Supplement · Tomcat

TLS termination, forwarded identity và AJP

Proxy headers là security boundary: client có thể tự gửi chúng nếu edge không strip/overwrite và Tomcat trust scope quá rộng.

Edge trust

Direct TLS

SSLHostConfig quản certificate, protocols, ciphers, client authentication và SNI. JSSE/OpenSSL implementation availability phụ thuộc runtime. Test chain, hostname, expiry/rotation, ALPN và rejected legacy protocols—not chỉ browser success.

Termination topology

Edge termination đơn giản hóa key ownership; re-encrypt hoặc mTLS bảo vệ/trust hop nội bộ khi threat model yêu cầu. Backend scheme/port phải phản ánh original request để redirect, absolute URL và secure cookie đúng.

RemoteIpValve

Valve chỉ nhận forwarded chain từ internal/trusted proxies và cần proxy strip/overwrite input. Test direct client spoof, nhiều proxy hop, malformed chain và framework double-processing. Audit phải lưu derived IP cùng trust context.

AJP

Chỉ enable nếu architecture cần; bind private interface, firewall và dùng secret theo documentation. HTTP reverse proxy thường đủ và dễ quan sát hơn. Patch current version và disable unused connector để giảm attack surface.

SSL/TLS HOW-TO · Remote IP Valve · AJP Connector
← SessionsSecurity →