Re: RemoteAddrValve | IP Subnet

2018-11-01 Thread Christopher Schultz
-BEGIN PGP SIGNED MESSAGE- Hash: SHA256 André, On 11/1/18 09:23, André Warnier (tomcat) wrote: > On 01.11.2018 13:34, Mark Thomas wrote: >> On 01/11/2018 12:23, André Warnier (tomcat) wrote: >>> On 01.11.2018 12:35, Madhur Khurana wrote: Hi, I am using tomcat8 and would li

Re: RemoteAddrValve | IP Subnet

2018-11-01 Thread tomcat
On 01.11.2018 13:34, Mark Thomas wrote: On 01/11/2018 12:23, André Warnier (tomcat) wrote: On 01.11.2018 12:35, Madhur Khurana wrote: Hi, I am using tomcat8 and would like to configure ip address with subnet in RemoteAddrValve for IP whitelisting (Example: 0.0.0.0/0). Can anyone help in how to

Re: RemoteAddrValve | IP Subnet

2018-11-01 Thread Mark Thomas
On 01/11/2018 12:23, André Warnier (tomcat) wrote: > On 01.11.2018 12:35, Madhur Khurana wrote: >> Hi, >> >> I am using tomcat8 and would like to configure ip address with subnet >> in RemoteAddrValve for IP whitelisting (Example: 0.0.0.0/0). Can >> anyone help in how to configure subnet in allow f

Re: RemoteAddrValve | IP Subnet

2018-11-01 Thread tomcat
On 01.11.2018 12:35, Madhur Khurana wrote: Hi, I am using tomcat8 and would like to configure ip address with subnet in RemoteAddrValve for IP whitelisting (Example: 0.0.0.0/0). Can anyone help in how to configure subnet in allow field. The page at http://tomcat.apache.org/tomcat-8.5-doc/co

Re: RemoteAddrValve block ip-ranges

2012-03-08 Thread Christopher Schultz
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 Thomas, On 3/8/12 4:47 AM, Thomas Scheer wrote: > Is there a way to block whole countries (e.g. Sudan) by ip-ranges > and/or CIDR data? (in regex it would be a mess of data) My spidey sense it tingling. I swear we discussed this. Aah, here it is: ht

Re: RemoteAddrValve block ip-ranges

2012-03-08 Thread André Warnier
Thomas Scheer wrote: Hi, Is there a way to block whole countries (e.g. Sudan) by ip-ranges and/or CIDR data? (in regex it would be a mess of data) In CIDR Format: # Country: SUDAN # ISO Code: SD # Total Networks: 19 # Total Subnets: 283,904 41.67.0.0/18 41.78.108.0/22 41.79.24.0/22 41.79.120.0/

Re: RemoteAddrValve syntax

2009-04-05 Thread Jonathan Mast
I looked at the javadocs for the RemoteAddrValve and they provided no further clarity on the syntax issue. You're right, my test case mistakenly returned a false positive, ".*" could match anything its true and their is no "common sense" wildcard in the Java Regex package. I looked at the javadoc

Re: RemoteAddrValve syntax

2009-04-05 Thread André Warnier
André Warnier wrote: [...] To match any address starting with "192.168.", use or (if you want to be really finicky about it) What is not very clear in the on-line Tomcat documentation, is whether a remote client address of 192.168.1.2 would be translated to the string "192.168.1.2" by Tomca

RE: RemoteAddrValve syntax

2009-04-05 Thread Caldarale, Charles R
> From: Jonathan Mast [mailto:jhmast.develo...@gmail.com] > Subject: RemoteAddrValve syntax > > The Tomcat docs says it uses the java.util.regex package But you apparently didn't read the doc for java.util.regex, which is not anything like the wildcards you tried to use: http://java.sun.com/j2se

Re: RemoteAddrValve syntax

2009-04-05 Thread André Warnier
Jonathan Mast wrote: How do I specify wildcards in the RemoteAddrValue declaration? The Tomcat docs says it uses the java.util.regex package, so i wrote a test case like this: String patternStr = "192.168.*.*"; String searchStr = "192.168.1.2"; Pattern p = Pattern.compi

Re: RemoteAddrValve and RemoteHostValve

2009-03-06 Thread Christopher Schultz
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 Ed, On 3/5/2009 12:02 PM, Edward Song wrote: > Regardless, I recently wrote a java filter to filter IP's at the application > level, which replicates the valve functionality. > http://j2eewebprogrammer.blogspot.com/2008/12/filtering-ip-traffic-using-j

Re: RemoteAddrValve and RemoteHostValve

2009-03-05 Thread Edward Song
I'm always a few days behind the thread, but wanted to share. If I had only known that I can configure the Valve at the Context level (from Chuck's prior email). Regardless, I recently wrote a java filter to filter IP's at the application level, which replicates the valve functionality. http://j2

Re: RemoteAddrValve and RemoteHostValve

2009-03-02 Thread Christopher Schultz
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 Zak, On 2/27/2009 9:28 PM, Zak Mc Kracken wrote: > I'd like to filter incoming requests with this criterion: > > if it's www.somewhere.com -> OK > else if it's 1.2.3.4 -> OK > else -> KO You could always use our favorite urlrewrite tool: http://tuck

RE: RemoteAddrValve and RemoteHostValve

2009-03-02 Thread Caldarale, Charles R
> From: Gregor Schneider [mailto:rc4...@googlemail.com] > Subject: Re: RemoteAddrValve and RemoteHostValve > > I understood that there was one open issue that Zac > needed to combine a hostname and IP-adress Early in the thread, someone pointed out that there's never any nee

Re: RemoteAddrValve and RemoteHostValve

2009-03-02 Thread Gregor Schneider
Hi Chuck, On Mon, Mar 2, 2009 at 3:07 PM, Caldarale, Charles R wrote: > Since a working setup was already provided, why not just use that? > Ehem - was it? I understood that there was one open issue that Zac needed to combine a hostname and IP-adress - which was not possible since both RemoteAdr

RE: RemoteAddrValve and RemoteHostValve

2009-03-02 Thread Caldarale, Charles R
> From: Gregor Schneider [mailto:rc4...@googlemail.com] > Subject: Re: RemoteAddrValve and RemoteHostValve > > Have you ever thought about fronting Tomcat with Apache HTTPD, then > connecting it via mod_jk? Are you serious? You want to add complexity and overhead just to control

Re: RemoteAddrValve and RemoteHostValve

2009-03-02 Thread Zak Mc Kracken
Thanks Gregor, that's very interesting for production environments. I'll try it. Cheers. M. Gregor Schneider wrote: On Mon, Mar 2, 2009 at 11:25 AM, Zak Mc Kracken wrote: Gregor Schneider wrote: you've been asking the valve-stuff because you want to limit the access to requests coming fro

Re: RemoteAddrValve and RemoteHostValve

2009-03-02 Thread Gregor Schneider
On Mon, Mar 2, 2009 at 11:25 AM, Zak Mc Kracken wrote: > Gregor Schneider wrote: >> >> you've been asking the valve-stuff because you want to limit the >> access to requests coming from localhost only? > > Yep! > >> why then not make tomcat listen on localhost only? configuration for >> that's a w

Re: RemoteAddrValve and RemoteHostValve

2009-03-02 Thread Zak Mc Kracken
Gregor Schneider wrote: you've been asking the valve-stuff because you want to limit the access to requests coming from localhost only? Yep! why then not make tomcat listen on localhost only? configuration for that's a walk in the park... My Tomcat is serving a number of webapps, I want t

Re: RemoteAddrValve and RemoteHostValve

2009-03-01 Thread Gregor Schneider
On Sun, Mar 1, 2009 at 6:05 PM, Zak Mc Kracken wrote: > > Yes, but localhost-only is simpler in my case. > ehem, still not sure if i got you right: you've been asking the valve-stuff because you want to limit the access to requests coming from localhost only? why then not make tomcat listen on lo

Re: RemoteAddrValve and RemoteHostValve

2009-03-01 Thread Zak Mc Kracken
Gregor wrote: marc, do i understand you correct that you only whant to accept requests from "localhost"? I have a Java web application that computes some data from an existing Java-based infrastructure and output it as simple plain text. The output is intended to be consumed by other PHP app

Re: RemoteAddrValve and RemoteHostValve

2009-03-01 Thread Zak Mc Kracken
Thanks again. André Warnier wrote: It would in my view make a lot more sense to have a single Remote Access Valve to which one could specify, in "allow" or "deny", a hostname AND/OR an IP address expression. Like deny=".*\.badguys.com,10\.20\.30\.0" /> That's how it works in Apache httpd, and

Re: RemoteAddrValve and RemoteHostValve

2009-02-28 Thread Gregor
marc, do i understand you correct that you only whant to accept requests from "localhost"? next: wouldn't authorization solve your problem? rgds gregor Am 28.02.2009 um 19:14 schrieb Zak Mc Kracken : Thank you all for replies and detailed explanation. Now I understand what's happening. My

Re: RemoteAddrValve and RemoteHostValve

2009-02-28 Thread André Warnier
Zak Mc Kracken wrote: ..., although it seems to imply that RemoteHostValve should be avoided (isn't DNS reverse lookup cached?) Well, I suppose it probably is, at some level. At the level of the Remote Host Valve possibly, if the designers thought about it, or else at some underlying level.

Re: RemoteAddrValve and RemoteHostValve

2009-02-28 Thread Zak Mc Kracken
Thank you all for replies and detailed explanation. Now I understand what's happening. My specific problem is restrict a single web application to clients coming from localhost only. This was not working (everything blocked): I am using a Mac and, after your replies, I tried to see wh

RE: RemoteAddrValve and RemoteHostValve

2009-02-28 Thread Caldarale, Charles R
> From: André Warnier [mailto:a...@ice-sa.com] > Subject: Re: RemoteAddrValve and RemoteHostValve > > What I'm getting at, is that if you want to accept requests from > "www.somewhere.com" It's not clear to me whether the OP wants to check the origin or the de

Re: RemoteAddrValve and RemoteHostValve

2009-02-28 Thread André Warnier
Zak Mc Kracken wrote: [...] Let's try this another way. You want to allow requests from either www.somewhere.com, or one or more IP addresses, and block all the rest. First, filtering requests on the base of a DNS hostname is "expensive" : it forces Tomcat to do a reverse DNS lookup. That

Re: RemoteAddrValve and RemoteHostValve

2009-02-28 Thread Zak Mc Kracken
Gregor Schneider wrote: What in the documentation (http://tomcat.apache.org/tomcat-6.0-doc/config/valve.html) is the part you don't understand? Thanks for replying. Maybe it's me, but what I gather from the documentation is that it's not possible to combine the two filters as I want, i.e.: tell

Re: RemoteAddrValve and RemoteHostValve

2009-02-28 Thread Zak Mc Kracken
Gregor Schneider wrote: What in the documentation (http://tomcat.apache.org/tomcat-6.0-doc/config/valve.html) is the part you don't understand? Thanks for replying. Maybe it's me, but what I gather from the documentation is that it's not possible to combine the two filters as I want, i.e.: tel

Re: RemoteAddrValve and RemoteHostValve

2009-02-28 Thread Gregor Schneider
What in the documentation (http://tomcat.apache.org/tomcat-6.0-doc/config/valve.html) is the part you don't understand? Rgds Gregor -- just because your paranoid, doesn't mean they're not after you... gpgp-fp: 79A84FA526807026795E4209D3B3FE028B3170B2 gpgp-key available @ http://pgpkeys.pca.dfn.d

Re: RemoteAddrValve and RemoteHostValve

2009-02-27 Thread Robert Koberg
On Feb 27, 2009, at 9:28 PM, Zak Mc Kracken wrote: Hi all, I'd like to filter incoming requests with this criterion: if it's www.somewhere.com -> OK else if it's 1.2.3.4 -> OK else -> KO Is it possible to do that by combining RemoteHostValve and RemoteAddrValve? How? I simply tried to write

Re: RemoteAddrValve for a specific URL pattern

2008-09-26 Thread André Warnier
Christopher Schultz wrote: [...] I see that tuckey's urlrewrite library can probably do this for me (redirect somewhere else if the address doesn't match), but it seems a bit overkill. I recommend though. The setup is very easy and flexible, and the author claims it is very light-weight. I ha

Re: RemoteAddrValve Blocking all addresses

2008-03-19 Thread Mark Leone
Found the problem. The docBase path was wrong. The "server" node in the file tree was a hangover from Tomcat 5. Mark Leone wrote: Is RemoteAddrValve broken in 6.0.16? I have the following in "manager.xml", located at %catalina_home%\Conf\Catalina\Localhost. privileged="true" antiReso

RE: RemoteAddrValve

2007-11-28 Thread Propes, Barry L
no you're not dude! You've helped me a lot! I've told you so before! -Original Message- From: Christopher Schultz [mailto:[EMAIL PROTECTED] Sent: Wednesday, November 28, 2007 4:11 PM To: Tomcat Users List Subject: Re: RemoteAddrValve -BEGIN PGP SIGNED MESSAGE- Ha

RE: RemoteAddrValve

2007-11-28 Thread Caldarale, Charles R
> From: Christopher Schultz [mailto:[EMAIL PROTECTED] > Subject: Re: RemoteAddrValve > > I'm an idiot. End of the month - time to reboot :-) - Chuck THIS COMMUNICATION MAY CONTAIN CONFIDENTIAL AND/OR OTHERWISE PROPRIETARY MATERIAL and is thus for use only by the intended

Re: RemoteAddrValve

2007-11-28 Thread Christopher Schultz
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 Chuck, Caldarale, Charles R wrote: >> From: Christopher Schultz [mailto:[EMAIL PROTECTED] >> Subject: Re: RemoteAddrValve >> >> Propes, Barry L wrote: >>> probably that path attribute is wrong, correct? Not nee

RE: RemoteAddrValve

2007-11-28 Thread Propes, Barry L
oh so I did recall correctly! ; ) Thought I'd seen Chuck punch that through a time or two. : ) -Original Message- From: Caldarale, Charles R [mailto:[EMAIL PROTECTED] Sent: Wednesday, November 28, 2007 11:48 AM To: Tomcat Users List Subject: RE: RemoteAddrValve > From: Chr

RE: RemoteAddrValve

2007-11-28 Thread Caldarale, Charles R
> From: Niki Diulgerov [mailto:[EMAIL PROTECTED] > Subject: Re: RemoteAddrValve > > if I remove the allow="192.9.202.231"/> It's className, not classname. Case matters. - Chuck THIS COMMUNICATION MAY CONTAIN CONFIDENTIAL AND/OR OTHERWISE PROPRIETARY MATERI

Re: RemoteAddrValve

2007-11-28 Thread Niki Diulgerov
Diulgerov Network Administrator E-mail: [EMAIL PROTECTED] Telephone : +33 4 89 87 77 77 Fax : +33 4 89 87 77 00 Web: http://www.codix-france.com Caldarale, Charles R wrote: From: Christopher Schultz [mailto:[EMAIL PROTECTED] Subject: Re: RemoteAddrValve Propes, Barry L wrote: prob

RE: RemoteAddrValve

2007-11-28 Thread Caldarale, Charles R
> From: Propes, Barry L [mailto:[EMAIL PROTECTED] > Subject: RE: RemoteAddrValve > > hmmm...ok...what is the one that is forgone in that version? > The docBase? No, you were correct about the path attribute, and Chris was mistaken. The docBase attribute is required since

Re: RemoteAddrValve

2007-11-28 Thread Niki Diulgerov
I removed the path= attribute looked at the manager.xml file with vi and with the text editor which midnight commander uses no strange characters and if I remove the http://www.codix-france.com Caldarale, Charles R wrote: From: Christopher Schultz [mailto:[EMAIL PROTECTED] Subject: Re

RE: RemoteAddrValve

2007-11-28 Thread Caldarale, Charles R
> From: Christopher Schultz [mailto:[EMAIL PROTECTED] > Subject: Re: RemoteAddrValve > > Propes, Barry L wrote: > > probably that path attribute is wrong, correct? Not needed on 5x? > > Yes, it's necessary, since the OP isn't dropping a WAR anywhere, but >

RE: RemoteAddrValve

2007-11-28 Thread Propes, Barry L
hmmm...ok...what is the one that is forgone in that version? The docBase? -Original Message- From: Christopher Schultz [mailto:[EMAIL PROTECTED] Sent: Wednesday, November 28, 2007 11:36 AM To: Tomcat Users List Subject: Re: RemoteAddrValve -BEGIN PGP SIGNED MESSAGE- Hash: SHA1

Re: RemoteAddrValve

2007-11-28 Thread Christopher Schultz
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 Barry, Propes, Barry L wrote: > probably that path attribute is wrong, correct? Not needed on 5x? Yes, it's necessary, since the OP isn't dropping a WAR anywhere, but installing a context.xml file. - -chris -BEGIN PGP SIGNATURE- Version: Gn

Re: RemoteAddrValve

2007-11-28 Thread Niki Diulgerov
Probably wrong? but I saw almost the same example here http://tomcat.apache.org/tomcat-5.5-doc/manager-howto.html so cant understand what's wrong ...I'm using completely fresh installation of 5.5.25 whthout any changes except these mentioned here Best regards, Nikolay Diulgerov Network Adminis

RE: RemoteAddrValve

2007-11-28 Thread Propes, Barry L
probably that path attribute is wrong, correct? Not needed on 5x? -Original Message- From: Niki Diulgerov [mailto:[EMAIL PROTECTED] Sent: Wednesday, November 28, 2007 10:57 AM To: Tomcat Users List Subject: RemoteAddrValve Hello there, Using tomcat 5.5.25 + jdk1.5.0_13 By default /tomcat