March 5, 2018

How to setup Httpd Reverse Proxy To Tomcat

Here is an example on how to configure httpd server with reverse proxy into Tomcat, and adding the authenticated user as header and passing to Tomcat server.

Here is an example of httpd.conf config file:

# Apache httpd v2.4 minimal configuration
ServerRoot "/etc/httpd"
Listen 80

LoadModule mpm_prefork_module modules/
LoadModule unixd_module modules/
LoadModule authz_core_module modules/
LoadModule authz_user_module modules/
LoadModule log_config_module modules/
LoadModule dir_module modules/

# Other useful features
LoadModule mime_module modules/
LoadModule autoindex_module modules/
LoadModule status_module modules/
LoadModule alias_module modules/
LoadModule env_module modules/
LoadModule setenvif_module modules/
LoadModule filter_module modules/
LoadModule ext_filter_module modules/

DirectoryIndex index.html
ErrorLog /var/log/httpd/error.log
LogFormat "%h %l %u %t \"%r\" %>s %b" common
CustomLog /var/log/httpd/access.log common
<Directory />
  AllowOverride None
  Require all denied

DocumentRoot "/srv/www/htdocs"
<Directory "/srv/www/htdocs">
  Require all granted

# Tomcat Reverse Proxy setup
LoadModule proxy_module modules/
LoadModule proxy_http_module modules/
LoadModule rewrite_module modules/
LoadModule headers_module modules/
LoadModule request_module modules/

LoadModule auth_form_module modules/
LoadModule auth_digest_module modules/
LoadModule authn_core_module modules/
LoadModule authn_file_module modules/
LoadModule session_module modules/
LoadModule session_cookie_module modules/

ProxyPass "/jspwebapp" "http://localhost:8080/jspwebapp"
ProxyPassReverse "/jspwebapp" "http://localhost/jspwebapp"
ProxyPass "/jspwebapp2" "http://localhost:8080/jspwebapp2"
ProxyPassReverse "/jspwebapp2" "http://localhost/jspwebapp2"

# HTTPD Form Login/logout process
<LocationMatch "/(jspwebapp|jspwebapp2)">
        Require valid-user
        AuthName "SecuredArea"
        AuthFormProvider file
        AuthUserFile "/etc/httpd/passwd/passwords"
        AuthType form
        AuthFormLoginRequiredLocation "/login.html"

        Session On
        SessionCookieName session path=/
        SessionMaxAge 1800
        SessionEnv On
        SessionHeader X-Replace-Session

        RewriteEngine On
        RewriteRule .* - [env=X_REMOTE_USER:%{LA-U:REMOTE_USER}]
        RequestHeader set appuser "%{X_REMOTE_USER}e"
<Location "/login">
        SetHandler form-login-handler
        AuthName "SecuredArea"
        AuthFormProvider file
        AuthUserFile "/etc/httpd/passwd/passwords"
        AuthType form
        AuthFormLoginRequiredLocation "/login.html"
        AuthFormLoginSuccessLocation "/secured/index.html"

        Session On
        SessionCookieName session path=/
        SessionMaxAge 1800
<Location "/logout">
        SetHandler form-logout-handler
        AuthName "SecuredArea"
        AuthFormLogoutLocation "http://localhost/logout.html"

        Session On
        SessionCookieName session path=/
        SessionMaxAge 1