Showing posts with label Apache. Show all posts
Showing posts with label Apache. Show all posts

Tuesday, 12 May 2015

Forcing maintenance page in WebCenter

When a WebCenter environment requires a shutdown or a restart, it is advisable to present a friendly error page instead of the traditional "Failure of server Apache bridge". This can be easily achieved by implementing a static html page and configuring OHS. This can be applied to other applications too.

The maintenance page could have a html structure similar to the web template, or it could just be an image with a friendly message. For example, maintenance.html could be defined as follows:


<!doctype html>
<html>
<head>
<meta charset="utf-8">
<meta http-equiv="X-UA-Compatible" content="IE=edge">
</head>
<body>
    <div>
        <img src="/Static/ClientPages/img/Maintenance.jpg">                   
    </div>   
</body>
</html>

Once page is uploaded to the server, some code must be inserted inside the OHS virtual host element in the configuration file (mod_wl_ohs.conf). For instance, the following code redirect all the OHS requests to the plain maintenance page.


RewriteEngine On

RewriteCond %{SCRIPT_FILENAME} !/Static/ClientPages/*

RewriteRule ^.*$ /Static/ClientPages/maintenance.html [R=503,L]
Header Set Cache-Control "max-age=0, no-store"

After that, OHS instance needs to be restarted using the opmnctl command.

Also, it is interesting to set error pages to different HTTP status codes. The following lines force the display of error and maintenance pages depending on the type of errror: Internal server error (500) or Service unavailable (503).

ErrorDocument 500 /Static/ClientPages/error.html

ErrorDocument 503 /Static/ClientPages/maintenance.html

Other options are:

  • IP exceptions: It is possible to set IP exceptions to the redirect operation, that could be developers' addresses.
           RewriteCond %{REMOTE_ADDR} !^123\.456\.789\.000
  • Checking first if the maintenance page exists.
           RewriteCond /Static/ClientPages/maintenance.html -f
  • External switch to enable and disable maintenance: OHS redirects to maintenance pages if a file exists.
           RewriteCond /Static/ClientPages/maintenance.enable -f

These options are well explained in this post.

References:

Redirect Site to Maintenance Page using Apache and HTAccess
Setting a WebCenter Maintenance Page
HTTP status codes
Apache mod_rewrite

Friday, 20 March 2015

Preventing a Slowloris attack on WebCenter

Slowloris refers to a software program that opens several connections to a target web server and tries to keep them alive as long as possible, it will send part of requests periodically, without finishing them, so the server will let the connections alive, waiting for the request to be completed; eventually connection pool will be full and all the requests from users will be refused. Thus, it is a type of hacking attack which makes the web server to stop granting access to users.

For WebCenter implementations that are publicly accessible on the internet, it is important to prevent this type of attacks by configuring the web server. If you are using Oracle HTTP Server (OHS) which is based on Apache technology, the mod_reqtimeout module will solve this issue, as it sets a timeout and a minimum data rate for incoming requests.

In the OHS configuration file (httpd.conf), the following lines would be added:


  <IfModule reqtimeout_module>
#Minimum time to receive the request header is 10 seconds, allowing an increase of 1 second for every 500 bytes received, with a maximum of 40 seconds.
RequestReadTimeout header=10-40,minrate=500
#Minimum time to receive the request body is 20 seconds, increasing 1 second for every 500 bytes received. Limit is set by LimitRequestBody.
RequestReadTimeout body=20,minrate=500
  </IfModule>

After restarting OHS, changes would be applied.

So, is that all? Wait, it is not that easy, those values should be adjusted according to the loading time of the Portal pages and the network perfomance of the users.

References

 

Slowloris Definition
Understanding OHS Modules
Apache Module mod_reqtimeout

Friday, 6 March 2015

Redirecting OAM errors

In a previous post I explained how to avoid an OAM timeout message being displayed in WebCenter Portal. Now, I am going to deal with OAM error pages at OHS/Apache level.

Recently, we faced the following access_denied error:


http://<myhost>:<ohs_port>/oic_rp/return?error=access_denied&state=2441cc276a41daca872fb2eaa364e6da785b0f58

To prevent that error to be displayed to users, we wanted to redirect that URL to the WC Portal login page. As OHS was the web server, we tried different RedirectMatch instructions like the following:



RedirectMatch 301 ^/oic_rp/return?error=access_denied.* http://<myhost>:<ohs_port>/myApp


However, the special character '?' was an issue and redirection did not work. Then we tried RewriteRule module with special characters flags (NE, B), but again, it did not work.

The solution was capturing errors instead of URL using RewriteCond. In this case:



        RewriteEngine on
        RewriteOptions Inherit
        RewriteCond %{QUERY_STRING} error=access_denied [NC]
        RewriteCond %{REQUEST_URI} ^/oic_rp/return$ [NC]
        RewriteRule ^/(.*) http://<myhost>:<ohs_port>/myApp? 


After restarting OHS, the naughty URL was redirecting to the login page.

References:


OAM Standard Error Codes

Redirecting and Remapping with mod_rewrite 

Apache Module mod_rewrite

RewriteRule Flags