Working on server.xml — Connectors, Security, Access Logs
Goal
You understand the hierarchy of server.xml, and become able to set up by yourself adding a connector, securing the shutdown port,
changing the access log format, an external docBase context, and response compression.
Why it matters
server.xml is the configuration file opened most often at SI sites. But it is mostly handled by
"copying a file received from somewhere and changing only the ports".
As a result the shutdown port goes to production at its default (the number one finding in security audits),
and with no response time in the access log, you can't back up your answer to a report that "it's slow".
In this lab you learn what each attribute changes by checking it yourself.
Steps
- Start Tomcat and back up
/opt/tomcat/conf/server.xmlto/opt/tomcat/conf/server.xml.orig. - Add an HTTP connector on port 8081 to
server.xmland restart.http://127.0.0.1:8081/must return 200. - Change the value of the
Serverelement'sshutdownattribute to a different string of 8 or more characters, other than the default (SHUTDOWN). - In
Host, add a specifier for processing time in milliseconds to theAccessLogValve'spattern, restart, then send one request so that a log entry is left in/opt/tomcat/logs/localhost_access_log.*.txt. - Create
/opt/tomcat/conf/Catalina/localhost/api.xmland setdocBaseto/opt/lab/fixtures/tomcat/api. After a restart,http://127.0.0.1:8080/api/index.htmlmust return 200. - Turn on compression for the 8080 connector and restart.
The response headers of
curl -H 'Accept-Encoding: gzip' -I http://127.0.0.1:8080/api/big.htmlmust containContent-Encoding: gzip. - Create
/root/tc/validate.sh. It takes one argument (an XML file path) and exits with code 0 if the XML is valid, and with a non-zero value if it is broken or the file doesn't exist. - Create
/root/tc/serverxml.csv. The first line iselement,attribute,value,why. Write the 5 settings changed in steps 2–6, one row each.whymust be 15 or more characters.
Notes
- Check values with
xmlstarlet sel -t -v "//Connector/@port" -n /opt/tomcat/conf/server.xml - Example context file:
<Context docBase="/경로" />(a single line is enough; the path goes inside the quotes) - Common mistake 1: not restarting after editing the XML. server.xml is not hot-reloaded.
- Common mistake 2: putting the connector inside
Engine.Connectoris a direct child ofService. - Common mistake 3: thinking compression is not on when in fact the response is smaller than the minimum size.
Back up the original
Start Tomcat and back up /opt/tomcat/conf/server.xml to
/opt/tomcat/conf/server.xml.orig.
Backing up before editing a configuration file is not negotiable. The backup only has meaning if it is valid XML too.
Create an additional connector
Add an HTTP connector on port 8081 to server.xml and restart.
http://127.0.0.1:8081/ must return 200.
You can have several Connectors under a Service. Copy the existing connector and change only the port. It takes effect after a restart.
Change the shutdown command
Change the value of the Server element's shutdown attribute to a different string
of 8 or more characters, other than the default (SHUTDOWN).
If the shutdown attribute of the Server element is at its default, anyone who can connect to port 8005 can bring down the WAS. It is a regular item in security audits.
Add response time to the access log
In Host, add a specifier for processing time in milliseconds to the AccessLogValve's pattern,
restart, then send one request so that
a log entry is left in /opt/tomcat/logs/localhost_access_log.*.txt.
Add to the pattern of the AccessLogValve a specifier that represents the processing time. There are separate specifiers for milliseconds and for seconds, so check the documentation. You have to send one request after the restart for a log to be created.
Serve a directory outside webapps
Create /opt/tomcat/conf/Catalina/localhost/api.xml and
set docBase to /opt/lab/fixtures/tomcat/api. After a restart,
http://127.0.0.1:8080/api/index.html must return 200.
If you put contextname.xml under conf/Catalina/localhost/, that name becomes the context path, and docBase can point to an arbitrary path.
Connector compression settings
Turn on compression for the 8080 connector and restart.
The response headers of curl -H 'Accept-Encoding: gzip' -I http://127.0.0.1:8080/api/big.html
must contain Content-Encoding: gzip.
Turn on compression with Connector attributes. There is a minimum size criterion, so small responses are not compressed. Don't forget that the client has to send Accept-Encoding.
Configuration validation script
Create /root/tc/validate.sh. It takes one argument (an XML file path) and
exits with code 0 if the XML is valid, and with a non-zero value if it is broken or the file doesn't exist.
It is a script that checks before deployment whether the XML is broken. It has to validate the file received as an argument and report through the exit code to be usable in automation. Use whichever is convenient, xmlstarlet or python.
Document the changes
Create /root/tc/serverxml.csv. The first line is element,attribute,value,why.
Write the 5 settings changed in steps 2–6, one row each.
why must be 15 or more characters.
Always leave 'what and why' together for a configuration change. What the person who wants to revert this value six months from now needs is not the value but the reason.