3 Replies Latest reply on Mar 5, 2013 9:38 AM by Jörg Hoh

    BadRequestException: header exceeds 8192


      We use IIS with enabled Kerberos authentication.


      This issue occur when the user is a member of many Active Directory user groups. When a user is a member of a large number of active directory groups the Kerberos authentication token for the user increases in size. The HTTP request that the user sends to the CQ server contains the Kerberos token in the WWW-Authenticate header, and the header size increases as the number of groups goes up.  If the HTTP header or packet size increases past the limits configured in CQ, CQ reject the request and send this "Bad Request" as the response.


      *WARN* [ [1362405622189] <parse>] servletengine Bad request. com.day.j2ee.servletengine.BadRequestException: header exceeds 8192 bytes

              at com.day.j2ee.servletengine.ServletHandlerImpl.checkSpace(ServletHandlerImpl.java:644)

              at com.day.j2ee.servletengine.ServletHandlerImpl.parseRequest(ServletHandlerImpl.java:613)

              at com.day.j2ee.servletengine.ServletHandlerImpl.process(ServletHandlerImpl.java:317)

              at com.day.j2ee.servletengine.HttpListener$Worker.run(HttpListener.java:625)

              at java.lang.Thread.run(Thread.java:662)




      In CQ 5.4 it was possible to change header size in server.xml, but in CQ 5.5 CQSE is a bundle.

      How to increase header size in CQ 5.5 ?