Thanks Chris..

See the below output and here not showing the secure.

< HTTP/1.1 200 OK
< Set-Cookie: JSESSIONID=D14ACAB7CADB83FAD5C11296C75A09DB; Path=/; HttpOnly
< X-Frame-Options: DENY
< X-Content-Type-Options: nosniff
< X-XSS-Protection: 1; mode=block
< Content-Type: text/html;charset=ISO-8859-1
< Content-Length: 5472
< Date: Thu, 30 Nov 2017 17:26:37 GMT
< Server:


Regards,
Naga Ramesh

-----Original Message-----
From: Christopher Schultz [mailto:ch...@christopherschultz.net] 
Sent: Thursday, November 30, 2017 10:52 PM
To: users@tomcat.apache.org
Subject: Re: unable to set the "secure="true" flag on server.xml

-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA256

Naga,

On 11/30/17 12:11 PM, Naga Ramesh wrote:
> I have configured the tomcat8 version & used the AWS ELB, but I have 
> set the “secure="true" flag on tomcat8/conf/server.xml file end, after 
> that service started and login page came but I am unable to login the 
> application and getting the oops session expired error message coming.

Please post your <Connector> configuration.

What did you expect secure="true" to actually do?

> Note: we have applied the SSL on AWS ELB end.

So you are terminating TLS at the ELB, right?

> ELB(https) -à tomcat-conenctor-8080

Traffic from ELB -> Tomcat is using HTTPS?

Why encrypt within your own VLAN?

- -chris
-----BEGIN PGP SIGNATURE-----
Comment: GPGTools - http://gpgtools.org
Comment: Using GnuPG with Thunderbird - http://www.enigmail.net/

iQJRBAEBCAA7FiEEMmKgYcQvxMe7tcJcHPApP6U8pFgFAlogPjgdHGNocmlzQGNo
cmlzdG9waGVyc2NodWx0ei5uZXQACgkQHPApP6U8pFjNsw/6AgqvEO54pTNb2Uid
V9sAx5XLpH3YCQpRifJRQwM/VIyL8WCCASeEKHOf9ZFGQwgmdGbsWhiVbGIXZiKP
JsT5NMWOvL22ipLwj4EiTq0w7+8va4+fQGmFWqR29pLb6lRP0xpvkZZGndYWAH88
67/giHBiSSD3HtmZtuwmR9UItBLepIrd4bxK37aZtMIMztVMfFZlFpQcBzmRhoVX
kR8rEyJnbAn7Gqc0MY+nYpD5t/1xlUwypjN/GekfpgJX1Kg9Ac3OO2UlwaXECgM1
Yt9IGHHn2xILryfRfBdgxY+M+f013kGDRGerE2K/dDSsF7/T1W6uYiuPCsj3UX2t
tzMvdr1gDtZIVbBm2YyUoh3QMISuteYNTufFCyAWrvOjSSWgTeySTowNWmMvOHG9
PG6a+/gZawGjDDerIcPdUMMPJfsqJ85a0TbYJpHf5FJPeOkFkzMrrMPIeLVUlNpV
eAAwV3z3hTlpgyV8xaRNCKeMmli0/XDcruVrEKJXHOhmH0e1rqWa2A6OMkcBGxbu
xoUqVf69BOQz460iGMtO6TqDGF5InELKShEsfELHoSTr0SJ20qBsDM73cOCAKIFF
wu8wPoWla2f2psoQTLIQ521UQq/bVGm3V68ILr7rvRBtuSLl8GzF2VQoJeo6Dmto
pPMCCQwV75qLTjnO2Nk6LZ39Ai8=
=1f6y
-----END PGP SIGNATURE-----

---------------------------------------------------------------------
To unsubscribe, e-mail: users-unsubscr...@tomcat.apache.org
For additional commands, e-mail: users-h...@tomcat.apache.org


---------------------------------------------------------------------
To unsubscribe, e-mail: users-unsubscr...@tomcat.apache.org
For additional commands, e-mail: users-h...@tomcat.apache.org

Reply via email to