Re: GlassFish 3.1.1 security

From: Glenn Holmer <>
Date: Mon, 22 Aug 2011 08:55:53 -0500

On Wed, 2011-08-17 at 09:58 +0530, Kumar Jayanti wrote:
> It seems to be a regression. We had a bug :
> and it appears the fix
> for that does not take care of a particular situation which is
> happening in your setup (that is causing the
> ArrayIndexOutOfBoundsException).
> Please file a bug we will fix it for the 3.1.2 release and the
> meantime we will let you know if there is any workaround that you can
> do.

Is there another way to do this? We'd really like to move up to 3.1.1 so
we can start work on clustering/load balancing.

> On 17-Aug-2011, at 3:20 AM, Glenn Holmer wrote:
> > We have an app that we've been running under GlassFish 3.0.1, and we
> > want to run it under 3.1.1. We've been running GlassFish fronted by
> > Apache, which handles SSL, and everything works OK. For 3.1.1, we used
> > these commands in place of the "old way" of putting the Tomcat jars in
> > GlassFish's lib/ directory:
> >
> > asadmin create-http-listener --listenerport 8009 --listeneraddress --defaultvs server jk-listener
> > asadmin set
> >
> > We are not yet using clustering/load balancing, so we are using the
> > default "server-config" configuration. Apache correctly forwards most
> > pages to GlassFish, except those that are protected.
> >
> > In web.xml, we have this:
> >
> > <security-constraint>
> > <web-resource-collection>
> > <web-resource-name>phoenix_auth</web-resource-name>
> > <description>Phoenix security</description>
> > <!-- the pages which will be protected: -->
> > <url-pattern>/customers/*</url-pattern>
> > <http-method>GET</http-method>
> > <http-method>POST</http-method>
> > <http-method>HEAD</http-method>
> > <http-method>PUT</http-method>
> > <http-method>OPTIONS</http-method>
> > <http-method>TRACE</http-method>
> > <http-method>DELETE</http-method>
> > </web-resource-collection>
> > <user-data-constraint>
> > <transport-guarantee>CONFIDENTIAL</transport-guarantee>
> > </user-data-constraint>
> > </security-constraint>
> >
> > This all worked fine under 3.0.1 (unless I forgot to write down a step
> > re. how we configured it).
> >
> > But under 3.1.1, when I hit a page under /customers/, I get this:
> >
> > [#|2011-08-16T16:38:07.075-0500|INFO|glassfish3.1.1||_ThreadID=22;_ThreadName=Thread-2;|JACC P
> > olicy Provider:Failed Permission Check: context (" phoenix-jee6/phoenix-jee6-war-bo_war ") , permission (" (
> > UserDataPermission /customers/checkout.html GET) ") |#]
> >
> > [#|2011-08-16T16:38:07.076-0500|SEVERE|glassfish3.1.1|org.apache.catalina.connector.CoyoteAdapter|_ThreadID=22;_ThreadName=Thread-2
> > ;|PWC3989: An exception or error occurred in the container during the request processing
> > java.lang.ArrayIndexOutOfBoundsException: 1
> > at
> > at
> > at
> > at
> > at org.apache.catalina.authenticator.AuthenticatorBase.invoke(

