Windows环境Solr 6.6.2主从架构SSL复制配置问题求助
Let's tackle this Solr 6.6.2 master-slave SSL replication issue on Windows step by step — I’ve dealt with similar Windows-specific SSL headaches before, so let’s break it down.
1. First, Validate Your Machine-Name Certificate
You switched to a machine-name signed cert, but let’s make sure it’s actually compatible with cross-node communication:
- Add both machine name and IP to the certificate: Most replication failures here happen because the cert only includes the machine name, but your slave uses the master’s IP to connect. Generate the cert with a SAN (Subject Alternative Name) that covers both:
keytool -genkeypair -alias solrssl -keyalg RSA -keysize 2048 -storetype PKCS12 -keystore solr-ssl.keystore.p12 -validity 3650 -ext SAN=DNS:your-master-machine-name,IP:192.168.x.x - Ensure the slave trusts the cert: Copy the keystore to both nodes (e.g.,
Solr-6.6.2/server/etc/). On the slave, either:- Import the cert into the JRE’s trust store:
keytool -exportcert -alias solrssl -keystore solr-ssl.keystore.p12 -storetype PKCS12 -rfc -file solr.crt keytool -importcert -alias solrssl -file solr.crt -keystore "C:\Program Files\Java\jre1.8.0_xxx\lib\security\cacerts" -storepass changeit - Or add trust store params directly to the slave’s
solr.cmd(more flexible for multi-JRE setups):set SOLR_JAVA_MEM=-Xms512m -Xmx1g -Djavax.net.ssl.trustStore=C:\solr-6.6.2\server\etc\solr-ssl.keystore.p12 -Djavax.net.ssl.trustStorePassword=your-keystore-pass -Djavax.net.ssl.trustStoreType=PKCS12
- Import the cert into the JRE’s trust store:
2. Verify Master Node SSL Configuration
Double-check the master’s setup to ensure it’s serving SSL correctly:
- Update
solr.in.cmd(Windows-specific config file) with SSL details:set SOLR_SSL_KEY_STORE=C:\solr-6.6.2\server\etc\solr-ssl.keystore.p12 set SOLR_SSL_KEY_STORE_PASSWORD=your-pass set SOLR_SSL_KEY_STORE_TYPE=PKCS12 set SOLR_SSL_TRUST_STORE=C:\solr-6.6.2\server\etc\solr-ssl.keystore.p12 set SOLR_SSL_TRUST_STORE_PASSWORD=your-pass set SOLR_SSL_TRUST_STORE_TYPE=PKCS12 set SOLR_SSL_NEED_CLIENT_AUTH=false set SOLR_SSL_WANT_CLIENT_AUTH=false - Confirm the replication listener in
solrconfig.xmluses the HTTPS master URL:<listener> <event>postCommit</event> <class>org.apache.solr.handler.ReplicationHandler</class> <lst name="defaults"> <str name="maxNumberOfBackups">1</str> <str name="enable">true</str> <str name="masterUrl">https://your-master-machine-name:8983/solr/your-core-name/replication</str> </lst> </listener> - Restart the master and test SSL access: Visit
https://your-master-machine-name:8983/solr/in a browser — even if it shows an "unsafe" warning, as long as you can load the Solr admin UI, the SSL setup is working.
3. Configure the Slave Node for SSL Replication
The slave needs to trust the master’s cert and point to the HTTPS replication endpoint:
- Mirror the master’s
solr.in.cmdSSL trust store settings on the slave. - Update the slave’s
solrconfig.xmlreplication handler:<requestHandler name="/replication" class="org.apache.solr.handler.ReplicationHandler"> <lst name="defaults"> <str name="masterUrl">https://your-master-machine-name:8983/solr/your-core-name/replication</str> <str name="pollInterval">00:00:60</str> <str name="compression">on</str> <!-- Add username/password here if your master uses basic auth --> <!-- <str name="username">solr</str> --> <!-- <str name="password">solrpass</str> --> </lst> </requestHandler> - Restart the slave, then manually trigger a replication test: Visit
https://slave-machine:8983/solr/your-core-name/replication?command=fetchindexand check the response for errors.
4. Windows-Specific Pitfalls to Fix
Don’t overlook these Windows-only gotchas:
- Firewall rules: Open port 8983 (or your custom SSL port) on the master’s Windows Firewall, allowing inbound traffic from the slave’s IP address. This is the #1 overlooked issue for cross-node communication on Windows.
- File permissions: Ensure the user running Solr (local system or your login user) has read access to the keystore file. Right-click the keystore → Properties → Security → Add the Solr user with Read permissions.
- Hostname resolution: Add an entry to the slave’s
C:\Windows\System32\drivers\etc\hostsfile:
This avoids DNS lookup failures that can break SSL validation.192.168.x.x your-master-machine-name - JDK version consistency: Solr 6.6.2 requires JDK 8. Make sure both master and slave use the exact same JDK 8 version — mismatched SSL implementations can cause handshake failures.
5. Debugging Tips
If replication still fails, dig into the logs:
- Check the
solr.logfiles inSolr-6.6.2/server/logson both nodes. Search for keywords likeSSLHandshakeException(cert trust issues),Connection refused(firewall/port problems), orreplicationto pinpoint errors. - Use curl (built into Windows 10+) to test connectivity from the slave:
# First test with cert validation disabled curl -k https://your-master-machine-name:8983/solr/your-core-name/replication?command=details # If that works, test without -k to confirm cert trust curl https://your-master-machine-name:8983/solr/your-core-name/replication?command=details
内容的提问来源于stack exchange,提问作者Kode
相关产品推荐
相关产品推荐

