<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: tSetKeyStore / tRestClient and setting disableCNCheck in Talend Studio</title>
    <link>https://community.qlik.com/t5/Talend-Studio/tSetKeyStore-tRestClient-and-setting-disableCNCheck/m-p/2233622#M23240</link>
    <description>Hi 
&lt;BR /&gt;It does not support HTTPS certificate right now, our developers already know this issue, and it has been reported in our bugtracker. see: 
&lt;BR /&gt; 
&lt;A href="https://jira.talendforge.org/browse/TESB-13391" rel="nofollow noopener noreferrer"&gt;https://jira.talendforge.org/browse/TESB-13391&lt;/A&gt; 
&lt;BR /&gt;Best regards 
&lt;BR /&gt;Shong</description>
    <pubDate>Tue, 27 Oct 2015 13:28:52 GMT</pubDate>
    <dc:creator>Anonymous</dc:creator>
    <dc:date>2015-10-27T13:28:52Z</dc:date>
    <item>
      <title>tSetKeyStore / tRestClient and setting disableCNCheck</title>
      <link>https://community.qlik.com/t5/Talend-Studio/tSetKeyStore-tRestClient-and-setting-disableCNCheck/m-p/2233621#M23239</link>
      <description>Hello,&amp;nbsp; 
&lt;BR /&gt;Any ideas on how to override the certificate check in the tRestClient component? 
&lt;BR /&gt;I ran into a case recently where in a non-production environment, &amp;nbsp;a vendor's staging environment is using a HTTPS Certificate which is for a dev environment. &amp;nbsp;The end result is that the SSL Handshake failed because the FQDN doesn't match the certificate. 
&lt;BR /&gt;I'm using TOS 6.0 and currently running the job on my local development station.The error message indicates that CSF Client TLS Config property "disableDNCheck" should be set to true. I am specifying a keystore which does have the certificate in it. 
&lt;BR /&gt;How do you set this propery in TOS, such that it picks it up? &amp;nbsp;I've tried setting this in the Job's run tab, Advanced settings (below) without any effect. 
&lt;BR /&gt;JVM args that didn't help 
&lt;BR /&gt;-Djsse.enableSNIExtension=false 
&lt;BR /&gt;-DsetDisableCNCheck=true 
&lt;BR /&gt;-DdisableCNCheck=true 
&lt;BR /&gt;-Ddisable-https-hostname-verification=true 
&lt;BR /&gt;--- 
&lt;BR /&gt;Error 
&lt;BR /&gt;Exception in component tRESTClient_1javax.ws.rs.ProcessingException: java.io.IOException: IOException invoking : The https URL hostname does not match the Common Name (CN) on the server certificate in the client's truststore. &amp;nbsp;Make sure server certificate is correct, or to disable this check (NOT recommended for production) set the CXF client TLS configuration property "disableCNCheck" to true.</description>
      <pubDate>Thu, 01 Oct 2015 20:51:20 GMT</pubDate>
      <guid>https://community.qlik.com/t5/Talend-Studio/tSetKeyStore-tRestClient-and-setting-disableCNCheck/m-p/2233621#M23239</guid>
      <dc:creator>Anonymous</dc:creator>
      <dc:date>2015-10-01T20:51:20Z</dc:date>
    </item>
    <item>
      <title>Re: tSetKeyStore / tRestClient and setting disableCNCheck</title>
      <link>https://community.qlik.com/t5/Talend-Studio/tSetKeyStore-tRestClient-and-setting-disableCNCheck/m-p/2233622#M23240</link>
      <description>Hi 
&lt;BR /&gt;It does not support HTTPS certificate right now, our developers already know this issue, and it has been reported in our bugtracker. see: 
&lt;BR /&gt; 
&lt;A href="https://jira.talendforge.org/browse/TESB-13391" rel="nofollow noopener noreferrer"&gt;https://jira.talendforge.org/browse/TESB-13391&lt;/A&gt; 
&lt;BR /&gt;Best regards 
&lt;BR /&gt;Shong</description>
      <pubDate>Tue, 27 Oct 2015 13:28:52 GMT</pubDate>
      <guid>https://community.qlik.com/t5/Talend-Studio/tSetKeyStore-tRestClient-and-setting-disableCNCheck/m-p/2233622#M23240</guid>
      <dc:creator>Anonymous</dc:creator>
      <dc:date>2015-10-27T13:28:52Z</dc:date>
    </item>
  </channel>
</rss>

