Class SSLValve
java.lang.Object
org.apache.catalina.util.LifecycleBase
org.apache.catalina.util.LifecycleMBeanBase
org.apache.catalina.valves.ValveBase
org.apache.catalina.valves.SSLValve
- All Implemented Interfaces:
MBeanRegistration, Contained, JmxEnabled, Lifecycle, Valve
When using mod_proxy_http, the client SSL information is not included in the protocol (unlike mod_jk and
mod_proxy_ajp). To make the client SSL information available to Tomcat, some additional configuration is required. In
httpd, mod_headers is used to add the SSL information as HTTP headers. In Tomcat, this valve is used to read the
information from the HTTP headers and insert it into the request.
Note: Ensure that the headers are always set by httpd for all requests to prevent a client spoofing SSL information by sending fake headers.
In httpd.conf add the following:
<IfModule ssl_module>
RequestHeader set SSL_CLIENT_CERT "%{SSL_CLIENT_CERT}s"
RequestHeader set SSL_CIPHER "%{SSL_CIPHER}s"
RequestHeader set SSL_SESSION_ID "%{SSL_SESSION_ID}s"
RequestHeader set SSL_CIPHER_USEKEYSIZE "%{SSL_CIPHER_USEKEYSIZE}s"
</IfModule>
In server.xml, configure this valve under the Engine element in server.xml:
<Engine ...> <Valve className="org.apache.catalina.valves.SSLValve" /> <Host ... /> </Engine>
-
Nested Class Summary
Nested classes/interfaces inherited from interface Lifecycle
Lifecycle.SingleUse -
Field Summary
Fields inherited from class ValveBase
asyncSupported, container, containerLog, next, smFields inherited from interface Lifecycle
AFTER_DESTROY_EVENT, AFTER_INIT_EVENT, AFTER_START_EVENT, AFTER_STOP_EVENT, BEFORE_DESTROY_EVENT, BEFORE_INIT_EVENT, BEFORE_START_EVENT, BEFORE_STOP_EVENT, CONFIGURE_START_EVENT, CONFIGURE_STOP_EVENT, PERIODIC_EVENT, START_EVENT, STOP_EVENT -
Constructor Summary
Constructors -
Method Summary
Modifier and TypeMethodDescriptionReturns the header name used to retrieve the cipher suite.Returns the header name used to retrieve the cipher key size.Returns the header name used to retrieve the client certificate.Returns the header name used to retrieve the escaped client certificate.Returns the header name used to retrieve the SSL session ID.voidPerform request processing as required by this Valve.mygetHeader(Request request, String header) Retrieves the value of the specified header from the request, handling null and "(null)" values.voidsetSslCipherHeader(String sslCipherHeader) Sets the header name used to retrieve the cipher suite.voidsetSslCipherUserKeySizeHeader(String sslCipherUserKeySizeHeader) Sets the header name used to retrieve the cipher key size.voidsetSslClientCertHeader(String sslClientCertHeader) Sets the header name used to retrieve the client certificate.voidsetSslClientEscapedCertHeader(String sslClientEscapedCertHeader) Sets the header name used to retrieve the escaped client certificate.voidsetSslSessionIdHeader(String sslSessionIdHeader) Sets the header name used to retrieve the SSL session ID.Methods inherited from class ValveBase
backgroundProcess, getContainer, getDomainInternal, getNext, getObjectNameKeyProperties, initInternal, isAsyncSupported, setAsyncSupported, setContainer, setNext, startInternal, stopInternal, toStringMethods inherited from class LifecycleMBeanBase
destroyInternal, getDomain, getObjectName, postDeregister, postRegister, preDeregister, preRegister, register, setDomain, unregister, unregisterMethods inherited from class LifecycleBase
addLifecycleListener, destroy, findLifecycleListeners, fireLifecycleEvent, getState, getStateName, getThrowOnFailure, init, removeLifecycleListener, setState, setState, setThrowOnFailure, start, stop
-
Constructor Details
-
SSLValve
public SSLValve()Default constructor.
-
-
Method Details
-
getSslClientCertHeader
Returns the header name used to retrieve the client certificate.- Returns:
- The client certificate header name
-
setSslClientCertHeader
Sets the header name used to retrieve the client certificate.- Parameters:
sslClientCertHeader- The client certificate header name
-
getSslClientEscapedCertHeader
Returns the header name used to retrieve the escaped client certificate.- Returns:
- The escaped client certificate header name
-
setSslClientEscapedCertHeader
Sets the header name used to retrieve the escaped client certificate.- Parameters:
sslClientEscapedCertHeader- The escaped client certificate header name
-
getSslCipherHeader
Returns the header name used to retrieve the cipher suite.- Returns:
- The cipher header name
-
setSslCipherHeader
Sets the header name used to retrieve the cipher suite.- Parameters:
sslCipherHeader- The cipher header name
-
getSslSessionIdHeader
Returns the header name used to retrieve the SSL session ID.- Returns:
- The session ID header name
-
setSslSessionIdHeader
Sets the header name used to retrieve the SSL session ID.- Parameters:
sslSessionIdHeader- The session ID header name
-
getSslCipherUserKeySizeHeader
Returns the header name used to retrieve the cipher key size.- Returns:
- The cipher key size header name
-
setSslCipherUserKeySizeHeader
Sets the header name used to retrieve the cipher key size.- Parameters:
sslCipherUserKeySizeHeader- The cipher key size header name
-
mygetHeader
Retrieves the value of the specified header from the request, handling null and "(null)" values.- Parameters:
request- The request objectheader- The header name to retrieve- Returns:
- The header value, or null if not present or equal to "(null)"
-
invoke
Description copied from interface:ValvePerform request processing as required by this Valve.
An individual Valve MAY perform the following actions, in the specified order:
- Examine and/or modify the properties of the specified Request and Response.
- Examine the properties of the specified Request, completely generate the corresponding Response, and return control to the caller.
- Examine the properties of the specified Request and Response, wrap either or both of these objects to supplement their functionality, and pass them on.
- If the corresponding Response was not generated (and control was not returned), call the next Valve in the
pipeline (if there is one) by executing
getNext().invoke(). - Examine, but not modify, the properties of the resulting Response (which was created by a subsequently invoked Valve or Container).
A Valve MUST NOT do any of the following things:
- Change request properties that have already been used to direct the flow of processing control for this request (for instance, trying to change the virtual host to which a Request should be sent from a pipeline attached to a Host or Context in the standard implementation).
- Create a completed Response AND pass this Request and Response on to the next Valve in the pipeline.
- Consume bytes from the input stream associated with the Request, unless it is completely generating the response, or wrapping the request before passing it on.
- Modify the HTTP headers included with the Response after the
getNext().invoke()method has returned. - Perform any actions on the output stream associated with the specified Response after the
getNext().invoke()method has returned.
- Parameters:
request- The servlet request to be processedresponse- The servlet response to be created- Throws:
IOException- if an input/output error occurs, or is thrown by a subsequently invoked Valve, Filter, or ServletServletException- if a servlet error occurs, or is thrown by a subsequently invoked Valve, Filter, or Servlet
-