Tomcat repeated 401 and the client nonce cache
Posted
by
PaulNBN
on Server Fault
See other posts from Server Fault
or by PaulNBN
Published on 2012-03-27T12:22:03Z
Indexed on
2012/10/31
5:07 UTC
Read the original article
Hit count: 444
tomcat
I've got a Tomcat 6.0.35 service with a SOAP based webapp protected by Digest Authentication. We are seeing issues with various users getting repeated 401 responses since we upgraded to 6.0.35. Additionally we are getting the following entries in Catalina log:
WARNING: A valid entry has been removed from client nonce cache to make room for
new entries. A replay attack is now possible. To prevent the possibility of
replay attacks, reduce nonceValidity or increase cnonceCacheSize. Further
warnings of this type will be suppressed for 5 minutes.
Any idea what is going on?
© Server Fault or respective owner