Thursday, May 30, 2013

Setup Tomcat 7 port redirects


*This guide is for a CentOS 6 (or Red Hat derivatives) server that has Tomcat 7. No Apache or any other web servers are installed. (Just Tomcat)

*Must be as root

Redirect traffic from 80 to 8080:
"iptables -t nat -A PREROUTING -p tcp --dport 80 -j REDIRECT --to-ports 8080"
"iptables -t nat -A OUTPUT -p tcp --dport 80 -lo -j REDIRECT --to-port 8080"

Redirect traffic from 443 to 8443:

"iptables -t nat -A PREROUTING -p tcp --dport 443 -j REDIRECT --to-ports 8443"
"iptables -t nat -A OUTPUT -p tcp --dport 443 -lo -j REDIRECT --to-port 8443"

Then save your changes
"/sbin/service iptables save"

You can verify the changes, if you look in the config file for iptables:
"vi /etc/sysconfig/iptables"

Now in Tomcat 7 "server.xml" a minor configuration must be set. Here is the configuration for Tomcat to work with port 8080.
<Connector compression="on" connectiontimeout="20000" connector="" port="8080" protocol="HTTP/1.1" redirectport="443"/>

redirectPort must be set to 443. This option is used if your Java web application has the restriction of only allowing secured connection. Thus if Tomcat receives a request for that application on port 8080 Tomcat will reply by redirecting the request to port 443. Which means that the Tomcat server must have configuration set to work with SSL.
Here is the configuration for Tomcat to work with SSL 
<Connector clientauth="false" compression="on" keystorefile="YOUR KEYSTORE FILE LOCATION" keystorepass="KEYSTORE PASSWORD" maxthreads="200" port="8443" protocol="HTTP/1.1" scheme="https" secure="true" sslenabled="true" sslprotocol="TLS"/>

You might ask why is Tomcat listening on 8443 and 8080 when the traffic will be on 80 and  443? Well that's where Iptables comes into play. All traffic that comes in at port 80/443 will be redirected to 8080/8443 respectively.

Besides making the installation of the Tomcat server a little easier and a step in the right direction in setting it up as a production server.  Having the ability to run Tomcat with a restricted user instead of root is a good start for securing your server. Security is very important now a days, if things can be simple and still be secure then DO IT!

Wednesday, July 07, 2010

Glassfish v3 with ssl (using verisign certificate)

Step by step guide on how to enable SSL on a Glassfish server.

1) create the keystore with this command (this is found in the jdk/bin)
keytool -genkey -alias test -keysize 2048 -keyalg RSA -keystore mykeystore.jks -dname "CN=www.testsite.hn, OU=testing, O=Org namel, L=City name, S=State, C=country"

*remember the CN is the url you wish to cerftify so place it as wished.

2)
*Create the request that versign needs
keytool -certreq -alias test -keystore mykeystore.jks -file testserver.cer

3)
Get all 3 certificates that versign gives you as following
*Save the email certificate as email.cer,
*Save the intermediate certificate as intermediate.cer
*Save the root certificate as root.cer
*perform the next steps, you can just copy & paste on the commandline

keytool -import -alias verisigncert -keystore mykeystore.jks -trustcacerts -file root.cer

keytool -import -alias verisigninter -keystore mykeystore.jks -trustcacerts -file intermediate.cer

keytool -import -alias test-server -keystore mykeystore.jks -trustcacerts -file email.cer

*Once that is done, go to and place the mykeystore.jks at glassfish/domain/domainX folder (domainX is the domain you wish the certificate to work at)

4)
*Now we configure the ssl, to make this simple go and use the web admin consule, go to network config/Network Listener/http-listener-2
-Enable security
-port to listen 443 (MAKE SURE NO OTHER APP HAS USED THIS PORT)

* Go to the SSL tab
Certificate NickName: test
Key Store: mykeystore.jks

5)
*Go to the virtual servers and add
hosts:www.testsite.hn
(Has to be the same as the CN in the first step)
(Set the app as the default app for the url)
Default Web Module: YOURapp

6)
* if your under windows go to windows/system32/drivers/hots and add
127.0.0.1 www.testsite.hn

7) *restart glassfish and run your app

Wednesday, February 11, 2009

LINEH V1

LINEH (Linux en las escuelas de Honduras)

El sistema operativo brinda asistencia a los maestros y alumnos en sus actividades diarias dentro y fuera de las escuelas. Esta asistencia se brinda por medio de varias configuraciones y programas, son estas configuraciones y programas que permiten a los usuarios dedicarse a su labor y no preocuparse en lo que ocupen para realizarlo.
Este sistema operativo es un derivado de Ubuntu Hardy. Por lo cual se puede instalar programas que se encuentran dentro de sus servidores.



Dentro muy poco se va publicar la pagina web.

Actualmente esta distribución se puede obtener por medio de torrent en www.mininova.org.
Al igual se puede encontrar en los siguientes links directos.
media Fire
florida dns

La meta distribución fue creada por mi parte, como mi proyecto de graduación. Pretendo seguir dándole mantenimiento a el. Lo cual sera de gran ayuda sus comentarios.

Problemas conocidos:

Existen 2 URLS de los repositorios que estan obsoletos y daran error al actualizar. Se tiene que eliminar los siguientes urls:
  • http://ppa.launchpad.net/network-manager/ubuntu hardy main
  • http://ppa.launchpad.net/openoffice-pkgs/ubuntu hardy main