Apache Tomcat - Embedded Servlet Container Configuration

Note that by default, the embedded container attempts to enable the HTTP2 protocol.

1
2
3
4
5
<dependency>
    <groupId>org.apereo.cas</groupId>
    <artifactId>cas-server-webapp-tomcat</artifactId>
    <version>${cas.version}</version>
</dependency>
1
implementation "org.apereo.cas:cas-server-webapp-tomcat:${project.'cas.version'}"
1
2
3
4
5
6
7
8
9
dependencyManagement {
    imports {
        mavenBom "org.apereo.cas:cas-server-support-bom:${project.'cas.version'}"
    }
}

dependencies {
    implementation "org.apereo.cas:cas-server-webapp-tomcat"
}
1
2
3
4
5
6
7
8
9
10
11
12
13
dependencies {
    /*
        The following platform references are included automatically and are listed for reference only.

        implementation enforcedPlatform("org.apereo.cas:cas-server-support-bom:${project.'cas.version'}")
        implementation platform(org.springframework.boot.gradle.plugin.SpringBootPlugin.BOM_COORDINATES)
        
        Including this module in the CAS WAR overlay is optional and unnecessary. This module is automatically included
        and bundled with the CAS server distribution and there are alternative options baked in to allow one to replace
        this module with another. The entry below is listed for reference only.
    */
    implementation "org.apereo.cas:cas-server-webapp-tomcat"
}

Configuration

The following settings and properties are available from the CAS configuration catalog:

server.tomcat.accept-countMaximum queue length for incoming connection requests when all possible request processing threads are in use.
100
Third party

Maximum queue length for incoming connection requests when all possible request processing threads are in use.

Type
Integer
Default
100
Defined by
TomcatServerProperties
server.tomcat.accesslog.bufferedWhether to buffer output such that it is flushed only periodically.
true
Third party

Whether to buffer output such that it is flushed only periodically.

Type
Boolean
Default
true
Defined by
TomcatServerProperties$Accesslog
server.tomcat.accesslog.check-existsWhether to check for log file existence so it can be recreated if an external process has renamed it.
false
Third party

Whether to check for log file existence so it can be recreated if an external process has renamed it.

Type
Boolean
Default
false
Defined by
TomcatServerProperties$Accesslog
server.tomcat.accesslog.condition-ifWhether logging of the request will only be enabled if "ServletRequest.getAttribute(conditionIf)" does not yield null.
no default
Third party

Whether logging of the request will only be enabled if "ServletRequest.getAttribute(conditionIf)" does not yield null.

Type
String
Default
none
Defined by
TomcatServerProperties$Accesslog
server.tomcat.accesslog.condition-unlessWhether logging of the request will only be enabled if "ServletRequest.getAttribute(conditionUnless)" yield null.
no default
Third party

Whether logging of the request will only be enabled if "ServletRequest.getAttribute(conditionUnless)" yield null.

Type
String
Default
none
Defined by
TomcatServerProperties$Accesslog
server.tomcat.accesslog.directoryDirectory in which log files are created.
logs
Third party

Directory in which log files are created. Can be absolute or relative to the Tomcat base dir.

Type
String
Default
logs
Defined by
TomcatServerProperties$Accesslog
server.tomcat.accesslog.enabledEnable access log.
false
Third party

Enable access log.

Type
Boolean
Default
false
Defined by
TomcatServerProperties$Accesslog
server.tomcat.accesslog.encodingCharacter set used by the log file.
no default
Third party

Character set used by the log file. Default to the system default character set.

Type
String
Default
none
Defined by
TomcatServerProperties$Accesslog
server.tomcat.accesslog.file-date-formatDate format to place in the log file name.
.yyyy-MM-dd
Third party

Date format to place in the log file name.

Type
String
Default
.yyyy-MM-dd
Defined by
TomcatServerProperties$Accesslog
server.tomcat.accesslog.ipv6-canonicalWhether to use IPv6 canonical representation format as defined by RFC 5952.
false
Third party

Whether to use IPv6 canonical representation format as defined by RFC 5952.

Type
Boolean
Default
false
Defined by
TomcatServerProperties$Accesslog
server.tomcat.accesslog.localeLocale used to format timestamps in log entries and in log file name suffix.
no default
Third party

Locale used to format timestamps in log entries and in log file name suffix. Default to the default locale of the Java process.

Type
String
Default
none
Defined by
TomcatServerProperties$Accesslog
server.tomcat.accesslog.max-daysNumber of days to retain the access log files before they are removed.
-1
Third party

Number of days to retain the access log files before they are removed.

Type
Integer
Default
-1
Defined by
TomcatServerProperties$Accesslog
server.tomcat.accesslog.patternFormat pattern for access logs.
common
Third party

Format pattern for access logs.

Type
String
Default
common
Defined by
TomcatServerProperties$Accesslog
server.tomcat.accesslog.prefixLog file name prefix.
access_log
Third party

Log file name prefix.

Type
String
Default
access_log
Defined by
TomcatServerProperties$Accesslog
server.tomcat.accesslog.rename-on-rotateWhether to defer inclusion of the date stamp in the file name until rotate time.
false
Third party

Whether to defer inclusion of the date stamp in the file name until rotate time.

Type
Boolean
Default
false
Defined by
TomcatServerProperties$Accesslog
server.tomcat.accesslog.request-attributes-enabledSet request attributes for the IP address, Hostname, protocol, and port used for the request.
false
Third party

Set request attributes for the IP address, Hostname, protocol, and port used for the request.

Type
Boolean
Default
false
Defined by
TomcatServerProperties$Accesslog
server.tomcat.accesslog.rotateWhether to enable access log rotation.
true
Third party

Whether to enable access log rotation.

Type
Boolean
Default
true
Defined by
TomcatServerProperties$Accesslog
server.tomcat.accesslog.suffixLog file name suffix.
.log
Third party

Log file name suffix.

Type
String
Default
.log
Defined by
TomcatServerProperties$Accesslog
server.tomcat.additional-tld-skip-patterns
no default
Third partyDeprecated
Type
List<String>
Default
none
Defined by
TomcatServerProperties
Deprecation
WARNING, replaced by server.tomcat.servlet.additional-tld-skip-patterns
server.tomcat.background-processor-delayDelay between the invocation of backgroundProcess methods.
10s
Third party

Delay between the invocation of backgroundProcess methods. If a duration suffix is not specified, seconds will be used.

Type
Duration
Default
10s
Defined by
TomcatServerProperties
server.tomcat.basedirTomcat base directory.
no default
Third party

Tomcat base directory. If not specified, a temporary directory is used.

Type
File
Default
none
Defined by
TomcatServerProperties
server.tomcat.connection-timeoutAmount of time the connector will wait, after accepting a connection, for the request URI line to be presented.
no default
Third party

Amount of time the connector will wait, after accepting a connection, for the request URI line to be presented.

Type
Duration
Default
none
Defined by
TomcatServerProperties
server.tomcat.keep-alive-timeoutTime to wait for another HTTP request before the connection is closed.
no default
Third party

Time to wait for another HTTP request before the connection is closed. When not set the connectionTimeout is used. When set to -1 there will be no timeout.

Type
Duration
Default
none
Defined by
TomcatServerProperties
server.tomcat.max-connectionsMaximum number of connections that the server accepts and processes at any given time.
8192
Third party

Maximum number of connections that the server accepts and processes at any given time. Once the limit has been reached, the operating system may still accept connections based on the "acceptCount" property.

Type
Integer
Default
8192
Defined by
TomcatServerProperties
server.tomcat.max-http-form-post-sizeMaximum size of the form content in any HTTP post request.
2MB
Third party

Maximum size of the form content in any HTTP post request.

Type
DataSize
Default
2MB
Defined by
TomcatServerProperties
server.tomcat.max-http-post-size
no default
Third partyDeprecated
Type
DataSize
Default
none
Deprecation
ERROR, replaced by server.tomcat.max-http-form-post-size
server.tomcat.max-http-response-header-sizeMaximum size of the HTTP response header.
8KB
Third party

Maximum size of the HTTP response header.

Type
DataSize
Default
8KB
Defined by
TomcatServerProperties
server.tomcat.max-keep-alive-requestsMaximum number of HTTP requests that can be pipelined before the connection is closed.
100
Third party

Maximum number of HTTP requests that can be pipelined before the connection is closed. When set to 0 or 1, keep-alive and pipelining are disabled. When set to -1, an unlimited number of pipelined or keep-alive requests are allowed.

Type
Integer
Default
100
Defined by
TomcatServerProperties
server.tomcat.max-parameter-countMaximum number of parameters (GET plus POST) that will be automatically parsed by the container.
1000
Third party

Maximum number of parameters (GET plus POST) that will be automatically parsed by the container. A value of less than 0 means no limit.

Type
Integer
Default
1000
Defined by
TomcatServerProperties
server.tomcat.max-part-countMaximum total number of parts permitted in a multipart/form-data request.
50
Third party

Maximum total number of parts permitted in a multipart/form-data request. Requests that exceed this limit will be rejected. A value of less than 0 means no limit.

Type
Integer
Default
50
Defined by
TomcatServerProperties
server.tomcat.max-part-header-sizeMaximum per-part header size permitted in a multipart/form-data request.
512B
Third party

Maximum per-part header size permitted in a multipart/form-data request. Requests that exceed this limit will be rejected. A value of less than 0 means no limit.

Type
DataSize
Default
512B
Defined by
TomcatServerProperties
server.tomcat.max-swallow-sizeMaximum amount of request body to swallow.
2MB
Third party

Maximum amount of request body to swallow.

Type
DataSize
Default
2MB
Defined by
TomcatServerProperties
server.tomcat.mbeanregistry.enabledWhether Tomcat's MBean Registry should be enabled.
false
Third party

Whether Tomcat's MBean Registry should be enabled.

Type
Boolean
Default
false
Defined by
TomcatServerProperties$Mbeanregistry
server.tomcat.processor-cacheMaximum number of idle processors that will be retained in the cache and reused with a subsequent request.
200
Third party

Maximum number of idle processors that will be retained in the cache and reused with a subsequent request. When set to -1 the cache will be unlimited with a theoretical maximum size equal to the maximum number of connections.

Type
Integer
Default
200
Defined by
TomcatServerProperties
server.tomcat.redirect-context-root
no default
Third partyDeprecated
Type
Boolean
Default
none
Defined by
TomcatServerProperties
Deprecation
WARNING, replaced by server.tomcat.servlet.redirect-context-root
server.tomcat.reject-illegal-header
no default
Third partyDeprecated
Default
none
Deprecation
ERROR, no replacement
server.tomcat.relaxed-path-charsList of additional unencoded characters that should be allowed in URI paths.
no default
Third party

List of additional unencoded characters that should be allowed in URI paths. Only "< > [ \ ] ^ ` { | }" are allowed.

Type
List<Character>
Default
none
Defined by
TomcatServerProperties
server.tomcat.relaxed-query-charsList of additional unencoded characters that should be allowed in URI query strings.
no default
Third party

List of additional unencoded characters that should be allowed in URI query strings. Only "< > [ \ ] ^ ` { | }" are allowed.

Type
List<Character>
Default
none
Defined by
TomcatServerProperties
server.tomcat.remoteip.host-headerName of the HTTP header from which the remote host is extracted.
X-Forwarded-Host
Third party

Name of the HTTP header from which the remote host is extracted.

Type
String
Default
X-Forwarded-Host
Defined by
TomcatServerProperties$Remoteip
server.tomcat.remoteip.internal-proxiesInternal proxies that are to be trusted.
10.0.0.0/8, 192.168.0.0/16, 169.254.0.0/16, 100.64.0.0/10, fc00::/7, 172.16.0.0/12, ::1/128, 127.0.0.0/8, fe80::/10
Third party

Internal proxies that are to be trusted. Can be set as a comma separate list of CIDR or as a regular expression.

Type
String
Default
10.0.0.0/8, 192.168.0.0/16, 169.254.0.0/16, 100.64.0.0/10, fc00::/7, 172.16.0.0/12, ::1/128, 127.0.0.0/8, fe80::/10
Defined by
TomcatServerProperties$Remoteip
server.tomcat.remoteip.port-headerName of the HTTP header used to override the original port value.
X-Forwarded-Port
Third party

Name of the HTTP header used to override the original port value.

Type
String
Default
X-Forwarded-Port
Defined by
TomcatServerProperties$Remoteip
server.tomcat.remoteip.protocol-headerHeader that holds the incoming protocol, usually named "X-Forwarded-Proto".
no default
Third party

Header that holds the incoming protocol, usually named "X-Forwarded-Proto".

Type
String
Default
none
Defined by
TomcatServerProperties$Remoteip
server.tomcat.remoteip.protocol-header-https-valueValue of the protocol header indicating whether the incoming request uses SSL.
https
Third party

Value of the protocol header indicating whether the incoming request uses SSL.

Type
String
Default
https
Defined by
TomcatServerProperties$Remoteip
server.tomcat.remoteip.remote-ip-headerName of the HTTP header from which the remote IP is extracted.
no default
Third party

Name of the HTTP header from which the remote IP is extracted. For instance, 'X-FORWARDED-FOR'.

Type
String
Default
none
Defined by
TomcatServerProperties$Remoteip
server.tomcat.remoteip.trusted-proxiesRegular expression defining proxies that are trusted when they appear in the "remote-ip-header" header.
no default
Third party

Regular expression defining proxies that are trusted when they appear in the "remote-ip-header" header.

Type
String
Default
none
Defined by
TomcatServerProperties$Remoteip
server.tomcat.resource.allow-cachingWhether static resource caching is permitted for this web application.
true
Third party

Whether static resource caching is permitted for this web application.

Type
Boolean
Default
true
Defined by
TomcatServerProperties$Resource
server.tomcat.resource.cache-max-sizeMaximum size of the static resource cache.
10MB
Third party

Maximum size of the static resource cache.

Type
DataSize
Default
10MB
Defined by
TomcatServerProperties$Resource
server.tomcat.resource.cache-ttlTime-to-live of the static resource cache.
5s
Third party

Time-to-live of the static resource cache.

Type
Duration
Default
5s
Defined by
TomcatServerProperties$Resource
server.tomcat.servlet.additional-tld-skip-patternsList of additional patterns that match jars to ignore for TLD scanning.
no default
Third party

List of additional patterns that match jars to ignore for TLD scanning. The special '?' and '*' characters can be used in the pattern to match one and only one character and zero or more characters respectively.

Type
List<String>
Default
none
Defined by
TomcatServerProperties$Servlet
server.tomcat.servlet.redirect-context-rootWhether requests to the context root should be redirected by appending a / to the path.
true
Third party

Whether requests to the context root should be redirected by appending a / to the path. When using SSL terminated at a proxy, this property should be set to false.

Type
Boolean
Default
true
Defined by
TomcatServerProperties$Servlet
server.tomcat.servlet.use-relative-redirectsWhether HTTP 1.1 and later location headers generated by a call to sendRedirect will use relative or absolute redirects.
true
Third party

Whether HTTP 1.1 and later location headers generated by a call to sendRedirect will use relative or absolute redirects.

Type
Boolean
Default
true
Defined by
TomcatServerProperties$Servlet
server.tomcat.threads.maxMaximum amount of worker threads.
200
Third party

Maximum amount of worker threads. Doesn't have an effect if virtual threads are enabled.

Type
Integer
Default
200
Defined by
TomcatServerProperties$Threads
server.tomcat.threads.max-queue-capacityMaximum capacity of the thread pool's backing queue.
2147483647
Third party

Maximum capacity of the thread pool's backing queue. This setting only has an effect if the value is greater than 0.

Type
Integer
Default
2147483647
Defined by
TomcatServerProperties$Threads
server.tomcat.threads.min-spareMinimum amount of worker threads.
10
Third party

Minimum amount of worker threads. Doesn't have an effect if virtual threads are enabled.

Type
Integer
Default
10
Defined by
TomcatServerProperties$Threads
server.tomcat.uri-encodingCharacter encoding to use to decode the URI.
UTF-8
Third party

Character encoding to use to decode the URI.

Type
Charset
Default
UTF-8
Defined by
TomcatServerProperties
server.tomcat.use-aprWhether to use APR.
never
Third party

Whether to use APR.

Type
TomcatServerProperties.UseApr
Default
never
Defined by
TomcatServerProperties
server.tomcat.use-relative-redirects
no default
Third partyDeprecated
Type
Boolean
Default
none
Defined by
TomcatServerProperties
Deprecation
WARNING, replaced by server.tomcat.servlet.use-relative-redirects

Required settings may be needed to activate or affect the feature; review them even when they have a default. Optional settings only need to be set to change a default or to turn on the behavior they control. Third party settings belong to libraries such as Spring Boot that CAS builds on; their own documentation may have more detail.

Notes on configuration

Configuration Metadata

The collection of configuration properties listed in this section are automatically generated from the CAS source and components that contain the actual field definitions, types, descriptions, modules, etc. This metadata may not always be 100% accurate, or could be lacking details and sufficient explanations.

Be Selective

This section is meant as a guide only. Do NOT copy/paste the entire collection of settings into your CAS configuration; rather pick only the properties that you need. Do NOT enable settings unless you are certain of their purpose and do NOT copy settings into your configuration only to keep them as reference. All these ideas lead to upgrade headaches, maintenance nightmares and premature aging.

YAGNI

Note that for nearly ALL use cases, declaring and configuring properties listed here is sufficient. You should NOT have to explicitly massage a CAS XML/Java/etc configuration file to design an authentication handler, create attribute release policies, etc. CAS at runtime will auto-configure all required changes for you. If you are unsure about the meaning of a given CAS setting, do NOT turn it on without hesitation. Review the codebase or better yet, ask questions to clarify the intended behavior.

Naming Convention

Property names can be specified in very relaxed terms. For instance cas.someProperty, cas.some-property, cas.some_property are all valid names. While all forms are accepted by CAS, there are certain components (in CAS and other frameworks used) whose activation at runtime is conditional on a property value, where this property is required to have been specified in CAS configuration using kebab case. This is both true for properties that are owned by CAS as well as those that might be presented to the system via an external library or framework such as Spring Boot, etc.

:information_source: Note

When possible, properties should be stored in lower-case kebab format, such as cas.property-name=value. The only possible exception to this rule is when naming actuator endpoints; The name of the actuator endpoints (i.e. ssoSessions) MUST remain in camelCase mode.

Settings and properties that are controlled by the CAS platform directly always begin with the prefix cas. All other settings are controlled and provided to CAS via other underlying frameworks and may have their own schemas and syntax. BE CAREFUL with the distinction. Unrecognized properties are rejected by CAS and/or frameworks upon which CAS depends. This means if you somehow misspell a property definition or fail to adhere to the dot-notation syntax and such, your setting is entirely refused by CAS and likely the feature it controls will never be activated in the way you intend.

Validation

Configuration properties are automatically validated on CAS startup to report issues with configuration binding, especially if defined CAS settings cannot be recognized or validated by the configuration schema. Additional validation processes are also handled via Configuration Metadata and property migrations applied automatically on startup by Spring Boot and family.

Indexed Settings

CAS settings able to accept multiple values are typically documented with an index, such as cas.some.setting[0]=value. The index [0] is meant to be incremented by the adopter to allow for distinct multiple configuration blocks.

IPv4 Configuration

In order to force Apache Tomcat to use IPv4, configure the following as a system property for your run command:

1
-Djava.net.preferIPv4Stack=true 

The same sort of configuration needs to be applied to your $CATALINA_OPTS environment variable in case of an external container.