Oracle Commerce Guided Search - Steps to enable the SSL 3.0 and TLS 1.0 protocols for Platform Services (2024)

Steps to enable the SSL 3.0 and TLS 1.0 protocols for Platform Services

Steps to enable the SSL 3.0 protocol for Forge

Parallel Forge

Steps to enable the SSL 3.0 protocol for Log Server

Note

If you enable SSL 3.0 and TLS 1.0 -- for compatibility or any other reason -- you thereby make your application vulnerable to the serious threats against which TLSv1.1 and TLSv1.2 provide protection.

To enable the SSL 3.0 protocol, follow these steps:

  1. Openserver.xml at %ENDECA_TOOLS_ROOT%\server\workspace\conf.

  2. Change sslEnabledProtocols tosslEnabledProtocols="SSLv3.0" in the SSL connector.

    <Connector port="8443" SSLEnabled="true" protocol="org.apache.coyote.http11.Http11Protocol" maxPostSize="0" maxThreads="150" scheme="https" secure="true" clientAuth="true" sslEnabledProtocols="SSLv3" keystoreFile="cert.ks" keystorePass="eacpass" truststoreFile="ca.ks" truststorePass="eacpass" URIEncoding="UTF-8"
  3. Open java.security file in %ENDECA_TOOLS_ROOT%/server/j2sdk/jre/lib/security.

  4. Uncomment the jdk.tls.disabledAlgorithms property and disable all protocols except SSLv3: "jdk.tls.disabledAlgorithms=TLSv1, TLSv1.1,TLSv1.2".

  5. Restart the Tools and Frameworks server.

To enable the TLS 1.0 protocol, follow these steps:

  1. Openserver.xml at %ENDECA_TOOLS_ROOT%\server\workspace\conf.

  2. Change sslEnabledProtocols tosslEnabledProtocols="TLSv1" in the SSL connector.

    <Connector port="8443" SSLEnabled="true" protocol="org.apache.coyote.http11.Http11Protocol" maxPostSize="0" maxThreads="150" scheme="https" secure="true" clientAuth="true" sslEnabledProtocols="TLSv1" keystoreFile="cert.ks" keystorePass="eacpass" truststoreFile="ca.ks" truststorePass="eacpass" URIEncoding="UTF-8"
  3. Open java.security file in %ENDECA_TOOLS_ROOT%/server/j2sdk/jre/lib/security.

  4. Uncomment the jdk.tls.disabledAlgorithms property and disable all other protocols except TLSv1:

    jdk.tls.disabledAlgorithms=SSLv3, TLSv1.1, TLSv1.2
  5. Restart the Tools and Frameworks server.

Note

When the SSLv3 protocol is enabled for Forge, it must also be enabled for both Platform Services and Tools and Frameworks.

  1. Open DataIngest.xml file at APP_NAME/config/script.

  2. Pass extra argument "-sslv3" in "args" argument for Forge component.

    <forge id="Forge" host-id="ITLHost"> <properties> <property name="numStateBackups" value="10" /> <property name="numLogBackups" value="10" /> </properties> <directories> <directory name="incomingDataDir">./data/incoming</directory> <directory name="configDir">./config/pipeline</directory> <directory name="wsTempDir">./data/workbench/temp</directory> </directories> <args> <arg>-vw</arg> <arg>--sslv3</arg> </args> <log-dir>./logs/forges/Forge</log-dir> <input-dir>./data/processing</input-dir> <output-dir>./data/forge_output</output-dir> <state-dir>./data/state</state-dir> <temp-dir>./data/temp</temp-dir> <num-partitions>1</num-partitions> <pipeline-file>./data/processing/pipeline.epx</pipeline-file> <ssl-config bean="sslConfig" ref="globalSslConfig"/> <!-- <credentials-map>CREDENTIALS_MAP</credentials-map> <jps-config-path>JPSCONFIG_LOCATION</jps-config-path> <opss-jars-dir>OPSS_JARS_DIR</opss-jars-dir> --> </forge>
  3. Modify the "globalSslConfig" in APP_NAME/config/script/AppConfig.xml file to pass the ciphers that are supported for Forge when SSLv3 protocol is enabled.

  4. Verify that the warning message "SSLv3 is enabled" is logged in apps\APP_NAME\logs\forges\Forge\Forge.log.

Note

The following ciphers are supported for Forge when the SSLv3 protocol is enabled.

  • AES128-sha

  • RC4-md5

  • RC4-sha

To enable SSLv3 during Parallel Forge execution, add -sslv3 to the arguments while starting Forge as server and Forge as client.

Note

When the SSLv3 protocol is enabled for the Logserver, it must also be enabled for both Platform Services and Tools and Frameworks.

  1. Open the ReportGeneration.xml file in APP_NAME/config/script.

  2. Specify "-sslv3" in an <arg> element:.

    <logserver id="LogServer" host-id="ReportGenerationHost" port="15010"> <properties> <property name="numLogBackups" value="10" /> <property name="targetReportGenDir" value="./reports/input" /> <property name="targetReportGenHostId" value="ReportGenerationHost" /> </properties> <args> <arg> --sslv3 </arg> <args> <log-dir>./logs/logservers/LogServer</log-dir> <output-dir>./logs/logserver_output</output-dir> <startup-timeout>120</startup-timeout> <gzip>false</gzip></logserver>
  3. Modify the "globalSslConfig" in APP_NAME/config/script/AppConfig.xml file to pass the ciphers that are supported for Logserver when the SSLv3 protocol is enabled. These ciphers are:

    • AES128-sha

    • RC4-md5

    • RC4-sha

  4. A warning message "SSLv3 is enabled" is logged in apps/APPNAME/logs\Logserver\Logserver.log.

Copyright © Legal Notices

Oracle Commerce Guided Search - Steps to enable the SSL 3.0 and TLS 1.0 protocols for Platform Services (2024)
Top Articles
Bug Out Bag Essentials: Tips from the Experts
The Debate on Repressed Memories
Poe T4 Aisling
Lowe's Garden Fence Roll
Fan Van Ari Alectra
Form V/Legends
Western Union Mexico Rate
Southland Goldendoodles
No Strings Attached 123Movies
Nj State Police Private Detective Unit
Burn Ban Map Oklahoma
Lesson 8 Skills Practice Solve Two-Step Inequalities Answer Key
Why Is 365 Market Troy Mi On My Bank Statement
Energy Healing Conference Utah
Laveen Modern Dentistry And Orthodontics Laveen Village Az
Between Friends Comic Strip Today
The EyeDoctors Optometrists, 1835 NW Topeka Blvd, Topeka, KS 66608, US - MapQuest
Bill Remini Obituary
Everything To Know About N Scale Model Trains - My Hobby Models
Skycurve Replacement Mat
The Procurement Acronyms And Abbreviations That You Need To Know Short Forms Used In Procurement
Craftsman Yt3000 Oil Capacity
FSA Award Package
Courtney Roberson Rob Dyrdek
Ryujinx Firmware 15
Experity Installer
Gridwords Factoring 1 Answers Pdf
Abga Gestation Calculator
Landing Page Winn Dixie
Verizon TV and Internet Packages
Gwen Stacy Rule 4
Petsmart Distribution Center Jobs
Bismarck Mandan Mugshots
Hebrew Bible: Torah, Prophets and Writings | My Jewish Learning
Ktbs Payroll Login
Busch Gardens Wait Times
Aita For Announcing My Pregnancy At My Sil Wedding
Firestone Batteries Prices
Santa Clara County prepares for possible ‘tripledemic,’ with mask mandates for health care settings next month
Winta Zesu Net Worth
The Great Brian Last
Darkglass Electronics The Exponent 500 Test
Dagelijkse hooikoortsradar: deze pollen zitten nu in de lucht
Playboi Carti Heardle
877-552-2666
Richard Mccroskey Crime Scene Photos
Bismarck Mandan Mugshots
El Patron Menu Bardstown Ky
French Linen krijtverf van Annie Sloan
Julies Freebies Instant Win
Pilot Travel Center Portersville Photos
Uncle Pete's Wheeling Wv Menu
Latest Posts
Article information

Author: Greg O'Connell

Last Updated:

Views: 5858

Rating: 4.1 / 5 (42 voted)

Reviews: 81% of readers found this page helpful

Author information

Name: Greg O'Connell

Birthday: 1992-01-10

Address: Suite 517 2436 Jefferey Pass, Shanitaside, UT 27519

Phone: +2614651609714

Job: Education Developer

Hobby: Cooking, Gambling, Pottery, Shooting, Baseball, Singing, Snowboarding

Introduction: My name is Greg O'Connell, I am a delightful, colorful, talented, kind, lively, modern, tender person who loves writing and wants to share my knowledge and understanding with you.