Received: from malur.postgresql.org ([217.196.149.56]) by arkaria.postgresql.org with esmtp (Exim 4.80) (envelope-from ) id 1YFmgT-0002Y3-J9 for pgsql-admin@arkaria.postgresql.org; Mon, 26 Jan 2015 16:38:41 +0000 Received: from localhost ([127.0.0.1] helo=postgresql.org) by malur.postgresql.org with smtp (Exim 4.80) (envelope-from ) id 1YFmgT-0001nS-0a for pgsql-admin@arkaria.postgresql.org; Mon, 26 Jan 2015 16:38:41 +0000 Received: from makus.postgresql.org ([2001:4800:1501:1::229]) by malur.postgresql.org with esmtps (TLS1.2:DHE_RSA_AES_256_CBC_SHA256:256) (Exim 4.80) (envelope-from ) id 1YFmgI-0001nD-J4 for pgsql-admin@postgresql.org; Mon, 26 Jan 2015 16:38:30 +0000 Received: from mail-am1on0740.outbound.protection.outlook.com ([2a01:111:f400:fe00::740] helo=emea01-am1-obe.outbound.protection.outlook.com) by makus.postgresql.org with esmtp (Exim 4.80) (envelope-from ) id 1YFmgE-0003S0-En for pgsql-admin@postgresql.org; Mon, 26 Jan 2015 16:38:28 +0000 Received: from AM2PR06MB0676.eurprd06.prod.outlook.com (25.161.19.13) by AM2PR06MB0673.eurprd06.prod.outlook.com (25.161.18.155) with Microsoft SMTP Server (TLS) id 15.1.65.19; Mon, 26 Jan 2015 16:38:00 +0000 Received: from AM2PR06MB0676.eurprd06.prod.outlook.com ([25.161.19.13]) by AM2PR06MB0676.eurprd06.prod.outlook.com ([25.161.19.13]) with mapi id 15.01.0065.013; Mon, 26 Jan 2015 16:38:00 +0000 From: Luc DALLEMANE To: "pgsql-admin@postgresql.org" Subject: LDAP authentication problem. Thread-Topic: LDAP authentication problem. Thread-Index: AQHQOYXu5kgXmvj1WEqIYIO2HCPDDA== Date: Mon, 26 Jan 2015 16:38:00 +0000 Message-ID: <1422290279924.8856@alaloop.com> Accept-Language: fr-FR, en-US Content-Language: fr-FR X-MS-Has-Attach: X-MS-TNEF-Correlator: x-originating-ip: [92.103.19.225] authentication-results: postgresql.org; dkim=none (message not signed) header.d=none; postgresql.org; dmarc=none action=none header.from=alaloop.com; x-dmarcaction-test: None x-microsoft-antispam: BCL:0;PCL:0;RULEID:(3005004);SRVR:AM2PR06MB0673; x-exchange-antispam-report-test: UriScan:; x-exchange-antispam-report-cfa-test: BCL:0;PCL:0;RULEID:;SRVR:AM2PR06MB0673; x-forefront-prvs: 0468FE4A2B x-forefront-antispam-report: SFV:NSPM; SFS:(10019020)(6009001)(450100001)(16236675004)(2656002)(87936001)(106116001)(66066001)(122556002)(36756003)(19627405001)(77156002)(40100003)(62966003)(102836002)(54356999)(50986999)(2900100001)(92566002)(46102003)(86362001)(229853001)(117636001)(2351001)(110136001)(19580395003)(107886001); DIR:OUT; SFP:1102; SCL:1; SRVR:AM2PR06MB0673; H:AM2PR06MB0676.eurprd06.prod.outlook.com; FPR:; SPF:None; MLV:sfv; LANG:en; Content-Type: multipart/alternative; boundary="_000_14222902799248856alaloopcom_" MIME-Version: 1.0 X-OriginatorOrg: alaloop.com X-MS-Exchange-CrossTenant-originalarrivaltime: 26 Jan 2015 16:38:00.2802 (UTC) X-MS-Exchange-CrossTenant-fromentityheader: Hosted X-MS-Exchange-CrossTenant-id: 90b3750c-fbeb-434c-86dd-9b9aa053b94e X-MS-Exchange-Transport-CrossTenantHeadersStamped: AM2PR06MB0673 X-Pg-Spam-Score: -1.9 (-) List-Archive: List-Help: List-ID: List-Owner: List-Post: List-Subscribe: List-Unsubscribe: X-Mailing-List: pgsql-admin Precedence: bulk Sender: pgsql-admin-owner@postgresql.org --_000_14222902799248856alaloopcom_ Content-Type: text/plain; charset="iso-8859-1" Content-Transfer-Encoding: quoted-printable Hello, I'm facing a problem with my web application. For this project, I'm using : Java 1.8, Postgres 9.4, Tomcat 7.0.56 and a cisco asa firewall. The firewall is configured with an IP and port restriction. The Web part is located in a DMZ and the database part in the LAN. I'm using a combined REALM (LDAP and Database). The problem is the following, we can connect to the application and use it,= but after a while (don't know really when), you cannot connect again. In the log, I can see that the LDAP authentication never ends. (I have put= logs before and after calling the authenticate method but the last log is = never displayed) In tomcat log, the problem begins with : org.apache.catalina.core.StandardService stopInternal INFO: Stopping service Catalina When we check the firewall, we get the following message : Deny TCP (no connection) from WEB/50790 to DB/5432 FIN ACK on interface DMZ= _clients You have to restart tomcat to fix this bug and it works again (for a while.= ..) I can't find the cause of this problem. Any answers are welcome. Luc. --_000_14222902799248856alaloopcom_ Content-Type: text/html; charset="iso-8859-1" Content-Transfer-Encoding: quoted-printable

Hello,

I'm facing a problem with my web application.
For this project, I'm using :
Java 1.8, Postgres 9.4, Tomcat 7.0.56 and a cisco asa firewall.

The firewall is configured with an IP and port restriction.

The Web part is located in a DMZ and the database part in the LAN.
I'm using a combined REALM (LDAP and Database).

The problem is the following, we can connect to the application and use it,= but after a while (don't know really when), you cannot connect again.
In the log, I can see that the LDAP authentication never ends.  (I hav= e put logs before and after calling the authenticate method but the la= st log is never displayed)

In tomcat log, the problem begins with :
    org.apache.catalina.core.StandardService stopInternal     INFO: Stopping service Catalina
    
When we check the firewall, we get the following message :

Deny TCP (no connection) from WEB/50790 to DB/5432 FIN ACK on interface DMZ= _clients

You have to restart tomcat to fix this bug and it works again (for a while.= ..)


I can't find the cause of this problem.

Any answers are welcome.


Luc.

--_000_14222902799248856alaloopcom_--