Return-Path: X-Original-To: archive-asf-public-internal@cust-asf2.ponee.io Delivered-To: archive-asf-public-internal@cust-asf2.ponee.io Received: from cust-asf.ponee.io (cust-asf.ponee.io [163.172.22.183]) by cust-asf2.ponee.io (Postfix) with ESMTP id 438AB200D54 for ; Fri, 8 Dec 2017 17:41:35 +0100 (CET) Received: by cust-asf.ponee.io (Postfix) id 41F3C160C0D; Fri, 8 Dec 2017 16:41:35 +0000 (UTC) Delivered-To: archive-asf-public@cust-asf.ponee.io Received: from mail.apache.org (hermes.apache.org [140.211.11.3]) by cust-asf.ponee.io (Postfix) with SMTP id 6179D160BFD for ; Fri, 8 Dec 2017 17:41:34 +0100 (CET) Received: (qmail 44963 invoked by uid 500); 8 Dec 2017 16:41:32 -0000 Mailing-List: contact users-help@tomcat.apache.org; run by ezmlm Precedence: bulk List-Help: List-Unsubscribe: List-Post: List-Id: Reply-To: "Tomcat Users List" Delivered-To: mailing list users@tomcat.apache.org Received: (qmail 44952 invoked by uid 99); 8 Dec 2017 16:41:32 -0000 Received: from pnap-us-west-generic-nat.apache.org (HELO spamd3-us-west.apache.org) (209.188.14.142) by apache.org (qpsmtpd/0.29) with ESMTP; Fri, 08 Dec 2017 16:41:32 +0000 Received: from localhost (localhost [127.0.0.1]) by spamd3-us-west.apache.org (ASF Mail Server at spamd3-us-west.apache.org) with ESMTP id 52605180162 for ; Fri, 8 Dec 2017 16:41:32 +0000 (UTC) X-Virus-Scanned: Debian amavisd-new at spamd3-us-west.apache.org X-Spam-Flag: NO X-Spam-Score: 2.629 X-Spam-Level: ** X-Spam-Status: No, score=2.629 tagged_above=-999 required=6.31 tests=[DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, HTML_MESSAGE=2, KAM_LOTSOFHASH=0.25, RCVD_IN_DNSWL_NONE=-0.0001, RCVD_IN_MSPIKE_H3=-0.01, RCVD_IN_MSPIKE_WL=-0.01, RCVD_IN_SORBS_SPAM=0.5, SPF_PASS=-0.001] autolearn=disabled Authentication-Results: spamd3-us-west.apache.org (amavisd-new); dkim=pass (2048-bit key) header.d=gmail.com Received: from mx1-lw-us.apache.org ([10.40.0.8]) by localhost (spamd3-us-west.apache.org [10.40.0.10]) (amavisd-new, port 10024) with ESMTP id m9urQKodpV6B for ; Fri, 8 Dec 2017 16:41:30 +0000 (UTC) Received: from mail-qt0-f169.google.com (mail-qt0-f169.google.com [209.85.216.169]) by mx1-lw-us.apache.org (ASF Mail Server at mx1-lw-us.apache.org) with ESMTPS id 0FB1E5F3D1 for ; Fri, 8 Dec 2017 16:41:30 +0000 (UTC) Received: by mail-qt0-f169.google.com with SMTP id f2so27292504qtj.4 for ; Fri, 08 Dec 2017 08:41:30 -0800 (PST) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20161025; h=mime-version:in-reply-to:references:from:date:message-id:subject:to; bh=wr+pj3wmd6mo8Q0zMSorsu1xlpjrDgAKAiWZrLSY+Cc=; b=NRXEG/atZqKpxxH1msSVRm8y54tzTMUS6AEQDUApx/n6gIZNpgohpY4FrvQMsxOeFE n3A3Q2n5CnHHdmemGNbGMZdkCK10nxjDqBV++H6LQVZNj8QvXftjxJtraOoUD78TVS5l wJ0gRHFE4Ye+shbShIq3+La+rWHpQTjxHiSJCIUOmYJxAvOgJsBU4XUKHKXIfTGZ6913 wpAsT2cgpc+PvXOVuSPOT3nirqZxwQ7w0P1nBmt4nLkKFrc0bGSPa0sjVxngrN545DVg pXKhoyVif5ZwCF2j4oZM67lMDFKgqcDW1LqnTbJOOJA6bUMgn4kdwliemSN5vqMmb1ak hoBw== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20161025; h=x-gm-message-state:mime-version:in-reply-to:references:from:date :message-id:subject:to; bh=wr+pj3wmd6mo8Q0zMSorsu1xlpjrDgAKAiWZrLSY+Cc=; b=L4TCNyl2F1262JCx6cFFpNXK1jXmfyzjIAeToGl4GBXvMXQl3+UO24xcLJIks6h0if R+wJXQxrnlQXbYEjb2GVkdEhgECk/awQBdHrwjw/kYN4Mp3jqswkjjVJk70EzrHDXkKc daG6craXkNT9y3rH0NsvNYyyQGjZ5BwLNsvVc/yQO2ino7p6afLMxbilg2MRvzmXo9rX 4gFO5Uz545bjsBKJdB7p/HGr/N7BDiXYXL372fDDJSc8+hqwR0Y91RyjCrgsQ3rE9O6T HfSWMl3PM2X9gt4rFM6xSSH+i/bBkjHl+FRmPqOnXp2OftYAKPhkShWfTrXKiz4YrBdh 4WPQ== X-Gm-Message-State: AKGB3mJEXbyrE/LJHD7QBFrKSXe44Dffa1Rvu0ACPKp1pOc0tyhEAK4L uqjYsxioD3CIHX8lOVWV5SCzCX3DL3eKJTnTf1G2cw== X-Google-Smtp-Source: ACJfBouic2G3Q3SJCXVC+vyuIWoDOSsBGYULvwwe7Au2MoB+pAbrElar4VBzkgoammpmU2tLJuVVRExPvP/XLT8STYU= X-Received: by 10.55.197.133 with SMTP id k5mr3999600qkl.223.1512751288834; Fri, 08 Dec 2017 08:41:28 -0800 (PST) MIME-Version: 1.0 Received: by 10.12.147.34 with HTTP; Fri, 8 Dec 2017 08:40:48 -0800 (PST) In-Reply-To: References: From: "Robert J. Carr" Date: Fri, 8 Dec 2017 08:40:48 -0800 Message-ID: Subject: Re: Configuring DIGEST auth for manager To: Tomcat Users List Content-Type: multipart/alternative; boundary="001a1149af6234606e055fd6db2b" archived-at: Fri, 08 Dec 2017 16:41:35 -0000 --001a1149af6234606e055fd6db2b Content-Type: text/plain; charset="UTF-8" Content-Transfer-Encoding: quoted-printable Hi Philippe- I'm new to the list, and didn't see the previous response either, but I just did this recently do a similar config so I might have some guidance. Where you have algorithm=3D"*SHA-256*", for digest.sh too, you shouldn't ne= ed the asterisks. Why are you using those? > Set the last part of password following "password1234:" in This should also include the iterations. It should be something like: $1$b9c950640e1b3740e98acb93e669c65766f6670dd1609ba91ff41052ba48c6f3 Good luck! Robert On Fri, Dec 8, 2017 at 12:59 AM, Philippe Mouawad < p.mouawad@ubik-ingenierie.com> wrote: > > Hi Mark, > Sorry but I didn't receive the reply otherwise I wouldn't be asking again= . > I'll see the archives then. > > Thanks > Regards > > On Fri, Dec 8, 2017 at 9:20 AM, Mark Thomas wrote: > > > On 07/12/17 21:24, Philippe Mouawad wrote: > > > Hello, > > > Last ping hoping to get some help. > > > > If you aren't going to read the replies Chris has already given you to > > your original question and your subsequent ping there isn't much more w= e > > can do to help you. > > > > Mark > > > > > > > > > > Thanks > > > > > > On Wed, Nov 8, 2017 at 10:19 PM, Philippe Mouawad < > > > p.mouawad@ubik-ingenierie.com> wrote: > > > > > >> Hello, > > >> Any feedback on this ? > > >> Thanks > > >> > > >> On Sun, Nov 5, 2017 at 9:16 PM, Philippe Mouawad < > > >> p.mouawad@ubik-ingenierie.com> wrote: > > >> > > >>> Hello, > > >>> I am having issues making Digest auth work in Tomcat 8.5.23 for manager > > >>> application. > > >>> > > >>> I have done the following: > > >>> > > >>> 1) Edit server.xml and have set MessageDigestCredentialHandler with > > >>> SHA-256 > > >>> > > >>> > > >>> > >>> resourceName=3D"*UserDatabase*"> > > >>> > >>> .realm.MessageDigestCredentialHandler" algorithm=3D"*SHA-256*" /> > > >>> > > >>> > > >>> > > >>> 2) Generated password using: > > >>> ./digest.sh -a *SHA-256* -h org.apache.catalina.realm. > > MessageDigestCredentialHandler > > >>> -i 1 -s 0 password1234 > > >>> > > >>> I also tried : > > >>> ./digest.sh -a SHA-256 -h org.apache.catalina.realm. > > MessageDigestCredentialHandler > > >>> -i 1 -s 0 tomcat:UserDatabase:password1234 > > >>> > > >>> 3) Set the last part of password following "password1234:" in > > >>> tomcat-users.xml > > >>> > > >>> > > >>> > > >>> > >>> cb93e669c65766f6670dd1609ba91ff41052ba48c6f3" > > >>> roles=3D"manager-gui,admin,manager"/> > > >>> > > >>> 4) Edit /webapps/manager/WEB-INF/web.xml > > >>> > > >>> > > >>> DIGEST > > >>> UserDatabase > > >>> > > >>> > > >>> I then try to login to http://localhost:8080/manager/html and enter > > >>> admin and password1234 > > >>> it fails. > > >>> > > >>> There must be something I am missing. > > >>> > > >>> Sorry if I misread some documentation or if my question is stupid, > > these > > >>> are the docs I have seen: > > >>> - https://tomcat.apache.org/tomcat-8.5-doc/config/credentialha > > >>> ndler.html#MessageDigestCredentialHandler Note the start of this part > > is > > >>> not that clear for me. I think my format is > > >>> *salt$iterationCount$encodedCredential* - a hex encoded salt, > > iteration > > >>> code and a hex encoded credential, each separated by $ > > >>> > > >>> I have also tried solutions described here without success: > > >>> - http://www.techpaste.com/2013/05/enable-password-encryption- > > >>> policy-tomcat-7/ > > >>> - https://stackoverflow.com/questions/39967289/how-to-use-dige > > >>> st-authentication-in-tomcat-8-5 > > >>> - https://stackoverflow.com/questions/2978884/tomcat-digest-wi > > >>> th-manager-webapp > > >>> > > >>> Regards > > >>> Philippe > > >>> > > >> > > >> > > >> > > >> -- > > >> Cordialement. > > >> Philippe Mouawad. > > >> Ubik-Ing=C3=A9nierie > > >> > > >> UBIK LOAD PACK Web Site > > >> > > >> UBIK LOAD PACK on TWITTER > > >> > > >> > > > > > > > > > > > > > -- > Cordialement. > Philippe Mouawad. > Ubik-Ing=C3=A9nierie > > UBIK LOAD PACK Web Site > > UBIK LOAD PACK on TWITTER --001a1149af6234606e055fd6db2b--