TT Lab
Get started
Learn Learning paths Courses

Tomcat & nginx Operations

Working on server.xml — Connectors, Security, Access Logs

Continue in TT Lab

Goal

You understand the hierarchy of server.xml, and become able to set up by yourself adding a connector, securing the shutdown port, changing the access log format, an external docBase context, and response compression.

Why it matters

server.xml is the configuration file opened most often at SI sites. But it is mostly handled by "copying a file received from somewhere and changing only the ports". As a result the shutdown port goes to production at its default (the number one finding in security audits), and with no response time in the access log, you can't back up your answer to a report that "it's slow". In this lab you learn what each attribute changes by checking it yourself.

Steps

  1. Start Tomcat and back up /opt/tomcat/conf/server.xml to /opt/tomcat/conf/server.xml.orig.
  2. Add an HTTP connector on port 8081 to server.xml and restart. http://127.0.0.1:8081/ must return 200.
  3. Change the value of the Server element's shutdown attribute to a different string of 8 or more characters, other than the default (SHUTDOWN).
  4. In Host, add a specifier for processing time in milliseconds to the AccessLogValve's pattern, restart, then send one request so that a log entry is left in /opt/tomcat/logs/localhost_access_log.*.txt.
  5. Create /opt/tomcat/conf/Catalina/localhost/api.xml and set docBase to /opt/lab/fixtures/tomcat/api. After a restart, http://127.0.0.1:8080/api/index.html must return 200.
  6. Turn on compression for the 8080 connector and restart. The response headers of curl -H 'Accept-Encoding: gzip' -I http://127.0.0.1:8080/api/big.html must contain Content-Encoding: gzip.
  7. Create /root/tc/validate.sh. It takes one argument (an XML file path) and exits with code 0 if the XML is valid, and with a non-zero value if it is broken or the file doesn't exist.
  8. Create /root/tc/serverxml.csv. The first line is element,attribute,value,why. Write the 5 settings changed in steps 2–6, one row each. why must be 15 or more characters.

Notes

Back up the original

Start Tomcat and back up /opt/tomcat/conf/server.xml to /opt/tomcat/conf/server.xml.orig.

Backing up before editing a configuration file is not negotiable. The backup only has meaning if it is valid XML too.

Create an additional connector

Add an HTTP connector on port 8081 to server.xml and restart. http://127.0.0.1:8081/ must return 200.

You can have several Connectors under a Service. Copy the existing connector and change only the port. It takes effect after a restart.

Change the shutdown command

Change the value of the Server element's shutdown attribute to a different string of 8 or more characters, other than the default (SHUTDOWN).

If the shutdown attribute of the Server element is at its default, anyone who can connect to port 8005 can bring down the WAS. It is a regular item in security audits.

Add response time to the access log

In Host, add a specifier for processing time in milliseconds to the AccessLogValve's pattern, restart, then send one request so that a log entry is left in /opt/tomcat/logs/localhost_access_log.*.txt.

Add to the pattern of the AccessLogValve a specifier that represents the processing time. There are separate specifiers for milliseconds and for seconds, so check the documentation. You have to send one request after the restart for a log to be created.

Serve a directory outside webapps

Create /opt/tomcat/conf/Catalina/localhost/api.xml and set docBase to /opt/lab/fixtures/tomcat/api. After a restart, http://127.0.0.1:8080/api/index.html must return 200.

If you put contextname.xml under conf/Catalina/localhost/, that name becomes the context path, and docBase can point to an arbitrary path.

Connector compression settings

Turn on compression for the 8080 connector and restart. The response headers of curl -H 'Accept-Encoding: gzip' -I http://127.0.0.1:8080/api/big.html must contain Content-Encoding: gzip.

Turn on compression with Connector attributes. There is a minimum size criterion, so small responses are not compressed. Don't forget that the client has to send Accept-Encoding.

Configuration validation script

Create /root/tc/validate.sh. It takes one argument (an XML file path) and exits with code 0 if the XML is valid, and with a non-zero value if it is broken or the file doesn't exist.

It is a script that checks before deployment whether the XML is broken. It has to validate the file received as an argument and report through the exit code to be usable in automation. Use whichever is convenient, xmlstarlet or python.

Document the changes

Create /root/tc/serverxml.csv. The first line is element,attribute,value,why. Write the 5 settings changed in steps 2–6, one row each. why must be 15 or more characters.

Always leave 'what and why' together for a configuration change. What the person who wants to revert this value six months from now needs is not the value but the reason.