Difference between revisions of "WebProtegeHttpsLogin"
Jack.elliott (talk | contribs) |
Jack.elliott (talk | contribs) |
||
Line 43: | Line 43: | ||
== Configure Tomcat to Use HTTPS == | == Configure Tomcat to Use HTTPS == | ||
− | For Tomcat to use https, | + | For Tomcat to use https, we need to add a new connector (Tomcat 6 is not configured for SSL by default) and point it to the keystore. To do this, simply add the following lines to your <code>server.xml</code>, found at <code>$TOMCAT_HOME/conf</code>: |
− | |||
− | |||
− | |||
<pre> | <pre> | ||
− | <-- Define a SSL Coyote HTTP/1.1 Connector on port | + | <-- Define a SSL Coyote HTTP/1.1 Connector on port 443 --> |
<Connector port="443" protocol="HTTP/1.1" SSLEnabled="true" | <Connector port="443" protocol="HTTP/1.1" SSLEnabled="true" | ||
maxThreads="150" scheme="https" secure="true" | maxThreads="150" scheme="https" secure="true" | ||
clientAuth="false" sslProtocol="TLS" keystoreFile="/path/to/my/keystore/.keystore" keystorePass="webprotege"/> | clientAuth="false" sslProtocol="TLS" keystoreFile="/path/to/my/keystore/.keystore" keystorePass="webprotege"/> | ||
</pre> | </pre> | ||
− | |||
− | |||
− | |||
− | |||
− | |||
− | |||
− | |||
− | |||
− | |||
− | |||
− | |||
− | |||
− | |||
− | |||
− | |||
− | |||
− | |||
− | |||
− | |||
− | |||
− | + | Be careful to substitute the /path/to/my/keystore with the correct path to your keystore, which you generated in step one. Note that this connector is already present in the tomcat server.xml file, but it is commented-out. It is very important to set the connector to listen to port 443, because webprotege will always use the default https port, which is 443, and the default Tomcat connector will only listen on port 8443. | |
− | + | == Start Tomcat == | |
+ | You are now ready to start Tomcat. Note that on some versions of Unix, you may need to run the Tomcat server as root or another user with authority over the lower ports; port 443 is secured by default. | ||
== About WebProtege == | == About WebProtege == |
Revision as of 12:25, May 19, 2010
Securing the WebProtege login window using SSL
WebProtege uses a form of client-side encryption for the http login configured by default. To use the more secure SSL login in Tomcat, start by enabling the https property in your protege.properties file.
http://webprotege.stanford.edu
14 Aug 2009: build 200 now available
01 Aug 2009: build 103 now available - compatible with Protege 3.4.1 release and upgraded to GWT 1.7
03 Apr 2009: build 102 now available - compatible with Protege 3.4 release
26 Oct 2008: We are very pleased to announce the initial release of WebProtege 0.5 alpha
View Release Notes
View Download Instructions
Contents
Generate a Key
If you do not have a signed certificate from a certifying authority, you will need to generate a dummy certificate that webprotege can use. Enter a password value of webprotege
when prompted, and be sure to keep a record of where you save the keystore to.
windows:
%JAVA_HOME%\bin\keytool -genkey -alias tomcat -keyalg RSA -keystore \path\to\my\keystore
unix:
$JAVA_HOME/bin/keytool -genkey -alias tomcat -keyalg RSA -keystore /path/to/my/keystore
Configure Tomcat to Use HTTPS
For Tomcat to use https, we need to add a new connector (Tomcat 6 is not configured for SSL by default) and point it to the keystore. To do this, simply add the following lines to your server.xml
, found at $TOMCAT_HOME/conf
:
<-- Define a SSL Coyote HTTP/1.1 Connector on port 443 --> <Connector port="443" protocol="HTTP/1.1" SSLEnabled="true" maxThreads="150" scheme="https" secure="true" clientAuth="false" sslProtocol="TLS" keystoreFile="/path/to/my/keystore/.keystore" keystorePass="webprotege"/>
Be careful to substitute the /path/to/my/keystore with the correct path to your keystore, which you generated in step one. Note that this connector is already present in the tomcat server.xml file, but it is commented-out. It is very important to set the connector to listen to port 443, because webprotege will always use the default https port, which is 443, and the default Tomcat connector will only listen on port 8443.
Start Tomcat
You are now ready to start Tomcat. Note that on some versions of Unix, you may need to run the Tomcat server as root or another user with authority over the lower ports; port 443 is secured by default.
About WebProtege
WebProtege is currently under development by the Protege team at the Stanford Center for Biomedical Informatics Research.
Contact Us
If you have questions or comments, please post them on the protege-discussion mailing list.