tomcat-users mailing list archives

Site index · List index
Message view « Date » · « Thread »
Top « Date » · « Thread »
From Christopher Schultz <>
Subject Re: how to auto redirect to https from http
Date Thu, 07 Feb 2008 16:07:18 GMT
Hash: SHA1


Dave wrote:
|   I moved the <user-data-constraint> inside the
<web-resource-collection> as the following:
|        <security-constraint>
|                 <web-resource-collection>
|                         <web-resource-name>Automatic SLL
|                         <url-pattern>/login.html</url-pattern>
|                         <user-data-constraint>
|                         </user-data-constraint>
|                 </web-resource-collection>
|         </security-constraint>
|   But  did not redirect to secure URL.


It's possible that Tomcat ignores that setting during its own
authentication process (which would suck if it were the case). What the
the URL say when you are being asked to login?

| As you mentioned, If I start as http, then redirect to https when
| login, and keep https after login. Does that mean https is using the
| http session?

Well, it's not a "http session" per-se... it's the session that was
created while you were in http mode. The answer is yes: Tomcat will
continue to use that session. If, however, you kill any sessions
(yourself) as you switch to https, then any fallback to http will lose
the session (because the browser will refuse to send a "secure" cookie
through a non-secure channel.

| Is there any security hole? If a man-in-the-middle knows the session
| id from http and the same session id is used by https?

This does not require man-in-the-middle. It's just plain-old session
hijacking. This can happen whether you are using SSL or not -- if
someone can guess your session id, you're pwned.

- -chris
Version: GnuPG v1.4.8 (MingW32)
Comment: Using GnuPG with Mozilla -


To start a new topic, e-mail:
To unsubscribe, e-mail:
For additional commands, e-mail:

View raw message