> obr.repository.url=http://felix.apache.org/obr/releases.xml
>>> testMode=true
>>>
>>>
>>> Peace,
>>> Sean
>>> --
>>>
>>> Sean Hennessee
>>> Central Computing Support
>>> Office of Information Technology
>>> UC Irvine
>>>
>>> ... . .- -. /  .... . -. -. . ... ... . .
>>> _______________________________________________
>>> Matterhorn mailing list
>>> [email protected]
>>> http://lists.opencastproject.org/mailman/listinfo/matterhorn
>>>
>>>
>>> To unsubscribe please email
>>> [email protected]
>>> _______________________________________________
>>>
>>>  _______________________________________________
>> Matterhorn mailing list
>> [email protected]
>> http://lists.opencastproject.org/mailman/listinfo/matterhorn
>>
>>
>> To unsubscribe please email
>> [email protected]
>> _______________________________________________
>>
> _______________________________________________
> Matterhorn mailing list
> [email protected]
> http://lists.opencastproject.org/mailman/listinfo/matterhorn
>
>
> To unsubscribe please email
> [email protected]
> _______________________________________________
>
_______________________________________________
Matterhorn mailing list
[email protected]
http://lists.opencastproject.org/mailman/listinfo/matterhorn


To unsubscribe please email
[email protected]
_______________________________________________

Reply via email to