WebDAV not working over SSL on CSS11503

SOME HISTORY
As you may recall we had an issue with interoperability between our WebCT Vista application and the Cisco CSS11503 Load Balancer. In a nutshell the Load Balancer would inject custom HTTP headers into HTTP packets, but only into the first HTTP packet of a TCP session. With your help we've learned that Cisco will change this in the August release of the CSS software.
OUR NEW PROBLEM
We are now having a related problem. In short, we cannot get WebDav to work over SSL. That is, when connect from Client to Load Balancer via SSL, and then Load Balancer to Web Server via plaintext, our application fails. Conversely, when we maintain a clear text connection straight through from Client to Web sever WebDav works.
After doing some network traces of WebDav connections both with and without SSL I think we've discovered the cause of the problem: the Load Balancer fails to add our custom HTTP header "WL-Proxy-SSL: true" to HTTP "PROPFIND" requests, even though it correctly adds them to the HTTP "OPTIONS" requests.
HOW WE CONFIGURED THE LOAD BALANCER
We configured our Load Balancer with the Global configuration of
http-method parse RFC2518-methods
and with the command
ssl-server 20 http-header static "WL-Proxy-SSL: true"
so that the header "WL-Proxy-SSL: true" will be passed with the HTTP headers used for WebDav was well as with the 'standard' HTTP headers "GET, POST, HEAD", etc.
Below is the relevant passage from the "CSS Command Reference" at
http://www.cisco.com/univercd/cc/td/doc/product/webscale/css/css_750/cmdrefgd/cmdgloba.htm#wp1432749
======================================================================
"By default, a Layer 5 content rule supports the HTTP CONNECT, GET, HEAD, POST, and PUT methods. Unless configured, the CSS recognizes and forwards the following HTTP methods directly to the destination server in a transparent caching environment, but does not load balance them:
OPTIONS, TRACE, PROPFIND, PROPPATCH, MKCOL, MOVE, LOCK, UNLOCK, COPY, and DELETE.
When you enable the CSS to support all RFC-2518 methods, the CSS parses the Request-URI field in an attempt to match a Layer 5 rule. If the contents of the Request-URI field are not in a compliant format of an absolute URI or an absolute path, the CSS tries to match the field to the next best wildcard ("/*") rule. If the match fails, the CSS attempts to match the Layer 4 rule, and then the Layer 3 rule."
========================================================================
I interpret this to mean that when we configure "http-method parse RFC2518-methods" that the load balancer will treat all the HTTP headers in the group "OPTIONS, TRACE, PROPFIND, ...", etc the same as the "standard" HTTP headers "GET, POST, HEAD", etc.
As I said earlier our network traces show that the "WL-Proxy-SSL: true"
header present in the HTTP header OPTIONS but *not* in the header "PROPFIND".
A BUG IN THE CSS COMMAND PROCESSOR?
By my reckoning, this behaviour must be a bug in the CSS Command processor, because whatever the CSS does for the "OPTIONS" header it should also do for the "PROFIND" header.
ATTACHMENTS
I've included three attachments.
trace.txt
- text output from Ethereal of the network trace
on the web server, with comments.
webdav.ssl.snoop
- the original network trace in Sun's 'snoop' format.
css.2.cfg
- the running configuration on the CSS11503
Thanks in advance for your help.

Hi
I finally discovered what is the issue here. In appears that in case of unsigned applets, the code is unable to access SunJCE provider which contains most of the ciphers used by SSL protocol. This means that a session with SSL server is broken and effectively applet is not initialised.
This problem is related to configuration of JRE under linux due to export control restrictions. Unfortunately I don't know how to make JRE to use SunJCE by default.
As a workaround I have set up the following policies using Policy Manager:
grant {
permission java.security.SecurityPermission "putProviderProperty.SunJCE";
grant {
permission java.lang.RuntimePermission "getProtectionDomain";
grant {
permission java.lang.RuntimePermission "accessClassInPackage.sun.security.*";
I don't know how insecure my actions are, but this definitely fixed problems with applets under SSL / HTTPS.
Feel free to send me your ideas how to fix this issue in more elegant way.
Best,
Marcin

Similar Messages

  • Facebook App not working over 3G, but works over Wi-Fi.

    I have a BlackBerry® Curve™ 3G 9330 Social Messaging Ready smartphone. My current software version is 6.0 Bundle 2333. My Facebook application worked perfectly fine when I got the phone a few months ago over the Verizon 3G network and Wi-Fi, but when I recently updated Facebook to version 2.0.0.58, it does not work over 3G anymore. But everytime I try to connect via 3G it says "We cannot reach the Facebook server at this time. Please try again later. (100)" It does however still work over Wi-Fi.
    I have tried various attempts to fix it: uninstalling the App and re-installing it and also removing the battery and putting it back in (hard reset), but nothing has worked.
    Is anyone else have this same issue? Is there a way to restore my Blackberry to its factory settings so that I can just use the older version of the Facebook App [that was previously installed]?
    Thank you.

    Hey metalhourse90,
    I can see from your PIN that you currently don't have browsing services included in your data plan. I would advise contacting your wireless provider to have this enabled.
    Thanks,
    -FS
    Come follow your BlackBerry Technical Team on Twitter! @BlackBerryHelp
    Be sure to click Kudos! for those who have helped you.
    Click Solution? for posts that have solved your issue(s)!

  • IMessage is not working over wifi. I need HELP D:

    My iMessage is not working over wifi. But it's only at my house. Actually it worked a while ago but then it stopped working.
    The browser, email, app store, youtube and any other apps are working just fine over the wifi. It's only my iMessage. It won't send any message. It say message not delivered. Does anybody what is going on and what can I do to fix it? Thanks, before. (:

    I recently moved my library on my time capsule
    You mean you moved your music files to the external. The library is more than the music files.
    Just copy the \Music\iTunes\ folder from internal to the Time Capsule.
    Add the Time Capsule to your Login items in System prefs -> Accounts.
    Hold Option and launch iTunes and select *Choose library*.
    Select the iTunes library file int ehiTunes folder on the Time Capsule.
    It is hte samae library you have previously. All artwork playlists, ratings, songs, movies, etc. will be there.
    Genius is already there so nothing needs to be done.

  • BBM not working over mobile network

    BBM on Q10 not working over mobile network.
    Working only via wifi.
    Carrier: KSA STC
    OS: Official 10.2.1.2102
    Please help.
    Its very disappointing that bbm is not working on bb.

    Can you try sending a BBM friend a PIN message, not in BBM, but in your Compose Message > PIN.
    You will need that contact's BBM PIN number...
    Do you see the message sent, and does it hae a D beside or R afterwards?
    1. If any post helps you please click the below the post(s) that helped you.
    2. Please resolve your thread by marking the post "Solution?" which solved it for you!
    3. Install free BlackBerry Protect today for backups of contacts and data.
    4. Guide to Unlocking your BlackBerry & Unlock Codes
    Join our BBM Channels (Beta)
    BlackBerry Support Forums Channel
    PIN: C0001B7B4   Display/Scan Bar Code
    Knowledge Base Updates
    PIN: C0005A9AA   Display/Scan Bar Code

  • Mail, iCal Server and iChat server will not work over VPN

    I have an Airport Extreme Base Station at the office running the network. Behind it sits a Mac Mini Snow Leopard server running 10.6.3. The ports necessary for Mail, iCal Server and iChat work fine through that external connection. I can also connect with VPN from my 10.6.3 clients.
    HOWEVER, when I connect with the VPN clients, I am suddenly unable to access the Mail, iCal Server, Wiki server and iChat server. All connections time out. I can ping the server and I can do other things that do NOT work on the public Airport like ssh or VNC. ssh and VNC are closed at the airport extreme.
    So it's pretty odd. When I'm connected via the VPN, all ports that are forwarded to the Snow Leopard server time out over the VPN.
    I've tried various and sundry configurations with the VPN client. This includes trying to send all traffic over the VPN, moving it up in the service order, etc. etc. Nothing fixes it. DNS resolution is working fine, however when I do a wireshark capture of ppp0 traffic, I notice that SSL and TLSv1 handshakes appear to occur on the public IP address instead of the private network IP address... and they're all resets.
    Has anyone gotten this to work successfully? Like I said, all ports that are NOT forwarded through the Airport work fine over the VPN, but will not work when connected to the VPN. It's really bizarre.

    New data: any ports that are normally forwarded on the Airport Extreme to the Mac Mini server will not work when connected to the VPN.
    For instance, if I have imaps/993 forwarded from the Airport Extreme to the Mac Mini, it works fine over the Internet. If I connect to the VPN, I can connect to all OTHER services on the Mac Mini, but Mail, for instance, will not work.

  • Safari 8 hover does not work over google map location pins

    OS X 10.10.1,   Safari 8,  Java 8-25
    I have always had little odd things not work when using safari on a large % of websites I visit,  the latest issues are
    no response when hovering over google map location pins, travel site calendars not opening or responding to mouse, drag and drop
    show the item being dragged several inches away from the actual pointer, some links don't respond, missing items
    or odd layout with print or pop ups going off the screen on some website pages, zooming in and out does not help. I have none
    of these issues when using Firefox or Chrome. Been using Safari for 4 years now.

    Have you tried a PRAM and an SMC reset? They're longshots, but don't take long to try.
    PRAM: http://support.apple.com/kb/HT1379
    SMC: http://support.apple.com/kb/HT3964
    Have you run Apple Diagnostics from the disc(s) that shipped with the computer?
    Since the problem occurs in all browsers, it still sounds like a video hardware or video RAM or maybe a software issue having to do with layers and rendering.
    The map layers aren't getting rendered, or if rendered, aren't getting displayed.
    Do you have any browser add-ins? Pop-up blockers?
    Since you have two video chipsets, it's possible that might be related to the issue.
    This non-Apple website talks about switching between chipsets on the various MacBook models so equipped, and points to a free 'donationware' program for the menubar that lets you easily switch between chipsets:
    http://www.everymac.com/systems/apple/macbook_pro/macbook-pro-unibody-faq/macboo k-pro-unibody-switching-between-graphics-processors.html
    Trying to think of other software that might help pinpoint the problem, does the iPhoto Slideshow 'Shatter' template work? Working properly, it 'shatters' images into several color layers and rotates them in and out to build and deconstruct photos.

  • I-pod still not working over year after malfunction.

    I would like to either know how to fix my ipod, how i can trade mine in for a new one, or get my money back for my ipod nano because i hav been on the support section of the apple website, posted questions and even tried everything they have suggested to fix my ipod and none of it worked. I'm just sick and tired of my ipod not working and tired of spending countless hours wasting my time trying everything people have offered. My ipod first gen. black 2GB nano has not worked in over a year now and turns on shows menu and even goes into the files. I hook it up to my computer( after syncing my ipod and being told the music is corrupted deleted all the music off it, then installed itunes 7), and the computer doesn't read it is even there, either does itunes (I've done this to a relatives computer as well and same results). Im not blaming Apple for anything but it is mysteriously funny how a few days(literally, not weeks or months) after my warranty/support runs out, my ipod stops working. I would just like to figure this out and get back to listening to my favorite music on my favorite listening device. Please, some-one help with this and let me know of anyone i can contact about this, no more suggestions, i'm sure ive tried them all.
    Message was edited by: Ipod-nano-man

    *My ipod first gen. black 2GB nano has not worked in over a year*
    It's been broken over a year and you are just now getting around to doing something?
    *it is mysteriously funny how a few days(literally, not weeks or months) after my warranty/support runs out, my ipod stops working.*
    So it's been broken over a year and the one year warranty ran out before it broke. That's two years. This would mean you purchased it before the 1st gen Nano was even released (12 October 2005).
    You don't want suggestions so you can get out of warranty service thru Apple for $79 here -> http://depot.info.apple.com/ipod/
    So you have successfully Restored it?
    You noted you have tried it on different computers but have you tried a different cable?

  • My bbm is not working over wifi connection.

    Hey, I just bought blackberry z10 in kuwait and my carrier is Viva , and i tried to connect the bbm over wifi it's not work for viva router ONLY !!! I dont know where is the problem !! but when I try to connect on other wifi it's work and looking fine  
    By the way, when I connect my z10 on viva router the internet and the browser it's connect BUT only BBM !!! 
    i really become confused !! HELP ME 
    PLEASE IF ANY ONE KNOW HOW TO SOLVE IT INFORME ME !!!! 
    THANKS

    First of all thanks to replay my massege 
    second. I'm the one who work in viva's carrier IT and the router is looking fine !! nothing wrong with it 
    on my ipohne i have viva line and when i turn on the hotspot and connect my z10 with my iphone's hotspot it's work !!!!!!!!!!!! only with the router !!
    is there any spicial thing to do with the setting on the router 
    BY THE WAY , my router is mobile wifi !! form Huawei
    PLEASE PLEASE HELP !!!
    SORRY if there any spelling mistakes because English is my second languages

  • Schedule tasks not working for SSL.

    I am running CF11 using Tomcat 7 and jdk1.7.0_45.  I have non-SSL sites that execute the exact same task fine.  However for my SSL enabled sites, the task will not run.  Does anyone have an idea as to what is causing this?

    I can confirm that cfschedule does work with SSL and yes you will need to import the certificate or root certificate into your certificate store if it is not one issued by a "well known" provider that the jre supports. The gotcha is that the certificate domain must match the server name used in the cfschedule call. For us this meant that our www.domain.com cert did not work, even after importing, for https://127.0.0.1/... To fix this we created a hosts file entry so the request didn't have to round trip outside the box.

  • Airplay not working over wireless, works over ethernet?

    I posted this in multiple forums in which it applies to.
    Just looking for troubleshooting suggestions from my wireless N MBPro, to my wired ATV2. Here is the rundown (all devices running latest updates):
    1)used to work just fine with old router
    2)airplay works in all directions, from wireless devises to the wired ATV2
    3)updated to a much newer N router from cisco
    4)now, airplay works over Ethernet from itunes to ATV2 (and iphone4s to ATV2), ATV2 plays music from my MBPro just fine
    5) however airplay fails to work from itunes to ATV2 over wirelesss
    6)all wireless connections are sound, it is not a bandwidth problem, it literally says "connecting to apple tv" and never stops or connects
    7)itunes sees the ATV2 just fine over both Ethernet and wireless connections, i can select ATV2 as an output even when on wireless
    8)it will even ask for the password once i select it
    So, any suggestions? I just dont know where I am going wrong, somehow the wireless aspect is the broken link. As a side note, all wireless clients and wired clients are on the same subnet.
    Thanks for any suggestions or help!

    I had the same problem.  Disable any IGMP, or IGMP proxy features on your router.  As soon as I disabled IGMP proxy on my router everything came up has been working for a while. Lack of driver support on the wireless clients is likely the cause. oh well, at least its working now.

  • HT4623 why is my facetime not working over cell service since the update

    I need help ? my Iphone 4s is not working ok on face time. I updated the phone and tried to use face time over the 3g network on Sprint and it stay on "connecting" please help ?

    Before you can use facetime, you have to contact sprint. or depends on the plan you have.

  • Logon trigger not working over DB-Link?

    Hi all,
    I have a serious question about accessing tables over a database link.
    I have three schema:
    DATA@SOURCE
    INTERFACE@SOURCE
    WORK@TARGET
    Schema DATA has one table called T1
    The INTERFACE schema has select privileges on all tables from DATA. Furthermore schema INTERFACE has a logon trigger to change the "current schema" to DATA:
    CREATE OR REPLACE TRIGGER TRG_A_LOGIN_SET_SCHEMA AFTER LOGON
    ON INTERFACE.SCHEMA
    BEGIN
    execute immediate 'ALTER SESSION SET CURRENT_SCHEMA = DATA';
    END;
    The WORK schema has a database link to the INTERFACE schema called INT_DB_LINK.
    I am now logged into schema WORK on the TARGET database and I am executing following statement:
    select a from T1@INT_DB_LINK
    -> it's working
    Next I execute
    declare
      cursor c is 
      select a
        from T1@INT_DB_LINK
       where rownum<2;
    begin
      for r in c loop
        null;
      end loop;
    end;
    This is not working. Error message is ORA-000942: table or view does not exist.
    But why?
    Can anyone help me?
    Thanks in advance
    Py

    Hi all,
    after a long, very long search I found what caused this strange behaviour.
    The ORA- Error was not raised by the SQL-Execution-Engine but by the SQL-Parser/SQL-Validation.
    As the second statement is an anonymous SQL block the Oracle Parser checks all objects dependencies before execution.
    This means a connection is established from TARGET to SOURCE checking if table T1 is available. The strange thing is
    that on this connection the "ALTER SESSION" trigger is not fired. So the parser does not find object T1 in schema INTERFACE.
    If I create an empty table T1 in INTERFACE the anonymous block gets parsed/validated and the statement is executed. But this
    time the block does a normal "connect session" and the trigger is fired. This means the statements accesses the T1 table in
    schema DATA. (But T1 in INTERFACE has to be existent that parse/validation works)
    I don't know if this is a bug or a feature.
    To workaround this I have created private synonyms in schema INTERFACE pointing to the objects in DATA.
    Thanks for your help!
    Py
    regarding the other qestion:
    Yes, permissions are granted over a role.

  • Audio echo cancellation not working over rtmp

    I'm doing a audio conferencing app, using RTMP to our server (freeswitch) and getting a bad echo from anyone using speakers & mic- headsets don't cause the echo.  I've also tried 3rd party audio chat apps and they have echo too.
    I'm using getEnhancedMicrophone() and have played with all the Microphone & MicrophoneEnhancedOptions I can find.  I followed this article carefully: Best practices for acoustic echo cancellation in Flash Player | Adobe Developer Connection
    Does echo cancellation work over RTMP or only over RTMFP?
    Here's code I use to connect to send and receive our server's stream:
    netConnection = new NetConnection();
    netConnection.connect("rtmp://whatever.com/phone");
    incomingNetStream = new NetStream(netConnection);
    incomingNetStream.client = this;
    incomingNetStream.bufferTime = 0.2;
    incomingNetStream.play("play");
    incomingNetStream.receiveAudio(true);
    outgoingNetStream = new NetStream(netConnection);
    outgoingNetStream.addEventListener(NetStatusEvent.NET_STATUS, netStatus);
    outgoingNetStream.addEventListener(AsyncErrorEvent.ASYNC_ERROR, asyncErrorHandler);
    outgoingNetStream.bufferTime = 0;
    outgoingNetStream.attachAudio(mic);
    outgoingNetStream.publish("publish", "live");
    Is anyone successfully using RTMP with echo cancellation?  Can you send a link so I can try it?
    Any other ideas?
    Thanks,
    Ken

    I am not sure about echo cancellation directly at RTPM level but you may also try echo cancellation solutions that can be integrated with freeswitch. Take a look at their wiki. For example they mention PBXMate integration to cancel echo and noise, etc.

  • Bbm not working over wifi out of country. Same with email.

    I am in the us and have turned off my data and mobile network and enabled wifi only. I was able to use bbm and email no problem over wifi but all of a sudden even though I'm fully connected to wifi with good signal, my bbm is not working at all and I'm. Not receiving emails. Please help!

    The BlackBerry servers in Europe have been experiencing some problems over the last couple of days.  That's why you've been unable to connect to any of the BlackBerry services.
    Glad I could clear things up for you. 
    - If my response has helped you, please click "Options" beside my post and mark it as solved. Clicking the "thumbs up" icon near the bottom of my response would also be appreciated.

  • Facebook app links not working over wifi

    This might be hard to explain let alone comprehend so bear with me.
    As of the last 24 hours or so I am having trouble using Facebook linked apps while on Wifi. To be specifc I was using the app called "Lost Friends?". I have used this app for months, no issues. All of a sudden last night it would not connect to my Facebook account. I went on to try another app called "Lost A Friend", same issue, no connection to Facebook via wifi. After I left my house (back to 3G) I tried it and it worked perfectly, but again, once home it was doing the same thing. While inside my house I turned off Wifi and it worked again. It sounds to me like there is something within wifi, Facebook or both. If anyone has any info it would be greatly appreciated.
    To skip a step or two, I went as far as factory resetting my phone, starting as a new iphone and still have the same issue.

    I'm using a Mac have a Airport express base station. Everything was fine and I could pull up Facebook on my Mac and Androids over my WiFi. Apple pushed a firmware upgrade and the IOS upgrade.  Now, voila, Facebook not working on my Mac or on other devices if logged on to my WiFi.  If I disconnect WiFi and am on 4G it works fine.  The same issues as others have described.
    After trying all the fixes listed and a few not listed like clearing my cookies, history, tmp files and cache, I tried a release/renew.  Nope. So I logged out of Facebook, uninstalled the apps, shut down computer, phone and tablet. I finally reset my routers by unplugging my comcast router and my basestation, let them all resync, thinking this might have been an issue with a router table (?). At any rate this would reset all the IPs. (I reinstalled the apps)  Worked the first time, about 2 hours later it quit working.  Tried the same trick but it didn't work again.
    I've read a number of blogs and other posts on 'fix it' type sites researching the issue.  It sounds like many of the streaming media sources that require lots of resources and will cost more to operate by using the data plans are no longer working on WiFi. 
    Interesting.

Maybe you are looking for

  • How to make smal areas in a map clickalbe and adjustable for Flash..

    I am trying to make a clickable map where you can click on small areas and be linked to another page.... I can of course break the map to 100 pieces and make 100 buttons and put them together... But this is so time consuming and I am sure there is a

  • Enlargements out of Lightroom

    How good is Lightroom at maintaining quality when enlargements are made via the export function. e.g. if you have a picture say 3000 x 4000 pixels & enlarge to 4500 x 6000 via not ticking the do not enlarge tick box on export. How does ity compare to

  • Reflection Themes have big white box in the background

    Rookie iDVD user here, and haven't been able to solve this one. Trying to use the 6.0 theme "Reflection Black" and it is sticking a big white square in the middle of the screen. It is behind the drop zones and I cannot figure out why it is there or h

  • CS5.5 Crashes on startup

    Hi, I'm running version CS5.5 with several user accounts on a 64 bit Windows 7 Professional machine with an M-Audio Delta 44 card.  This configuration has been in use without an issue for approximately a year, and working without a hitch.  Recently,

  • Options set to remember history, but Firefox won'e save

    Firefox won't save my browsing history even though the options privacy setting is set to remember history