Skip to content

Commit 5af86a3

Browse files
RANGER-4993 : Ranger KMS - Missing HSTS Headers for 404 Not found requests port 9494
1 parent 30b1988 commit 5af86a3

File tree

3 files changed

+184
-111
lines changed

3 files changed

+184
-111
lines changed

kms/config/webserver/ranger-kms-site.xml

Lines changed: 59 additions & 60 deletions
Original file line numberDiff line numberDiff line change
@@ -12,67 +12,66 @@
1212
limitations under the License. See accompanying LICENSE file.
1313
-->
1414

15-
1615
<configuration>
17-
<property>
18-
<name>ranger.service.host</name>
19-
<value>localhost</value>
20-
</property>
16+
<property>
17+
<name>ranger.service.host</name>
18+
<value>localhost</value>
19+
</property>
20+
21+
<property>
22+
<name>ranger.service.http.port</name>
23+
<value>9292</value>
24+
</property>
25+
26+
<property>
27+
<name>ranger.service.shutdown.port</name>
28+
<value>7085</value>
29+
</property>
30+
31+
<property>
32+
<name>ranger.contextName</name>
33+
<value>/</value>
34+
</property>
2135

22-
<property>
23-
<name>ranger.service.http.port</name>
24-
<value>9292</value>
25-
</property>
26-
27-
<property>
28-
<name>ranger.service.shutdown.port</name>
29-
<value>7085</value>
30-
</property>
31-
32-
<property>
33-
<name>ranger.contextName</name>
34-
<value>/kms</value>
35-
</property>
36-
37-
<property>
38-
<name>xa.webapp.dir</name>
39-
<value>./webapp</value>
40-
</property>
41-
<property>
42-
<name>ranger.service.https.port</name>
43-
<value>9393</value>
44-
</property>
45-
<property>
46-
<name>ranger.service.https.attrib.ssl.enabled</name>
47-
<value>false</value>
48-
</property>
49-
<property>
50-
<name>ajp.enabled</name>
51-
<value>false</value>
52-
</property>
53-
<property>
54-
<name>ranger.service.https.attrib.client.auth</name>
55-
<value>want</value>
56-
</property>
57-
<property>
58-
<name>ranger.credential.provider.path</name>
59-
<value>/etc/ranger/kms/rangerkms.jceks</value>
60-
</property>
61-
<property>
62-
<name>ranger.service.https.attrib.keystore.file</name>
63-
<value></value>
64-
</property>
65-
<property>
66-
<name>ranger.service.https.attrib.keystore.keyalias</name>
67-
<value>rangerkms</value>
68-
</property>
69-
<property>
70-
<name>ranger.service.https.attrib.keystore.pass</name>
71-
<value></value>
72-
</property>
73-
<property>
74-
<name>ranger.service.https.attrib.keystore.credential.alias</name>
75-
<value>keyStoreCredentialAlias</value>
76-
</property>
36+
<property>
37+
<name>xa.webapp.dir</name>
38+
<value>./webapp</value>
39+
</property>
40+
<property>
41+
<name>ranger.service.https.port</name>
42+
<value>9393</value>
43+
</property>
44+
<property>
45+
<name>ranger.service.https.attrib.ssl.enabled</name>
46+
<value>false</value>
47+
</property>
48+
<property>
49+
<name>ajp.enabled</name>
50+
<value>false</value>
51+
</property>
52+
<property>
53+
<name>ranger.service.https.attrib.client.auth</name>
54+
<value>want</value>
55+
</property>
56+
<property>
57+
<name>ranger.credential.provider.path</name>
58+
<value>/etc/ranger/kms/rangerkms.jceks</value>
59+
</property>
60+
<property>
61+
<name>ranger.service.https.attrib.keystore.file</name>
62+
<value></value>
63+
</property>
64+
<property>
65+
<name>ranger.service.https.attrib.keystore.keyalias</name>
66+
<value>rangerkms</value>
67+
</property>
68+
<property>
69+
<name>ranger.service.https.attrib.keystore.pass</name>
70+
<value></value>
71+
</property>
72+
<property>
73+
<name>ranger.service.https.attrib.keystore.credential.alias</name>
74+
<value>keyStoreCredentialAlias</value>
75+
</property>
7776

7877
</configuration>
Lines changed: 64 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,64 @@
1+
/*
2+
* Licensed to the Apache Software Foundation (ASF) under one
3+
* or more contributor license agreements. See the NOTICE file
4+
* distributed with this work for additional information
5+
* regarding copyright ownership. The ASF licenses this file
6+
* to you under the Apache License, Version 2.0 (the
7+
* "License"); you may not use this file except in compliance
8+
* with the License. You may obtain a copy of the License at
9+
*
10+
* http://www.apache.org/licenses/LICENSE-2.0
11+
*
12+
* Unless required by applicable law or agreed to in writing,
13+
* software distributed under the License is distributed on an
14+
* "AS IS" BASIS, WITHOUT WARRANTIES OR CONDITIONS OF ANY
15+
* KIND, either express or implied. See the License for the
16+
* specific language governing permissions and limitations
17+
* under the License.
18+
*/
19+
20+
package org.apache.hadoop.crypto.key.kms.server;
21+
22+
import org.slf4j.Logger;
23+
import org.slf4j.LoggerFactory;
24+
25+
import javax.servlet.Filter;
26+
import javax.servlet.FilterChain;
27+
import javax.servlet.FilterConfig;
28+
import javax.servlet.ServletException;
29+
import javax.servlet.ServletRequest;
30+
import javax.servlet.ServletResponse;
31+
import javax.servlet.http.HttpServletRequest;
32+
import javax.servlet.http.HttpServletResponse;
33+
34+
import java.io.IOException;
35+
36+
public class HSTSFilter implements Filter {
37+
38+
static final Logger LOG = LoggerFactory.getLogger(HSTSFilter.class);
39+
40+
@Override
41+
public void init(FilterConfig filterConfig) throws ServletException {
42+
// Initialization logic if needed
43+
}
44+
45+
@Override
46+
public void doFilter(ServletRequest request, ServletResponse response, FilterChain chain)
47+
throws IOException, ServletException {
48+
if (LOG.isDebugEnabled()) {
49+
LOG.debug("===> HSTSFilter:doFilter()");
50+
}
51+
String path = ((HttpServletRequest) request).getRequestURI();
52+
if (LOG.isDebugEnabled()) {
53+
LOG.debug("==> HSTSFilter:doFilter() path = " + path);
54+
}
55+
HttpServletResponse resp = (HttpServletResponse) response;
56+
resp.setHeader("Strict-Transport-Security", "max-age=31536000; includeSubDomains; preload");
57+
chain.doFilter(request, response);
58+
}
59+
60+
@Override
61+
public void destroy() {
62+
// Cleanup logic if needed
63+
}
64+
}

kms/src/main/webapp/WEB-INF/web.xml

Lines changed: 61 additions & 51 deletions
Original file line numberDiff line numberDiff line change
@@ -18,56 +18,66 @@
1818

1919
<web-app version="2.4" xmlns="http://java.sun.com/xml/ns/j2ee">
2020

21-
<display-name>ranger-kms</display-name>
22-
<absolute-ordering />
23-
24-
<listener>
25-
<listener-class>org.apache.hadoop.crypto.key.kms.server.KMSWebApp</listener-class>
26-
</listener>
27-
28-
<servlet>
29-
<servlet-name>webservices-driver</servlet-name>
30-
<servlet-class>com.sun.jersey.spi.container.servlet.ServletContainer</servlet-class>
31-
<init-param>
32-
<param-name>com.sun.jersey.config.property.packages</param-name>
33-
<param-value>org.apache.hadoop.crypto.key.kms.server</param-value>
34-
</init-param>
35-
<load-on-startup>1</load-on-startup>
36-
</servlet>
37-
38-
<servlet>
39-
<servlet-name>jmx-servlet</servlet-name>
40-
<servlet-class>org.apache.hadoop.crypto.key.kms.server.KMSJMXServlet</servlet-class>
41-
</servlet>
42-
43-
<servlet-mapping>
44-
<servlet-name>webservices-driver</servlet-name>
45-
<url-pattern>/*</url-pattern>
46-
</servlet-mapping>
47-
48-
<servlet-mapping>
49-
<servlet-name>jmx-servlet</servlet-name>
50-
<url-pattern>/jmx</url-pattern>
51-
</servlet-mapping>
52-
53-
<filter>
54-
<filter-name>authFilter</filter-name>
55-
<filter-class>org.apache.hadoop.crypto.key.kms.server.KMSAuthenticationFilter</filter-class>
56-
</filter>
57-
58-
<filter>
59-
<filter-name>MDCFilter</filter-name>
60-
<filter-class>org.apache.hadoop.crypto.key.kms.server.KMSMDCFilter</filter-class>
61-
</filter>
62-
63-
<filter-mapping>
64-
<filter-name>authFilter</filter-name>
65-
<url-pattern>/*</url-pattern>
66-
</filter-mapping>
67-
68-
<filter-mapping>
69-
<filter-name>MDCFilter</filter-name>
70-
<url-pattern>/*</url-pattern>
71-
</filter-mapping>
21+
<display-name>ranger-kms</display-name>
22+
<absolute-ordering />
23+
24+
<listener>
25+
<listener-class>org.apache.hadoop.crypto.key.kms.server.KMSWebApp</listener-class>
26+
</listener>
27+
28+
<servlet>
29+
<servlet-name>webservices-driver</servlet-name>
30+
<servlet-class>com.sun.jersey.spi.container.servlet.ServletContainer</servlet-class>
31+
<init-param>
32+
<param-name>com.sun.jersey.config.property.packages</param-name>
33+
<param-value>org.apache.hadoop.crypto.key.kms.server</param-value>
34+
</init-param>
35+
<load-on-startup>1</load-on-startup>
36+
</servlet>
37+
38+
<servlet>
39+
<servlet-name>jmx-servlet</servlet-name>
40+
<servlet-class>org.apache.hadoop.crypto.key.kms.server.KMSJMXServlet</servlet-class>
41+
</servlet>
42+
43+
<servlet-mapping>
44+
<servlet-name>webservices-driver</servlet-name>
45+
<url-pattern>/kms/*</url-pattern>
46+
</servlet-mapping>
47+
48+
<servlet-mapping>
49+
<servlet-name>jmx-servlet</servlet-name>
50+
<url-pattern>/jmx</url-pattern>
51+
</servlet-mapping>
52+
53+
<filter>
54+
<filter-name>authFilter</filter-name>
55+
<filter-class>org.apache.hadoop.crypto.key.kms.server.KMSAuthenticationFilter</filter-class>
56+
</filter>
57+
58+
<filter>
59+
<filter-name>MDCFilter</filter-name>
60+
<filter-class>org.apache.hadoop.crypto.key.kms.server.KMSMDCFilter</filter-class>
61+
</filter>
62+
63+
<filter>
64+
<filter-name>HSTSFilter</filter-name>
65+
<filter-class>org.apache.hadoop.crypto.key.kms.server.HSTSFilter</filter-class>
66+
</filter>
67+
68+
<filter-mapping>
69+
<filter-name>authFilter</filter-name>
70+
<url-pattern>/kms/*</url-pattern>
71+
</filter-mapping>
72+
73+
<filter-mapping>
74+
<filter-name>MDCFilter</filter-name>
75+
<url-pattern>/kms/*</url-pattern>
76+
</filter-mapping>
77+
78+
<filter-mapping>
79+
<filter-name>HSTSFilter</filter-name>
80+
<url-pattern>/*</url-pattern>
81+
</filter-mapping>
7282

7383
</web-app>

0 commit comments

Comments
 (0)