Oracle Commerce Guided Search - Steps to enable the SSL 3.0 and TLS 1.0 protocols for Platform Services (2024)

Steps to enable the SSL 3.0 and TLS 1.0 protocols for Platform Services

Steps to enable the SSL 3.0 protocol for Forge

Parallel Forge

Steps to enable the SSL 3.0 protocol for Log Server

Note

If you enable SSL 3.0 and TLS 1.0 -- for compatibility or any other reason -- you thereby make your application vulnerable to the serious threats against which TLSv1.1 and TLSv1.2 provide protection.

To enable the SSL 3.0 protocol, follow these steps:

  1. Openserver.xml at %ENDECA_TOOLS_ROOT%\server\workspace\conf.

  2. Change sslEnabledProtocols tosslEnabledProtocols="SSLv3.0" in the SSL connector.

    <Connector port="8443" SSLEnabled="true" protocol="org.apache.coyote.http11.Http11Protocol" maxPostSize="0" maxThreads="150" scheme="https" secure="true" clientAuth="true" sslEnabledProtocols="SSLv3" keystoreFile="cert.ks" keystorePass="eacpass" truststoreFile="ca.ks" truststorePass="eacpass" URIEncoding="UTF-8"
  3. Open java.security file in %ENDECA_TOOLS_ROOT%/server/j2sdk/jre/lib/security.

  4. Uncomment the jdk.tls.disabledAlgorithms property and disable all protocols except SSLv3: "jdk.tls.disabledAlgorithms=TLSv1, TLSv1.1,TLSv1.2".

  5. Restart the Tools and Frameworks server.

To enable the TLS 1.0 protocol, follow these steps:

  1. Openserver.xml at %ENDECA_TOOLS_ROOT%\server\workspace\conf.

  2. Change sslEnabledProtocols tosslEnabledProtocols="TLSv1" in the SSL connector.

    <Connector port="8443" SSLEnabled="true" protocol="org.apache.coyote.http11.Http11Protocol" maxPostSize="0" maxThreads="150" scheme="https" secure="true" clientAuth="true" sslEnabledProtocols="TLSv1" keystoreFile="cert.ks" keystorePass="eacpass" truststoreFile="ca.ks" truststorePass="eacpass" URIEncoding="UTF-8"
  3. Open java.security file in %ENDECA_TOOLS_ROOT%/server/j2sdk/jre/lib/security.

  4. Uncomment the jdk.tls.disabledAlgorithms property and disable all other protocols except TLSv1:

    jdk.tls.disabledAlgorithms=SSLv3, TLSv1.1, TLSv1.2
  5. Restart the Tools and Frameworks server.

Note

When the SSLv3 protocol is enabled for Forge, it must also be enabled for both Platform Services and Tools and Frameworks.

  1. Open DataIngest.xml file at APP_NAME/config/script.

  2. Pass extra argument "-sslv3" in "args" argument for Forge component.

    <forge id="Forge" host-id="ITLHost"> <properties> <property name="numStateBackups" value="10" /> <property name="numLogBackups" value="10" /> </properties> <directories> <directory name="incomingDataDir">./data/incoming</directory> <directory name="configDir">./config/pipeline</directory> <directory name="wsTempDir">./data/workbench/temp</directory> </directories> <args> <arg>-vw</arg> <arg>--sslv3</arg> </args> <log-dir>./logs/forges/Forge</log-dir> <input-dir>./data/processing</input-dir> <output-dir>./data/forge_output</output-dir> <state-dir>./data/state</state-dir> <temp-dir>./data/temp</temp-dir> <num-partitions>1</num-partitions> <pipeline-file>./data/processing/pipeline.epx</pipeline-file> <ssl-config bean="sslConfig" ref="globalSslConfig"/> <!-- <credentials-map>CREDENTIALS_MAP</credentials-map> <jps-config-path>JPSCONFIG_LOCATION</jps-config-path> <opss-jars-dir>OPSS_JARS_DIR</opss-jars-dir> --> </forge>
  3. Modify the "globalSslConfig" in APP_NAME/config/script/AppConfig.xml file to pass the ciphers that are supported for Forge when SSLv3 protocol is enabled.

  4. Verify that the warning message "SSLv3 is enabled" is logged in apps\APP_NAME\logs\forges\Forge\Forge.log.

Note

The following ciphers are supported for Forge when the SSLv3 protocol is enabled.

  • AES128-sha

  • RC4-md5

  • RC4-sha

To enable SSLv3 during Parallel Forge execution, add -sslv3 to the arguments while starting Forge as server and Forge as client.

Note

When the SSLv3 protocol is enabled for the Logserver, it must also be enabled for both Platform Services and Tools and Frameworks.

  1. Open the ReportGeneration.xml file in APP_NAME/config/script.

  2. Specify "-sslv3" in an <arg> element:.

    <logserver id="LogServer" host-id="ReportGenerationHost" port="15010"> <properties> <property name="numLogBackups" value="10" /> <property name="targetReportGenDir" value="./reports/input" /> <property name="targetReportGenHostId" value="ReportGenerationHost" /> </properties> <args> <arg> --sslv3 </arg> <args> <log-dir>./logs/logservers/LogServer</log-dir> <output-dir>./logs/logserver_output</output-dir> <startup-timeout>120</startup-timeout> <gzip>false</gzip></logserver>
  3. Modify the "globalSslConfig" in APP_NAME/config/script/AppConfig.xml file to pass the ciphers that are supported for Logserver when the SSLv3 protocol is enabled. These ciphers are:

    • AES128-sha

    • RC4-md5

    • RC4-sha

  4. A warning message "SSLv3 is enabled" is logged in apps/APPNAME/logs\Logserver\Logserver.log.

Copyright © Legal Notices

Oracle Commerce Guided Search - Steps to enable the SSL 3.0 and TLS 1.0 protocols for Platform Services (2024)
Top Articles
1981 Penny Error List & Value
Cognitive Bias in Zoo Animals: An Optimistic Outlook for Welfare Assessment
Knoxville Tennessee White Pages
Cold Air Intake - High-flow, Roto-mold Tube - TOYOTA TACOMA V6-4.0
Moon Stone Pokemon Heart Gold
Wizard Build Season 28
Readyset Ochsner.org
Apex Rank Leaderboard
Elden Ring Dex/Int Build
Skip The Games Norfolk Virginia
Oppenheimer & Co. Inc. Buys Shares of 798,472 AST SpaceMobile, Inc. (NASDAQ:ASTS)
Elizabethtown Mesothelioma Legal Question
Missing 2023 Showtimes Near Landmark Cinemas Peoria
Sony E 18-200mm F3.5-6.3 OSS LE Review
Gino Jennings Live Stream Today
Munich residents spend the most online for food
Tamilrockers Movies 2023 Download
Katherine Croan Ewald
Diamond Piers Menards
The Ultimate Style Guide To Casual Dress Code For Women
Site : Storagealamogordo.com Easy Call
Is Windbound Multiplayer
Filthy Rich Boys (Rich Boys Of Burberry Prep #1) - C.M. Stunich [PDF] | Online Book Share
Integer Division Matlab
Sandals Travel Agent Login
Horn Rank
Ltg Speech Copy Paste
Cognitive Science Cornell
Random Bibleizer
Craigslist Fort Smith Ar Personals
The Clapping Song Lyrics by Belle Stars
Poe T4 Aisling
R/Sandiego
Kempsville Recreation Center Pool Schedule
Beaver Saddle Ark
Log in or sign up to view
A Man Called Otto Showtimes Near Amc Muncie 12
Powerspec G512
The Minneapolis Journal from Minneapolis, Minnesota
Saybyebugs At Walmart
2007 Jaguar XK Low Miles for sale - Palm Desert, CA - craigslist
Miami Vice turns 40: A look back at the iconic series
Love Words Starting with P (With Definition)
Tlc Africa Deaths 2021
Youravon Com Mi Cuenta
Nope 123Movies Full
Kushfly Promo Code
Diario Las Americas Rentas Hialeah
Game Akin To Bingo Nyt
Marion City Wide Garage Sale 2023
Latest Posts
Article information

Author: Greg O'Connell

Last Updated:

Views: 5858

Rating: 4.1 / 5 (42 voted)

Reviews: 81% of readers found this page helpful

Author information

Name: Greg O'Connell

Birthday: 1992-01-10

Address: Suite 517 2436 Jefferey Pass, Shanitaside, UT 27519

Phone: +2614651609714

Job: Education Developer

Hobby: Cooking, Gambling, Pottery, Shooting, Baseball, Singing, Snowboarding

Introduction: My name is Greg O'Connell, I am a delightful, colorful, talented, kind, lively, modern, tender person who loves writing and wants to share my knowledge and understanding with you.