Bug 1659939
| Summary: | CC: Simplifying Web UI session timeout configuration [rhel-7.6.z] | ||
|---|---|---|---|
| Product: | Red Hat Enterprise Linux 7 | Reporter: | RAD team bot copy to z-stream <autobot-eus-copy> |
| Component: | pki-core | Assignee: | Endi Sukma Dewata <edewata> |
| Status: | CLOSED ERRATA | QA Contact: | Asha Akkiangady <aakkiang> |
| Severity: | unspecified | Docs Contact: | Marc Muehlfeld <mmuehlfe> |
| Priority: | high | ||
| Version: | 7.7 | CC: | edewata, mharmsen, msauton, prisingh, rhcs-maint, rpattath |
| Target Milestone: | rc | Keywords: | TestCaseProvided, ZStream |
| Target Release: | --- | ||
| Hardware: | Unspecified | ||
| OS: | Unspecified | ||
| Whiteboard: | |||
| Fixed In Version: | pki-core-10.5.9-10.el7_6 | Doc Type: | Bug Fix |
| Doc Text: |
Previously, the pki-core package installed multiple web.xml files. To configure a HTTP session timeout, the session-timeout parameter had to be set in each of these files. To simplify the configuration, the session-timeout parameter has been removed from the files installed by the pki-core package and is now available only in the /etc/pki/<instance_name>/web.xml file. As a result, administrators need only to configure the HTTP session timeout in this one file.
|
Story Points: | --- |
| Clone Of: | 1658293 | Environment: | |
| Last Closed: | 2019-01-29 17:21:57 UTC | Type: | --- |
| Regression: | --- | Mount Type: | --- |
| Documentation: | --- | CRM: | |
| Verified Versions: | Category: | --- | |
| oVirt Team: | --- | RHEL 7.3 requirements from Atomic Host: | |
| Cloudforms Team: | --- | Target Upstream Version: | |
| Embargoed: | |||
| Bug Depends On: | 1658293 | ||
| Bug Blocks: | |||
|
Description
RAD team bot copy to z-stream
2018-12-17 08:57:13 UTC
DOGTAG_10_5_9_RHEL_BRANCH:
commit fe72b8b6947ee1f842fc1eed986fcbff757ae309
Author: Endi S. Dewata <edewata>
Date: Fri Dec 14 13:16:39 2018 -0500
Added docs on session timeout (#125)
https://pagure.io/dogtagpki/issue/3084
(cherry picked from commit 359c05060953cd9124e616067ed545b3b32cb943)
commit 05ebd730708f4dd6b59c667535fef0808e0e0468
Author: Endi S. Dewata <edewata>
Date: Tue Dec 11 08:17:20 2018 +0100
Simplifying Web UI session timeout configuration
The web.xml files for PKI webapps have been modified to remove
hard-coded <session-timeout> parameters. The webapps will now
use the timeout defined in /etc/pki/<instance>/web.xml.
Unused web.xml files have been removed as well.
https://pagure.io/dogtagpki/issue/3084
(cherry picked from commit 30a47907af087a9d2f7739e8d577d7cdd28de18b)
NOTE: Commit fe72b8b6947ee1f842fc1eed986fcbff757ae309 is not included in any RPM,
as it is not a part of the pki-core-10.5.9.tar.gz source tarball.
It's contents is viewable in the upstream git repo:
* https://github.com/dogtagpki/pki/blob/DOGTAG_10_5_BRANCH/docs/admin/Session_Timeout.md
TEST PROCEDURE: * see https://bugzilla.redhat.com/show_bug.cgi?id=1658293#c3 RHEL Version: [root@auto-hv-01-guest01 ~]# cat /etc/redhat-release Red Hat Enterprise Linux Server release 7.7 Beta (Maipo) Pki Version: [root@auto-hv-01-guest01 ~]# pki --version PKI Command-Line Interface 10.5.9-10.el7_6 Version of Firefox verified on: [root@auto-hv-01-guest01 ~]# firefox --version Mozilla Firefox 60.4.0 Steps of Verification: https://bugzilla.redhat.com/show_bug.cgi?id=1658293#c3 CA Audit log: [root@auto-hv-01-guest01 ~]# tail -f /var/lib/pki/pki-tomcat/logs/ca/signedAudit/ca_audit 0.http-bio-8443-exec-5 - [09/Jan/2019:04:30:14 EST] [14] [6] [AuditEvent=ACCESS_SESSION_ESTABLISH][ClientIP=10.19.34.100][ServerIP=10.19.34.100][SubjectID=CN=PKI Administrator,E=caadmin.eng.bos.redhat.com,OU=pki-tomcat,O=idmqe.lab.eng.bos.redhat.com Security Domain][Outcome=Success] access session establish success 0.http-bio-8443-exec-17 - [09/Jan/2019:04:30:14 EST] [14] [6] [AuditEvent=ACCESS_SESSION_ESTABLISH][ClientIP=10.19.34.100][ServerIP=10.19.34.100][SubjectID=CN=PKI Administrator,E=caadmin.eng.bos.redhat.com,OU=pki-tomcat,O=idmqe.lab.eng.bos.redhat.com Security Domain][Outcome=Success] access session establish success 0.http-bio-8443-exec-17 - [09/Jan/2019:04:30:17 EST] [14] [6] [AuditEvent=AUTH][SubjectID=caadmin][Outcome=Success][AuthMgr=certUserDBAuthMgr] authentication success 0.http-bio-8443-exec-22 - [09/Jan/2019:04:30:17 EST] [14] [6] [AuditEvent=ACCESS_SESSION_ESTABLISH][ClientIP=10.19.34.100][ServerIP=10.19.34.100][SubjectID=CN=PKI Administrator,E=caadmin.eng.bos.redhat.com,OU=pki-tomcat,O=idmqe.lab.eng.bos.redhat.com Security Domain][Outcome=Success] access session establish success 0.http-bio-8443-exec-22 - [09/Jan/2019:04:31:18 EST] [14] [6] [AuditEvent=ACCESS_SESSION_TERMINATED][ClientIP=10.19.34.100][ServerIP=10.19.34.100][SubjectID=CN=PKI Administrator,E=caadmin.eng.bos.redhat.com,OU=pki-tomcat,O=idmqe.lab.eng.bos.redhat.com Security Domain][Outcome=Success][Info=CLOSE_NOTIFY] access session terminated 0.http-bio-8443-exec-5 - [09/Jan/2019:04:31:18 EST] [14] [6] [AuditEvent=ACCESS_SESSION_TERMINATED][ClientIP=10.19.34.100][ServerIP=10.19.34.100][SubjectID=CN=PKI Administrator,E=caadmin.eng.bos.redhat.com,OU=pki-tomcat,O=idmqe.lab.eng.bos.redhat.com Security Domain][Outcome=Success][Info=CLOSE_NOTIFY] access session terminated 0.http-bio-8443-exec-17 - [09/Jan/2019:04:31:18 EST] [14] [6] [AuditEvent=ACCESS_SESSION_TERMINATED][ClientIP=10.19.34.100][ServerIP=10.19.34.100][SubjectID=CN=PKI Administrator,E=caadmin.eng.bos.redhat.com,OU=pki-tomcat,O=idmqe.lab.eng.bos.redhat.com Security Domain][Outcome=Success][Info=CLOSE_NOTIFY] access session terminated 0.http-bio-8443-exec-2 - [09/Jan/2019:04:31:27 EST] [14] [6] [AuditEvent=ACCESS_SESSION_ESTABLISH][ClientIP=10.19.34.100][ServerIP=10.19.34.100][SubjectID=CN=PKI Administrator,E=caadmin.eng.bos.redhat.com,OU=pki-tomcat,O=idmqe.lab.eng.bos.redhat.com Security Domain][Outcome=Success] access session establish success 0.http-bio-8443-exec-10 - [09/Jan/2019:04:31:27 EST] [14] [6] [AuditEvent=ACCESS_SESSION_ESTABLISH][ClientIP=10.19.34.100][ServerIP=10.19.34.100][SubjectID=CN=PKI Administrator,E=caadmin.eng.bos.redhat.com,OU=pki-tomcat,O=idmqe.lab.eng.bos.redhat.com Security Domain][Outcome=Success] access session establish success 0.http-bio-8443-exec-2 - [09/Jan/2019:04:32:27 EST] [14] [6] [AuditEvent=ACCESS_SESSION_TERMINATED][ClientIP=10.19.34.100][ServerIP=10.19.34.100][SubjectID=CN=PKI Administrator,E=caadmin.eng.bos.redhat.com,OU=pki-tomcat,O=idmqe.lab.eng.bos.redhat.com Security Domain][Outcome=Success][Info=CLOSE_NOTIFY] access session terminated 0.http-bio-8443-exec-10 - [09/Jan/2019:04:32:27 EST] [14] [6] [AuditEvent=ACCESS_SESSION_TERMINATED][ClientIP=10.19.34.100][ServerIP=10.19.34.100][SubjectID=CN=PKI Administrator,E=caadmin.eng.bos.redhat.com,OU=pki-tomcat,O=idmqe.lab.eng.bos.redhat.com Security Domain][Outcome=Success][Info=CLOSE_NOTIFY] access session terminated 0.http-bio-8443-exec-8 - [09/Jan/2019:04:33:37 EST] [14] [6] [AuditEvent=ACCESS_SESSION_ESTABLISH][ClientIP=10.19.34.100][ServerIP=10.19.34.100][SubjectID=CN=PKI Administrator,E=caadmin.eng.bos.redhat.com,OU=pki-tomcat,O=idmqe.lab.eng.bos.redhat.com Security Domain][Outcome=Success] access session establish success 0.http-bio-8443-exec-19 - [09/Jan/2019:04:33:37 EST] [14] [6] [AuditEvent=ACCESS_SESSION_ESTABLISH][ClientIP=10.19.34.100][ServerIP=10.19.34.100][SubjectID=CN=PKI Administrator,E=caadmin.eng.bos.redhat.com,OU=pki-tomcat,O=idmqe.lab.eng.bos.redhat.com Security Domain][Outcome=Success] access session establish success 0.http-bio-8443-exec-19 - [09/Jan/2019:04:33:37 EST] [14] [6] [AuditEvent=AUTH][SubjectID=caadmin][Outcome=Success][AuthMgr=certUserDBAuthMgr] authentication success 0.http-bio-8443-exec-19 - [09/Jan/2019:04:34:39 EST] [14] [6] [AuditEvent=ACCESS_SESSION_TERMINATED][ClientIP=10.19.34.100][ServerIP=10.19.34.100][SubjectID=CN=PKI Administrator,E=caadmin.eng.bos.redhat.com,OU=pki-tomcat,O=idmqe.lab.eng.bos.redhat.com Security Domain][Outcome=Success][Info=CLOSE_NOTIFY] access session terminated 0.http-bio-8443-exec-8 - [09/Jan/2019:04:34:39 EST] [14] [6] [AuditEvent=ACCESS_SESSION_TERMINATED][ClientIP=10.19.34.100][ServerIP=10.19.34.100][SubjectID=CN=PKI Administrator,E=caadmin.eng.bos.redhat.com,OU=pki-tomcat,O=idmqe.lab.eng.bos.redhat.com Security Domain][Outcome=Success][Info=CLOSE_NOTIFY] access session terminated Hence, Marking this bugzilla as verified. Pastebin: http://pastebin.test.redhat.com/692736 Since the problem described in this bug report should be resolved in a recent advisory, it has been closed with a resolution of ERRATA. For information on the advisory, and where to find the updated files, follow the link below. If the solution does not work for you, open a new bug report. https://access.redhat.com/errata/RHBA-2019:0168 |