This is an automated email from the ASF dual-hosted git repository.

rmaucher pushed a commit to branch 11.0.x
in repository https://gitbox.apache.org/repos/asf/tomcat.git

commit 306e4de195e94b857982e4e082dee5473ed651d5
Author: opencode <[email protected]>
AuthorDate: Wed Oct 7 16:37:44 2026 +0200

    Reject non-positive check periods in TLSCertificateReloadListener
    
    A check period of zero or less left the next scheduled check in the
    past, so the certificate renewal check - including keystore re-reads
    and SSLContext recreation for any SSLHostConfig with a certificate
    inside the renewal window - ran on every periodic event (every ten
    seconds by default) instead of once per check period. Warn and retain
    the current value when a non-positive period is configured.
---
 .../catalina/security/LocalStrings.properties      |  1 +
 .../security/TLSCertificateReloadListener.java     |  9 ++++-
 .../security/TestTLSCertificateReloadListener.java | 38 ++++++++++++++++++++++
 3 files changed, 47 insertions(+), 1 deletion(-)

diff --git a/java/org/apache/catalina/security/LocalStrings.properties 
b/java/org/apache/catalina/security/LocalStrings.properties
index 676fb41242..4a0c09d2c4 100644
--- a/java/org/apache/catalina/security/LocalStrings.properties
+++ b/java/org/apache/catalina/security/LocalStrings.properties
@@ -27,6 +27,7 @@ SecurityListener.checkUserWarning=Start attempted while 
running as user [{0}]. R
 
 listener.notServer=This listener must only be nested within Server elements, 
but is in [{0}].
 
+tlsCertRenewalListener.invalidCheckPeriod=The check period [{0}] is invalid. 
It must be greater than zero. The current value will be retained.
 tlsCertRenewalListener.notRenewed=[{0}], TLS virtual host [{1}] certificate 
with subject [{2}] that expires on [{3}] is overdue for renewal
 tlsCertRenewalListener.reloadFailed=[{0}], TLS virtual host [{1}] reload of 
TLS configuration failed
 tlsCertRenewalListener.reloadSuccess=[{0}], TLS virtual host [{1}] attempted 
to reload TLS configuration
diff --git 
a/java/org/apache/catalina/security/TLSCertificateReloadListener.java 
b/java/org/apache/catalina/security/TLSCertificateReloadListener.java
index e48d56276f..dd31132653 100644
--- a/java/org/apache/catalina/security/TLSCertificateReloadListener.java
+++ b/java/org/apache/catalina/security/TLSCertificateReloadListener.java
@@ -78,11 +78,18 @@ public class TLSCertificateReloadListener implements 
LifecycleListener {
 
 
     /**
-     * Set the time, in seconds, between reloading checks.
+     * Set the time, in seconds, between reloading checks. Values less than or 
equal to zero are rejected and the
+     * current value is retained.
      *
      * @param checkPeriod The new time, in seconds, between reloading checks
      */
     public void setCheckPeriod(int checkPeriod) {
+        if (checkPeriod <= 0) {
+            // A non-positive period would leave the next check time in the
+            // past, causing the reload check to run on every periodic event.
+            log.warn(sm.getString("tlsCertRenewalListener.invalidCheckPeriod", 
checkPeriod));
+            return;
+        }
         this.checkPeriod = checkPeriod;
     }
 
diff --git 
a/test/org/apache/catalina/security/TestTLSCertificateReloadListener.java 
b/test/org/apache/catalina/security/TestTLSCertificateReloadListener.java
new file mode 100644
index 0000000000..3a86e5506d
--- /dev/null
+++ b/test/org/apache/catalina/security/TestTLSCertificateReloadListener.java
@@ -0,0 +1,38 @@
+/*
+ * Licensed to the Apache Software Foundation (ASF) under one or more
+ * contributor license agreements.  See the NOTICE file distributed with
+ * this work for additional information regarding copyright ownership.
+ * The ASF licenses this file to You under the Apache License, Version 2.0
+ * (the "License"); you may not use this file except in compliance with
+ * the License.  You may obtain a copy of the License at
+ *
+ *      http://www.apache.org/licenses/LICENSE-2.0
+ *
+ * Unless required by applicable law or agreed to in writing, software
+ * distributed under the License is distributed on an "AS IS" BASIS,
+ * WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
+ * See the License for the specific language governing permissions and
+ * limitations under the License.
+ */
+package org.apache.catalina.security;
+
+import org.junit.Assert;
+import org.junit.Test;
+
+public class TestTLSCertificateReloadListener {
+
+    @Test
+    public void testSetCheckPeriodRejectsNonPositive() {
+        TLSCertificateReloadListener listener = new 
TLSCertificateReloadListener();
+        int defaultPeriod = listener.getCheckPeriod();
+
+        listener.setCheckPeriod(0);
+        Assert.assertEquals(defaultPeriod, listener.getCheckPeriod());
+
+        listener.setCheckPeriod(-1);
+        Assert.assertEquals(defaultPeriod, listener.getCheckPeriod());
+
+        listener.setCheckPeriod(60);
+        Assert.assertEquals(60, listener.getCheckPeriod());
+    }
+}


---------------------------------------------------------------------
To unsubscribe, e-mail: [email protected]
For additional commands, e-mail: [email protected]

Reply via email to