Liferay 6.1是否支持TLSv1.2?更换JRE能否实现?
关于Liferay 6.1更换JRE及启用TLS 1.2的问题解答
Hey there, let's break down your questions clearly and practically:
1. 是否可以更换Liferay 6.1配套的JRE?
Absolutely yes, and it's actually the key to getting TLS 1.2 support later. Here's what you need to know:
- Liferay 6.1’s official docs confirm it supports both JRE 1.6 and JRE 1.7. Later maintenance releases (like GA3 and above) can also work with JRE 1.8, though you’ll want to run full compatibility tests for custom portlets or integrations.
- Step-by-step upgrade tips:
- First, back up your entire environment (database, custom plugins, configuration files—everything) to avoid headaches if something goes wrong.
- Uninstall JRE 1.6.0_20 and install a newer version: aim for JRE 1.7u80 or higher, or JRE 1.8 (these versions have stable, native TLS 1.2 support).
- Update Tomcat’s
setenv.sh(Linux) orsetenv.bat(Windows) to pointJAVA_HOMEto your new JRE installation path. - Start Tomcat and verify Liferay runs smoothly: check database connections, custom portlets, and any third-party integrations for compatibility issues.
2. 能否在Liferay 6.1中运行TLS 1.2?
It depends entirely on your JRE version:
- With JRE 1.6: No, JRE 1.6 doesn’t natively support TLS 1.2. While there are some unofficial workarounds (like patching or tweaking system properties), they’re not recommended—they introduce stability risks and potential security gaps.
- With upgraded JRE (1.7u80+/1.8): Yes, you can enable TLS 1.2 by configuring Tomcat’s SSL connector:
- Open Tomcat’s
conf/server.xmland locate the SSL Connector block (usually bound to port 8443). - Update it to explicitly enable TLS 1.2 by adding/modifying the
sslEnabledProtocolsattribute. Here’s a sample configuration:<Connector port="8443" protocol="HTTP/1.1" maxThreads="150" SSLEnabled="true" scheme="https" secure="true" clientAuth="false" sslProtocol="TLS" sslEnabledProtocols="TLSv1.2" keystoreFile="${catalina.base}/conf/localhost-rsa.jks" keystorePass="changeit"/> - For outbound HTTPS requests from Liferay (like calling external APIs), force TLS 1.2 by adding this system property to Tomcat’s startup arguments:
-Dhttps.protocols=TLSv1.2.
- Open Tomcat’s
Quick Summary
Upgrading your JRE is the only reliable way to get TLS 1.2 support in Liferay 6.1. Stick to supported JRE versions (1.7 or 1.8) and test thoroughly after changes to ensure all parts of your system work as expected.
内容的提问来源于stack exchange,提问作者Antonio mc
相关产品推荐
相关产品推荐

