Solr跟踪失败报错求助:GetModelsDiff返回403状态码
Looking at your error logs, the core issue is that the Solr ModelTracker is getting a 403 Forbidden response when calling the GetModelsDiff API on your Alfresco Repository. This almost always points to an authentication/authorization mismatch between Solr and Alfresco, or a network/security restriction blocking the request. Let’s break down the most common causes and fixes:
Common Causes & Solutions
1. Mismatched Authentication Credentials
Solr uses a dedicated user account to communicate with Alfresco. If the username/password configured in Solr doesn’t match what’s set in Alfresco, you’ll get a 403.
- Check & Sync Credentials:
- In Solr, open the
solrcore.propertiesfile (usually located at<solr_home>/cores/alfresco/conf/solrcore.properties) and verify the values foralfresco.userandalfresco.password. - In Alfresco, check
alfresco-global.propertiesfor the correspondingsolr.userandsolr.passwordsettings. Make sure both sides use the exact same credentials. - You can quickly verify the credentials with a curl command from the Solr server:
If this returns 403, your credentials are definitely the problem.curl -u <solr_user>:<solr_password> http://<alfresco_host>:<alfresco_port>/alfresco/api/-default-/public/alfresco/versions/1/solr/models/diff
- In Solr, open the
2. IP Whitelist Restrictions in Alfresco
Alfresco is configured to only allow specific Solr hosts to access its indexing APIs. If your Solr server’s IP isn’t on this list, it’ll reject the request.
- Update Solr Host Whitelist:
- Open Alfresco’s
alfresco-global.propertiesand look for thesolr.hostproperty. Add your Solr server’s IP or hostname here (separate multiple entries with commas):solr.host=192.168.1.100,solr-server.example.com - Restart Alfresco after making this change to apply the new whitelist.
- Open Alfresco’s
3. SSL Certificate Issues (If Using HTTPS)
If you’ve enabled secure communication between Solr and Alfresco, invalid or missing SSL certificates in Solr’s trust store can cause the request to be rejected (sometimes manifesting as a 403 instead of an SSL handshake error).
- Verify SSL Configuration:
- Check Solr’s
solrcore.propertiesforalfresco.secureComms– it should be set tohttpsif you’re using SSL. - Ensure Solr’s trust store (configured via
solr.ssl.trustStoreinsolrcore.properties) contains a valid, unexpired copy of Alfresco’s SSL certificate. You can list the certificates in the trust store with:keytool -list -keystore <path_to_solr_truststore> -storepass <truststore_password> - If the certificate is missing or expired, re-import Alfresco’s certificate into Solr’s trust store.
- Check Solr’s
4. Insufficient Permissions for the Solr User
The default solr user in Alfresco is assigned the SOLR role, which grants access to all indexing-related APIs. If this role was removed or modified, the user won’t have permission to call GetModelsDiff.
- Check User Roles:
- Log into the Alfresco Admin Console (usually at
http://<alfresco_host>:<alfresco_port>/alfresco/service/enterprise/admin). - Navigate to Users > Search for "solr" > Edit User.
- Ensure the
SOLRrole is listed under the user’s assigned roles. If not, add it and save the changes.
- Log into the Alfresco Admin Console (usually at
Final Verification
After applying any of these fixes, restart Solr and monitor the logs for the Tracking failed ERROR message. If the issue persists, double-check your network connectivity between Solr and Alfresco (no firewalls blocking port 8080/8443, depending on your setup) and confirm all configuration files were saved correctly.
内容的提问来源于stack exchange,提问作者karuppasamy

