Enterprise Architecture & Integration, SOA, ESB, Web Services & Cloud Integration

Enterprise Architecture & Integration, SOA, ESB, Web Services & Cloud Integration

Showing posts with label Load Balancing. Show all posts
Showing posts with label Load Balancing. Show all posts

Tuesday, 24 July 2012

Apache SSL configuration with sample


Many a times, you might want to set up an Apache httpd server as front end that talks to back end application servers such as Oracle WebLogic or Apache Tomcat. While httpd acts as a proxy, you might also want to use it as an SSL server. It will ensure that the communication between browser and apache httpd is secure. But, have you ever thought how easy it is to set up SSL using apache? Believe me, it is really easy. Apache configuration is so powerful (I agree, sometimes it is painful if you don’t know what you are usingJ) and needs very minimal configuration.

The minimum things that you would need are: -
a) Server certificate
                - Your browser user can identify which server he/she is connecting to. This is PEM encoded certificate. If you open the certificate in an editor like notepad, you can see scrambled text which starts with -----BEGIN CERTIFICATE----- and ends with -----END CERTIFICATE-----.

b) Private key to decrypt the encrypted data
                - Please make sure that your private key is kept secure. You can use key that use either RSA or DSA.

c) Certificate chain from your certificate authority
                - The end certificate in the chain will be a root certificate. If you don’t have the complete chain, SSL might not work.

If you have all the above, then you can easily set up 'one-way' SSL which is otherwise known as 'Server authentication'. Please see below the snippet that is the minimal configuration required:

Listen 443
<VirtualHost *:443>
     SSLEngine on
     SSLCertificateFile public.crt
     SSLCertificateKeyFile private.key
     SSLCertificateChainFile intermediate.crt      
</VirtualHost>

The mod_ssl module also allows you to access certain environment variables which you may use them for debugging purpose. Use the following line that will allow you to create a separate log file for capturing SSL related information. You may also decide to switch on logging only in development.

CustomLog logs/ssl_request_log "%t %h %l %u %{SSL_PROTOCOL}x %{SSL_CIPHER}x %{HTTPS}x %{REFERER}i %{X-Forwarded-For}i \"%r\" %s %b"

One common issue that every one might face is with configuring 443 for SSL. you might get an error that is given below: -
(13)Permission denied: AH00072: make_sock: could not bind to address xx.xxx.xx.xx:443
no listening sockets available, shutting down
AH00015: Unable to open logs

Please make sure that you have 'root' access which is required for using standard ports 80 for http and 443 for https.

Hope this information will be useful for you. 

Wednesday, 20 June 2012

Configure apache (2.4.2) load balancer with virtual hosts

My boss asked me couple of days ago to configure apache load balancer. It has been some time since I have done one. I could still remember most of the things, so started making changes to httpd configuration files (thanks to so many site/blogs including apache official site offering help on load balancer configuration). The journey is so far nice. Here is my initial load balancer configuration (all important lines, if not all, are shown here) -

My server needs to be configured with two virtual hosts listening on 8081 and 9081 respectively.

Listen 8081
Listen 9081

ProxyRequests off
LoadModule proxy_module modules/mod_proxy.so
LoadModule proxy_connect_module modules/mod_proxy_connect.so
#LoadModule proxy_ftp_module modules/mod_proxy_ftp.so
LoadModule proxy_http_module modules/mod_proxy_http.so

#LoadModule proxy_scgi_module modules/mod_proxy_scgi.so
#LoadModule proxy_ajp_module modules/mod_proxy_ajp.so
LoadModule proxy_balancer_module modules/mod_proxy_balancer.so
LoadModule rewrite_module modules/mod_rewrite.so

LoadModule headers_module             modules/mod_headers.so
LoadModule status_module             modules/mod_status.so

LoadModule lbmethod_byrequests_module     modules/mod_lbmethod_byrequests.so
 

<Proxy balancer://mycluster8081>
  BalancerMember http://myserver1:6001
  BalancerMember http://myserver1:7001
  BalancerMember http://myserver2:6001
  BalancerMember http://myserver2:7001

 </Proxy>

<Proxy balancer://mycluster9081>
  BalancerMember http://myserver3:6001
  BalancerMember http://myserver3:7001
  BalancerMember http://myserver4:6001
  BalancerMember http://myserver4:7001
</Proxy>

<Location /manager>
    SetHandler balancer-manager
</Location>

<VirtualHost *:8081>
    ProxyPass /myportal balancer://mycluster8081/myportal
    ProxyPassReverse /myportal balancer://mycluster8081/myportal
</VirtualHost>

<VirtualHost *:9081>
    ProxyPass /myportal balancer://mycluster9081/myportal
    ProxyPassReverse /myportal balancer://mycluster9081/myportal
</VirtualHost>


I restarted the server and I encountered my first issue - the server refused to start after spitting an error "AH01177: Failed to lookup provider 'shm' for 'slotmem': is mod_slotmem_shm loaded??". After spending time on investigation, I have added the following module (which has been added in 2.4.x, it didn't exist in 2.2.x) -

LoadModule slotmem_shm_module modules/mod_slotmem_shm.so

Now, I got the second problem, bigger than the first one - "(22)Invalid argument: AH01186: worker slotmem_grab failed". After googling, I have found that this is an existing issue with 2.4.x. The technical details can be obtained from here https://issues.apache.org/bugzilla/show_bug.cgi?id=52402

What was working in 2.2.x is not working now in 2.4.x, but Apache keeps adding more features and improving its existing features too. So, this happens. However, as I am running against time, I can't wait till someone fixes this issue, so tried searching for a workaround. After several attempts by changing the configuration, there seems to be a workaround available - move all proxy balancer stuffs into respective VirtualHost configuration. Please see below the modified configuration -

Listen 8081
Listen 9081

ProxyRequests off
LoadModule proxy_module modules/mod_proxy.so
LoadModule proxy_connect_module modules/mod_proxy_connect.so
#LoadModule proxy_ftp_module modules/mod_proxy_ftp.so
LoadModule proxy_http_module modules/mod_proxy_http.so

#LoadModule proxy_scgi_module modules/mod_proxy_scgi.so
#LoadModule proxy_ajp_module modules/mod_proxy_ajp.so
LoadModule proxy_balancer_module modules/mod_proxy_balancer.so
LoadModule rewrite_module modules/mod_rewrite.so

LoadModule headers_module             modules/mod_headers.so
LoadModule status_module             modules/mod_status.so

LoadModule lbmethod_byrequests_module     modules/mod_lbmethod_byrequests.so LoadModule slotmem_shm_module modules/mod_slotmem_shm.so


<Location /manager>
    SetHandler balancer-manager
</Location>

<VirtualHost *:8081>
<Proxy balancer://mycluster8081>
   BalancerMember http://myserver1:6001
  BalancerMember http://myserver1:7001
  BalancerMember http://myserver2:6001
  BalancerMember http://myserver2:7001
</Proxy>

    ProxyPass /myportal balancer://mycluster8081/myportal
    ProxyPassReverse /myportal balancer://mycluster8081/myportal
</VirtualHost>

<VirtualHost *:9081>
<Proxy balancer://mycluster9081>
BalancerMember http://myserver3:6001
  BalancerMember http://myserver3:7001
  BalancerMember http://myserver4:6001
  BalancerMember http://myserver4:7001
</Proxy>

    ProxyPass /myportal balancer://mycluster9081/myportal
    ProxyPassReverse /myportal balancer://mycluster9081/myportal
</VirtualHost>

At least this workaround will keep you move forward till you get the official fix. (At least, a new patch is not an option in my case). Hope this workaround works for you. If not, please respond to me.