Problem with JMS via the SSL protocol in clustered environment

Hello

We run Weblogic 11 g Cluster (area) which consists of admin server and two managed server MS1, MS2.
LIKE and run it on the computer 1, MS1 MS2 runs on machine 2. Both machines have two network interfaces, a public used for client connections and an intern for cluster communication, monitoring etc. The default channel of each Weblogic Server is listening on the internal network interface, and Moreover we have two channels (for http and t3 Protocol) configured to the public interface.
The two managed servers are JMS provider and there is a JMS Module myModule in the field with the following JMS resources: custom connection factory myConnFactory (Load Balancing active = true = false server affinity, target: entire cluster JMS) and myQueue, which is a uniform distributed queue (targets: MS1, MS2). The queue is accessed by its logical JNDI name, but she is stuck on each managed server.

JMS communication flows normally through t3 dedicated listening on the public interface. However, a new external client will send messages to myQueue and communication must be encrypted for security reasons. For this reason, we have implemented SSL. Instead activate a DefaultSecure channel, we left 'SSL listen Port active' = false (as the default channel would be linked to the internal network interface) and created a new channel T3SChannel t3s Protocol on the public interface for incoming client connections.

The customer creates a t3s connection to the cluster (through T3SChannel) and gets the factory connections and the queue, use the JNDI ( source) search. The JMS connection is in real-time with MS1. If we want to create two consumers for this queue, the consumer of fist is created the MS1 and the second will be created on MS2 (thanks to active balancing). However, the creation of the second consumer fails with an exception (it is thrown on the client):

java.rmi.ConnectException: no valid port known for: "DefaultSecure [t3s]: t3s (t3s): mserver1 - internal .company .com: 56213:null:-1 ';" No router available at destination
at weblogic.rjvm.ConnectionManager.bootstrap(ConnectionManager.java:464)
at weblogic.rjvm.ConnectionManager.bootstrap(ConnectionManager.java:396)
at weblogic.rjvm.RJVMImpl.ensureConnectionEstablished(RJVMImpl.java:303)
at weblogic.rjvm.RJVMImpl.getOutputStream(RJVMImpl.java:347)
at weblogic.rjvm.RJVMImpl.getRequestStreamInternal(RJVMImpl.java:610)
... 18 more

We were told that the exception can be avoided with t3s < default protocol > - < / default protocol > element (default is t3) added to the config.XML in the Weblogic domain. If we configure t3s as default protocol, we also need to activate the DefaultSecure channel on each server and then everything works and the customer is able to correctly create consumers.

However, as a side effect, the entire cluster on weblogic.rjvm communication layer and then by t3s. We do not want that because internal cluster communications are set enough with other methods and it will have impact on the notable performance in the production environment. In principle, it should be possible to enable the external client to connect to the JMS provider via the channel new, safe, without affecting the existing internal communication in the cluster (which should be a black box for the customer).

My question: is it possible to run the example described without defining the default protocol to t3s?

Thanks for the reply.

My question: is it possible to run the example described without defining the default protocol to t3s?

Thanks for the very clear problem description. I checked with our customer support guru and I'm sure that the answer to your question is no, I think you have encountered a known problem and have already struck with the recommended workaround.

That said, you can be able to avoid at least partially the problem by setting "server-affinity = true" on your CF. as you probably well know, affinity = false encourages consumer and producer traffic to route customer, on its server host connection, then possibly on a "second leap" to another server in the cluster. It looks like the attempt of an implicit downgrade of a secure request origin SSL in the first bond on a channel not secure in this second jump is to throw the exception.

HTH,

Tom

Tags: Fusion Middleware

Similar Questions

  • Custom problem race workspace via the SSL protocol

    Hello

    If we try to run our workspace personalized via the SSL protocol, we get the following in the trace error message: * took place an error event: an error occurred during initialization of workspace. (ALC-WKS-007-049)

    So the stuff of successful connection... but then the error occurs while initializing the workspace .

    In the trace you can also see, that service of the workspace still tries to connect via http, but with the secure port: http://xxx.xxx.xxx.xx:8443 / work-server/messagebroker/amfpolling space

    When we use the Internet-Explorer, the problem only occurs on the first connection. The second time everything works fine.

    Unfortunately, we cannot solve the problem when you use other browsers (Firefox, Safari. Etc.)

    It would be great if someone could give a clue.

    Thank you!

    We use the next version of livecycle:

    Version: 8.2.1, GM

    Patch Version: SP2

    Service Pack Version: 8.2.2353.1.195587.2

    Trace debugging:

    -Built in 3729ms AuthenticatingApplication.

    -called createComponentsFromDescriptors to 3761ms.

    [SWF] /xyz/workspace-theme.swf - 496 567 bytes after decompression

    Finished loading the theme to 3997ms.

    -init called 3998ms.

    Workspace created string: id = work-survey-amf space, url = https://192.168.196.60:8443 / work-server/messagebroker/amfpolling space .

    -checkLogin-

    singleSignOn: SSO connection

    login: https://192.168.196.60:8443/um/login time = 4053 Ms

    an error event occurred: verification of credentials: credentials not found. connection is required. (ALC-WKS-007-149)

    -showLogin to 4240ms.

    [SWF] /xyz/LoadingCircle.swf - 673 bytes after decompression

    -doAuthenticate to 10171ms.

    Login: credentials

    login: https://192.168.196.60:8443/um/login time = 10176 Ms

    sendWorkspaceLogin: https://192.168.196.60:8443 / space work-server/authenticate , time = 10357ms.

    exit sendWorkspaceLogin: https://192.168.196.60:8443 / space work-server/authenticate , time = 10363ms.

    loginHandler

    loginSuccessHandler: time = 10455ms.

    Workspace created string: id = null, url = https://192.168.196.60:8443 / remote/messagebroker/amf access .

    the authentication expires in 6899; to re-authenticate timer set to 6869 s.

    = initialize()

    handleChannelFault - faultCode = Channel .connect .failed NetConnection.Call.BadVersion: url: ' http://192.168.196.60:8443 / work-server/messagebroker/amfpolling space '

    an error occurred: an error occurred during initialization of workspace. (ALC-WKS-007-049)

    an error occurred: an error occurred during initialization of workspace. (ALC-WKS-007-049)

    -showLogin to 10526ms.

    We had the same problem.  There is a patch for it: http://www.adobe.com/support/products/enterprise/support_knowledge_center_livecycle_ES_ser ver.html

  • BlackBerry, call web services via the SSL protocol

    Hi guys,.

    We are developing an application BlackBerry to OS 4.1 and we test it on the 8330.  This application calls several web services on a remote server via the SSL Protocol (side).  There is a valid certificate from Entrust installed on the remote server - it works properly with all major desktop browsers.  The certificate has not been installed on the BES - is it necessary?  Some BlackBerry devices will be linked to a company BES, others not.

    When the application calls the web service, a window opens with the following message: "you try to open a secure connection, but the server certificate is not approved."  Continue to push works fine, but the window opens again a few moments later.  Pushing view certificate indicates that the certificate is considered invalid ('unverifiable Cert chain').  The same information is given when you navigate to the certificates of the aircraft.  Certificate trust pushing watch a 2nd window asking you the key Store password, which we are not aware of.

    You guys can help us with this?

    Thank you!

    We have solved the problem.  It seems that the BlackBerry device is having a hard time with a certificate signed by the Entrust 2048 bit root certificate.  Give us a new intermediate certificate signed by their 1024-bit root certificate, which we have installed on our Apache server.  While the window 'certificate is not approved' arises at once, pushing "Continue" worked and it never came up again.  To do this, it will probably install the certificate on the BES, something we don't have yet.

    Thank you for taking the time to answer!

  • How to get the JSP to transmit a request via the SSL protocol?

    I'm new to JSP and servlets, although I worked with Java for a long time. I am writing a registration system and connection of single user to teach myself JSP. I want to put things up so that the user is able to connect securely over https. I don't know how to do this, however. There seems to be no place in the relative URLS to indicate that you must send a request via the SSL protocol. I've got sample page to login below - someone knows how to change it so that it happens safely?

    Also, do I need to install a certificate on my web server?

    index.jsp
    <html>
        <body>
            <h1>Index</h1>
            <a href="login.jsp">Login</a>
        </body>
    </html>
    Login.jsp
    <%@page contentType="text/html" pageEncoding="UTF-8"%>
    <!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN"
       "http://www.w3.org/TR/html4/loose.dtd">
    
    <html>
        <body>
            <h1>Login</h1>
    
            <jsp:useBean id="userLogin"
                         class="com.kitfox.webrpg.UserLogin"/>
            <jsp:setProperty name="userLogin"
                             property="*"/>
    
            <%if (userLogin.isValid()) {%>
            <jsp:useBean id="userId"
                         class="com.kitfox.webrpg.UserIdent"
                         scope="session"/>
            <jsp:setProperty name="userId" property="*"/>
    
            <jsp:forward page="index.jsp"/>
    
            <%} else {%>
    
            <form action="login.jsp" method="post">
                <fieldset>
                    <legend>Enter login information</legend>
    
                    <label for="login">Login</label>
                    <input type="text" name="login" value="${userLogin.login}"/> <br/>
    
                    <label for="password">Password</label>
                    <input type="password" name="password"/> <br/>
    
                    <input type="submit" value="submit">
                </fieldset>
            </form>
    
            <%}%>
        </body>
    </html>

    The first step would be to install an SSL certificate on your web/application server and ensure that it works.

    You can add something like the following to your web.xml file to automatically switch to https

    
      
        Secure Login
        /login.jsp
      
      
        CONFIDENTIAL
      
    
    
  • Several clients that connect to the same user via the SSL protocol

    It's possible? I can't find any documentation about it. Essentially, because of the way our system has been designed, connect us the two our system and our front-end web server to the same processing back-end user. Now, we have an obligation to use PKI/SSL to connect users.

    I have experimented with OWM and the TCPS, and was finally able to get a connection between Client1 and the server a user to test called PKI_TEST. The problem is that I get an ORA-28860 error when I try to connect Client2 to the server to the same user. I tried to import the Client2 certificate into server's wallet, but which is perhaps the origin of the problem. So here are my thoughts/questions.

    1. how to import the client certificates in the server with the same CN wallet? Seems to be a 'no', but maybe I am doing something wrong.

    2. can I import certificate user of Client1 Client2 portfolio so Client2 performs authentication by using the same certificate that worked for Client1?

    3. can I copy portfolio of Client1 to Client2 so Client2 uses the same portfolio that has worked for Client1?

    4. can I associate a single user with multiple CNs for the client certificates will be different in the wallet of server?

    Any help would be appreciated.

    Hello

    You can just copy the client1 client2 on portfolio, so the client2 can connect / authenticate over SSL to the same DB user.

  • Problem with InfoPath via the Adobe pdf printer print

    Hello

    It seems that in some cases to the printer Adobe pdf makes the text box a little narrower than THE InfoPath. So we have packaging Word and number of lines in the PDF can be only in the InfoPath form. But the output area is not resolved. So the end of the text may be corrupted:

    I checked this approach, but it does not help:

    https://helpx.Adobe.com/Acrobat/KB/missing-or-garbled-text-printing.html

    The same behavior is with different IEs.

    Could you please help to solve this problem?

    Must be a bug in InfoPath from the Adobe PDF printer simply reports the available printer box and print what they say in print, where it says print. Could be a problem with the printer driver change. Try to set default Adobe PDF before you start InfoPath, might work.

  • Strange problem with measurement of the color under Mac.

    Hello, I have a strange problem with measurement of the color under Mac. For example I create a gradient in Photoshop color 200 200 200 color 240 240 240. When I measure the color of the gradient with the Photoshop color measurement tool or with the built in OS X color measurement tool measured color is of 200 199 197 to 240 240 238. I measured the same gradient with Photoshop for PC and the values are OK (the same values that I create).

    I don't know what the problem is, but I think that the colors that I create are the same I have measure after creating them and also values between Mac and PC. I appreciate much help or information you could give me that helps me understand what is happening here.

    Thank you for your time

    Marcelo.

    Yep, you guessed it, evidence as monitor basically removes all profiling and just offer it right.

    is it possible to make the OS X color measurement tool to measure the original color values

    You mean the colors of paper - No., as I said photoshop filter your image through the profile document, proof of installation and the monitor profile. Why use Digital color meter for this though?

    I don't understand what is measurement of color values that will change every time point calibrate it my monitor.

    Because color values are "larger" what is on your monitor. Your monitor (via photoshop) makes only the best he can to display these values, which can be anything from LAB colors outside the range of your monitor - to the CMYK color. Calibration, it is the only way to allow your monitor to do this in any way accurately. (never really impossible) The monitors have a certain range and are only representations / would the REAL colors who is the holder of a document, with a profile. There's only one good reason to measure the monitor values so that is to build a monitor profile.

  • problem with Safari and the opening of sites

    problem with Safari and the opening of sites

    Please describe the problem in more detail?

    Try to reset the settings of Safari:

    1. open Safari

    2. click on the Safari menu at the top (to the right of the Apple logo)

    3. Select the Preferences/Privacy tab

    4. click on remove all data from the Web site

    5. close Safari.

    Remove cache Safari files:

    1. click on finder

    2. look for the menu GO to top

    3. click on GO and hold down the option key. This will show a user library folder.

    4. click library and find the Caches folder

    5. in the folder caches com.apple.Safari Ouvrezledossier

    6. move the Cache.db file Trash.

    This should solve the problem. If it does not help, try to disable the Safari extensions

    1. open Safari

    2. click on the Safari menu at the top (to the right of the Apple logo)

    3. Select Preferences

    4. find the Extensions tab

    5 disable all extensions of

    6. relaunch Safari

  • Having a problem with loading in the combustion chamber

    Hello

    I'm having a small problem I could use help with. I'm not really sure what's going on, but I'm having a problem with one of the pages of my site does not when you try to view the page in Firefox. But if I loaded this page in Safari or Chrome, it loads very well.

    Here is the URL of the page to take a look:
    Specific link removed by moderator display ~ J99 < sitename >.com/top-10/top...services/

    No idea why this might be happening or how to fix it? I don't know if it's just my computer, or if others have the same problem.

    Thanks in advance,

    Mike

    There's two of us have confirmed the page will load so I deleted the link to display as it could be construed as advertising.

    P.S. Note only forum content in the resolved threads is now indexed by search engines.

    (Last updated: February 14, 2015 08:45 CEST)

    Solved the locked thread now ~ J99

  • Using an IP191 monitor, have random horizontal stripes on the screen - have no problems with other browsers. also no problem with FF on the other PCs on the family

    Using an IP191 monitor, have random horizontal stripes on the screen - have no problems with other browsers. also no problem with FF on the other PCs on the family.

    These "streaks" seem to be the domain of the high frequency analysis; they can be eliminated by scrolling upwards or downwards.

    Hello, maybe it's a problem with hardware acceleration - try updating your graphic driver, or in case this does not solve the problem, or there is no new version available at the time, disable hardware acceleration in the firefox menu

    > options > advanced > General.

  • I have an older version of Firefox 3.6.6 I think I'm having a problem with one of the websites that I sign. Is it possible to upgrade to the latest version

    I have an older version of Firefox 3.6.6 I think I'm having a problem with one of the websites that I sign. Is it possible to upgrade to the latest version. Without losing all my favorites and the saved passwords?

    Yes, see this article:

    After:

  • Problem with Vista hit the Satellite X 200 - 20 s

    Sometimes during typing on vista, it will stutter and freeze. The time is very short. Is this a problem with vista or the laptop. The T7300 Core 2 Duo 2 ghz processor.

    Hello

    I have a Satellite Pro S200 and the same problem was with my camera. It s is not a hardware problem, it s more a driver related issue No. So, the best thing you can do is update your bios and keep your drivers up-to-date. Just check the download Drivers Toshiba site and make sure you have the latest drivers installed.

    I had resolved my stuttering (core2duo 2.33 Ghz, 2 GB RAM) by updating all drivers...

    That's all

    Good bye

  • Want to Phoenix 860-010: problem with fonts and the noisy fan

    I have a new machine, just a day old, and I'm having a problem with fonts.  The file Explorer, Edge and other similar programs seem to go from a very readable font that lights up in half a second or less whenever I move down on the page in these applications.  Police that results is much more difficult for me to read because of the lightness that results. I have not met this problem before.  Frankly, I don't know the source of the problem.  Is it hardware (video card) or (Windows 10) operating system software?

    Hello @PhotoGene47,

    Thanks for the quick response!

    Have you tried to see the document that I mentioned in my previous post?  If you prefer to have the Board repaired, you can consider contacting the HP support by phone for additional options.  Please use the following http://www.hp.com/contacthp and create a folder for your question and contact HP. If you do not live in the United States / Canada, please click on the link below to get contact information for your region.
    http://WWW8.HP.com/us/en/contact-HP/WW-phone-assist.html

    I hope this helps.

    Please let me know if this information helps you solve the problem by marking this message as 'accept as Solution' , this will help others easily find the information they seek.  In addition, by clicking on the Thumbs up below is a great way to say thank you!

    Kind regards!

  • a problem with one of the files in the TestStand\AdapterSupport\LabVIEW directory

    When looking at the module a LabVIEW VI called for TestStand, I get the following message:

    A problem with one of the files in the TestStand\AdapterSupport\LabVIEW directory.  Please reinstall or repair.

    I made the mistake of cleaning C: in my computer.  Clean the C:\National Instruments downloads

    Why would someone put bits of applications or modules, etc. in such a directory?

    I'm not too crazy about restoring 11FR in this folder.  It's just crazy!

    If anyone has encountered this before?  No "easy"? outside re - install TS...

    Side note: I do not touch anything in the \Program files. National Instruments\TestStand\AdapterSupport\LabVIEW

    What version of LabVIEW and TestStand do you use?

    In 2012, TestStand, this directory is mapped to:

    C:\Documents and Settings\All Users\Documents\National Instruments\TestStand 2012\AdapterSupport\LabVIEW

    Have you tried mass compiling the screws in this folder?

    I had to create a new 'TestStand - default values XX.llb"file, where XX is the last version of LabVIEW you use, but I have not seen this message before.

    Good luck

    PH

  • Problems with access to the web pages, email, video, etc. even when I have 4-5 bars.

    I installed a Dell Wireless 1505 low-profile carrier 1.2 antenna dim/insp in desktop. Its a PCIe wireless lan card. But since last Tuesday patches have been installed I had problems with access to the web pages, email, video, etc., even when I have 4-5 bars.  Someone at - it an idea of what's going on.

    Hi William e. Swann

    1. what web browser do you use?

    Method 1:

    You can read the following article and check.

    You may experience connectivity problems or performance issues when you connect a portable computer that is running Windows Vista or Windows 7 to a wireless access point

    Method 2:

    You can also read the following article.

    How to troubleshoot network connectivity problems in Internet Explorer

    Hope this information is useful.

Maybe you are looking for

  • iPhone 6 s the ear speaker volume is low

    iPhone 6 s the ear speaker volume is low, I turned the volume all the way to the top and there is still no improvement and the volume of the phone's normal when on a call by speaker and earpods. Problem volume level is only known when using the earph

  • Portege M205-S809-PXE-E61 Media Test failure PXE - M0F error

    I replaced (what I thought was) a HD on my Portege M205-S809 failure (I was getting the error "PXE - E61 Media Test failure PXE - M0F").I put in the HD and turned on the laptop to get the same error. My intention was to reistall the BONES of the reco

  • can I use HP Officejet J4580 to scan negatives?

    I was wondering if my all-in-one HP scan negatives. If so, how it looks like a regular (normal) JPEG file?

  • HP Pavilion dv6-3120us

    I have a virus that prevents me to come back & reset to factory settings.  Whenever I turn it on it shows a screen that looks like the IRS page & tells me to pay $400.00 to have removed.  There type ome so that I can buy a recovery disc or even help?

  • Lenovo 3000 N500 graphics card problem!

    Hi all! I have a problem with my laptop newly purchased, about the graphics card. This is supposed to be an nVidia GeForce 9300 M. Above all, I bought this laptop to play World of Warcraft on the subject, if that means something to you. My problem is