Imperva Cyber Community

communities_1.jpg
 View Only
  • 1.  Reports are Not generating for DAM

    Posted 12-19-2021 15:34
    I have two MX in HA . while downloading  data base report from the MX it stops at a certain percentage and after one hour it shows failed to create report and for another MX it is showing page not found error . The reports are contains insert delete update command which are run on the data base and except one data base i m finding error in all other data bases . 

    Screen shorts are like this For MX 1



    and for MX 2 i m getting error like this 

    I have tried to purge the OLD logs still i m getting the same error and gateway and MX are preforming normally and adequate space is also available . 

    if any one encounter such type of problem kindly suggest the solution .
    #DatabaseActivityMonitoring

    ------------------------------
    Mayukh Bhattacharya
    Information Security
    Kolkata
    ------------------------------


  • 2.  RE: Reports are Not generating for DAM

    Posted 12-21-2021 02:35
    Hi Mayukh!

    1.- Can you plase take a look of the following file:
    • /opt/SecureSphere/server/SecureSphere/jakarta-tomcat-secsph/conf/server.xml
    You can put the output here.

    2.- This is happen in all types of report that you tried to running?

    Regards!

    ------------------------------
    Edson A. Perez Hernandez
    Data Warden S.A. de C.V. | Support Engineer | IDSC
    Mexico City
    ------------------------------



  • 3.  RE: Reports are Not generating for DAM

    Posted 12-21-2021 02:57
    1.Output 
    [root@IMMGMTBDC01 conf]# cat server.xml
    <?xml version="1.0"?>
    <Server port="8005" shutdown="SHUTDOWN">
    <Listener className="com.mprv.tomcat.MprvJmxRemoteLifecycleListener" rmiRegistryPortPlatform="8833" rmiServerPortPlatform="8834"/>
    <Listener className="com.mprv.tomcat.MprvDefaultExceptionHandlerLifecycleListener"/>
    <Listener className="org.apache.catalina.core.JreMemoryLeakPreventionListener"/>
    <Listener className="org.apache.catalina.core.ThreadLocalLeakPreventionListener"/>
    <Listener className="org.apache.catalina.startup.VersionLoggerListener"/>
    <Listener className="org.apache.catalina.mbeans.GlobalResourcesLifecycleListener"/>
    <Service name="Catalina">
    <Connector address="127.0.0.1" port="8080" protocol="HTTP/1.1" socket.directBuffer="true" redirectPort="8083" keyAlias="tomcat" connectionTimeout="60000" URIEncoding="UTF-8" server="NA" minSpareThreads="2" maxThreads="10" acceptCount="10"/>
    <Connector address="::1" port="8080" protocol="HTTP/1.1" socket.directBuffer="true" redirectPort="8083" connectionTimeout="60000" URIEncoding="UTF-8" server="NA" minSpareThreads="2" maxThreads="5" acceptCount="10"/>
    <Connector address="127.0.0.1" port="8081" protocol="com.mprv.tomcat.MprvHttp11NioProtocol" socket.directBuffer="true" connectionTimeout="60000" SSLEnabled="true" secure="true" scheme="https" sslEnabledProtocols="SSLv2Hello,TLSv1,TLSv1.1,TLSv1.2" useServerCipherSuitesOrder="true" ciphers="TLS_RSA_WITH_AES_256_CBC_SHA256,TLS_RSA_WITH_AES_128_CBC_SHA256,TLS_RSA_WITH_AES_256_CBC_SHA,TLS_RSA_WITH_AES_128_CBC_SHA" keyAlias="reports" clientAuth="false" keystoreFile="conf/reports.kst" keystoreType="JCEKS" disableUploadTimeout="true" allowUnsafeLegacyRenegotiation="false" URIEncoding="UTF-8" server="NA" minSpareThreads="2" maxThreads="10" acceptCount="10"/>
    <Connector address="::1" port="8083" protocol="com.mprv.tomcat.MprvHttp11NioProtocol" socket.directBuffer="true" SSLEnabled="true" secure="true" scheme="https" sslEnabledProtocols="SSLv2Hello,TLSv1,TLSv1.1,TLSv1.2" useServerCipherSuitesOrder="true" ciphers="TLS_RSA_WITH_AES_256_CBC_SHA256,TLS_RSA_WITH_AES_128_CBC_SHA256,TLS_RSA_WITH_AES_256_CBC_SHA,TLS_RSA_WITH_AES_128_CBC_SHA" keyAlias="tomcat" clientAuth="want" keystoreFile="conf/securesphere.kst" keystoreType="JCEKS" truststoreFile="conf/securesphere_truststore.kst" truststoreType="JCEKS" disableUploadTimeout="true" allowUnsafeLegacyRenegotiation="false" URIEncoding="UTF-8" server="NA" minSpareThreads="2" maxThreads="10" acceptCount="100" relaxedQueryChars="\[]{}"/>
    <Connector address="127.0.0.1" port="8083" protocol="com.mprv.tomcat.MprvHttp11NioProtocol" socket.directBuffer="true" SSLEnabled="true" secure="true" scheme="https" sslEnabledProtocols="SSLv2Hello,TLSv1,TLSv1.1,TLSv1.2" useServerCipherSuitesOrder="true" ciphers="TLS_RSA_WITH_AES_256_CBC_SHA256,TLS_RSA_WITH_AES_128_CBC_SHA256,TLS_RSA_WITH_AES_256_CBC_SHA,TLS_RSA_WITH_AES_128_CBC_SHA" keyAlias="tomcat" clientAuth="want" keystoreFile="conf/securesphere.kst" keystoreType="JCEKS" truststoreFile="conf/securesphere_truststore.kst" truststoreType="JCEKS" disableUploadTimeout="true" allowUnsafeLegacyRenegotiation="false" URIEncoding="UTF-8" server="NA" minSpareThreads="2" maxThreads="10" acceptCount="100" relaxedQueryChars="\[]{}"/>
    <Connector connectorType="plain" protocol="HTTP/1.1" enableLookups="true" connectionTimeout="60000" URIEncoding="UTF-8" server="NA" acceptCount="10" port="8080" redirectPort="8083" address="1.1.1.1" interface="lan"/>
    <Connector connectorType="ssl" protocol="com.mprv.tomcat.MprvHttp11NioProtocol" socket.directBuffer="true" SSLEnabled="true" secure="true" scheme="https" sslEnabledProtocols="SSLv2Hello,TLSv1,TLSv1.1,TLSv1.2" useServerCipherSuitesOrder="true" ciphers="TLS_RSA_WITH_AES_256_CBC_SHA256,TLS_RSA_WITH_AES_128_CBC_SHA256,TLS_RSA_WITH_AES_256_CBC_SHA,TLS_RSA_WITH_AES_128_CBC_SHA" keyAlias="tomcat" clientAuth="want" trustManagerClassName="com.mprv.tomcat.ssl.X509ClientTrustManager" keystoreFile="conf/securesphere.kst" keystoreType="JCEKS" disableUploadTimeout="true" allowUnsafeLegacyRenegotiation="false" URIEncoding="UTF-8" server="NA" minSpareThreads="25" maxThreads="150" acceptCount="100" port="8083" address="1.1.1.1" interface="lan" relaxedQueryChars="\[]{}"/>
    <Connector connectorType="somtomx" bindOnInit="false" protocol="com.mprv.tomcat.MprvHttp11NioProtocol" socket.directBuffer="true" SSLEnabled="true" secure="true" scheme="https" sslEnabledProtocols="SSLv2Hello,TLSv1,TLSv1.1,TLSv1.2" useServerCipherSuitesOrder="true" ciphers="TLS_RSA_WITH_AES_256_CBC_SHA256,TLS_RSA_WITH_AES_128_CBC_SHA256,TLS_RSA_WITH_AES_256_CBC_SHA,TLS_RSA_WITH_AES_128_CBC_SHA" keyAlias="default_key_pair_momtomx_mx" clientAuth="true" keystoreFile="conf/securesphere.kst" keystoreType="JCEKS" truststoreFile="conf/securesphere_momtomx_truststore.kst" truststoreType="JCEKS" disableUploadTimeout="true" allowUnsafeLegacyRenegotiation="false" URIEncoding="UTF-8" server="NA" minSpareThreads="3" maxThreads="10" acceptCount="100" port="8084" address="1.1.1.1" interface="lan"/>
    <Connector connectorType="trust" bindOnInit="false" protocol="com.mprv.tomcat.MprvHttp11NioProtocol" socket.directBuffer="true" SSLEnabled="true" secure="true" scheme="https" sslEnabledProtocols="TLSv1.2" useServerCipherSuitesOrder="true" ciphers="TLS_RSA_WITH_AES_256_CBC_SHA256,TLS_RSA_WITH_AES_128_CBC_SHA256,TLS_RSA_WITH_AES_256_CBC_SHA,TLS_RSA_WITH_AES_128_CBC_SHA" keyAlias="trustcertificate" clientAuth="true" keystoreFile="conf/trustclient_keystore.kst" keystoreType="JCEKS" trustManagerClassName="com.mprv.tomcat.ssl.DynamicTrustManager" enableLookups="false" disableUploadTimeout="true" allowUnsafeLegacyRenegotiation="false" URIEncoding="UTF-8" server="NA" minSpareThreads="3" maxThreads="10" acceptCount="100" port="8085" address="1.1.1.1" interface="lan"/>
    <Connector connectorType="plain" protocol="HTTP/1.1" enableLookups="true" connectionTimeout="60000" URIEncoding="UTF-8" server="NA" acceptCount="10" port="8080" redirectPort="8083" address="172.19.5.114" interface="server-ha-vip"/>
    <Connector connectorType="ssl" protocol="com.mprv.tomcat.MprvHttp11NioProtocol" socket.directBuffer="true" SSLEnabled="true" secure="true" scheme="https" sslEnabledProtocols="SSLv2Hello,TLSv1,TLSv1.1,TLSv1.2" useServerCipherSuitesOrder="true" ciphers="TLS_RSA_WITH_AES_256_CBC_SHA256,TLS_RSA_WITH_AES_128_CBC_SHA256,TLS_RSA_WITH_AES_256_CBC_SHA,TLS_RSA_WITH_AES_128_CBC_SHA" keyAlias="tomcat" clientAuth="want" trustManagerClassName="com.mprv.tomcat.ssl.X509ClientTrustManager" keystoreFile="conf/securesphere.kst" keystoreType="JCEKS" disableUploadTimeout="true" allowUnsafeLegacyRenegotiation="false" URIEncoding="UTF-8" server="NA" minSpareThreads="25" maxThreads="150" acceptCount="100" port="8083" address="172.19.5.114" interface="server-ha-vip" relaxedQueryChars="\[]{}"/>
    <Connector connectorType="somtomx" bindOnInit="false" protocol="com.mprv.tomcat.MprvHttp11NioProtocol" socket.directBuffer="true" SSLEnabled="true" secure="true" scheme="https" sslEnabledProtocols="SSLv2Hello,TLSv1,TLSv1.1,TLSv1.2" useServerCipherSuitesOrder="true" ciphers="TLS_RSA_WITH_AES_256_CBC_SHA256,TLS_RSA_WITH_AES_128_CBC_SHA256,TLS_RSA_WITH_AES_256_CBC_SHA,TLS_RSA_WITH_AES_128_CBC_SHA" keyAlias="default_key_pair_momtomx_mx" clientAuth="true" keystoreFile="conf/securesphere.kst" keystoreType="JCEKS" truststoreFile="conf/securesphere_momtomx_truststore.kst" truststoreType="JCEKS" disableUploadTimeout="true" allowUnsafeLegacyRenegotiation="false" URIEncoding="UTF-8" server="NA" minSpareThreads="3" maxThreads="10" acceptCount="100" port="8084" address="172.19.5.114" interface="server-ha-vip"/>
    <Connector connectorType="trust" bindOnInit="false" protocol="com.mprv.tomcat.MprvHttp11NioProtocol" socket.directBuffer="true" SSLEnabled="true" secure="true" scheme="https" sslEnabledProtocols="TLSv1.2" useServerCipherSuitesOrder="true" ciphers="TLS_RSA_WITH_AES_256_CBC_SHA256,TLS_RSA_WITH_AES_128_CBC_SHA256,TLS_RSA_WITH_AES_256_CBC_SHA,TLS_RSA_WITH_AES_128_CBC_SHA" keyAlias="trustcertificate" clientAuth="true" keystoreFile="conf/trustclient_keystore.kst" keystoreType="JCEKS" trustManagerClassName="com.mprv.tomcat.ssl.DynamicTrustManager" enableLookups="false" disableUploadTimeout="true" allowUnsafeLegacyRenegotiation="false" URIEncoding="UTF-8" server="NA" minSpareThreads="3" maxThreads="10" acceptCount="100" port="8085" address="172.19.5.114" interface="server-ha-vip"/>
    <Connector connectorType="plain" protocol="HTTP/1.1" enableLookups="true" connectionTimeout="60000" URIEncoding="UTF-8" server="NA" acceptCount="10" port="8080" redirectPort="8083" address="172.19.5.112" interface="management"/>
    <Connector connectorType="ssl" protocol="com.mprv.tomcat.MprvHttp11NioProtocol" socket.directBuffer="true" SSLEnabled="true" secure="true" scheme="https" sslEnabledProtocols="SSLv2Hello,TLSv1,TLSv1.1,TLSv1.2" useServerCipherSuitesOrder="true" ciphers="TLS_RSA_WITH_AES_256_CBC_SHA256,TLS_RSA_WITH_AES_128_CBC_SHA256,TLS_RSA_WITH_AES_256_CBC_SHA,TLS_RSA_WITH_AES_128_CBC_SHA" keyAlias="tomcat" clientAuth="want" trustManagerClassName="com.mprv.tomcat.ssl.X509ClientTrustManager" keystoreFile="conf/securesphere.kst" keystoreType="JCEKS" disableUploadTimeout="true" allowUnsafeLegacyRenegotiation="false" URIEncoding="UTF-8" server="NA" minSpareThreads="25" maxThreads="150" acceptCount="100" port="8083" address="172.19.5.112" interface="management" relaxedQueryChars="\[]{}"/>
    <Connector connectorType="somtomx" bindOnInit="false" protocol="com.mprv.tomcat.MprvHttp11NioProtocol" socket.directBuffer="true" SSLEnabled="true" secure="true" scheme="https" sslEnabledProtocols="SSLv2Hello,TLSv1,TLSv1.1,TLSv1.2" useServerCipherSuitesOrder="true" ciphers="TLS_RSA_WITH_AES_256_CBC_SHA256,TLS_RSA_WITH_AES_128_CBC_SHA256,TLS_RSA_WITH_AES_256_CBC_SHA,TLS_RSA_WITH_AES_128_CBC_SHA" keyAlias="default_key_pair_momtomx_mx" clientAuth="true" keystoreFile="conf/securesphere.kst" keystoreType="JCEKS" truststoreFile="conf/securesphere_momtomx_truststore.kst" truststoreType="JCEKS" disableUploadTimeout="true" allowUnsafeLegacyRenegotiation="false" URIEncoding="UTF-8" server="NA" minSpareThreads="3" maxThreads="10" acceptCount="100" port="8084" address="172.19.5.112" interface="management"/>
    <Connector connectorType="trust" bindOnInit="false" protocol="com.mprv.tomcat.MprvHttp11NioProtocol" socket.directBuffer="true" SSLEnabled="true" secure="true" scheme="https" sslEnabledProtocols="TLSv1.2" useServerCipherSuitesOrder="true" ciphers="TLS_RSA_WITH_AES_256_CBC_SHA256,TLS_RSA_WITH_AES_128_CBC_SHA256,TLS_RSA_WITH_AES_256_CBC_SHA,TLS_RSA_WITH_AES_128_CBC_SHA" keyAlias="trustcertificate" clientAuth="true" keystoreFile="conf/trustclient_keystore.kst" keystoreType="JCEKS" trustManagerClassName="com.mprv.tomcat.ssl.DynamicTrustManager" enableLookups="false" disableUploadTimeout="true" allowUnsafeLegacyRenegotiation="false" URIEncoding="UTF-8" server="NA" minSpareThreads="3" maxThreads="10" acceptCount="100" port="8085" address="172.19.5.112" interface="management"/>
    <Engine name="Catalina" defaultHost="localhost">
    <Host name="localhost" appBase="webapps" unpackWARs="true" autoDeploy="true" errorReportValveClass="com.mprv.tomcat.MprvErrorReportValve" startStopThreads="2"/>
    </Engine>
    </Service>
    </Server>



    2. No .Except one data base the issues are same for all other data bases .

    ------------------------------
    Mayukh Bhattacharya
    Information Security
    Kolkata
    ------------------------------



  • 4.  RE: Reports are Not generating for DAM

    Posted 12-21-2021 04:16

    Hi, Mayukh,

    Edson had a post stuck in moderation. It has some additional steps that may be useful.

    Thanks,

    sarah



    ------------------------------
    Sarah Lamont(csp)
    Digital Community Manager
    ------------------------------



  • 5.  RE: Reports are Not generating for DAM

    Posted 12-21-2021 04:14
    Hi Mayukh!

    1.- This is happen in all type of report that you tried to generate for this database?
    2.- It's probably that yoy have an MX-HA configuration and you can only get access to the active MX or by the virtual IP of this MX-HA
    3.- Could you plase take a look to the next file or provide the output:
    • /opt/SecureSphere/server/SecureSphere/jakarta-tomcat-secsph/conf/server.xml
    Regards!

    ------------------------------
    Edson Perez Hernandez
    Support Engineer
    Mexico City
    ------------------------------



  • 6.  RE: Reports are Not generating for DAM

    Posted 12-21-2021 05:00
    1. The error is appearing to all data bases except one data bases .
    2.Yes MX in HA and Virtual IP is configured and Access to MX-HA through Virtual IP open the CLI of active MX .
    3.Output file is attached here 

    ?xml version="1.0"?>
    <Server port="8005" shutdown="SHUTDOWN">
      <Listener className="com.mprv.tomcat.MprvJmxRemoteLifecycleListener" rmiRegistryPortPlatform="8833" rmiServerPortPlatform="8834"/>
      <Listener className="com.mprv.tomcat.MprvDefaultExceptionHandlerLifecycleListener"/>
      <Listener className="org.apache.catalina.core.JreMemoryLeakPreventionListener"/>
      <Listener className="org.apache.catalina.core.ThreadLocalLeakPreventionListener"/>
      <Listener className="org.apache.catalina.startup.VersionLoggerListener"/>
      <Listener className="org.apache.catalina.mbeans.GlobalResourcesLifecycleListener"/>
      <Service name="Catalina">
        <Connector address="127.0.0.1" port="8080" protocol="HTTP/1.1" socket.directBuffer="true" redirectPort="8083" keyAlias="tomcat" connectionTimeout="60000" URIEncoding="UTF-8" server="NA" minSpareThreads="2" maxThreads="10" acceptCount="10"/>
        <Connector address="::1" port="8080" protocol="HTTP/1.1" socket.directBuffer="true" redirectPort="8083" connectionTimeout="60000" URIEncoding="UTF-8" server="NA" minSpareThreads="2" maxThreads="5" acceptCount="10"/>
        <Connector address="127.0.0.1" port="8081" protocol="com.mprv.tomcat.MprvHttp11NioProtocol" socket.directBuffer="true" connectionTimeout="60000" SSLEnabled="true" secure="true" scheme="https" sslEnabledProtocols="SSLv2Hello,TLSv1,TLSv1.1,TLSv1.2" useServerCipherSuitesOrder="true" ciphers="TLS_RSA_WITH_AES_256_CBC_SHA256,TLS_RSA_WITH_AES_128_CBC_SHA256,TLS_RSA_WITH_AES_256_CBC_SHA,TLS_RSA_WITH_AES_128_CBC_SHA" keyAlias="reports" clientAuth="false" keystoreFile="conf/reports.kst" keystoreType="JCEKS" disableUploadTimeout="true" allowUnsafeLegacyRenegotiation="false" URIEncoding="UTF-8" server="NA" minSpareThreads="2" maxThreads="10" acceptCount="10"/>
        <Connector address="::1" port="8083" protocol="com.mprv.tomcat.MprvHttp11NioProtocol" socket.directBuffer="true" SSLEnabled="true" secure="true" scheme="https" sslEnabledProtocols="SSLv2Hello,TLSv1,TLSv1.1,TLSv1.2" useServerCipherSuitesOrder="true" ciphers="TLS_RSA_WITH_AES_256_CBC_SHA256,TLS_RSA_WITH_AES_128_CBC_SHA256,TLS_RSA_WITH_AES_256_CBC_SHA,TLS_RSA_WITH_AES_128_CBC_SHA" keyAlias="tomcat" clientAuth="want" keystoreFile="conf/securesphere.kst" keystoreType="JCEKS" truststoreFile="conf/securesphere_truststore.kst" truststoreType="JCEKS" disableUploadTimeout="true" allowUnsafeLegacyRenegotiation="false" URIEncoding="UTF-8" server="NA" minSpareThreads="2" maxThreads="10" acceptCount="100" relaxedQueryChars="\[]{}"/>
        <Connector address="127.0.0.1" port="8083" protocol="com.mprv.tomcat.MprvHttp11NioProtocol" socket.directBuffer="true" SSLEnabled="true" secure="true" scheme="https" sslEnabledProtocols="SSLv2Hello,TLSv1,TLSv1.1,TLSv1.2" useServerCipherSuitesOrder="true" ciphers="TLS_RSA_WITH_AES_256_CBC_SHA256,TLS_RSA_WITH_AES_128_CBC_SHA256,TLS_RSA_WITH_AES_256_CBC_SHA,TLS_RSA_WITH_AES_128_CBC_SHA" keyAlias="tomcat" clientAuth="want" keystoreFile="conf/securesphere.kst" keystoreType="JCEKS" truststoreFile="conf/securesphere_truststore.kst" truststoreType="JCEKS" disableUploadTimeout="true" allowUnsafeLegacyRenegotiation="false" URIEncoding="UTF-8" server="NA" minSpareThreads="2" maxThreads="10" acceptCount="100" relaxedQueryChars="\[]{}"/>
        <Connector connectorType="plain" protocol="HTTP/1.1" enableLookups="true" connectionTimeout="60000" URIEncoding="UTF-8" server="NA" acceptCount="10" port="8080" redirectPort="8083" address="1.1.1.1" interface="lan"/>
        <Connector connectorType="ssl" protocol="com.mprv.tomcat.MprvHttp11NioProtocol" socket.directBuffer="true" SSLEnabled="true" secure="true" scheme="https" sslEnabledProtocols="SSLv2Hello,TLSv1,TLSv1.1,TLSv1.2" useServerCipherSuitesOrder="true" ciphers="TLS_RSA_WITH_AES_256_CBC_SHA256,TLS_RSA_WITH_AES_128_CBC_SHA256,TLS_RSA_WITH_AES_256_CBC_SHA,TLS_RSA_WITH_AES_128_CBC_SHA" keyAlias="tomcat" clientAuth="want" trustManagerClassName="com.mprv.tomcat.ssl.X509ClientTrustManager" keystoreFile="conf/securesphere.kst" keystoreType="JCEKS" disableUploadTimeout="true" allowUnsafeLegacyRenegotiation="false" URIEncoding="UTF-8" server="NA" minSpareThreads="25" maxThreads="150" acceptCount="100" port="8083" address="1.1.1.1" interface="lan" relaxedQueryChars="\[]{}"/>
        <Connector connectorType="somtomx" bindOnInit="false" protocol="com.mprv.tomcat.MprvHttp11NioProtocol" socket.directBuffer="true" SSLEnabled="true" secure="true" scheme="https" sslEnabledProtocols="SSLv2Hello,TLSv1,TLSv1.1,TLSv1.2" useServerCipherSuitesOrder="true" ciphers="TLS_RSA_WITH_AES_256_CBC_SHA256,TLS_RSA_WITH_AES_128_CBC_SHA256,TLS_RSA_WITH_AES_256_CBC_SHA,TLS_RSA_WITH_AES_128_CBC_SHA" keyAlias="default_key_pair_momtomx_mx" clientAuth="true" keystoreFile="conf/securesphere.kst" keystoreType="JCEKS" truststoreFile="conf/securesphere_momtomx_truststore.kst" truststoreType="JCEKS" disableUploadTimeout="true" allowUnsafeLegacyRenegotiation="false" URIEncoding="UTF-8" server="NA" minSpareThreads="3" maxThreads="10" acceptCount="100" port="8084" address="1.1.1.1" interface="lan"/>
        <Connector connectorType="trust" bindOnInit="false" protocol="com.mprv.tomcat.MprvHttp11NioProtocol" socket.directBuffer="true" SSLEnabled="true" secure="true" scheme="https" sslEnabledProtocols="TLSv1.2" useServerCipherSuitesOrder="true" ciphers="TLS_RSA_WITH_AES_256_CBC_SHA256,TLS_RSA_WITH_AES_128_CBC_SHA256,TLS_RSA_WITH_AES_256_CBC_SHA,TLS_RSA_WITH_AES_128_CBC_SHA" keyAlias="trustcertificate" clientAuth="true" keystoreFile="conf/trustclient_keystore.kst" keystoreType="JCEKS" trustManagerClassName="com.mprv.tomcat.ssl.DynamicTrustManager" enableLookups="false" disableUploadTimeout="true" allowUnsafeLegacyRenegotiation="false" URIEncoding="UTF-8" server="NA" minSpareThreads="3" maxThreads="10" acceptCount="100" port="8085" address="1.1.1.1" interface="lan"/>
        <Connector connectorType="plain" protocol="HTTP/1.1" enableLookups="true" connectionTimeout="60000" URIEncoding="UTF-8" server="NA" acceptCount="10" port="8080" redirectPort="8083" address="172.19.5.114" interface="server-ha-vip"/>
        <Connector connectorType="ssl" protocol="com.mprv.tomcat.MprvHttp11NioProtocol" socket.directBuffer="true" SSLEnabled="true" secure="true" scheme="https" sslEnabledProtocols="SSLv2Hello,TLSv1,TLSv1.1,TLSv1.2" useServerCipherSuitesOrder="true" ciphers="TLS_RSA_WITH_AES_256_CBC_SHA256,TLS_RSA_WITH_AES_128_CBC_SHA256,TLS_RSA_WITH_AES_256_CBC_SHA,TLS_RSA_WITH_AES_128_CBC_SHA" keyAlias="tomcat" clientAuth="want" trustManagerClassName="com.mprv.tomcat.ssl.X509ClientTrustManager" keystoreFile="conf/securesphere.kst" keystoreType="JCEKS" disableUploadTimeout="true" allowUnsafeLegacyRenegotiation="false" URIEncoding="UTF-8" server="NA" minSpareThreads="25" maxThreads="150" acceptCount="100" port="8083" address="172.19.5.114" interface="server-ha-vip" relaxedQueryChars="\[]{}"/>
        <Connector connectorType="somtomx" bindOnInit="false" protocol="com.mprv.tomcat.MprvHttp11NioProtocol" socket.directBuffer="true" SSLEnabled="true" secure="true" scheme="https" sslEnabledProtocols="SSLv2Hello,TLSv1,TLSv1.1,TLSv1.2" useServerCipherSuitesOrder="true" ciphers="TLS_RSA_WITH_AES_256_CBC_SHA256,TLS_RSA_WITH_AES_128_CBC_SHA256,TLS_RSA_WITH_AES_256_CBC_SHA,TLS_RSA_WITH_AES_128_CBC_SHA" keyAlias="default_key_pair_momtomx_mx" clientAuth="true" keystoreFile="conf/securesphere.kst" keystoreType="JCEKS" truststoreFile="conf/securesphere_momtomx_truststore.kst" truststoreType="JCEKS" disableUploadTimeout="true" allowUnsafeLegacyRenegotiation="false" URIEncoding="UTF-8" server="NA" minSpareThreads="3" maxThreads="10" acceptCount="100" port="8084" address="172.19.5.114" interface="server-ha-vip"/>
        <Connector connectorType="trust" bindOnInit="false" protocol="com.mprv.tomcat.MprvHttp11NioProtocol" socket.directBuffer="true" SSLEnabled="true" secure="true" scheme="https" sslEnabledProtocols="TLSv1.2" useServerCipherSuitesOrder="true" ciphers="TLS_RSA_WITH_AES_256_CBC_SHA256,TLS_RSA_WITH_AES_128_CBC_SHA256,TLS_RSA_WITH_AES_256_CBC_SHA,TLS_RSA_WITH_AES_128_CBC_SHA" keyAlias="trustcertificate" clientAuth="true" keystoreFile="conf/trustclient_keystore.kst" keystoreType="JCEKS" trustManagerClassName="com.mprv.tomcat.ssl.DynamicTrustManager" enableLookups="false" disableUploadTimeout="true" allowUnsafeLegacyRenegotiation="false" URIEncoding="UTF-8" server="NA" minSpareThreads="3" maxThreads="10" acceptCount="100" port="8085" address="172.19.5.114" interface="server-ha-vip"/>
        <Connector connectorType="plain" protocol="HTTP/1.1" enableLookups="true" connectionTimeout="60000" URIEncoding="UTF-8" server="NA" acceptCount="10" port="8080" redirectPort="8083" address="172.19.5.112" interface="management"/>
        <Connector connectorType="ssl" protocol="com.mprv.tomcat.MprvHttp11NioProtocol" socket.directBuffer="true" SSLEnabled="true" secure="true" scheme="https" sslEnabledProtocols="SSLv2Hello,TLSv1,TLSv1.1,TLSv1.2" useServerCipherSuitesOrder="true" ciphers="TLS_RSA_WITH_AES_256_CBC_SHA256,TLS_RSA_WITH_AES_128_CBC_SHA256,TLS_RSA_WITH_AES_256_CBC_SHA,TLS_RSA_WITH_AES_128_CBC_SHA" keyAlias="tomcat" clientAuth="want" trustManagerClassName="com.mprv.tomcat.ssl.X509ClientTrustManager" keystoreFile="conf/securesphere.kst" keystoreType="JCEKS" disableUploadTimeout="true" allowUnsafeLegacyRenegotiation="false" URIEncoding="UTF-8" server="NA" minSpareThreads="25" maxThreads="150" acceptCount="100" port="8083" address="172.19.5.112" interface="management" relaxedQueryChars="\[]{}"/>
        <Connector connectorType="somtomx" bindOnInit="false" protocol="com.mprv.tomcat.MprvHttp11NioProtocol" socket.directBuffer="true" SSLEnabled="true" secure="true" scheme="https" sslEnabledProtocols="SSLv2Hello,TLSv1,TLSv1.1,TLSv1.2" useServerCipherSuitesOrder="true" ciphers="TLS_RSA_WITH_AES_256_CBC_SHA256,TLS_RSA_WITH_AES_128_CBC_SHA256,TLS_RSA_WITH_AES_256_CBC_SHA,TLS_RSA_WITH_AES_128_CBC_SHA" keyAlias="default_key_pair_momtomx_mx" clientAuth="true" keystoreFile="conf/securesphere.kst" keystoreType="JCEKS" truststoreFile="conf/securesphere_momtomx_truststore.kst" truststoreType="JCEKS" disableUploadTimeout="true" allowUnsafeLegacyRenegotiation="false" URIEncoding="UTF-8" server="NA" minSpareThreads="3" maxThreads="10" acceptCount="100" port="8084" address="172.19.5.112" interface="management"/>
        <Connector connectorType="trust" bindOnInit="false" protocol="com.mprv.tomcat.MprvHttp11NioProtocol" socket.directBuffer="true" SSLEnabled="true" secure="true" scheme="https" sslEnabledProtocols="TLSv1.2" useServerCipherSuitesOrder="true" ciphers="TLS_RSA_WITH_AES_256_CBC_SHA256,TLS_RSA_WITH_AES_128_CBC_SHA256,TLS_RSA_WITH_AES_256_CBC_SHA,TLS_RSA_WITH_AES_128_CBC_SHA" keyAlias="trustcertificate" clientAuth="true" keystoreFile="conf/trustclient_keystore.kst" keystoreType="JCEKS" trustManagerClassName="com.mprv.tomcat.ssl.DynamicTrustManager" enableLookups="false" disableUploadTimeout="true" allowUnsafeLegacyRenegotiation="false" URIEncoding="UTF-8" server="NA" minSpareThreads="3" maxThreads="10" acceptCount="100" port="8085" address="172.19.5.112" interface="management"/>
        <Engine name="Catalina" defaultHost="localhost">
          <Host name="localhost" appBase="webapps" unpackWARs="true" autoDeploy="true" errorReportValveClass="com.mprv.tomcat.MprvErrorReportValve" startStopThreads="2"/>
        </Engine>
      </Service>
    </Server>


    ------------------------------
    Mayukh Bhattacharya
    Information Security
    Kolkata
    ------------------------------