You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Windows环境Solr 6.6.2主从架构SSL复制配置问题求助

Let's tackle this Solr 6.6.2 master-slave SSL replication issue on Windows step by step — I’ve dealt with similar Windows-specific SSL headaches before, so let’s break it down.

1. First, Validate Your Machine-Name Certificate

You switched to a machine-name signed cert, but let’s make sure it’s actually compatible with cross-node communication:

  • Add both machine name and IP to the certificate: Most replication failures here happen because the cert only includes the machine name, but your slave uses the master’s IP to connect. Generate the cert with a SAN (Subject Alternative Name) that covers both:
    keytool -genkeypair -alias solrssl -keyalg RSA -keysize 2048 -storetype PKCS12 -keystore solr-ssl.keystore.p12 -validity 3650 -ext SAN=DNS:your-master-machine-name,IP:192.168.x.x
    
  • Ensure the slave trusts the cert: Copy the keystore to both nodes (e.g., Solr-6.6.2/server/etc/). On the slave, either:
    • Import the cert into the JRE’s trust store:
      keytool -exportcert -alias solrssl -keystore solr-ssl.keystore.p12 -storetype PKCS12 -rfc -file solr.crt
      keytool -importcert -alias solrssl -file solr.crt -keystore "C:\Program Files\Java\jre1.8.0_xxx\lib\security\cacerts" -storepass changeit
      
    • Or add trust store params directly to the slave’s solr.cmd (more flexible for multi-JRE setups):
      set SOLR_JAVA_MEM=-Xms512m -Xmx1g -Djavax.net.ssl.trustStore=C:\solr-6.6.2\server\etc\solr-ssl.keystore.p12 -Djavax.net.ssl.trustStorePassword=your-keystore-pass -Djavax.net.ssl.trustStoreType=PKCS12
      
2. Verify Master Node SSL Configuration

Double-check the master’s setup to ensure it’s serving SSL correctly:

  • Update solr.in.cmd (Windows-specific config file) with SSL details:
    set SOLR_SSL_KEY_STORE=C:\solr-6.6.2\server\etc\solr-ssl.keystore.p12
    set SOLR_SSL_KEY_STORE_PASSWORD=your-pass
    set SOLR_SSL_KEY_STORE_TYPE=PKCS12
    set SOLR_SSL_TRUST_STORE=C:\solr-6.6.2\server\etc\solr-ssl.keystore.p12
    set SOLR_SSL_TRUST_STORE_PASSWORD=your-pass
    set SOLR_SSL_TRUST_STORE_TYPE=PKCS12
    set SOLR_SSL_NEED_CLIENT_AUTH=false
    set SOLR_SSL_WANT_CLIENT_AUTH=false
    
  • Confirm the replication listener in solrconfig.xml uses the HTTPS master URL:
    <listener>
      <event>postCommit</event>
      <class>org.apache.solr.handler.ReplicationHandler</class>
      <lst name="defaults">
        <str name="maxNumberOfBackups">1</str>
        <str name="enable">true</str>
        <str name="masterUrl">https://your-master-machine-name:8983/solr/your-core-name/replication</str>
      </lst>
    </listener>
    
  • Restart the master and test SSL access: Visit https://your-master-machine-name:8983/solr/ in a browser — even if it shows an "unsafe" warning, as long as you can load the Solr admin UI, the SSL setup is working.
3. Configure the Slave Node for SSL Replication

The slave needs to trust the master’s cert and point to the HTTPS replication endpoint:

  • Mirror the master’s solr.in.cmd SSL trust store settings on the slave.
  • Update the slave’s solrconfig.xml replication handler:
    <requestHandler name="/replication" class="org.apache.solr.handler.ReplicationHandler">
      <lst name="defaults">
        <str name="masterUrl">https://your-master-machine-name:8983/solr/your-core-name/replication</str>
        <str name="pollInterval">00:00:60</str>
        <str name="compression">on</str>
        <!-- Add username/password here if your master uses basic auth -->
        <!-- <str name="username">solr</str> -->
        <!-- <str name="password">solrpass</str> -->
      </lst>
    </requestHandler>
    
  • Restart the slave, then manually trigger a replication test: Visit https://slave-machine:8983/solr/your-core-name/replication?command=fetchindex and check the response for errors.
4. Windows-Specific Pitfalls to Fix

Don’t overlook these Windows-only gotchas:

  • Firewall rules: Open port 8983 (or your custom SSL port) on the master’s Windows Firewall, allowing inbound traffic from the slave’s IP address. This is the #1 overlooked issue for cross-node communication on Windows.
  • File permissions: Ensure the user running Solr (local system or your login user) has read access to the keystore file. Right-click the keystore → Properties → Security → Add the Solr user with Read permissions.
  • Hostname resolution: Add an entry to the slave’s C:\Windows\System32\drivers\etc\hosts file:
    192.168.x.x  your-master-machine-name
    
    This avoids DNS lookup failures that can break SSL validation.
  • JDK version consistency: Solr 6.6.2 requires JDK 8. Make sure both master and slave use the exact same JDK 8 version — mismatched SSL implementations can cause handshake failures.
5. Debugging Tips

If replication still fails, dig into the logs:

  • Check the solr.log files in Solr-6.6.2/server/logs on both nodes. Search for keywords like SSLHandshakeException (cert trust issues), Connection refused (firewall/port problems), or replication to pinpoint errors.
  • Use curl (built into Windows 10+) to test connectivity from the slave:
    # First test with cert validation disabled
    curl -k https://your-master-machine-name:8983/solr/your-core-name/replication?command=details
    # If that works, test without -k to confirm cert trust
    curl https://your-master-machine-name:8983/solr/your-core-name/replication?command=details
    

内容的提问来源于stack exchange,提问作者Kode

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.05.25 07:15:57