HTTPS - Redirection : Security aspect in our application


General J2EE: HTTPS - Redirection : Security aspect in our application

  1. Hi,
    Well, I am trying to really figure out, how the control is redirecting to the login page (HTTPS), when I click on a link (jsp page - index.jsp) under the directory res/tool -and it pops up the security certificate acceptance window. So, index.jsp is present in this folder (res/tool). I checked out web.xml, where there no restrictions for this folder or file. I checked out weblogic.xml too - couldn't figure out. This is too too puzzling. Could any of you please tell me where else the restrictions could've been enabled for security in the application.

    Thanks so much in advance.
    Best Wishes

    Threaded Messages (12)

  none


    On which port is your application deployed?
    Checkout file for ssl configurations.

  HTTPS

    Appreciate much your reply.
    Well, but, there isn't any file called '' in our project, though we are using weblogic server for development. Any other file related to SSL configurations you think ?? We run our project at port 7001 and I think it leads to port 7002 HTTPS after redirection. Please respond.
  SSL

    The properties file belong to your server and not application.I am not sure which weblogic server version you are using but weblogic root directory might be having the file.It is the main config file for weblogic server 5.1.x
    refer this site
  SSL


    Thanks much for your reply.
    Well, yeah, I did search through the server stuff only. I only see config file (config.xml)and not We are using weblogic 8.0. But I don't see any particular setting for that particular directory in the config file - from where the control leads to HTTPS - 7002. Could you please help me figure this out, as to where exactly the security setting would have been enabled. It's too puzzling. I actually searched for the directory and file name, in the server directories but couldnt get any matching string.

  SSL


    config.xml is the one for this version of weblogic.
    It will be difficult to say what exacly is wrong...Maybe you can post your config .xml here which might help to figure out what settings you have in there.
    If your application is not referring to https atall this should not be a problem.Unless something went wrong while deploying the app.
  SSL

    Thanks so much for the timely responses.
    Well, my application is referring to HTTPS, as my page is redirected from HTTP at 7001 to HTTPS at 7002. I just wanna find out this 'part of functionality' in my application, where exactly this security aspect has been enabled.
    Accessing files in resources/tool is getting redirected to HTTPS at 7002. Even if you jus say http//localhost7001/resources/tool it goes to https//localhost7002/secure/
    For this to happen resources/tool should have got the security settings right? but I dont see the directory names mentioned in config.xml nor in web.xml or weblogic.xml. PLease tell where I could find it.
    Really appreciate your assiatnce.
  SSL

    This forum here doesn't take colons.. thats why there r no colons in the urls mentioned.
  struts

    ok so you are using struts duh!

    For starters check if in your struts-config you have mistakenly typed https: in the forward attribute for your login.check the global forwards too.
  struts

    We r using string as 'https' in struts.config.
    Well, I just click on that link and it forwards to https..really puzzled abt this redirection part where it's been me out.
    look forward to ur reply.
  None


    Is it possible for you to paste struts-config and weblogic config.xml in this forum ?

    It will be difficult to say otherwise.

  None

    Hey...I dont have rights to paste the code here bcoz of security reasons of mmy company. But ok, in those 2 files I just dont see those folder names at all - I am sure the security aspect has been dealt in these 2 files. Help me out pl.
  None

    In my last reply I meant the security aspect has not been dealt in those 2 files.sorry.