Bugzilla will be upgraded to version 5.0. The upgrade date is tentatively scheduled for 2 December 2018, pending final testing and feedback.
Bug 1126490 - [GSS] (6.3.1) Digest Authenticaion within a cluster environment (mod_cluster)
[GSS] (6.3.1) Digest Authenticaion within a cluster environment (mod_cluster)
Status: CLOSED CURRENTRELEASE
Product: JBoss Enterprise Application Platform 6
Classification: JBoss
Component: Web (Show other bugs)
6.3.0
x86_64 Linux
unspecified Severity urgent
: CR1
: EAP 6.3.1
Assigned To: Aaron Ogburn
Michal Karm Babacek
Russell Dickenson
: Triaged
Depends On: 1132357
Blocks: 1130564 eap631-blockers/eap631-payload/eap63-cp01-blockers 1131814
  Show dependency treegraph
 
Reported: 2014-08-04 10:42 EDT by Patrick
Modified: 2014-10-13 14:37 EDT (History)
6 users (show)

See Also:
Fixed In Version:
Doc Type: Bug Fix
Doc Text:
Story Points: ---
Clone Of:
: 1132357 (view as bug list)
Environment:
Last Closed: 2014-10-13 14:37:14 EDT
Type: Bug
Regression: ---
Mount Type: ---
Documentation: ---
CRM:
Verified Versions:
Category: ---
oVirt Team: ---
RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: ---


Attachments (Terms of Use)

  None (edit)
Description Patrick 2014-08-04 10:42:21 EDT
Description of problem:


Digest authentication works fine with a single node within a JBoss cluster with httpd as loadbalancer.

But when a second node is added to the cluster, the Digest authentication is no longer working, as expected.

Observations:

- The stick-session isn't maintained during the authentication mechanism:

-> On the client response, the request gets bounced on different nodes, 
resulting as failed authentication and looping in such way that the authentication succeed after several time or sometimes just ends with a 401 error.


Version-Release number of selected component (if applicable):

-EAP-6.1.1
-Apache is 2.2.15
-mod_cluster is 1.2.6.final


How reproducible:

2 jboss instances clustered behind a httpd loadbalancer

1DC(hosting servers),1HC, and Apache mod_cluster, testApp( Digest Authentication)



Steps to Reproduce:

0.Configure a loadbalancer on Apache (mod_cluster)
1.Set a Digest Authentication security-domain, deploy the testApp
2.Try to access testApp from the browser to the loabalancer <-- works fine
2.Bring the second node into the cluster, (HC joining the DC)
3.Kill the brwoser
5.Try to access the same App

Actual results:
-Authentication fails several times before it succeed.
-Sometimes, ends up with 401 error after several tries

Expected results:

The sticky-session should be maintained during the Digest-Ath process, so that mod_cluster can route the couple of requests to the same node.


Additional info:

I'm not sure if this should be corrected in mod_cluster code or Digest-Auth code.


Thanks.
Patrick
Comment 3 Aaron Ogburn 2014-08-15 10:06:25 EDT
Reproduced and fixed it in branch 7.4.x with r2485.  Changed the DigestAuthenticator valve to ensure has a session in place by the time the 401 response is sent.  Thus the loadbalancer will receive a session from the client that it can use to maintain stickiness and the issue is avoided.

Future releases will need to upgrade to JBossWeb 7.4.9.Final+.
Comment 4 Aaron Ogburn 2014-08-20 08:59:09 EDT
r2492 for branch 7.5.x.
Comment 6 baranowb 2014-08-20 09:53:25 EDT
r2485 for 7.4.9
Comment 8 Michal Karm Babacek 2014-09-02 08:16:39 EDT
Verified 6.3.1.CP1.CR1

Note You need to log in before you can comment on or make changes to this bug.