Thursday, May 11, 2017

Shawnee National Forest: Indian Point Trail

Indian Point Trail is the third of four trails I hiked over a weekend while visiting family down south.

I had no intention of hiking Indian Point; I didn't even know it was there until I drove past it on the way to Observation Trail. I had some extra time to kill, however, so I thought I'd give it a go.

Trail head

The trail started out a little muddy. It was no doubt hit by the same storms that impacted the Panther's Den trails. It dried quickly as I gained elevation. It starts with a subtle uphill climb. You walk past a small pond, that we'll come back to later. Next, there's a moderately steep uphill climb. The trail levels out as it winds around the south edge of the mountain top with a few places to get really nice views. Unfortunately, the well worn left turn will cut out a good portion of the actual trail which continues on south for a while before returning to the mountaintop. You can see in the map below, the actual trail (a light-gray line) versus the trail I followed in blue. There are no markings indicating that the trail continues on straight.

A view of Garden of the Gods Wilderness northwest of the trail.

The trail has camp sights dotted along it with remnants of campfires. They are close enough where campers cannot really get much privacy from hikers passing by.

Vegetation is a sparse enough that you can easily see through the forest. There is a thin layer of soil sitting on top of the rock, so foliage isn't as lush as some others. The ground is covered with small plants along most of the trail, with more pine needles along the top.

Some of the flora along the trail.

I stopped for some water and a granola bar looking out over a rocky outcrop, and took a little time to sit and enjoy the view to the west.

Soaking in a view of the Garden of the Gods wilderness.

I continued on, and found what looked like a small trail going down the side of the mountain. I headed down a very steep path between the rocks to explore a little. I found some caves in the side of the mountain just under where I was sitting that residue from campfires in them.

There were a few caves like this tucked into the side of the mountain, just underneath the trail. Both had residue from campfires in them.


I went down a little further to where the path exited the rocks and went into woodland, then headed back up to the top.

Time to turn around and head back up. It's a 50' climb from here, and I'll end up at the top just above the tree.

The remainder of the trail is a winding path back around the top of the mountain to the pond, where I picked back up with the trail heading back to the trail-head.

This trail is not overly maintained, and not well marked. There are no blazes or signs, so it's up to you to figure out where to find the trail. It's generally not a problem, as it's well worn, and not easily confused with streams (see my earlier account of the Panther Den hike). As mentioned above, the lack of marking has the potential to cut your hike short.



Details:
Min Elevation: 768 ft.
Max elev.: 928
Distance: 1.37 mi.

Shawnee National Forest: Observation Trail

The Observation Trail is the second of four trails I hit last weekend while visiting family down south.



The Observation Trail is not really a hiking trail; rather, it's a walking path paved with sedimentary rock and cement mortar. It's really laid out more as a park service supported tourist attraction than a trail, but the views are really nice. The walking path is a quarter mile long, and about three feet wide in most spots. It includes benches and plaques describing the rock formations and geology of the region.

The first visible rock formation and the walking path

Garden of the Gods has some beautiful views, particularly for the mostly flat Midwest. I arrived at around 8:30 a.m. on a Sunday. There were only a few visitors, So photography opportunities were frequent.

Just minutes into the walk, a view to the north opens up. There are no guardrails on most of the outcroppings of rocks to stop you from going over the cliffs.

Looking north. Most of the visible land is part of the Shawnee Wilderness.


Looking south by southwest.


The Devil's Smokestack. This formation occurred as softer sandstone was eroded from around the rock.


Camel Back Rock bears a striking resemblance to a camel.

Saturday, May 6, 2017

Panther Den Wilderness Hike



This is the first of four trails I hit last weekend as I made a trip down south to see family. It is brought to you in part by Samuel Adams IPA, which I have been drinking all night while writing this. :)

While heading down to see family down south, I decided to stop off at Panther Den Wilderness for a little hike. Panther Den is just south of Marion, IL, off of I-57. It's part of the Shawnee National Forest, a dispersed set of parks in Southern Illinois. I read a review on some blog, and the author gave it a pretty bad review (something like 2.5 stars of 5). I would not go that far. It had some issues, but... Well, let's just get into the hike.

Some sage advice for entering the wilderness.
The adventure begins by exiting I-57. I went quickly from civilization to back country in the blink of an eye. Seems there was a gas station at exit 40, but it's long gone, now. All that's left is the pump shelter. After numerous back roads, turns, and partially washed out gravel roads, I made it to the trail-head. There were 4 other cars when I arrived in a space that can accommodate 7 or 8. Not bad for a Saturday afternoon. I cleaned off my shoes on the obligatory shoe brushes (we don't want to bring in any invasive species, now do we?), then it was off to the hike. I left the Questing Trail-head (lower left point on the map) heading for the Panther Den Loop.

The first section was very nice, but I noticed that the sedimentary rock and limestone on the path was damp, and there were fresh green leaves laying all over the trail. In addition, there were lots of small streams - some no more than a few inches wide, and a half inch deep running across the trail. A storm had obviously passed through within the last day. For the most part, this part of the trail (trail 371 leading up to the loop) was well cared for

I entered the trail just after another couple, and as long as I stayed 100 feet or so behind them, I could not hear or see them. That is the one of the niceties of this trail. The foliage is so dense, you really feel secluded.

I was also struck by how green the forest was. Perhaps it's because we just came out of winter, but the green was amazing.

Sidebar: That said, there was one jackass that seemed to think it was cool to bring his iWhatever music player out with a battery-powered external speaker and play music so the whole forest could hear him. He should have received a medal for achieving heretofore unseen levels of douchbaggery. I'm a music lover. I really am. But if you're going to bring music out to the trails, bring headphones. Seriously, no one wants to hear you're music, and it's bad enough we humans go lumbering through the wild making the noise we do, scaring off the wildlife. We don't need to make it worse by playing music out loud.

I came upon a sign that gave me two options: go straight for the Panther Den loop, or go straight for the River to River trail. I chose straight.

Decisions, decisions. Maybe go straight?

While still easy to follow, there was clearly less maintenance taking place on the trail as I ventured deeper in. I ran across this beautiful example of a fern.

The ferns thrive in this forest.

Ferns are indigenous to the area, and thrive in the dense vegetation and moist environment.

Next I came upon my first stream crossing. The amount of sedimentary rock in the stream beds makes crossing pretty easy; surprisingly so, given that the area just received a good amount of rain. That's where I got my first glimpse of the rock formations.

My first glimpse of the rocky outcrops in the wilderness.

Continuing on, I am faced with a fork in the road. Go left for the River-to-River Trail (actually, a subset of the larger River-toRiver trail going between the Ohio and Mississippi rivers), or right for the Panther Den Loop. Enticing me to go left was the "Rock formations" sign. But, I came here to do the loop, and I figured I would just add a little to the hike by taking the left path on my way back.

At this point, the path quickly deteriorated. The runoff from the storm had turned much of the trail into a stream. Heading north on the upper-right portion of the trail, I was sure I had gone off-trail until I compared my GPS record to the trail map. As it turns out, when I thought I ended up walking some random stream, I was, in fact, on the loop the entire time. The westbound portion at the far north end of the trail was even worse. Much of the trail was overgrown, numerous trees had fallen across the trail, and there was standing water throughout. I started to become pretty discouraged, now, thinking I was just wandering through streams. As I started to head back downhill, I walked through an area where bare rock was the trail, and it was really beautiful to look at. A little further down, and I had the most wonderful surprise.

A welcome surprise after wondering if I'm on trail.

I stumbled right into the rock formations indicated by the earlier sign. These were much larger than what I saw at the stream, and incredibly beautiful. They were eroded by time and rain, covered in moss, and displayed a wonderful set of colors including gray, tan, and orange. It was time to explore in the crevices, a bit.

The crevices were stunning.


Heading into the big crevice, the temperature dropped about 10 - 15 degrees F. Also, the change in sound was overwhelming. The sounds of birds and wind through the trees disappeared, and the silence was overpowering. While ambient noise faded, any sound I made bounced around in a reverb/echo fashion.

The rock formations were beautiful.

Deep in the rock, the air was cooler, the sound of the forest disappeared, and the views were incredible.


While in this crevice, there was a gentle patter of water all around dropping from the tops of the rock cliffs. It felt not unlike rain, but that I could easily evade by just walking back under a cliff.

Another awe-inspiring crevice.

The trail now tracked along the rock-faces, presenting serene views of mossy rock in the forest. This, to me is amazing. I come from Northern Indiana, generally referred to as the "Heartland of America" (code for flat and boring as hell). Seeing rock just popping up like this is a real treat for me. What's especially interesting is that just 20 miles north, the terrain was all generally flat and farm land. Here, at the very start of the hills in the south was such a gem.

I hit a number of stream crossings, and came across horseshoe marks on the trail. My first big stream crossing was fun - I ended up crossing over a fallen tree.

Stream crossings were frequent, but this one was too wide to try to jump. Fortunately, some fallen trees were available to help.

A little further down, I had another stream crossing that left me with a very wet right shoe (which is now drying on the counter next to the sink in my hotel room). A few hundred feet later, another stream crossing. The plan was simple: pop off the right foot, lay the left foot on the 6" rock in the middle of the stream, then swing the right leg forward to grab the bank. Left shoe now wet.

As I headed further south, I hit a small set of switchbacks going up a small hill. Then I saw signs marking the River to River Trail. and left the 'formal' Panther Den Wilderness.

Looking backward, heading out of the wilderness, proper.

Before long, I was back at the signs in the fork, offering the loop or the rock formations. I was back on the trail I started on, heading back to the trail-head.

7.6 K after the start, I'm back at the trail-head. The only downside of the trail was the lack of blazing. The service's website calls out, explicitly that the trail is well-marked. I would argue that there is some room for improvement. Some additional blazes on the trees would have been really helpful. That said, it probably would not have been as much of an issue, had a storm not just passed through, and left the trails in a poor state. The rock formations really made up for it, though, and left me feeling that I made the right choice stopping by.

 The Panther Den Loop

The Panther Den Loop elevation profile

Statistics


Min Altitude: 161m
Max Altitude: 239m
Cmumulative Climb: 301m
Distance: 7.6 Km
Time: 1 hour, 55 minutes
Weather: Sunny, wind: n/a, 68-72 deg F.

Sunday, April 23, 2017

Shooting the Sun - 2 (and Jupiter, too)

Last night was the first clear night since the last of my astrophotography parts came in, so I went out to do some imaging. I started yesterday with some afternoon shots of the sun. They were good as far as the exposure, but a little blurry. One of the features of my Sony camera I was interested in is the Manual Focus Assist. Basically, it enlarges the image on the screen for a few seconds to allow you to work on the focus before putting the entire image back in the frame. As it happens, the function does not work without a lens attached.

Later in the evening, I decided to check and see where Jupiter was in the sky, and sure enough, it was right over head around midnight. Initially the intent was just to observe through the telescope. Once I saw its moons, however, I could not resist. I set up the camera again, and went back out. The first round was around 9:00 p.m. CDT. I took some decent images, but they were all washed out. Jupiter was a white fuzzy circle, and the four largest moons were fuzzy, as well. I decided to try again, this time around 10:30 p.m. I shot around 60 images, adjusting the ISO and shutter speed for each shot. When I got those onto the computer, every one was out of focus. I set the focus as best as I could once, a the beginning of the session, and I just couldn't get close enough to get it spot on. I threw away that entire batch, and went out once more, this time at 1:00 a.m. I shot varied ISO/shutter speed combinations this time as well. But, this time, for each combination, I shot three images, refocusing each time. It took longer, but at least there was a chance of getting one good one for the ISO/shutter speed combination. Here are two images I ended up with.

In this image, Jupiter is washed out, but we can see its four largest moons quite nicely. (from left to right: Europa, Callisto, Jupiter, Io, Ganymeade)

Here we see a much better image of Jupiter, but the moons are not very visible. On the original 20Mp image, they take up only a few pixels, and are rather dark.

Today, the sky was beautifully clear, so I thought I would give Sol another shot (pun totally intended). The first challenge I ran into was the angle. It seems even in April, the sun is high enough in the sky that you need to really tilt the scope up. Since I don't have a tripod yet, I'm using bricks as a stand for the scope. I put an extra block underneath the scope to get the angle I needed.

Telescope stand when you don't have a tripod. The pipe wrench made a suitable counter weight.
So, I slid a 2x4 block underneath the front of the scope. That provided the angle I needed, but now the the camera was pulling on the telescope, and it was no longer safe. Solution: bailing wire and a pipe wrench. The sockets used for the table mount are 1/4-20 threads, so I found a 1/4-20 threaded bolt in the workbench, and screwed it into the front of the scope. Next, I hung a pipe wrench from it using a piece of bailing wire. It was enough to keep the front solidly on the wood block, and solar imaging ensued.

I applied the same technique from last night: vary the ISO and shutter speed, refocusing for each image. I came up with some really good shots. ISO of 800 and above for this application were entirely too high - it left a washed out image that could not be post-processed into anything usable. 400 was good, and I think ISO 200 was best.

Image of the sun through my telescope using a solar filter.
As far as the equipment, I use a Meade ETX90EC scope. Mead makes a T-mount adapter that allows one to affix a camera to the back of the scope. It's a #64 T-mount Adapter. For the camera, I'm using a Sony a3000, on Manual, with the 'lens-removed' setting enabled. I picked up a cheap shutter release for under $10 to fire the camera. These would not be possible without that shutter release.

Friday, April 14, 2017

Caja: Check MD5sum in a Context Menu

This post applies only to the Caja file manager. It's used in Linux Mint, and likely other distributions.

Why Calculate an MD5 Checksum?

Free software is available all over the Internet. An unfortunate side effect, however is that you download something that has been surreptitiously replaced with malware, or other such malfeasance. Also, minor disruptions in data transfers have the ability, rare as it is, to cause a deformed packet, which still makes it past basic error checking mechanisms. So we want to validate files that we download to ensure they are reputable, and unchanged from the originals. Reputable websites that offer downloads will often display an MD5 checksum value (a string of characters and digits), typically placed near the download link. You will usually see the code preceded with "MD5: ", "md5sum: ", or similar. This code is calculated based upon the contents of the file that it represents, and if you perform an MD5 checksum of the file on your computer, it should match what is displayed on the website.

Why Wouldn't You Calculate an MD5 Checksum?

There are a few reasons we don't do this. First, many sites don't provide an MD5 checksum value. There's not much we can do about that, other can contact the website owner and request one. Even when there is a checksum value displayed, it's cumbersome, and it takes time for larger files. You have to open a terminal shell locate the file, run the md5sum command... In a word, it's inconvenient. This is where cajamd5 comes in. This is a small shell script that you can add to the Caja file manager to make checking an MD5 quick and easy.

Creating the Script

First, we need to write our script. Open your favorite text editor, and type in the following:

#!/bin/bash

for file in $CAJA_SCRIPT_SELECTED_FILE_PATHS
do
  # Begin calculating the md5 sum of a file.
  md5sum "$file" | tee >(cut -d ' ' -f1 > /tmp/sum) |zenity \
         --progress --title="MD5sum" --text="Calculating MD5 \
         for:\n${file##*/}" --pulsate --auto-close

  # This block exits the operation if the user clicks Cancel.
  if [ "${PIPESTATUS[2]}" -ne "0" ]; then
    rm /tmp/sum
    exit 0
  fi

  # Calculation is finished, so display the result.
  sum=$(cat /tmp/sum)
  zenity --info --title="MD5sum" --text="MD5sum : $sum\nFile : \
        ${file##*/}"
  rm /tmp/sum
done

exit 0

Save the file in your home directory as with the name cajamd5.

Preparing the Script for the Menu

This is pretty simple, actually. All we need to do is make the script executable, then copy it into a directory Caja uses for scripts. To do this, Click the Menu, then Terminal.
In the terminal, type in the following (just what's in bold):

you@computer ~ $ chmod +x cajamd5
you@computer ~ $ mv cajamd5 ~/.config/caja/scripts
you@computer ~ $ exit

That's it. You can now calculate an MD5 checksum on any file from within the graphical Caja file manager.

Below is a quick step-by-step of checking an MD5 sum. You'll want to click each image to get a better view.

When you right-click on the file, the context menu appears, and you now have a Scripts option at the top, with our new script in it. Just left-click the cajamd5 item.





This automatically starts the md5 sum calculation against the file you selected.




After a short period of time, a new window is opened displaying the MD5 sum for the file, and the file name. If you compare the value in the cajamd5 box with the MD5 sum under the second item in the list, you'll see they are the same.



All done. We can now ensure the files we download are what the publisher intended, quickly and easily.

One small note: Caja will allow you to select multiple files, and calculate MD5 sums on all of them with one click of the cajamd5 script. This is done one file at a time. Normally it's not a big deal, but if the files are large (such as multiple .ISO images), this can take a while.

Credits:
  • Ethan J. Eldridge provides a basic script on his blog to execute an action in Caja.
  • Belham2 posted the code for calculating the MD5 sum, and displaying in a window on the Solus Project forums.

Thursday, March 2, 2017

Secure Tomcat Servlets Behind Apache httpd

OVERVIEW


We take the tomcat/httpd configuration we created in THIS POST, and we secure those applications using HTTPS. We will be using a self-signed certificate in this example, but the process is essentially the same for trusted certs, providing they come as .key, and .cert files. Again, I assume you are familiar with the command line in Linux, and all work will be performed as root.

Below is a simple diagram that illustrates our application architecture.

A secured application
We'll be working strictly between the two blocks on the far right of the diagram. We will secure the connection between the client browser and the Apache httpd server. Virtually everything I've read to this point indicates that the connection from the httpd server on to the actual applications do not require the same level of security. Consider that Tomcat may reside on the same physical host as the httpd server, or that the httpd server is a perimeter device, thus connections behind it are internal, and thus considered secure (at least, reasonably).

SECURE THE HTTPD TRAFFIC


This is a short, 5-step process. We will be securing traffic using openssl/mod_ssl.

Install mod_ssl


If you followed the process of placing tomcat behind httpd in my previous post, you know that we're using CentOS 6, and we installed the version of httpd server compiled for RHEL/CentOS that is available via the default yum repository. We'll be using the same for mod_ssl, which makes installation as easy as:

# yum install mod_ssl

Create a Directory to House the Certificate and Key Files


# mkdir /etc/httpd/ssl

Create the Self-Signed Certificate


# openssl req -x509 -nodes -days 365 -newkey rsa:2048 -keyout /etc/httpd/ssl/apache.key -out /etc/httpd/ssl/apache.crt

You will be prompted for a number of pieces of information. Provide answers to each, paying close attention to the Common Name field. This will be the DNS name or IP address of your httpd server. Once created, the certificate and key files are valid for one year, and will be dropped into our custom directory created above.

Configure the httpd Server to Use the Certificate


Edit the /etc/httpd/conf/ssl.conf file:

# vim /etc/httpd/conf/ssl.conf

Locate the <VirtualHost _default_:443> section. We will be working inside that block. Uncomment the DocumentRoot and ServerName lines, and replace the example.com with your server name.
Next, locate the following three keys, and set to the values indicated below:

SSLEngine on
SSLCertificateFile /etc/httpd/ssl/apache.crt
SSLCertificateKeyFile /etc/httpd/ssl/apache.key


Save the file, and exit back to the command prompt.
Test the Apache httpd config, and Restart httpd:

# apachectl -t (should come back with "Syntax OK")
# service restart httpd


Now, if you browse to the document root of the server, you should see the Apache httpd test page that comes with CentOS, and you should see in the address bar that you are using HTTPS (though there will likely be a warning symbol of some sort, as the certificate is self-signed).

Enable Secure Access to Tomcat Servlets


Try to browse to the tomcat examples directory, and you will notice a "Not Found" error. This is because while we configured httpd for HTTPS, we're not passing that back to tomcat yet. As it turns out, this is very simple. Edit the ssl.conf file, and go back into the <VirtualHost _default_:443> section.

# vim /etc/httpd/conf/ssl.conf

Add the following two lines:

JkMountCopy On
JkMount /* ajp13


Save and close the file.

Now when you browse to the examples directory using https (https://<server-name-or-ip>/examples/) you should see the examples directory. Clicking on the Servlet examples link will show the page of example servlets provided by tomcat.
Accessing Tomcat servlets over https

Run Tomcat Behind Apache httpd

OVERVIEW


I ran into an issue recently where I needed to set up Apache Tomcat behind the Apache httpd web server. The book I was referencing was a bit dated, and sources on the web always seemed to leave out a critical piece of information. I'm documenting here, in the event someone might find it useful. Note that this procedure is less about installation (though I touch on it briefly) and more about the actual connection process between the two components.

I assume you are familiar with working around the command line in Linux. All commands here are also performed as root.

Why use Apache httpd as a front-end to Tomcat?



  • Clustering/Load Balancing: mod_jk (the module we will use) provides a nice load-balancing feature set allowing you to set up multiple tomcat servers behind the httpd server.
  • Security: You can implement security through httpd, which has a more mature feature set, and is well understood by the community. In addition, you have the flexibility to move security settings between tomcat and httpd (where such settings overlap).
  • Flexibility: We can leverage the many add-on modules and extensions of httpd.
  • Socket Error Handling: Since httpd runs natively on Linux, it has the ability to interact directly with socket errors.

What is the environment we're working in?


We'll be configuring the following:
  • Architecture: x86_64
  • OS: CentOS Linux 6.8 (This will work equally well on Red Hat Enterprise Linux 6)
  • Web Server: Apache httpd 2.2 (using the server built for CentOS 6 from the default yum repo)
  • Tomcat: Apache Tomcat 8.5.11, pulled from the Apache website (apache-tomcat-8.5.11.tar.gz)
  • Java: Oracle Java 8 (1.8.0_121) downloaded from Oracle.com (jdk-8u121-linux-x64.tar.gz)

INSTALLATION

Java


Install Java, and set the JAVA_HOME environment variable in root's .bash_profile:

JAVA_HOME=/usr/java/jdk1.8.0_121
PATH=$PATH:$JAVA_HOME:$HOME/bin
export PATH

As you can see, I simply uncompressed the tarball into /usr/java (thus bypassing fully the 'alternatives' functionality. If you are not aware of alternatives in RHEL/CentOS - read up on it; it's pretty interesting from a flexibility perspective). There are plenty of tutorials on the web for Java - seek one out if you have issues.

Apache httpd


We're using the stock httpd that comes with RHEL/CentOS, so it's really as simple as:

# yum install httpd

Tomcat


Drop the Tomcat tarball into /usr/share, then extract it (from within the same directory):

# tar -zxvf apache-tomcat-8.5.11.tar.gz
# rm apache-tomcat-8.5.11.tar.gz

This will create a directory /usr/hare/apache-tomcat-8.5.11 containing all of the files required for tomcat. Once done, we remove the tarball. It is no longer needed.

We also need a start/stop script for tomcat. Every good service should have a start/stop script for management. 

# cd /etc/init.d/
# vim tomcat

Paste in the following:

#!/bin/bash
# description: Tomcat Start Stop Restart
# processname: tomcat
# chkconfig: 234 20 80

if [ "$JAVA_HOME" == "" ]; then
    JAVA_HOME=/usr/java/jdk1.8.0_121
    export JAVA_HOME
    PATH=$JAVA_HOME/bin:$PATH
    export PATH
fi

CATALINA_HOME=/usr/share/apache-tomcat-8.5.11

case $1 in
    start)
      sh $CATALINA_HOME/bin/startup.sh
      ;;
    stop)
      sh $CATALINA_HOME/bin/shutdown.sh
      ;;
    restart)
      sh $CATALINA_HOME/bin/shutdown.sh
      sleep 1
      sh $CATALINA_HOME/bin/startup.sh
      ;;
esac

exit 0

and save the file. Next we make the file executable, add it to chkconfig and test.

# chmod +x tomcat 
# chkconfig tomcat on
# chkconfig --add tomcat
# chkconfig --level 234 tomcat on
# chkconfig --list tomcat
# service tomcat start

At this point you should be able to browse to the host on port 8080, and see the tomcat page:

We have validated that Tomcat is up and running.


If there are any issues, search for "Exception" in /usr/share/apache-tomcat-8.5.11/logs/catalina.out.

CONNECTING HTTPD AND TOMCAT


First, we need to find the mod_jk.so module. For the newcomer, this can be a little challenging, since many of the links to the binaries provided on the tomcat site link only to Windows versions, and the name of the binary listed is not mod_jk.so (as one might expect). I'm using the binary version, and pulled my version from HERE. Given the versions of middleware components specified above, you'll want mod_jk-1.2.31-httpd-2.2.x.so.

The following will download the file, name it appropriately, and drop it in the correction location:

# wget https://archive.apache.org/dist/tomcat/tomcat-connectors/jk/binaries/linux/jk-1.2.31/x86_64/mod_jk-1.2.31-httpd-2.2.x.so
# mv mod_jk-1.2.31-httpd-2.2.x.so mod_jk.so
# cp mod_jk.so /usr/lib64/httpd/modules/
# chmod 755 /usr/lib64/httpd/modules/mod_jk.so

Next, we need a configuration file for httpd to tell it about the module, and it's settings. Note that this file should go into the conf.d directory for all httpd add-on configuration files (default: /etc/httpd/conf.d/)

vim /etc/httpd/conf.d/tomcat.conf

Paste in the following:

# Load the module
LoadModule jk_module modules/mod_jk.so

# Where to find workers.properties
# Update this path to match your conf directory location (put workers.properties next to httpd.conf)
JkWorkersFile /etc/httpd/conf/workers.properties

# Where to put jk shared memory
# Update this path to match your local state directory or logs directory
JkShmFile     /var/log/httpd/mod_jk.shm

# Where to put jk logs
# Update this path to match your logs directory location (put mod_jk.log next to access_log)
JkLogFile     /var/log/httpd/mod_jk.log

# Set the jk log level [debug/error/info]
JkLogLevel    info

# Select the timestamp log format
JkLogStampFormat "[%a %b %d %H:%M:%S %Y] "

# Send everything for context /examples to worker named worker1 (ajp13)
JkMount  /examples/* worker1

Save the file and exit vim.

Finally, we need to configure Tomcat with the settings for the worker that we referenced in the tomcat.conf file. This file should be located in the same directory as the main httpd server configuration file, httpd.conf.

vim /etc/httpd/conf/workers.properties

Paste in the following:

# Define 1 real worker using ajp13
worker.list=worker1

# Set properties for worker1 (ajp13)
worker.worker1.type=ajp13
worker.worker1.host=localhost
worker.worker1.port=8009

Save the file, and exit vim.

We'll do a quick config test, then restart both services to pick up the changes, and perform a full test:

# apachectl -t
# service httpd restart
# service tomcat restart

Browse to http://<server-name-or-ip>/examples/

You should see the following:

The main Tomcat examples page, brought to you by Tomcat


So how do we know the examples page is being handled through Apache httpd? Note in the URL, the lack of a port # (8080 was the port we configured tomcat to run on earlier, and was required). When we specified "examples/" as our desired URL, and left off the port 8080, the request went to httpd on port 80, httpd used mod_jk and it's associated configuration files to discover that tomcat is serving up "examples", and then forwarded the request along. Tomcat responded with the page, which was then returned to the browser by httpd.

---
In the NEXT POST, we will secure access to the Tomcat servlets using HTTPS.

REFERENCES