Bug 1657193 - Timeout configuration is not working as defined in the product documentation.
Summary: Timeout configuration is not working as defined in the product documentation.
Alias: None
Product: Red Hat Enterprise Linux 8
Classification: Red Hat
Component: pki-core
Version: 8.3
Hardware: Unspecified
OS: Unspecified
Target Milestone: rc
: ---
Assignee: RHCS Maintainers
QA Contact: Asha Akkiangady
Depends On:
TreeView+ depends on / blocked
Reported: 2018-12-07 11:59 UTC by Amol K
Modified: 2021-02-01 14:34 UTC (History)
2 users (show)

Fixed In Version:
Doc Type: If docs needed, set a value
Doc Text:
Clone Of:
Last Closed: 2021-02-01 07:31:03 UTC
Type: Bug
Target Upstream Version:

Attachments (Terms of Use)

Description Amol K 2018-12-07 11:59:59 UTC
Description of problem:
I tried to setup web UI session timeout as mentioned in the documenation[1]. But when I restart the system it throws the Subsystem unavailable exception.

[1] https://access.redhat.com/documentation/en-us/red_hat_certificate_system/9/html/administration_guide/configuring_session_timeouts

Version-Release number of selected component (if applicable):

How reproducible:

Steps to Reproduce:
1. In doc path is different but I tried with the following way:
  cp /var/lib/pki/topology-ecc-CA/conf/web.xml /var/lib/pki/topology-ecc-CA/ca/
2. Edit /var/lib/pki/topology-ecc-CA/ca/web.xml and set timeout parameter
3. Edit /etc/pki/topology-ecc-CA/Catalina/localhost/ca.xml and add the following text: 
<Context docBase="/var/lib/pki/topology-ecc-CA/webapps/ca" crossContext="true" allowLinking="true">
4. chown -R pkiuser:pkiuser /var/lib/pki/topology-ecc-CA/webapps
5. Restart the server

Actual results:
cat /var/log/pki/topology-ecc-CA/localhost.2018-12-07.log

SEVERE: Exception Processing /ca/agent/ca
javax.ws.rs.ServiceUnavailableException: Subsystem unavailable
        at com.netscape.cms.tomcat.ProxyRealm.findSecurityConstraints(ProxyRealm.java:145)
        at org.apache.catalina.authenticator.AuthenticatorBase.invoke(AuthenticatorBase.java:500)
        at org.apache.catalina.core.StandardHostValve.invoke(StandardHostValve.java:169)
        at org.apache.catalina.valves.ErrorReportValve.invoke(ErrorReportValve.java:103)
        at org.apache.catalina.valves.AccessLogValve.invoke(AccessLogValve.java:962)
        at org.apache.catalina.core.StandardEngineValve.invoke(StandardEngineValve.java:116)
        at org.apache.catalina.connector.CoyoteAdapter.service(CoyoteAdapter.java:445)
        at org.apache.coyote.http11.AbstractHttp11Processor.process(AbstractHttp11Processor.java:1087)
        at org.apache.coyote.AbstractProtocol$AbstractConnectionHandler.process(AbstractProtocol.java:637)
        at org.apache.tomcat.util.net.JIoEndpoint$SocketProcessor.run(JIoEndpoint.java:318)
        at java.util.concurrent.ThreadPoolExecutor.runWorker(ThreadPoolExecutor.java:1149)
        at java.util.concurrent.ThreadPoolExecutor$Worker.run(ThreadPoolExecutor.java:624)
        at org.apache.tomcat.util.threads.TaskThread$WrappingRunnable.run(TaskThread.java:61)
        at java.lang.Thread.run(Thread.java:748)

Expected results:
Server should start and web GUI session timeout should end in specified time.

Additional info:

Comment 2 Christina Fu 2020-02-11 00:53:29 UTC
Please see Session Timeout of https://www.niap-ccevs.org/MMO/Product/st_10831-agd2.pdf

The regular (non-CC) guide will contain this same section once we are done integrating the docs.

Comment 3 Amol K 2020-03-27 08:42:07 UTC
Steps to reproduce explain the timeout configuration. As far as I remember it is not working as expected. 

After setting the timeout it should expected to work for 5 mins. But it does not. Console get closed in 1 or 2 mins.

If this scenario is still not applicable please close this bug.

Comment 6 RHEL Program Management 2021-02-01 07:31:03 UTC
After evaluating this issue, there are no plans to address it further or fix it in an upcoming release.  Therefore, it is being closed.  If plans change such that this issue will be fixed in an upcoming release, then the bug can be reopened.

Note You need to log in before you can comment on or make changes to this bug.