You are here

Installing and configuring Alfresco Search and Insight Engine with mutual TLS using the distribution zip

Use this information to install Alfresco Search and Insight Engine on the same machine as Alfresco Content Services with mutual TLS.
Mutual TLS is used for authentication between the Repository and Alfresco Search and Insight Engine.
This task assumes you have:
  • Installed Alfresco Content Services 6.0 or above, with clustering enabled, see Supported Platforms and Languages.
  • Set the following properties in the <TOMCAT_HOME>/shared/classes/ file:
Important: Alfresco strongly recommends you use firewalls and other infrastructure means to ensure the Alfresco Search and Insight Engine server is not accessible from anything other than trusted hosts and/or users, and only on the ports needed for Alfresco Search and Insight Engine.
  1. Browse to the Alfresco Support Portal and download
  2. Extract the Alfresco Search and Insight Engine distribution.

    By default, the contents of are decompressed in a root folder as /alfresco-insight-engine. See Alfresco Search and Insight Engine directory structure for more details.

  3. If you use several languages across your organization, you must enable cross-language search support in all fields. To do this update the alfresco-insight-engine/solrhome/conf/ file:

  4. (Optional) Suggestion is disabled by default. To enable suggestion update the alfresco-insight-engine/solrhome/conf/ file.{}name{}title{}description{}content
    Note: The spell check functionality does not work with Alfresco Search and Insight Engine when suggestion is enabled.
  5. To secure access to Alfresco Search and Insight Engine, you must create a new set of keystores and keys.
    1. Generate secure keys specific to your Alfresco installation. For more information, see Generating secure keys overview.
    2. Create a new keystore directory at alfresco-insight-engine/solrhome.
    3. In the production environment, copy your custom keystore and truststore to the alfresco-insight-engine/solrhome/keystore directory.
    4. Update the SSL-related system properties by replacing <SOLR_HOME> with alfresco-insight-engine/solrhome, and set your keystore and truststore passwords.

      (Windows) update the alfresco-insight-engine/ file:

      set SOLR_SSL_KEY_STORE=<SOLR_HOME>\keystore\ssl.repo.client.keystore
      set SOLR_SSL_KEY_STORE_PASSWORD=password
      set SOLR_SSL_TRUST_STORE=<SOLR_HOME>\keystore\ssl.repo.client.truststore

      (Linux) update the alfresco-insight-engine/ file:

    5. Set the SOLR_PORT environment variable:

      (Windows) update the alfresco-insight-engine/ file:

      set SOLR_PORT=8983

      (Linux) update the alfresco-insight-engine/ file:

  6. (Optional) If you want to install Alfresco Search and Insight Engine on a separate machine, set the SOLR_SOLR_HOST and SOLR_ALFRESCO_HOST environment variables before starting Alfresco Search and Insight Engine, for more see Alfresco Search and Insight Engine externalized configuration.

    (Windows) update the alfresco-insight-engine/ file:

    set SOLR_SOLR_HOST=localhost
    set SOLR_ALFRESCO_HOST=localhost

    (Linux) update the alfresco-insight-engine/ file:

  7. To configure the Solr6 cores, set the following:

    • Before creating the alfresco and archive cores:
      • Set alfresco.secureComms=https in alfresco-insight-engine/solrhome/templates/rerank/conf/
      • Copy the custom keystores to the alfresco-insight-engine/solrhome/templates/rerank/conf directory.
    • If the alfresco and archive cores already exist, ensure that alfresco.secureComms is set to https for both the cores. For example:
      • alfresco-insight-engine/solrhome/alfresco/conf/
      • alfresco-insight-engine/solrhome/archive/conf/
  8. For running a single instance of Alfresco Search and Insight Engine (i.e. not sharded), use the following commands:

    cd alfresco-insight-engine
    ./solr/bin/solr start -a " -Dsolr.ssl.checkPeerName=false -Dcreate.alfresco.defaults=alfresco,archive"
    Note: The -Dcreate.alfresco.defaults=alfresco,archive command automatically creates the alfresco and archive cores. Therefore, you should only start Alfresco Search and Insight Engine with -Dcreate.alfresco.defaults=alfresco,archive the first time you run Alfresco Search and Insight Engine.
    Note: To ensure that Alfresco Search and Insight Engine connects using the IPv6 protocol instead of IPv4, add to the startup parameters.
    Note: You should run this application as a dedicated user. For example, you can create a Solr user.

    The default port used is 8983.

    The command line parameter, -a passes additional JVM parameters, for example, system properties using -D.

    Once Alfresco Search and Insight Engine is up and running, you should see a message like:

    Waiting up to 180 seconds to see Solr running on port 8983 [\]  
    Started Solr server on port 8983 (pid=24289). Happy searching!
    To stop all instances of Alfresco Search and Insight Engine, use:
    ./solr/bin/solr stop

    The logs are stored in the alfresco-insight-engine/logs/solr.log file, by default. This can be configured in (for Linux) or (for Windows) using SOLR_LOGS_DIR.

    You have successfully created an alfresco core and an archive core. To verify, in a browser, navigate to the Solr URL, https://localhost:8983/solr. In the Solr Admin UI, select the core selector drop-down list and verify that both the alfresco and archive cores are present.

    Allow a few minutes for Alfresco Search and Insight Engine to start indexing.

If you are not using sharded Alfresco Search and Insight Engine:
  1. Access the Admin Console > Search Service Sharding page.
  2. Deselect Dynamic Shard Instance Registration.
  3. Select Purge at Startup.

Sending feedback to the Alfresco documentation team

You don't appear to have JavaScript enabled in your browser. With JavaScript enabled, you can provide feedback to us using our simple form. Here are some instructions on how to enable JavaScript in your web browser.