This is an automated email from the ASF dual-hosted git repository. rmaucher pushed a commit to branch 10.1.x in repository https://gitbox.apache.org/repos/asf/tomcat.git
commit 08f3be2c0988a0e8f9936c4682163b855b6fe3b2 Author: opencode <[email protected]> AuthorDate: Wed Oct 7 16:37:44 2026 +0200 Reject non-positive check periods in TLSCertificateReloadListener A check period of zero or less left the next scheduled check in the past, so the certificate renewal check - including keystore re-reads and SSLContext recreation for any SSLHostConfig with a certificate inside the renewal window - ran on every periodic event (every ten seconds by default) instead of once per check period. Warn and retain the current value when a non-positive period is configured. --- .../catalina/security/LocalStrings.properties | 1 + .../security/TLSCertificateReloadListener.java | 9 ++++- .../security/TestTLSCertificateReloadListener.java | 38 ++++++++++++++++++++++ 3 files changed, 47 insertions(+), 1 deletion(-) diff --git a/java/org/apache/catalina/security/LocalStrings.properties b/java/org/apache/catalina/security/LocalStrings.properties index 2a42d116f1..f8cff8f859 100644 --- a/java/org/apache/catalina/security/LocalStrings.properties +++ b/java/org/apache/catalina/security/LocalStrings.properties @@ -29,6 +29,7 @@ SecurityUtil.doAsPrivilege=An exception occurs when running the PrivilegedExcept listener.notServer=This listener must only be nested within Server elements, but is in [{0}]. +tlsCertRenewalListener.invalidCheckPeriod=The check period [{0}] is invalid. It must be greater than zero. The current value will be retained. tlsCertRenewalListener.notRenewed=[{0}], TLS virtual host [{1}] certificate with subject [{2}] that expires on [{3}] is overdue for renewal tlsCertRenewalListener.reloadFailed=[{0}], TLS virtual host [{1}] reload of TLS configuration failed tlsCertRenewalListener.reloadSuccess=[{0}], TLS virtual host [{1}] attempted to reload TLS configuration diff --git a/java/org/apache/catalina/security/TLSCertificateReloadListener.java b/java/org/apache/catalina/security/TLSCertificateReloadListener.java index e48d56276f..dd31132653 100644 --- a/java/org/apache/catalina/security/TLSCertificateReloadListener.java +++ b/java/org/apache/catalina/security/TLSCertificateReloadListener.java @@ -78,11 +78,18 @@ public class TLSCertificateReloadListener implements LifecycleListener { /** - * Set the time, in seconds, between reloading checks. + * Set the time, in seconds, between reloading checks. Values less than or equal to zero are rejected and the + * current value is retained. * * @param checkPeriod The new time, in seconds, between reloading checks */ public void setCheckPeriod(int checkPeriod) { + if (checkPeriod <= 0) { + // A non-positive period would leave the next check time in the + // past, causing the reload check to run on every periodic event. + log.warn(sm.getString("tlsCertRenewalListener.invalidCheckPeriod", checkPeriod)); + return; + } this.checkPeriod = checkPeriod; } diff --git a/test/org/apache/catalina/security/TestTLSCertificateReloadListener.java b/test/org/apache/catalina/security/TestTLSCertificateReloadListener.java new file mode 100644 index 0000000000..3a86e5506d --- /dev/null +++ b/test/org/apache/catalina/security/TestTLSCertificateReloadListener.java @@ -0,0 +1,38 @@ +/* + * Licensed to the Apache Software Foundation (ASF) under one or more + * contributor license agreements. See the NOTICE file distributed with + * this work for additional information regarding copyright ownership. + * The ASF licenses this file to You under the Apache License, Version 2.0 + * (the "License"); you may not use this file except in compliance with + * the License. You may obtain a copy of the License at + * + * http://www.apache.org/licenses/LICENSE-2.0 + * + * Unless required by applicable law or agreed to in writing, software + * distributed under the License is distributed on an "AS IS" BASIS, + * WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. + * See the License for the specific language governing permissions and + * limitations under the License. + */ +package org.apache.catalina.security; + +import org.junit.Assert; +import org.junit.Test; + +public class TestTLSCertificateReloadListener { + + @Test + public void testSetCheckPeriodRejectsNonPositive() { + TLSCertificateReloadListener listener = new TLSCertificateReloadListener(); + int defaultPeriod = listener.getCheckPeriod(); + + listener.setCheckPeriod(0); + Assert.assertEquals(defaultPeriod, listener.getCheckPeriod()); + + listener.setCheckPeriod(-1); + Assert.assertEquals(defaultPeriod, listener.getCheckPeriod()); + + listener.setCheckPeriod(60); + Assert.assertEquals(60, listener.getCheckPeriod()); + } +} --------------------------------------------------------------------- To unsubscribe, e-mail: [email protected] For additional commands, e-mail: [email protected]
