Pages

Showing posts with label Tomcat 7. Show all posts
Showing posts with label Tomcat 7. Show all posts

Sunday, September 23, 2018

Jenkins - Integrating with Tomcat

As a part of CI/CD , Some time Jenkins will be doing the part of the Deployment tool. Jenkins multiple plunges to deploy packages to different types of end points. One of the normal use case is to deploy your java war package to a web server like tomcat. In this article we will see how one can deploy a java war file to a tomcat server. For the demo purpose we will be using the “Deploy to a container” plugin.

1.Install the Plugin from the Manage Jenkins -> Package Manager 
2. We don’t need to configure any thing for this plugin. 
3. This plugin supports deployment to multiple containers like jboss, tomcat etc 
4. Go to your maven job , and Select “Deploy ear/war to a Container” and we will see seeing a window like below attached, 
We need to fill some of the fields in the window as, 
War/Ear file location 
Context path to deploy to container 
Now choose the container ( tomcat 7.x here ) and fill the details of the url where that server can be accessed and also credentials to login to the machine. Once done , run the job and we can see that the war file is deployed to the tomcat and can be see with the same context that we have given. 

Note - There are few issues with the tomcat roles while configuring this plugin. The role and user in tomcat should be configured correctly to enable the communication between Jenkins and Tomcat. 

Below is the my configuration in the tomcat-user.xml file for more details. Iam using the “system/system” credentials configured in Jenkins for accessing the server. 
 <role rolename="manager-gui"/> 
<role rolename="manager-script"/> 
<user username="tomcat" password="tomcat" roles="manager-script,manager-gui,admin-gui"/> 
<user username="system" password="system" roles=“manager-script,admin-script,manager-gui"/> 

More to Come ,Happy learning :-) 

Read More

Tuesday, June 30, 2015

Tomcat 7 Additional features

Here are the some of the additional features of Tomcat 7 with previous versions

1) Embeddeding tomcat has become more easier than 6. This helps in integration tests

2) Tomcat cache control - Tomcat 7 provides you a ExpiresFilter that will determine the caching behavior of the clients. This filter controls the setting of the Expires HTTP header and the max-age directive of the Cache-Control HTTP header in server responses.

3) Tomcat 7 has the Servlet 3 specs. This allows the programmatic configuration includeing for elements in web.xml

4) error-on-undeclared-namespace - The default behavior when a tag with unknown namespace is used in a JSP page (regular syntax) is to silently ignore it. If this is set to true then an error must be raised during the translation time.

5) MemoryLeak protection -  It’s implemented as a listener which tries to detect and fix the possible memory leaks whenever it can

6) Tomcat 7 provides new aliases that allow storing static content outside the WAR File.

7) A new security feature for Apache Tomcat 7 is Session Fixation Protection. Essentially, when a user authenticates their session, Tomcat will change the session ID. It does not destroy the previous session , rather it renames it so it is no longer found by that ID. 

8) One of the new features with Tomcat 7 is a replacement to the commons-dbcp connection pool. While the commons-dbcp connection pool works fine for small or low traffic applications, it is known to have problems in highly concurrent environments .It is a completely new connection pool which has been written from the ground up, with a focus on highly concurrent environments and performance.

9) The Apache JServ Protocol (AJP) , is a binary protocol that can proxy inbound requests from a web server. Typically used in load balanced web applications where the web server has to pass requests to multiple application servers. New I/O, usually shortened to NIO, is a set of Java APIs that allow for more scalable I/O operations. Among other things, NIO provides support for non-blocking of data connections which ensures a response from the application server. Without NIO, admins must configure their web servers and application servers to match the number of threads between the web server and application server.

10) Adding of Crawler Session Manager Valve

11) Parallel deployment is supported

14) Use a LockOutRealm. Now standard by default in Tomcat 7, this realm simply protects your application from brute force attacks by locking out the offending account after a number of unsuccessful attempts.

14) Access log enabled by default

15) Instead of using a path of "/foo" like Tomcat 6 did, Tomcat 7 will add a trailing slash to the cookie path, or "/foo/".  This can be disabled, it turns out, by setting the sessionCookiePathUsesTrailingSlash flag to "false" on the <Context> element –

16) Jarscanner element was added which will scan all the jars in the web application lib location. This can be disabled by adding scanpath=false in context.xml

17) useHttpOnly set to false in 6 and true in 7

18)  Tomcat 7 has File upload support will enable Tomcat users to use file upload functionality within their web applications with the need for additional libraries

19) Tomcat 7 manager application has a ‘find Leak’ Button which enables a Full GC and also finds the leaks.

20) Deploying from Command line is changed by adding a “text” like
http://{host}:{port}/manager/text/{command}?{parameters}


Hope this Helps, More to come.
Read More

Identify Tomcat version

While working with Tomcat server, there are needs where we need to check for the version of the Tomcat. We will see how many ways available for finding the version of the tomcat.

1)  [root@localhost bin]# ./catalina.sh version
Using CATALINA_BASE:   /work/tomcat
Using CATALINA_HOME:   /work/tomcat
Using CATALINA_TMPDIR: /work/tomcat/temp
Using JRE_HOME:        /root/jrockit/
Using CLASSPATH:       /work/tomcat/bin/bootstrap.jar:/work/tomcat/bin/tomcat-juli.jar
Server version: Apache Tomcat/7.0.62
Server built:   May 7 2015 17:14:55 UTC
Server number:  7.0.62.0
OS Name:        Linux
OS Version:     3.10.0-123.el7.x86_64
Architecture:   amd64
JVM Version:    1.6.0_45-b06
JVM Vendor:     Oracle Corporation

2) [root@localhost lib]# java -cp catalina.jar org.apache.catalina.util.ServerInfo
Server version: Apache Tomcat/7.0.62
Server built:   May 7 2015 17:14:55 UTC
Server number:  7.0.62.0
OS Name:        Linux
OS Version:     3.10.0-123.el7.x86_64
Architecture:   amd64
JVM Version:    1.7.0_51-mockbuild_2014_04_04_16_39-b00
JVM Vendor:     Oracle Corporation

3) [root@localhost bin]# ./version.sh
Using CATALINA_BASE:   /work/tomcat
Using CATALINA_HOME:   /work/tomcat
Using CATALINA_TMPDIR: /work/tomcat/temp
Using JRE_HOME:        /root/jrockit/
Using CLASSPATH:       /work/tomcat/bin/bootstrap.jar:/work/tomcat/bin/tomcat-juli.jar
Server version: Apache Tomcat/7.0.62
Server built:   May 7 2015 17:14:55 UTC
Server number:  7.0.62.0
OS Name:        Linux
OS Version:     3.10.0-123.el7.x86_64
Architecture:   amd64
JVM Version:    1.6.0_45-b06
JVM Vendor:     Oracle Corporation

Read More

Monday, October 20, 2014

Tomcat Version Change

While working with Tomcat, we observed that Tomcat displays Error Page which has the Tomcat version on it. When ever we call a page which is not available , the tomcat server will push a Error page along with the version like














The Error page will also display the Version of the apache which may allow people to exploit the server since old tomcat server has some known exploits.

In this article we will see how we can change the version number on the error page to a different one.

Create a Directory location in  Tomcat Server lib location as
mkdir –p /lib/org/apache/catalina/util/

In the util location, create a properties file as
[root@localhost util]# cat ServerInfo.properties
server.info=Apache Tomcat Version XXX

Now restart tomcat and access a application which is not available and we will see this,


Read More

Friday, September 19, 2014

Custom Error Page in Tomcat

Recently we were faced with a issue where we need to configure a Custom error page for tomcat. When there is a issue with any of the application running in tomcat or tomcat going down, we usually used to show error pages from  the front end web server.

But we want to give the application teams more information on the error and also information like the tomcat name where the application was running and also more information on the error.

While trying to configure a Generic 404 Page for all application running inside a Tomcat Container , Here are my findings

1. Custom Error Pages can be configured from the Server side but it will not work for all applications running. We can write our own Error page and ask the application teams to include that error page in their war files ( also enable in the web.xml )

2. Another Option is to develop a sample web application which holds the Custom Error pages and display then whenever we see Exceptions but this requires to push application to all existing containers

3. The Third Option since we use the web server proxies traffic back to Tomcat.  we can use the ProxyErrorOverride directive in Apache HTTP server and with this setting the web server intercepts any traffic coming back from Tomcat that has an error status code (codes 400-599) and replaces it with custom error pages you define on the web server layer.

4. The other options is to customize the Error Reporting. We do have something called as Valve available in Tomcat Container. The Valve Element represents a Component that will be inserted into the request processing for a associated Cataline container like Engine , Host and Context. We are provided with a Valve called ErrorReportValve Which helps in generating Custom Error Messages. I have  Written a Sample code by extending the ErrorReportValve.

Here is the Code

import org.apache.catalina.connector.Request;
import org.apache.catalina.connector.Response;
import org.apache.catalina.valves.ErrorReportValve;

public class ErrorPage extends ErrorReportValve{

    @Override
    protected void report(Request request, Response response, Throwable t) {
        try {
                  
                   int statusCode = response.getStatus();
                   PrintWriter out=response.getWriter();
                   out.write("<html><head><title>Error Page : 404</title><body>");
                   out.write("Date : "+new java.util.Date());
                   out.write("Instance Name : "+System.getProperties().getProperty("jbs.name","unknown"));
                   out.write("Description : Requested Resource is Not Available");
                   out.write("</body></html>");
                  
        } catch (IOException e) {
            e.printStackTrace();
        }
    }
}

Make a Jar of this Code , copy to the Server/Lib. Now add the Valve Element to the Host in Tomcat Server.xml file as

<Host appBase="webapps" autoDeploy="true" name="localhost" unpackWARs="true" xmlNamespaceAware="false" xmlValidation="false" errorReportValveClass="com.uprr.custom.error.ErrorPage">
</Host>


Now when ever there is 404 , the Custom error message is Shown as

Read More