TLS termination, forwarded identity và AJP
Proxy headers là security boundary: client có thể tự gửi chúng nếu edge không strip/overwrite và Tomcat trust scope quá rộng.
Edge trust
Direct TLS
SSLHostConfig quản certificate, protocols, ciphers, client authentication và SNI. JSSE/OpenSSL implementation availability phụ thuộc runtime. Test chain, hostname, expiry/rotation, ALPN và rejected legacy protocols—not chỉ browser success.
Termination topology
Edge termination đơn giản hóa key ownership; re-encrypt hoặc mTLS bảo vệ/trust hop nội bộ khi threat model yêu cầu. Backend scheme/port phải phản ánh original request để redirect, absolute URL và secure cookie đúng.
RemoteIpValve
Valve chỉ nhận forwarded chain từ internal/trusted proxies và cần proxy strip/overwrite input. Test direct client spoof, nhiều proxy hop, malformed chain và framework double-processing. Audit phải lưu derived IP cùng trust context.
AJP
Chỉ enable nếu architecture cần; bind private interface, firewall và dùng secret theo documentation. HTTP reverse proxy thường đủ và dễ quan sát hơn. Patch current version và disable unused connector để giảm attack surface.