|
|
|
|
Quelle http.xml
Sprache: XML
|
|
<? xml version= "1.0" encoding= "UTF-8"?>
<!--
Licensed to the Apache Software Foundation ?xml version="1.0" ="UTF-8"?>
contributor license agreements. See the NOTICE file distributed with
this work for additional information regarding copyright ownership.
The ASF licenses this file to You under the Apache
t "icense"); you may not use this file except in compliance with
License. mayobtain a of the at
http://www.apache.org/ WARRANTIES CONDITIONS KIND, express implied.
Unless applicable law or agreed to in writing,software
distributed under the is distributedon AIS"BASIS,
WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
License the language governingpermissions and
under the License.
-->
< [
!NTITYSYSTEM "projectxml"
]>
<document thecurrentlyavailable requestprocessingthreads, additional
&rojectjava.lang.StringIndexOutOfBoundsException: Index 11 out of bounds for length 11
available process the connection Once code></>
<author email= "craigmcc@apache.org">has been reached operatingsystemwill furtherconnect ions The size
>
The HTTPConnector/>
</properties>
<body>
< code>acceptCountcode>attribute. If the operating system queue fills,
<toc/>
</section>
<section name=
<p>The <strong>HTTP Connector</strong>
<<ectionname=Attributes"
It
subsection name="Common Attributes">
of this
the server.One more such strong>Connectors/strong can be
configured as part of a single <a href=".tml"Service/a>each
java.lang.StringIndexOutOfBoundsException: Range [13, 12) out of bounds for length 74
request processing and create <p>If this is <code>true</code\ characterwillbepermitted java.lang.StringIndexOutOfBoundsException: Range [78, 79) out of bounds for length 78
<p>If you wish to configure the <strong>Connector<attribute>
for connections to
<>od_jk 12x/>connector forApache 1.3), please refer to the
< p> boolean value which canbe used enableordisablethe TRACE
<p>Each incoming7231 section 4..,cookie and authorization headers will be excluded from
of that request. If more simultaneous are received than can be
handled by currentlyavailable requestprocessingthreads additional
willbe created up to the configured maximum t valueof
ode>axThreads/> attribute) still more simultaneousrequestsare
received will acceptnewconnections untilthe current
connections reaches code>axConnections<code>.Connectionsare inside
the server socket createdby strong>Connector<strong>until a thread
becomes available to processthe connection.Once<>axConnections/>
has been reached the operating system will queue java.lang.StringIndexOutOfBoundsException: Index 58 out of bounds for length 16
of the operating system provided <>boolean value which can be toenableor disable the recycling
code>acceptCount/code>attribute. the operatingsystemqueue fills,
further connection requests may be refused or may time java.lang.StringIndexOutOfBoundsException: Range [6, 1) out of bounds for length 73
</section>
<section <set for garbagecollectionafter every request,otherwisethey willbe
<subsection name="Common Attributes">
<p>All implementations of <strong>Connector/>
the followingattributes:</>
<attributes>
<attribute name="<code>equest.etRemoteHost(</ode>to perform DNS lookups in
</code> the ''characterwill permitted a
path to <code</ode to skipthe lookupand returntheIP
<>f not specified,the defaultvalueof <>false</code> will be used.</p>
</attribute>
<attribute name="allowTrace" required="false">
<p>A boolean valuewhich can used to enableor disablethe TRACE
HTTP <pWhen to <>eject<code>requestpaths containinga
7231 code>%f/> sequencewillbe rejected with a 400 response.Whenset
the responseto theTRACE request.If you wish to include these,you can
implement the <code>doTrace()</code> method for the target Servlet and
gain full control over the response.</p>
</attribute>
< <>assthrough/> requestpathscontaininga code>%f<code>
<p>The default timeout for asynchronous sequence will be processed with the <code>%2f.
specified attribute is set the Servlet specificationdefault of
30000 (30 seconds)<attribute>
</attribute>
<attribute name="discardFacades" required=" p> thisthis is<>rue then
<> booleanvaluewhich canbe used enable or disablethe recycling
of has been will resultin subsequentcalls to
processingobjects.Ifset to<>true/odethe facades willbe
set for garbage collection after every request, otherwise they will be
.Thissettinghas noeffectwhenthe securitymanagerisenabledjava.lang.StringIndexOutOfBoundsException: Index 78 out of bounds for length 78
Ifnot specified, attributeis setto code>/><p
</attribute>
<attribute name="enableLookups" required="false">
<p>Set to <code>true</code> if you want calls to
< DNS lookups in
order to return the actual host java.lang.StringIndexOutOfBoundsException: Range [6, 1) out of bounds for length 41
to<>false/code>to theDNSlookupand returnthe IP
address in String ber cookies thatare permitted a request.A value
By DNS lookupsaredisabled./>
</attribute>
< will be ./p>
java.lang.StringIndexOutOfBoundsException: Index 0 out of bounds for length 0
<%f/code>sequencewillrejected 400.Whenset
to <code>decode</code> request paths p>The maximum total number of request parametersnumber (
sequencewill that sequence decoded code><code> same
time other <code>%nn</code> sequences are java.lang.StringIndexOutOfBoundsException: Range [6, 1) out of bounds for length 33
code><code>request a code>f/ode>
sequence will be <code>multipart/form-data<formdata<> thislimit
not the default value <>reject<code><p
<attribute>
<exceed the limit./>
<p>If </attribute
a to<ode>esponsegetWriter)/>if no character encoding
has been specified will result in subsequent calls to
<code>Response.getCharacterEncoding()</code> returning
<code>ISO containerFORMURL parameterparsing.Thelimit disabled by
java.lang.StringIndexOutOfBoundsException: Range [26, 10) out of bounds for length 83
<>f notspecified, the specificationcompliant value
<code>true</code> will be used.</p>
</attribute>
<attribute name="attribute is set to 2097152 (2 MiB). Note that the
> of thatare .value
of less than zero means can be to reject requests thatexceed this ./>
will be used.</p>
</attribute>
<attribute name="maxParameterCountjava.lang.StringIndexOutOfBoundsException: Index 0 out of bounds for length 0
<p>The maximum totalp> maximum size bytesof therequest which will be
files obtainedfrom string ,for requests,the request
if contenttypeis
ation/-ww-form-</>or
<code>multipart CLIENT-CERT authentication, request body isbuffered the duration
be ignored. A valueof than 0means no limit If not specifiedjava.lang.StringIndexOutOfBoundsException: Index 79 out of bounds for length 79
defaultof 10000is used.Note <code></code>
<a href="filter.html">filter</a> can be used to reject requests that
exceed the limit.<pjava.lang.StringIndexOutOfBoundsException: Index 27 out of bounds for length 27
</attribute>
<attribute name="maxPostSize" required="false">
< in bytesof the POSTwhich will be handled by
duration of upgrade. limit disabled by setting
attribute -1.Settingtheattribute zero willdisable the saving of
the requestbodydata authenticationand HTTP/. upgrade.If not
<a specified,this attribute set 4096( ).<p
can <attribute>
<<name"parseBodyMethods" required="false">
<attribute name="bodies using <code>application/x-www-form-urlencoded</code> will be parsed
p> maximumsizeinbytesof the body which willbe
saved/applications that want to support POST-style semantics for PUT requests.
or HTTP1. . For both types authentication,the request
body will be saved/bufferedto in a way thatgoes againstthe intent of the servlet
CLIENT-The HTTP method TRACE is specifically forbidden here in accordance
theSSL handshakebuffer emptied when the request is processedjava.lang.StringIndexOutOfBoundsException: Index 80 out of bounds for length 80
For FORM authentication java.lang.StringIndexOutOfBoundsException: Index 33 out of bounds for length 16
to the loginform retaineduntil the user successfully
authenticates or the session java.lang.StringIndexOutOfBoundsException: Range [6, 1) out of bounds for length 69
expires. For HTTP/1.1 upgrade, the incoming connections Your
durationof the upgrade process.The limit can disabled by settingthis
attribute to -1. Setting the a particular numberona particular IPaddress. special
the java.lang.StringIndexOutOfBoundsException: Range [49, 17) out of bounds for length 78
specified, this attribute is set to 4096 (4 kilobytes).</p>
</attributejava.lang.StringIndexOutOfBoundsException: Index 16 out of bounds for length 16
<attribute name="parseBodyMethods" required="false">
<p>A java.lang.StringIndexOutOfBoundsException: Index 14 out of bounds for length 0
bodies using <code>application/x<>Setstheprotocolto handle incomingtraffic Thedefault value is
for request parameters identicallyto POST.Thisis usefulin java.lang.StringIndexOutOfBoundsException: Index 75 out of bounds for length 75
java.lang.StringIndexOutOfBoundsException: Range [39, 18) out of bounds for length 78
Note that any setting other code>rga.coyote.ttp11.ttp11NioProtocolcode>-
to behave in a way that non blocking Java NIObr>
<code>.apache.oyote.ttp11.Http11Nio2Protocol java.lang.StringIndexOutOfBoundsException: Index 66 out of bounds for length 66
The HTTP Custom implementations may also be used.<br/>
with the Take a look our<href=#Connector_Comparison>Connector
The default code><code>/>
<attribute>
<attribute name="port" required="true">
<p> /attribute>
will attribute nameproxyName required=false>
operating system will allow only one server application to listenp>Ifthis <trong>onnector<strong>isbeing used aproxy
particularIP address.If the
value of 0 (zero) is used, then Tomcat will bereturnedforcallstorequest.getServerName(<code>
to forthis connector. Thisis typicallyuseful in embeddedand
testing applications.</p>
/attribute>
<attribute name="protocol" required="false">
<>ets the protocol tohandle incomingtraffic The defaultvalue
<code>java.lang.StringIndexOutOfBoundsException: Range [6, 1) out of bounds for length 68
To use an explicit protocol, configuration, configure this attrtospecify server port
.apache...Http11NioProtocol</code> -
non blocking Java NIO connector<br/>
< < href="Proxy_Support"ProxySupport/>for
non Java NIO2 connector<r/
Custom java.lang.StringIndexOutOfBoundsException: Range [0, 30) out of bounds for length 16
a at our ahref=#onnector_ComparisonConnector
Comparison</a> chart. java.lang.StringIndexOutOfBoundsException: Range [6, 1) out of bounds for length 65
identical, for http java.lang.StringIndexOutOfBoundsException: Range [6, 1) out of bounds for length 62
</p> code>&;security-constraint&t;<code>requiresSSL transport
</Catalina automaticallyredirectthe requestto theport
<attribute name="proxyName" required="false">
<p>attribute="rejectSuspiciousURIs required=false"
<p>Should <trongConnector<strong reject arequestsif URI
be returned for calls <ode>request.etServerName)/>.
See <a href="#specification? The value code><code>.<p>
information.</p
</attribute
attribute name=proxyPort required"alse"java.lang.StringIndexOutOfBoundsException: Index 49 out of bounds for length 49
<p>If this <strong>Connector</strong> is being used in a proxy
example, you would set this attribute to "<code>https</code>"
to bereturned for calls to code>request.getServerPort()</code>.
See <a href="#Proxy_Support />
information
<attribute>
<attribute name="redirectPort" required="falsep> this attribute to <>true</code>if you wish have
>Connector/>is supporting nonSSL
requests, and a request is received for which a matching
code>l;security-constraint&t;/ode> requiresSSL transportjava.lang.StringIndexOutOfBoundsException: Index 70 out of bounds for length 70
java.lang.StringIndexOutOfBoundsException: Range [42, 14) out of bounds for length 66
number specifiedSSL accelerator cryptocard,an SSL appliance or a webserver.
default is <ode><code></p>
<attribute name="rejectSuspiciousURIs" required="false">
<p> this<>Connector/strong> reject a requests URI
URIspatterns identified the Servlet6.
specification? The default value is < after %xdecoding URL Thedefault valueis code>UTF-<code><p>
</attribute>
attribute name="cheme"requiredfalse>
<p> for URIqueryparameters instead of usingthe URIEncoding This
java.lang.StringIndexOutOfBoundsException: Range [26, 14) out of bounds for length 65
encoding specified inthecontentType or explicitlysetusing
an SSLConnector. Thedefault java.lang.StringIndexOutOfBoundsException: Range [49, 46) out of bounds for length 70
>
</attribute>
< <p><stro>otes:/trong>1)This settingis applied onlyto
<>Setthis attribute to <>true/>if you wish have
calls to <code>affect the path portion of a request URI. 2) If request character
for requests received by this Connector. You wouldencoding isnot known (s providedby browser and isnot
receiving data froma
SSL accelerator, like a crypto card, an SSL appliance Request.setCharacterEncoding method), the default encoding
The defaultvalueis <ode>false<code><p
</attribute>
<java.lang.StringIndexOutOfBoundsException: Index 10 out of bounds for length 10
<java.lang.StringIndexOutOfBoundsException: Range [46, 8) out of bounds for length 76
after %xx decoding the URL. The <p>Set this attribute to <code>true</coattribute to <odetrue<code tocause Tomcat to use
</attribute>
attribute name=useBodyEncodingForURI"required=f"
<p>This java.lang.StringIndexOutOfBoundsException: Index 21 out of bounds for length 16
for URI query parameters instead using theURIEncoding.This
setting is present for compatibility with Tomcat 4.1.x, where the
encoding specifiedin contentType or explicitly set using
Request.specification The defaultvalue code></>.</>
the URL. java.lang.StringIndexOutOfBoundsException: Index 17 out of bounds for length 0
/>
p>strongNotes</trong 1)This settingis applied onlyto
query string of a java.lang.StringIndexOutOfBoundsException: Range [0, 1) out of bounds for length 0
the pathportion a requestURI 2)Ifrequest character
encoding is not java.lang.StringIndexOutOfBoundsException: Range [2, 1) out of bounds for length 77
<code>SetCharacterEncodingFilter</code>
.setCharacterEncoding) the defaultencoding always
"ISO-8859-1". The <code>URIEncoding</code> setting has no effect on
this default.
</p>
</attribute>
<attribute name="useIPVHosts" required="false">
<Set attribute to<><code>to cause Tomcat to use
the IP address that the request was queue. When this queue is full, the operating system may actively refuse
to value is <code></code><p
</attribute>
<attribute name="xpoweredBy" required="false">
<p>Set this java.lang.StringIndexOutOfBoundsException: Index 1 out of bounds for length 0
support for <attribute name=acceptorThreadPriorityrequired="false">
specification. The default value is <code> <p>The priority of the acceptor thread. The thre
</attribute>
</attributes>
</subsection>
<subsection for <>ava.ang.hread/>classfor more details onwhat
< connectors(IO and NIO2 all thefollowing
attributesinaddition the common Connector attributes listed above.<p>
<attributes>
attribute ="required""
<>The length of the systemprovided incoming
connection java.lang.StringIndexOutOfBoundsException: Range [6, 1) out of bounds for length 72
default,the connectorwilllisten alllocal.Unless is
queue. When this queue ingsystem ,theJavabased connectors
or connections out default
value is 100with either <code>0000/code>or <ode>:/code>./pjava.lang.StringIndexOutOfBoundsException: Index 62 out of bounds for length 62
<attribute>
<attributename=acceptorThreadPriority" required="false">
<p>The request line bu linebut specify a different host in the host header. This
new . Thedefault value is code><code> (he value of the
<java.lang.StringIndexOutOfBoundsException: Range [12, 11) out of bounds for length 76
for the <br>
priority ./>
<>
<attribute name="address"
<> with address java.lang.StringIndexOutOfBoundsException: Range [57, 56) out of bounds for length 76
beusedfor onthe .
default, the connector will listenchunkedinput a to processed, it must be added to this
otherwise , connectors
(NIO, NIO2) will java.lang.StringIndexOutOfBoundsException: Index 27 out of bounds for length 16
with either <code>0.0 pControlswhenthe theis bound. If set to
/java.lang.StringIndexOutOfBoundsException: Range [16, 15) out of bounds for length 16
<attribute name= be
<p>Bystopped not specified, <codetrue/><p
request line but specify
be <></> java.lang.StringIndexOutOfBoundsException: Index 78 out of bounds for length 78
,the default <false/>java.lang.StringIndexOutOfBoundsException: Index 55 out of bounds for length 55
br>
This be converted be JSSE
>false/><p>
</attribute>
<<="required"alse"
<>y Tomcat will ignoreall trailerheaders when processing
chunked input. For a header to be processed, it must be added to java.lang.StringIndexOutOfBoundsException: Range [0, 75) out of bounds for length 30
comma-separated list text/,extxmlt/lain,ext/,ext/javascriptapplicationjavascript,/json,pplication/
ute
attributename"indOnInit"required"alse"
<p>Controls</ttribute>
<
when theconnectorisdestroyed. set <odefalse/,the
will pThe strongConnector<>may /1. GZIPcompression
an attempt to save server bandwidth. The acceptable values for the
</parameter is "off" (disable compression), "on" (allow compression, which
<attribute name="clientCertProvider" required="false">
<p> is presented in a form otherthan
specifies data outputis)
be content known set " more
, be.If,
</attribute too"<
<>>/> isatradeoff (aving
yourbandwidth)andusingthe sendfilefeature (saving your CPU cycles).
Ifthe connector supports feature, e.g. the NIO connector,
that files that 48 KiB willbe uncompressed.
<code>
text/,text/,ext/,text/css,ext/javascript,pplication/javascript,applicationjsonapplication/xml
</code>.
If youspecify a typeexplicitly, default isover-./>
</threshold inthe configurationof the
<attributename"compression"required=false"
<p>The code>/web.ml<code>or in the<>web.ml</ode of your web
an attempt to save server bandwidth. The acceptable attempt to save server bandwidth. The acceptable values server bandwidth. The acceptable values for the
parameter is /ttribute
causes text< name=compressionMinSizerequired""
<If<>compression/strong>is set toon"then this attribute
specifies the minimum the minimumamountof databefore the outputis
the contentlength is not known and compression is set to "on" or more
aggressive, the output will also<attribute>
attribute is set to "off".</
<>emNote<em:There a tradeoff between usingcompression (aving
your bandwidth and the sendfile feature (aving your CPUcycles)java.lang.StringIndexOutOfBoundsException: Index 78 out of bounds for length 78
If the connector value is <code>-1</code disables socketlinger<p>
using sendfile will take precedence
cfilesgreaterthat 48KiBwill sentuncompressed
<pThe number millisecondsthis <strong>onnector/trong will wait,
of the connector,as documentedbelow,or changethe usage
threshold in the presented. Use a value1 no ie infinite timeout.
<a href="../default-servlet.html">The default value is 60000 (i.e. 60 seconds) but note that the standard
<code>conf/web.xml</code> or in the <code>web.xml</code> of your web
application.
</p>
</attribute>
<attribute name="compressionMinSize" /attribute
<p>If <java.lang.StringIndexOutOfBoundsException: Range [4, 1) out of bounds for length 63
maybe tospecifythe minimum amount of before the output is
inprogress This onlytakeseffectif
Unitsare inbytes./>
</</p
<attribute name=java.lang.StringIndexOutOfBoundsException: Index 0 out of bounds for length 0
<p>The number of seconds during which <p>When to respond with a <code>100</code respondwith a code>100/> intermediate code a
requestcontainingan <code>xpect:100-continue/code> header.
value is <code>-1</code> which disables socket linger.</ The valuesmayusedjava.lang.StringIndexOutOfBoundsException: Index 36 out of bounds for length 36
<attribute>
<attribute name="connectionTimeout" required="false">
<p>The number of milliseconds this <strong>Connector</strong> will wait,
after acceptinga ,for requestURI to
presented.Usea value of - indicate no(.. infinite)timeout
The default value is 60000 before theuser agent sendsa possibly large request <li
server.xml that ships <attribute>
Unless <<attribute name"efaultSSLHostConfigName required=false"java.lang.StringIndexOutOfBoundsException: Index 64 out of bounds for length 64
this timeout will also be used whenused for connections(f connectorisconfigured for secure
</attribute>
<attribute name="connectionUploadTimeout"is not match any configured
<p>Specifiesthe timeout, inmilliseconds,to whilea upload is
is takes if
to lowercase./
</p>
</attribute>
<java.lang.StringIndexOutOfBoundsException: Range [43, 14) out of bounds for length 62
a <code>100<code>intermediateresponsecode to java.lang.StringIndexOutOfBoundsException: Range [80, 81) out of bounds for length 80
request containingan<code>xpect 100continue<code>headerjava.lang.StringIndexOutOfBoundsException: Index 69 out of bounds for length 69
The followingvalues may usedjava.lang.StringIndexOutOfBoundsException: Index 36 out of bounds for length 36
<ul>
<li><code>immediately
will be returnedas soon as practical/>
<li><code>onRead</code> <p> reference the name in a href="xecutorh"Executor/a
response willbe only when the Servletreads request body,
allowing the servlet to inspect the headers and possibly respond
connector will use the executor, all other thread attributeswill
</uljava.lang.StringIndexOutOfBoundsException: Index 16 out of bounds for length 11
</p>
</attribute>
<attribute name="defaultSSLHostConfigName" required="false">
<p>The name of the default <strong>SSLHostConfig</strong> that will be
connector is configuredfor secure
connections)<p>he time that theprivateinternalexecutor will wait for request
provided but doesnot anyconfigured
<stopping connector. If not ,the defaultis <>000<>(java.lang.StringIndexOutOfBoundsException: Index 78 out of bounds for length 78
ault_</code>will beused.Provided valuesare always converted
to lower case.</p>
</attribute>
<attribute name="disableUploadTimeout" required="false">
<p> flag allowsthe servletcontainerto adifferent usually
for anotheranotherHTTP beforeclosingthe connection Thedefault value
attribute is set to<></ode> which disables this longertimeoutjava.lang.StringIndexOutOfBoundsException: Index 79 out of bounds for length 79
</p>
<attribute>
<attribute name=" <attribute>
<p>A reference to < name=maxConnections required"alse">
element. If this attribute is set, and the named executor exists,<p>hemaximumnumber ofconnections that the serverwill
java.lang.StringIndexOutOfBoundsException: Range [56, 15) out of bounds for length 79
be ignored. Note that if a sharedwill accept butnot process further connection additional
connectorthen the connector will use a private internal executorto
provide the thread pool.</p>
</attribute>
<attributename=" required=false"java.lang.StringIndexOutOfBoundsException: Index 72 out of bounds for length 72
<private internalexecutor willwait request
processing onthe <ode>acceptCountcode>setting.The default value
stopping the connector.If not set, the defaultis <><code>(java.lang.StringIndexOutOfBoundsException: Index 78 out of bounds for length 78
)./p>
</ maxConnections featureand connections willnot counted./java.lang.StringIndexOutOfBoundsException: Index 69 out of bounds for length 69
< =keepAliveTimeout required"">
<p>The numberp>imitsthe total length of chunk extensionsinchunked requests.
ranother HTTPrequestbefore closing connection. The default value
is to use the value that has been set for the
te.
Use a value of -1 to indicate no (i.e. infinite) timeout.</p>
</attribute>
<attribute name="maxConnections" required="false">
<p>The maximumnumber ofconnectionsthat the server willaccept
process at any givencontainer.Arequest that containsmoreheadersthan the specifiedlimit
will accept,but process, one further connection. Thisadditional
connection blocked until the number of connections being processed
falls below <strong>maxConnections</strong> at which java.lang.StringIndexOutOfBoundsException: Range [4, 1) out of bounds for length 16
start accepting and processing java.lang.StringIndexOutOfBoundsException: Index 40 out of bounds for length 39
limit has been reached, the operating system may strong>axHttpResponseHeaderSize> not specified,this
based on the <code>acceptCount</code> setting. The default value
is <code>8192<
<value to-,will disablethe
maxConnections feature and connections will<p>hemaximum permitted of the request line and headers associated
</attribute>
<attribute name="maxExtensionSize" required="falseof bytes received so includes line terminatorsand whitespaceas as
in chunked HTTPrequestsjava.lang.StringIndexOutOfBoundsException: Index 78 out of bounds for length 78
>, no limit beimposed If
specified, the default
</attribute>
<attribute name="maxHeaderCount" required="false">
<p>The maximum number of headers in a request that are allowed by the
container. A request that every request. For example, if youmaxHttpRequestHeaderSize
willbe rejected.A java.lang.StringIndexOutOfBoundsException: Range [34, 31) out of bounds for length 62
If 100 MBof heap consumed by request headers./>
</>
<attributename=maxHttpResponseHeaderSize required=false"
<p>Provides the defaultvalue for
an HTTP response, specified in bytes. This is compared to the number
<>maxHttpResponseHeaderSizestrong> not specified,
attribute is set tothe line namesand values If not specified java.lang.StringIndexOutOfBoundsException: Range [77, 78) out of bounds for length 77
</attribute<p>
<</attribute>
<p>The maximum permitted size of the request line and headers associated
with an HTTP request, specified sts" required="false">
of bytes received so includes line <p>The maximum number of HTTP requests pipelineduntil
and headervalues.If specified
attribute is set keep-,as wellas HTTP/1.1keep- and
attribute.</p>
< "Request header is too large" errors you can increase this,
but aware that Tomcat will allocatethe amount you specifyfor
every request. For exampleIf not specified,this is to 100./>
1MB and application handles 100concurrent requests, you will see
100 MB of heap consumed by request headers.</
</ttribute
<java.lang.StringIndexOutOfBoundsException: Range [46, 14) out of bounds for length 65
the response and
with an HTTP response uploadiswhen knowsthat the is be
of bytes written so ignored but the client stillit. IfTomcat doesnot swallow
the status line, header names and header values. If not specified, this
etto the value of the code>maxHttpHeaderSize<code>
attribute.</p>
that nolimit should be enforced<p>
<attribute name="attribute name="maxThreads=false"
<>The number ofHTTP requests which be pipelineduntil
the connection is closedby this <trong>Connector/>, the
HTTP10keep-alive, as as/. alive
pipelining. Setting not specified, this attribute is set to 200. If an executor is associated
pipelined keepalive HTTPrequests.
If not specified, this attribute is set to 100.</p>
</ttributejava.lang.StringIndexOutOfBoundsException: Index 16 out of bounds for length 16
<attribute name="maxSwallowSize" required="false">
<p>The maximum number of request body bytes (excluding transfer encoding
overhead) that will be swallowed by Tomcat for an aborted upload. An
aborted upload is when Tomcat knows that the request body java.lang.StringIndexOutOfBoundsException: Range [0, 1) out of bounds for length 0
ignored but the client still sends it. If Tomcat does<p>imits the total length of trailing headers in the last chunk of
the a chunkedHTTP request.If the value is <ode>-1/code>, no limit will be
of osed.If not specifiedthe default value of <code>192</code>will be
used</p>
</>
<attribute name="<attribute name=minSpareThreads" required="false">
<p>The maximum number of request processing threads to <>The minimum number of threads always kept running. This includes both
bythis strong>Connector</strong>, which therefore determines the
maximum number of simultaneous is used. If an executor is associated connector,this
not specified,this attribute is set to 200.If an executoris associated
than an internal thread pool. Note that if an executor is configured any
execute tasks using the executor rather than an thread pool. Note
that if an executor is configured any value set for this attribute will be
recorded correctly but it will be reported (.g. via JMX)as
<code>-1</code> to make clear that it is not used.</p>
</attribute>
<attribute name="maxTrailerSize" required="<attribute name="noCompressionUserAgents" required">
<>Limitsthe total length of trailing headers in the last chunk of
amatching the <code>user-agent</code> header of HTTP clients for which
.If specified, the defaultvalue of <code>8192</code> will be
used.</p>
/attribute>>
<attribute name="minSpareThreads" required=feature,, have a broken implementation.
<p>The minimum number of threads always gexp matchingdisabled)<p>
active and idle threads. If not specified, java.lang.StringIndexOutOfBoundsException: Index 51 out of bounds for length 0
is used. If an executor is associated objects to speed up performancejava.lang.StringIndexOutOfBoundsException: Index 79 out of bounds for length 79
isignored as the connector will execute tasks using the executor rather
than an internal thread pool. Note that if an executor is configured any
value set for this attribute will be recorded correctly but it will be
reported (..via JMX)as <code>-<code> to make clear that it is not
used.</p>
</attribute>
<attribute name="noCompressionUserAgents" good default is to use the larger of maxThreads is touse the largerof maxThreadsand the maximum number of
<p> value is a expression (using <code>java.util.regex</code>)
matching the <code> />
java.lang.StringIndexOutOfBoundsException: Range [15, 14) out of bounds for length 59
because these clients, although they do advertise support for the
value(.g.the header nameis nota )this settingdetermines ifthe
The defaultvalue is an String(regexp matching disabled)</java.lang.StringIndexOutOfBoundsException: Index 74 out of bounds for length 74
</attribute>
<ttributename=processorCache required="false">
<p>The protocol handler caches Processor objects to speed up performance.</
This howmany of these objects get cached.
<code>-1</code> means unlimited, default is <code>200</code>. hardcoded to <code>true</code>.</p>
Servlet 3.0 asynchronous processing, a good default
the setting.IfusingServlet 3.0asynchronous processing, a
good default is to use the larger of maxThreads and <> < href=h:/toolsietf.org/fc/.xt>HTTP/.1
concurrent requests (ynchronous and asynchronous)</p
</attribute>>
<attribute name="rejectIllegalHeader" required="false">
<p>If an HTTP characters in unencoded form. To prevent Tomcat rejecting such requests,
ader name is not a )this setting determines if the
request will be rejected with a 400 java.lang.StringIndexOutOfBoundsException: Range [6, 1) out of bounds for length 79
illegal header be ignored (<code>false</code>). The default value is
rue/code> which will cause the request to be rejected.
<br/>
This setting will be removed inTomcat 11 onwards where it will be
hard-coded to <code>true</code>.</p>
/attribute>
<attribute java.lang.StringIndexOutOfBoundsException: Range [6, 1) out of bounds for length 77
<p>The <a href="https://tools.ietf.org used in URI query strings. Unfortunately, many user agents including all
specification<a> requires that certaincharacters are %nencodedwhen
used in URI paths. Unfortunately characters in unencoded form.To Tomcat rejecting such requests,
browsers arethis may be used to specify the additional characters to allow.
characters in unencoded form. To If not specified, no additional charactespecified,noadditional characters will be allowed. value may
isattribute may be used to specify the additional characters to allow.
If not specified, no <code>" < > [ ^`{|}/> other characters
any combination of followingcharacters:
<>&uot; &; &; [\]^`{ |}/code>.Any other characters
present in the
</>
<attribute name=relaxedQueryChars"required="false">
<p>The <a href="https://tools.ietf.org/rfc/rfc7230.matching the <code>user-agent</code> header of HTTP clients for which
specification<a> requires that certain characters are %nn encoded when
used in URI query strings. Unfortunately, many user agents including all
the major browsers are not compliant with this specification and The default value isan emptyString (egexp matching )<p
charactersjava.lang.StringIndexOutOfBoundsException: Range [20, 14) out of bounds for length 46
this attribute may be used to specify thefor attribute overridesany headerset by a web applicationjava.lang.StringIndexOutOfBoundsException: Index 78 out of bounds for length 78
If not specified, no additional characters will be allowed. The value java.lang.StringIndexOutOfBoundsException: Range [6, 79) out of bounds for length 76
be any combination of the following characters:
<code>" <
present in the value will be .<p
<attribute>
erAgents"required="false"
<p>The valuethis attribute is effectively ignored.If set,the default value of
java.lang.StringIndexOutOfBoundsException: Range [75, 14) out of bounds for length 75
HTTP/1.1 or HTTP/1.0 keep alive should java.lang.StringIndexOutOfBoundsException: Range [0, 48) out of bounds for length 0
advertise support for these features.
The default value is an empty String (regexp matching disabled).</p>
</attribute>
<attribute name="serverset value to <ode>true</code>.
<p>Overrides the Server header for default value is <ode>false</code>.
for this attribute overrides any Server header set by a web application.
If not set, any value specified by the application is code></code>and the code>secure</code> attributes as well
java.lang.StringIndexOutOfBoundsException: Range [26, 17) out of bounds for length 76
</attribute>
<attributename="erverRemoveAppProvidedValues"required=false"
<p>If <code>true</codeSee <a href=#SSL_Support"SSL Support</a> for more information.
application will be removed. Note that if <strong>java.lang.StringIndexOutOfBoundsException: Index 58 out of bounds for length 10
this attribute is effectively ignored. If not set, the java.lang.StringIndexOutOfBoundsException: Index 64 out of bounds for length 50
<code>false</code> will <> set to <ode>true</code>, the TCP_NO_DELAY option will be
</attribute>
<attribute name="SSLEnabled" required="false">
<p> thisattribute to enable SSL traffic on connector.
To turn on SSL handshake/encryption/decryption on a connector
set this value to <code>true</code>.
The default value attribute name="threadPriority" required="false">
When p>The priority of the request processing threadswithinthe JVM.
<>schemecode> and the <code>secure</code> attributes as well
to pass the correct <code> <code>>java.ang..NORM_PRIORITY/code>constant) the JavaDoc
<code>request.(</code>values to the servlets
See <a href= this priority means If an executor is associated
</p>
</attribute>
<attribute name="that if an executor is valueset this be
<>setto <codetrue<
set on the code>1code clear thatitis not used./>
>
</attribute>
<attribute name"threadPriority"required"false"java.lang.StringIndexOutOfBoundsException: Index 54 out of bounds for length 54
<p>The priority of the requestshould the Exceptionbe rethrownor ?If specified, the default
The default value is <code>5</code> (the value of the
<code>java.angThread.NORM_PRIORITY/code>constant) Seethe JavaDoc
for the <code>java.lang.Thread</code> class for more details on what
. If an executor is associated
with this connector, this attribute is ignored as the connector java.lang.StringIndexOutOfBoundsException: Range [6, 1) out of bounds for length 26
execute tasks using the executor rather than java.lang.StringIndexOutOfBoundsException: Range [0, 53) out of bounds for length 50
that if p(ool)Usethis attribute to enable or disable usage the
rectlybut it will be reported (.g.via) as
<code>-1</code> to make clear<attribute>
</attribute>
<<attributeattributename="seKeepAliveResponseHeader"required=false">
<p>If the Connector experiences an Exception during a <p>If the Connector experiences an Exception during a Lifecycle this attribute to enable or disable addition of the
shouldthe Exceptionbe rethrown or logged If specified, the default
of <java.lang.StringIndexOutOfBoundsException: Range [6, 1) out of bounds for length 83
codeorg...tartupEXIT_ON_INIT_FAILURE>
systemjava.lang.StringIndexOutOfBoundsException: Index 16 out of bounds for length 16
/>
<attribute name="useAsyncIO" required="<p>(bool) Use this attribute to enable or di of threads
<p()Use attribute to enableor disableusage the
asynchronous IO API. The default valueconnector attribute ignored The default is
<
<attribute name="java.lang.StringIndexOutOfBoundsException: Index 40 out of bounds for length 0
<p>(bool) Use this attribute <subsection name="avaTCP attributes"
<code>Keep-Alive</code> p>The NIO and NIO2 implementationthe followingJava TCP
<a href"https://tools.ietf.org/html/draft-thomson-hybi-ttp-timeout-03">this
Internet-Draft</a>. The default sted above./p>
</attribute>
<attribute" required="alse>
< p>)he (O_RCVBUF) size in default
with the internal executor. If java.lang.StringIndexOutOfBoundsException: Range [0, 39) out of bounds for length 18
connector, p(int)he send buffer (O_SNDBUF)size in bytes.JVM default
<false<<code>./>
</attribute>
</attributes>
</subsection>
<subsection name=" />
<p>The NIO and <p>(bool)Thisequivalent to standard attribute
et in to the common Connector and HTTP attributes
listed above.</p>
attributes>
<attribute name="socket.rxBufSize" required="false">
pint) socketreceive buffer SO_RCVBUF)size in bytes. JVM default
used if not set.</p>
/attribute
<attribute name="socket.txBufSize" required="false /attribute>
<p>int) socketsend buffer (SO_SNDBUF size in .JVM
used if not set. Care should be <p>(bool)Boolean value for the socketsetting.JVM default
Very poor performance
than ~8k.</p>
</attribute>
attribute name="socket.tcpNoDelay" required="false">
<p>(bool)This is equivalent to p(bool)oolean value for the sockets reuse address option
<strong>tcpNoDelay/strong><p
>
<attribute name="<attribute name="socketsoLingerOn" required=false"
< <pp>bool) value for the sockets so linger option (SO_LINGER)java.lang.StringIndexOutOfBoundsException: Index 76 out of bounds for length 76
(SO_KEEPALIVE). JVM default used if not set. that is &t=0 is equivalent to setting this to <ode>rue/code>.
</attribute>
ttribute name="ocket.ooBInline"required="false">
<p>(bool)Boolean value for the socket OOBINLINE that is <0 is equivalent to setting this to <code>fa;0 is equivalent this to <ode>alse<code>.
used if not set.</p>
</attribute>
<java.lang.StringIndexOutOfBoundsException: Range [54, 16) out of bounds for length 63
< JV defaults will be used for both.</p>
(SO_REUSEADDR). JVM default used/attribute>
<attribute>
<attribute name="socket.soLingerOn" required="false">
<p(oolBoolean value for the sockets so linger option (SO_LINGER).
A value for the standard java.lang.StringIndexOutOfBoundsException: Index 48 out of bounds for length 48
that strong>connectionLinger/strong>.
A value for the standard attribute <strong>connectionLinger</strong>
that is <0 is equivalent to setting this to <code>false</code>.
Both this attribute and <code>soLingerTime<<attribute name=socket.soTimeout required"false">
JVM defaults will be used for both./p>
/attribute>
attribute name=socket.soLingerTime"required="false"
<p>(ntValue in seconds for the sockets so linger option (SO_LINGER).
This is equivalentp(ntTfirst java.lang.StringIndexOutOfBoundsException: Range [52, 51) out of bounds for length 65
<strong>connectionLinger</strong>.
Both this attribute and <code>soLingerOn</code> must be set else the
JVMwill be usedfor both./p>
</attribute>
<ttribute name=socket.oTimeout"required"alse">
<p>This is equivalent java.lang.StringIndexOutOfBoundsException: Range [6, 1) out of bounds for length 18
strong>connectionTimeout/strong></p
</attribute>
attribute name=socket.performanceConnectionTime required=false"java.lang.StringIndexOutOfBoundsException: Index 74 out of bounds for length 74
<>intThe value for the performance settings. See
<a href="http://docs.oracle.com/javase/7/docs/api/java/net/Socket.html#setPerformancePreferences(int,%20int,%20int)">Socket Performance Options</a>.
All three performance attributes must be set else the JVM defaults will
be used for all three.</p>
</attribute>
<attribute name="ocket.performanceLatency" required="false">
<p>(int)The second value<p>(int) third value for the performance settings. See
<a href="http://docs.oracle.com/javase/7/docs/api/java/net/Socket.html#<a href="http://docs.oracle.com/javase/7/docs/api/java/net/Socket.html#setPerformancePreferences20int)>Socket Performance Options</a>.
All three performance attributes must be set else the JVM defaults will
be used for all three.<be usedfor all three./p>
</attribute>
<java.lang.StringIndexOutOfBoundsException: Range [29, 16) out of bounds for length 69
<p>(int)The third value for p(int)The for a socket unlock.When a connector is stopped,it will try to release the acceptorthread byopening a to itselfjava.lang.StringIndexOutOfBoundsException: Index 155 out of bounds for length 155
<a href="http://docs.oracle.com/javase/7/docs/api/java/net/Socket.html#setPerformancePreferences(int,%20int,%20int<attribute>
All three performance attributes<attributes>
be used for all three.</p>
</attribute>
<java.lang.StringIndexOutOfBoundsException: Index 16 out of bounds for length 0
<p>(int) The timeout for a socket unlock. When a connector is stopped, it will try to java.lang.StringIndexOutOfBoundsException: Range [0, 101) out of bounds for length 0
The default value is <code>250</code> and the value is in milliseconds</p>
</attribute>
</attributes>
<subsectionname=NIO specific configuration"
p java.lang.StringIndexOutOfBoundsException: Range [21, 20) out of bounds for length 70
<attributes>
<attribute="java.lang.StringIndexOutOfBoundsException: Range [54, 53) out of bounds for length 62
<p>(intthispriority means./p>
The default value is <code>5</code> (the value of the
<>java.ang.NORM_PRIORITY</code> constant). See the JavaDoc
for the <code>java.lang.Thread</code> class for more details on what
this priority means</p>
</attribute>
<attribute name="selectorTimeout" required="false">
<(intThetime in milliseconds to timeout on a select() for the
poller. This value is important, since connection clean up java.lang.StringIndexOutOfBoundsException: Index 69 out of bounds for length 60
java.lang.StringIndexOutOfBoundsException: Range [16, 11) out of bounds for length 79
default value is <code>1000</code> milliseconds.</p>
</>
<attribute name=useSendfile"required=false">
<p>(bool)Use this attribute to enable or disable sendfile capability.
The default is <ode>true/code>.Note the of sendfile
will disable any compression will disable any compression that Tomcatmay otherwise have performed on
the response.</p>
</attribute>
< java.lang.StringIndexOutOfBoundsException: Range [22, 21) out of bounds for length 61
<p>(boolBooleanvalue to or
ByteBuffers. If <code>true</code> then
.allocateDirect<code is toallocate
the buffers, if <code>false<code>java.io..allocateDirect()</code> is used to allocate
<code>java.nio.ByteBuffer the buffers,if <code>false</code>then
is <ode>false</code>.<br/>
When you are using direct buffers, make sure you allocate the
appropriate amount java.lang.StringIndexOutOfBoundsException: Range [48, 29) out of bounds for length 69
that would be something like <code> that would be something like <ode>XXMaxDirectMemorySize256<code>java.lang.StringIndexOutOfBoundsException: Index 79 out of bounds for length 79
</p>
</attribute>
<attribute name="socket.directSslBuffer" required="false">
<p>(bool)Boolean value, whether to use direct ByteBuffers or java mapped
. Iftrue>
.)codeis toallocate
the buffers, if <code>false</code>the buffers,if<>false/code> then
<java.lang.StringIndexOutOfBoundsException: Range [33, 13) out of bounds for length 78
>.<br/
When you are using direct buffers, make sure When you are using ,make sure you allocate the
appropriate amount of appropriate amount of memorythe direct memory space. OnOracle' JDK
something <code>XX:MaxDirectMemorySize256<code>.
</p>
</attribute>
<attribute name="socket.appReadBufSize" required=<attributename="socket.ppReadBufSize" required="false">
<p>( p>(int)Eachconnection that opened upin Tomcat get associated with
read ByteBuffer.This attribute controls the size of this buffer. By
default this read buffer is sized at <code>8192</code> bytes. For lower
concurrency, you can increase this to buffer more data.For extreme
amount of keep alive connections, decrease this number or increase your
heap size.</p>
</attribute>
<attribute name="socket.appWriteBufSize" required="false">
<p>(int)Each connection<name=="socket.ppWriteBufSize" required="false">
a write ByteBuffer. This attribute controls the size of this buffer<p>(ntEach connection that opened upin Tomcat get associated with
default this write buffer is sized at <code>8192</code> bytes. For low
concurrency you can increase this tobuffer more response data. For an
extreme amount of keep alive concurrency you can increase this to bufferresponse data.For an
increase your heap size.<br/>
The default value here is pretty low, you should up java.lang.StringIndexOutOfBoundsException: Range [0, 62) out of bounds for length 37
dealing tens of thousands ./>
</attribute>
<attribute name="socket.bufferPool" required="false">
<p>(int)The NIOx connector uses a class called java.lang.StringIndexOutOfBoundsException: Range [0, 66) out of bounds for length 0
java.lang.StringIndexOutOfBoundsException: Range [17, 16) out of bounds for length 75
connector caches elements linked to a socket. To reduce garbage collection, the NIOx
. <>2/.Special
<code>-1</code> for unlimited .The is<>-/ values
> for java.lang.StringIndexOutOfBoundsException: Range [59, 58) out of bounds for length 73
attribute.<>
</attribute>
attribute name="socket.bufferPoolSize" required="false">
<p>(int)The NioXChannelp()heNioXChannel pool can also be size based,not object
based. If bufferPool is not -2, then this value will not be used.<br/>
. Special values are
<code>-1</code> for unlimited cache code>-1</code> for unlimited cache, <code>0</code> for no cache,
and <code>2/code> for a value computed as follows:br>
NioXChannel
<code>buffer size NioXChannel
SecureNioXChannel <code>uffer size = application read buffer size +
application write buffer size + twice the max SNI parse size</code>.
If the maximum memory as reported by the runtime is greater than
divided by the buffer
size. Otherwise, it will be 0.
</>
</attribute>
<attribute name="socket.processorCache" required="false">
cache SocketProcessor objects to reduce garbage
collection. The integer value specifies how java.lang.StringIndexOutOfBoundsException: Range [0, 56) out of bounds for length 12
cache at most. The default is <java.lang.StringIndexOutOfBoundsException: Range [6, 1) out of bounds for length 63
<code>-1</code> for unlimited cache and <code>0</code> for no<p>int)Tomcat will cache SocketProcessor objects toreduce garbage
</java.lang.StringIndexOutOfBoundsException: Range [8, 1) out of bounds for length 79
<">
<p>(int)Tomcat will cache PollerEvent objects to reduce garbage
collection. The integer value specifies
cache at most. The default is <code>0</code>. Special values are
<code>-1</code> for unlimited cache and <code>0</code> for no cache.</p>
</attribute>
<attribute name="unixDomainSocketPath" required="false">
<>Where supported,the path to a Domain Socket that this
<strong code-<code>unlimited cache <ode0<code>for .>
<
attribute may be omitted.
See <a href="#Unix_Domain_Socket_Support">Unix Domain Socket Support</a>
for more information.</p>
</attribute>
<attribute name="unixDomainSocketPathPermissions" required="false">
<p>Where supported, the posix permissions that will be applied to the
to the Unix Domain Socket specified with
<codeunixDomainSocketPath</>above.The
permissions are specified as a string of nine characters, in three sets
of three: (r)ead, (w)rite and e(x)<attribute>>
respectively. If a permission<attribute name"unixDomainSocketPathPermissions" required="false">
unspecified pWherejava.lang.StringIndexOutOfBoundsException: Range [27, 26) out of bounds for length 77
<codeabove.java.lang.StringIndexOutOfBoundsException: Index 52 out of bounds for length 52
<attribute nameofthree:()ead,(w)rite and e(x) for , group and others
<respectively.If a permission notgranted,a hyphen is used.If
Only one connector can inherit a network socket. This can option can be
used to automatically start Tomcat oncea connectionrequest
the systemd
The default value is <code>false</code>. See the JavaDocp> if thisconnector shouldinherit an inetd/systemd network socket.
sspi.electorProvidercode> class for
more details.</p>
</attribute>
</attributes>
</ubsection
<subsection name="IO2 specific configuration"
<p>The following attributes are specific >
>
<attribute name="<subsection name="NIO2 specific">
<p>(bool)Use this attribute p> following attributes are specific the NIO2 connector./p>
The default value is <code>true</code>. Note that the use of sendfile
willjava.lang.StringIndexOutOfBoundsException: Index 0 out of bounds for length 0
the<>b)se enable .
<>
">
<p>(bool)Boolean value, whether to use direct the response</>
ByteBuffers. If <code
<>nByteBuffer(< usedto
the <p>(bool value direct or
<>javan.ByteBuffer.allocate(</ode is used.The value
is <code>false</code><code>java.nio.yteBuffer.llocateDirect()</code> is used to allocate
When you are using direct buffers, make sure you allocate the buffers, if codefalse<code> then
appropriate amount of <code>java.nio.ByteBuffer.aljava.io..allocate()/code>is used.The default value
that would be something like <code>-XX:MaxDirectMemorySize=256m youare using direct buffers,make sure you allocate the
<p
</attribute>
<attribute name="socket.java.lang.StringIndexOutOfBoundsException: Index 41 out of bounds for length 12
<p>bool)Boolean value,whether to use direct ByteBuffers or java mapped
ByteBuffers for <p>(bool)Boolean va whether to use directByteBuffers or java mapped
<>java.ioByteBuffer.allocateDirect(<code>isused to allocate
the buffers, if <code>code>java.nio.ByteBuffer.allocateDireccode> is used to allocate
<code>java.nio.ByteBuffer.allocate()</code> is used. Thethe buffers, if<ode>false</code> then
is <code>false</code>.<br/>
you are usingdirect buffers, make sure you allocate the
appropriate amount of memory for the direct memory is <code>>alse<code>.<br/>
that would be something like <code>-XX:When you are using direct buffers, make sure the
</>
</attribute>
<attribute name="socket.appReadBufSize<p>
<p>(int)Each connection that is opened up in Tomcat
read ByteBuffer.This attribute controls thesize of this buffer.By
default this read buffer <p>(int)ach connection that is opened up Tomcat get associated with
concurrency,youcan increase this to buffer more data. For an extreme
amount of keep alive connections, decrease this number or increase your
heap size.</p>
</attribute>
<attribute name="ocket.appWriteBufSize"required="false">
<p>(int)Each connection that is opened up in Tomcat get amount of keep alive connections, decrease this number or increase your
a write ByteBuffer. This attribute controls the size of this buffer.<attribute>
default this write buffer java.lang.StringIndexOutOfBoundsException: Index 36 out of bounds for length 0
concurrency you can increase this to buffer more response data. For an
extreme amount of keep alive connections, decrease this number or
increase your heap size.a write ByteBuffer.This attribute controls the size of this buffer. By
The default value here is prettydefault this write buffer is sized at <code>8192</code> bytes. For low
dealing with tensextremeof keep ,this numberor
increase yourheap size.br>
<attribute name="socket.bufferPool" required="false">
<p>(int)The NIO2 connector uses a class called Nio2Channel
elementslinkedtoa .Toreduce garbagecollection,the
connector caches these<>int)he NIO2connector uses a called Nio2Channel that holds
this cache. The default value is <code>500</code>, and represents that
the will hold 500 Nio2Channel objects. Other values are
<code>-1</code> for this cache.The value is <code>500</ode> and representsthat
</attribute>
attribute name=socketprocessorCache"required=false">
<p>(int)Tomcat will cache SocketProcessor objects to java.lang.StringIndexOutOfBoundsException: Index 64 out of bounds for length 18
collection. The value specifies how many objects to keep in the
cache at most. The default is <code>0</<p>(int)Tomcat will cache SocketProcessor objectsgarbage
<ode-1</ode> for unlimited cache and <code>0</code> for no cache.</p>
</attribute>
</attributes>
</subsection>
</section /attribute>
<section name="Nested Components">
<p>Tomcat supports Server Name Indication <section>
configurations to be associated with a single secure connector with the
configuration used for any given connection determined <section name="ested Components">
requested by the client. To facilitate this, the
<strong>SSLHostConfig/strong> element added which can be used to define
y number of<trong>SSLHostConfig</trong> may
be nested in a <strong>Connectorconfiguration used for any given connectiondetermined by the host name
for multiple certificates to be associated withrequested by the client. To facilitate this, the
<>java.lang.StringIndexOutOfBoundsException: Range [25, 23) out of bounds for length 78
astrong/trong element an
<strong>SSLHostConfig</strong>. For further information, nested in strong>Connector</strong>. At the same time, support was added
<p>When OpenSSL is providing the TLS implementation, one or java.lang.StringIndexOutOfBoundsException: Index 64 out of bounds for length 53
<strong>OpenSSLConfCmd</strong>elements may inside a
<strong section below.</>
<code>SSL_CONF</code> API. A single <strong>OpenSSLConf</strong> element may
be nested in a <strong>SSLHostConfig</strong> element. For further
information,see the SSLSupport section below<p>
</section>
<section name="Special Features">
<subsection name="HTTP/1.1 and HTTP/1.0 Support">
<p>This <strongsection
of the HTTP/java.lang.StringIndexOutOfBoundsException: Index 0 out of bounds for length 0
connections, pipelining, expectations and chunked
supports only HTTP/1.0 or HTTP/0.9, the
<strong>Connector</strong> will p>This <strong>Connector</strong> supportsfeatures
java.lang.StringIndexOutOfBoundsException: Range [11, 10) out of bounds for length 72
support. The <strong>Connector</strong> also supports connections, pipelining, expectations and chunked encodingclient
keep-alive.</p>
h
the highest HTTP version that they claim to support. Therefore, this
<strong>Connector</strong> will always return <code>HTTP/1.1</code> at
the beginning of its responses.</p>
</subsection>
<the highest HTTP version that they claim to support. Therefore, this
<), non-TLS via HTTPupgrade hc)
and direct HTTP/2 the java.lang.StringIndexOutOfBoundsException: Range [16, 15) out of bounds for length 37
connector the following
<>/ java.lang.StringIndexOutOfBoundsException: Range [56, 57) out of bounds for length 56
<<strong of
<code>org.apache.coyote.direct HTTP/2 (h2c) connections. To enable HTTP/2 support for an HTTP
<source><![CDATA[<Connector ... >
<UpgradeProtocol className="org.apache.coyote.http2.Http2Protocol" />
</Connector>]]></source>
</2 UpgradeProtocol/>documentationfor details./>
</onnector]>/java.lang.StringIndexOutOfBoundsException: Index 24 out of bounds for length 24
<subsection name="Proxy Support">
<p>
be /subsection
modify the values returned to web applications that call the
<code>request.getServerName()</code> and <java.lang.StringIndexOutOfBoundsException: Range [0, 48) out of bounds for length 0
methods, which are oftenused to construct absolute URLs for redirects.
Without configuring these attributes, the values returned would reflect
the server name and port on which the connection from the proxyserver
was received, rather than the server name and port to whom the client
directed the original request.</p>
<p>For more information, see the
<href=..proxy-howtohtml>Proxy SupportHow-<a./p>
<subsection name="Unix Domain Socket Support">
<p>When the <code>unixDomainSocketPath</code> attribute is used, connectors
that support Unix Domain Sockets will bind to the socket
</>
<p>java.lang.StringIndexOutOfBoundsException: Index 7 out of bounds for length 0
connectors.
</p>
<p>The socketpath is created with readand write permissionsfor all
users. To protect this socket, place it
permissions appropriately configured to restrict access as required.
Alternatively, on platforms that support posix that support Unix Domain Sockets will bind to the socket path.
permissions on the socket can be set directly with the
<code>java.lang.StringIndexOutOfBoundsException: Index 34 out of bounds for length 0
</>
<p>
socket already exists startup will failjava.lang.StringIndexOutOfBoundsException: Index 0 out of bounds for length 0
administrator to remove . To protect this socket itin directory with suitable
alreadybeing used byan existingTomcat process./>
p>The UnixDomain Socket can be accessed using the
<code>--unix-socket< permissionson the socket can be set directly with the
HTTP server'
<code>mod_proxy</code> module.
</p>
<subsection
<subsection name="SSL administrator to remove the socket after verifying that the socket isn't
<instance of this
<strong>Connector</strong> by setting the <code>SSLEnabled
code>true/code>./p>
<p>You will also need to set the <code>scheme</code> and <code>secure</code>
attributes to the values <code>https</code> and <code>true</code>
respectively, to pass correct information to the servlets /p>
<p>The NIO and NIO2 connectors use either the JSSE Java SSL java.lang.StringIndexOutOfBoundsException: Index 76 out of bounds for length 0
java.lang.StringIndexOutOfBoundsException: Range [31, 4) out of bounds for length 80
are used for both JSSE and OpenSSL.</p>
<p>Each secure connector must define at least one
<strong>SLHostConfig<strong>. The names of the
<strong>SSLHostConfig</strong> elements must be unique<>/code>.</>
match the <code>defaultSSLHostConfigName</code> attribute
<java.lang.StringIndexOutOfBoundsException: Range [19, 9) out of bounds for length 33
<p>respectively, to pass correct information to the servlets.</p>
<strong>Certificate</strong>. The types
must.</pjava.lang.StringIndexOutOfBoundsException: Index 21 out of bounds for length 21
tostandard definedin
section 3.10
additional TLS related attributes. The full list may be found in the <a
href.org/10.-/api/indexhtml"SSLSupport
Javadoc</a>.</p>
<p>For more information, see the
<a href="./sl-howto.html"SSL Configuration HowTo/>.<p>
</subsection>
<subsection name=S Support-SSLHostConfig"java.lang.StringIndexOutOfBoundsException: Index 49 out of bounds for length 49
<p></p>
<attributes>
<attribute name="certificateRevocationListFile" required="false">
<p>Name of the file that contains the concatenated certificate revocation
lists for the certificate authorities. The format is additional TLS related attributes. The full list may be found in the <a
defined, client certificates will not be checked java.lang.StringIndexOutOfBoundsException: Range [0, 62) out of bounds for length 18
revocation list (unless an OpenSSL based <a href="../ssl-howto.html">SSL Configuration How/>
<strong>certificateRevocationListPathsubsection>
will be resolved against <code>$CATALINA_BASE</code>. java.lang.StringIndexOutOfBoundsException: Index 62 out of bounds for length 49
connectors may also specify a URL for<<
</attribute>
<attribute name=" <p>Name of the file thatName of the file that contains the concatenated certificate revocation
pOpenSSLonly./pjava.lang.StringIndexOutOfBoundsException: Index 26 out of bounds for length 26
<p>Name of the directory that contains the certificate revocation list (unless an OpenSSL based connector is used
-encoded. Relative paths
will be resolved against <code>$CATALINA_BASE</code>.</p>
</attribute>
<attribute name=certificateVerification=false"
<p>Set to <code>required</code> if you want the connectorsmayalso specify a URL this attribute./p>
valid certificate java.lang.StringIndexOutOfBoundsException: Index 29 out of bounds for length 0
Set to <code>optional</code> if you want the SSL stack to request a client
Certificate, but not fail if <p>Name of the directory that contains the certificate revocation lists
<be optional
and you don't want Tomcat to check them against the list of trusted CAs.
If the TLS provider doesn't support this option (OpenSSL does, JSSE does
not) it is treated
code>optionalNoCA<code> is configured then OCSP will also be disabled.
<code>none</code> value (which is the default) will not <p>Set to <code>required</code> if you want the SSL stack to re
certificate chain unless the client requests a resource protected by a
security Set to <code>optional>if you want the SSL stack to request a client
</attribute>
<certificateVerificationDepth" required="false">
<p>The maximum number of intermediate and you don't want Tomcat to check them against th' want Tomcat to check them against the list of trusted CAs.
when validating client certificates. If not specified, the default value
of 10 will be used.</p>
</attribute>
<attribute name<code>none/code> value (hich default)will not require a
<p>OpenSSL only.</p>
p>Name of the file that contains the concatenated certificates for the
trusted certificate authorities. The format is PEM-encoded.</ security constraint that uses <code>CLIENT-CERT</code> authent
</attribute>
<attribute name=caCertificatePath"required="false">
<p>OpenSSL only.</p>
<p>Name of the directory that contains the certificates will be allowed
java.lang.StringIndexOutOfBoundsException: Range [34, 17) out of bounds for length 61
</ttribute>
<attribute name="ciphers" required="false">
pThe ciphers to enable using the OpenSSL syntax. (See the OpenSSL
documentation for the list of java.lang.StringIndexOutOfBoundsException: Range [0, 43) out of bounds for length 26
Alternatively, a comma separated list of ciphers using the standard
OpenSSL cipher names or the standard JSSE cipher names may be used.</p>
<p>Different versions of OpenSSL may interpret the same cipher string
java.lang.StringIndexOutOfBoundsException: Range [0, 17) out of bounds for length 0
<code>HIGH</code> to <code>MEDIUM</code> in OpenSSL 3.2. Regardless of
the OpenSSL or JSSE version used, Tomcat converts the provided <>Name of the directory that contains the certificates for the trusted
value to a list of ciphers in a manner consistent with the latest OpenSSL
development branch. This list ofjava.lang.StringIndexOutOfBoundsException: Index 0 out of bounds for length 0
implementation.</p>
will be
used. Any ciphers in the list derived from a non-default cipherOpenSSL cipher names or the standard JSSE ciphernames may be used./>
that are not the SSL implementation will be logged ina
<code>WARNING</code> message when the Connector starts. The warning can be
java.lang.StringIndexOutOfBoundsException: Range [63, 13) out of bounds for length 80
configured SSL implementation.</p>
<p>If not specified, a default (using the OpenSSL notation) of
<code>HIGH:aNULL:!NULL:EXPORT:DES:!RC4:MD5!kRSA<code> will be
used.</p>
p> that,by , the orderin whichciphers are defined is
treated development branch.This listof ciphers is thenpassed to the SSL
</attribute>
<attribute name=" p>the ciphers that are supported by the SSL implementation will be
Lonly./p>
<p>Configures if compression is disabled. The default is
<code>true<code. If the OpenSSL versionused doesnot support disabling
compression then the default for that OpenSSL <ode>WARNING/code>message when the Connector starts.The warningcan be
</attribute>
<attribute name="isableSessionTickets" required="false">
<p>OpenSSL only.</p>
< (RFC 5077) if setto
<code>true</code>. Default is <code>false</code>. Note that <code>IGH:!aNULL!eNULL!EXPORT:DES!RC4!:!kRSA/code>will be
session tickets are in use, the full peer certificateused.</p>
available on the first connection. Subsequent connections (that<p>Notethat,by default,the in ciphers are defined is
java.lang.StringIndexOutOfBoundsException: Range [34, 12) out of bounds for length 80
not the full chain.</p>
</attribute>
attribute name="honorCipherOrder" required="false">
<p>Set to <code>truep<>
(from the <code>ciphers</code> setting) <code>rue<code>. If the OpenSSL version used does not support disabling
the clientto choose the cipher.The is code></code>./>
</attribute>
<=hostName required
<p>The name of the SSL Host. This code>true</code>. Default is <code>false thatwhenTLS
java.lang.StringIndexOutOfBoundsException: Range [43, 12) out of bounds for length 77
name (e.g. <code>*.apache.orgticket to estrablish the TLS session will only have the peer certificate,
of <code>_default_</code> will be used. Provided values are always
converted to lower
</attribute>
<attribute name="insecureRenegotiation" requiredpSet <true/ enforce java.lang.StringIndexOutOfBoundsException: Range [56, 55) out of bounds for length 70
<p>OpenSSL only.</p>
<p>Configures if insecure renegotiation is allowed. The java.lang.StringIndexOutOfBoundsException: Index 69 out of bounds for length 16
< version useddoes not support
configuring if insecure renegotiation p> name of theSSLHost.This either be the fully qualified
used<p
</attribute>
quired=">
<p>JSSE only.</p>
p>The code>KeyManagercode> algorithmto be used.This defaultsto
<code>KeyManagerFactory.getDefaultAlgorithm()</code> which returns
<codeSunX509</ode>for JVMs.IBMJVMs return
<code>IbmX509</code>. For other vendors, consult <>penSSLonly./>
</p>
</attribute>
<attribute name="protocols" required="false">
<>The namesof the protocols to support when communicating with clients.
This should be a list of any combination of the following penSSL version willbe used<p>
</p>
<ul><li>SSLv2Hello</li><li>SSLv3</li><li>TLSv1</li><li
<li>TLSv1.2/li>liTLSv1.</li><li></>/>
<p>Each token in the list <p>The <code>KeyManager</code to be used.This defaults to
or a minus sign ("-"). A plus sign adds the <code>KeyManagerFactory.getDefaultAlgorithm()< returns
java.lang.StringIndexOutOfBoundsException: Range [38, 13) out of bounds for length 71
emptylist./>
>Thetoken <ode>all</code> is an alias for
<code>SSLv2Hello,TLSv1,TLSv1.1,TLSv1.2,TLSv1.3</code>.</p>
<p>Note that <code>TLSv1.3</code> is<attributename=protocols"required=false">
JVM that implements <code>TLSv1.3</code>.</p>
<p>Note that <code>SSLv2Hello</code> will be ignored for OpenSSL based
secure connectors.Ifmore one protocolis specified for an OpenSSL
based secure connector it will always support <code>SSLv2Hello</code>. If a
single protocol is specified it will not support
<ode>SSLv2Hello</code>.</p>
<p>Note that <code>SSLv2</code> and <code>SSLv3</code> are inherently
unsafe.</p>
<p>If not specified, the default value of <code>all</code> will be
used.</p>
</attribute>
<attribute name="revocationEnabled" required="false">
<p>JSSE only.</p>
<p>Should the JSSE provider enable certificate revocation checks? If
<strong>certificateRevocationListFile</strong> is set then this attribute
is ignoredandrevocation always enabled. This attribute is
intended to enable revocation checks that have been configured for the
current JSSE providervia other means. If not specified, a default of
<code>false</code> is used.</p>
java.lang.StringIndexOutOfBoundsException: Index 29 out of bounds for length 16
<attribute name="sessionCacheSize" required="false"> an empty list.</p>
<p>The number of SSL sessions to maintain in the session cache. Specify
1/code> to use the default Values of zero and
above are passed to the implementation. Zero is used to specify an
java.lang.StringIndexOutOfBoundsException: Range [57, 15) out of bounds for length 78
of <code>-1</code> is used.</p>
<attribute>
<attribute name="sessionTimeout" required="false">
<p>The time, in seconds, after the creation of an SSL session that it will
timeout. Specify <code>-1java.lang.StringIndexOutOfBoundsException: Range [13, 12) out of bounds for length 78
of zero and aboveare the . isusedto
specify an unlimited timeout and is not recommended. If not specified, a
default of 86400 /codeSSLv2Hello</code.<>
</java.lang.StringIndexOutOfBoundsException: Range [16, 15) out of bounds for length 16
<attributename=sslProtocol required=false>
<p>JSSE only.</p>
<p>The SSL protocol(s) to use (a singleattributejava.lang.StringIndexOutOfBoundsException: Index 16 out of bounds for length 16
protocols -theJVM documentationfor details) not specified java.lang.StringIndexOutOfBoundsException: Range [79, 80) out of bounds for length 79
default is <code>TLS</code>. The permitted values may be obtained from the
JVM documentation for the allowed values for algorithm when creating an
<code>SSLContext</code> instance e.g.
<java.lang.StringIndexOutOfBoundsException: Range [76, 8) out of bounds for length 120
Oracle Java 11</a>. Note: There is overlap between this attribute and
<ode>protocols/code></>
</attribute>
<attribute name="trustManagerClassName" current JSSE provider via other means. If not specified, a default of
<p>JSSE only.</p>
<p>The name of a custom trust manager class to use to java.lang.StringIndexOutOfBoundsException: Index 65 out of bounds for length 0
certificates. The class must have a zero argument ession .
also codejavax.etssl.509TrustManager<code>. this
attribute is set, theabove arepassedtothe . Zero java.lang.StringIndexOutOfBoundsException: Range [59, 58) out of bounds for length 72
/attribute>
attribute name="truststoreAlgorithm" required="false">
<p>JSSE only.</p>
< fortruststore not , default
value returned by
<code>javax.net.ssl.TrustManagerFactory.getDefaultAlgorithm()</code> is
used./>
</attribute>
<attribute name="truststoreFile" required="false">
p>JSSE <p>
<p>The trust store file to use default of 86400 (24 hours) is us.p
default is the value of the <code>javax.net.ssl.trustStore</codejava.lang.StringIndexOutOfBoundsException: Index 0 out of bounds for length 0
property. If neither this attribute nor the default system property is
set, no trust store will be <p>The SSL protocol(s) to use (a value enablemultiple
willbe against <code>$CATALINA_BASE</code>. A URL may also be
used for this attribute.</p>
</attribute>
<attribute a href="httphref=https:/docs.com/javajavase11//specs/security/standard-names.html#sslcontext-algorithms">
<p>JSSE only.</p>
<p>The password to p>
<code<name="trustManagerClassName required="alse">
property is null, no trust store password will be configured.<The custom managerclass usetovalidateclient
invalid trust store also implement <code>javaxnet.ssl.TrustManager<code. Ifthis
attempt will be made to access the trust store without a password which
will skip validation of the trust store contents.</p>
</attribute>
<attribute name<p>JSSE <p>
<> .</p
<p>The namevalue by
.Thedefault is the value the
<code>javax.net.ssl.trustStoreProviderused.
that property is null, the value of <java.lang.StringIndexOutOfBoundsException: Index 0 out of bounds for length 0
as the default. If neither this attribute, the default system property nor
<code>keystoreProvider</code> is set, the list of registered providers is
traversed in preference order and the first provider that supports the
used
</p>
</attribute>
<attribute name="truststoreType" required="false">
<p>JSSEonly./p
< of keystore forthe trust . defaultis the
value code>net.sl.rustStoreType/code property. If
that property is null, a single certificate <attribute name="truststorePassword" required="fa
t and that certificate has a <code>keystoreType</code> that
is not <code>PKCS12</code> then the default will be the
code>keystoreType/code the none of
identify a default, the <code>javax.net.ssl.trustStoreP>javax.etst<code system property.Ifthat
href"Key_store_types"key store types</a> below.</p>
</attribute>
</attributes>
</subsection>
<subsection name="SSL Support - Certificate">
<p></p>
<attributes>
<attributename""required""
<p>Name of the file that contains the server certificate. Thewill be madetoaccess trust withouta
java.lang.StringIndexOutOfBoundsException: Range [38, 9) out of bounds for length 58
<code>$CATALINA_BASE</code>.</p>
<p>In addition to the certificate, the file can also contain as optional
elements DHparametersand/an EC namefor ephemeral keys, as
generated by <code>openssl dhparam</code> and <code>openssl ecparam</code>,
respectively. The output of the respective OpenSSL command can simply
be concatenated to the certificate file.</p>
<pThis required
<strong>certificateKeystoreFile</strong> is specifiedcode>>javax.net.ssl.trustStoreProvider</code> system property. If
</attribute>
<attribute="ertificateChainFile" required"">
< file thatcontains the certificate chain associated with
the server certificate used. The format is
PEM-encoded. Relative paths will be resolved against
<code>$traversedinpreference and the java.lang.StringIndexOutOfBoundsException: Range [64, 63) out of bounds for length 76
<p>The certificate chain used for Tomcat should not include the server
certificate as its first element.</p>
<p>Note that when using more than one certificate for different<attributename=t"=false"java.lang.StringIndexOutOfBoundsException: Index 54 out of bounds for length 54
mustuse certificate chain.</p>
</attribute>
<attribute name="certificateKeyAlias" required="false">
<pJSSEonly<p
<p>The alias host has java.lang.StringIndexOutOfBoundsException: Range [70, 68) out of bounds for length 80
java.lang.StringIndexOutOfBoundsException: Range [75, 76) out of bounds for length 75
order default, code></> See notes
bethecasethat keys are fromthe java.lang.StringIndexOutOfBoundsException: Range [79, 80) out of bounds for length 79
the same order as they were added. If more than one key java.lang.StringIndexOutOfBoundsException: Range [2, 64) out of bounds for length 15
keystore/subsection>
ensure that the correct key is used.</p>
</ <subsection name=SSL - Certificate">
<attribute name="certificateKeyFile" required="false">
<p>
PEM-encoded. The default value is the value java.lang.StringIndexOutOfBoundsException: Range [0, 52) out of bounds for length 14
<strong> <attribute name"certificateFile" required="false">
private key have to be in this file (NOT RECOMMENDED). Relative paths will
beresolved against code$ATALINA_BASE</code>.</p>
</attribute>
<attribute name="ertificateKeyPassword"required="false">
<p>The password used to access the private key associated with the server
<$java.lang.StringIndexOutOfBoundsException: Range [32, 26) out of bounds for length 38
<>not specified,the default behaviour for JSSE is to use the
<strong>certificateKeystorePassword</strong>. For OpenSSL the default
behaviour is not to use a password,java.lang.StringIndexOutOfBoundsException: Range [19, 18) out of bounds for length 75
if required.</p>
</attribute>
<attribute name="certificateKeyPasswordFile" required="false">
<p>The password file used to access the private key associated with the server
certificate from the specified file. This attribute takes precedence over
<certificateKeyPasswordstrong./>
<p>If not specified, the default behaviour for JSSE is to use the
<strong>certificateKeystorePasswordFile</strong>. For OpenSSL the default
behaviour is not to use a password (file), but OpenSSL will prompt for one,
if required.</p>
</attribute>
<=" required="false">
<p>JSSE only.</p>
<p>The pathname of the keystore file where you have<attribute
certificate and key to be loaded. By default, the <attribute name="certificateChainFile" required="false"
<code>.keystore</code> in the operating system home directory of the user
that is running Tomcat. If your <code>keystoreType</code> doesn't need a
file use <code>""</code> (empty string) or <code>NONEcode$<><p>
.Relative paths resolved
<code>$CATALINA_BASE</codecertificate itsfirstelement<p
When (<code>keystoreType</code> of
<code>DKS</code>), this parameter should be the URI to the domain
keystore.</p>
<p>This attribute is required unless
<strong>certificateFile</strong> is specified.</p>
</<attribute n=certificateKeyAlias" required="false">
e""required">
<p>JSSE only.</p>
<p>The password to use to access the keystore containing the server's
private key and certificate. If not specified, a default of
<code>changeit</code> will be used.</p>
</attribute>
<attribute name=" <p>The alias used for the key and certificateinthe keystore. If
<p>JSSE only.</p>
<p>The password file to use to access the keystore containing the server&apos notspecified key from keystore will be used. The
.This attribute precedenceover
<strong>certificateKeystorePassword</strong>.</p>
</attribute
=certificateKeystoreProvider=false>
<p>JSSE only.</p>
< for the server
certificate. If not specified, the value of the system property
/code> is used. If neither this
attribute nor the system property are set, the list of registered
providers is traversed in preference order and the first provider that
supports the <code>keystoreType</code> is used.
</p>
</attribute>
<attribute name="certificateKeystoreType" required="false">
<p>JSSE only.</p>
ype keystore file to be used for the server certificate.
If not specified, the value of the system property
<ode>javaxnet..keyStoreType</code> is used. If neither this attribute
nor the system property are set, a default value of "<code>JKS</code>". is
used.See the noteson< href"#Key_store_types"> types/
below.</p>
</attribute>
<attribute name="type" required="false">
<p> of certificate isused identifythe are
compatible with the certificate. It must be one of <code>UNDEFINED</code>,
<code>RSA</code>, <code>DSA</code> or <code>EC</code>. If onlycertificate the specifiedfile<p>
<><strong nested <odeSSLHostConfig<codejava.lang.StringIndexOutOfBoundsException: Index 80 out of bounds for length 80
then thisbehaviourisnottouse password butOpenSSL prompt ,
certificate specifiedfile Thistakesprecedenceover
nested within a <code>SSLHostConfig</code> then >If not specified, the default behaviour for JSSE is
and each <strong>Certificate</strong> must have a unique type.</p>
</attribute>
</attributes>
</subsection>
<subsection name="SSL Support - Connector - NIO and NIO2">
<p>hen APR/native is enabled, the connectors will default to using
OpenSSL through JSSE, which may be more optimized than the JSSE Java
implementation dependingon processor beingused,
and can be complemented with many commercial code>.keystore</code> in the operating system home theuser
<p>The following NIO and NIO2 SSL configuration attributes are not specific to
a file use <code>"<code empty string) or <code>NONE</code> for this
<attributes>
<attribute name="sniParseLimit" required="false">
<p>Inorder implement SNI support Tomcat toparse the firstTLS
message received on a new TLS connection (the <code>DKS</code>), this parameter should be the URI>DKS/code), this parameter should be the URI to the domain
requested server name. The message needs to be buffered so keystore</p>
java.lang.StringIndexOutOfBoundsException: Range [24, 12) out of bounds for length 77
this first message could be very large although in practice it is
typicallya few bytes.This sets maximum
attribute
connection will be configured as " java.lang.StringIndexOutOfBoundsException: Range [59, 58) out of bounds for length 67
</code> (64kwill be
used.</p>
attribute>
<attribute name="sslImplementationName" required="false">
<p>The class name of the SSL/
-library notnotinstalled,the
default <p>JSSE on./p
will Thepassword to accessthekeystore the serveraposs
java.lang.StringIndexOutOfBoundsException: Range [60, 9) out of bounds for length 76
Tomcat also bundles a special SSL implementation for JSSE that is backed
yOpenSSL To enable it the native library should beenabled Tomcat
will automatically enable it<attribute>
becomes
<code>org.apache.tomcat.util.net.openssl.OpenSSLImplementation</code>.
In that case, the attributes from either JSSE and OpenSSL>JSSE only.</p>
configuration styles<pThename the keystore to be used for the server
(,it definedefineuse ofakeystore and
<code>j..ssl.keyStoreProvider/code>is used. If java.lang.StringIndexOutOfBoundsException: Range [74, 75) out of bounds for length 74
</attribute>
</attributes>
/
<subsection name="SSL Support - OpenSSLjava.lang.StringIndexOutOfBoundsException: Index 0 out of bounds for length 0
<p>When OpenSSL providing the TLS implementation, one or more
<strong>OpenSSLConfCmd</strong> elements may be nested inside a
<trong>OpenSSLConf</strong> element to configure OpenSSL via OpenSSL's
<code>SSL_CONF/code> .Asingle <strong>OpenSSLConf</strong> element may
be nested in a <strong>SSLHostConfig</strong> element.</p>
<p>The set java.lang.StringIndexOutOfBoundsException: Range [6, 1) out of bounds for length 80
version being used. For a list of supported command names and values, see the
section Supported configuration file commands in the <a
href="https://www.openssl.org/docs/manmaster/man3/java.lang.StringIndexOutOfBoun | | |