Re: Officially released Apache tomcat version with CVE-2014-0230

2015-05-05 Thread Raghavendra Nilekani
Hi. Thanks for the information. This is useful. I feel I should take the latest available version and upgrade. Once the new version (6.0.44) with fix is available, I can upgrade once again. Can I know the tentative data (month) during which we get the official release of the version 6.0.44 ? T

[SECURITY] CVE-2014-0230: Apache Tomcat DoS

2015-05-05 Thread Mark Thomas
-BEGIN PGP SIGNED MESSAGE- Hash: SHA256 CVE-2014-0230 Denial of Service Severity: Low Vendor: The Apache Software Foundation Versions Affected: - - Apache Tomcat 8.0.0-RC1 to 8.0.8 - - Apache Tomcat 7.0.0 to 7.0.54 - - Apache Tomcat 6.0.0 to 6.0.43 Description: When a response for a re

Re: typesafe-config reference.conf file not found in a .jar in WEB_INF/lib

2015-05-05 Thread Christopher Schultz
-BEGIN PGP SIGNED MESSAGE- Hash: SHA256 David, On 5/5/15 4:30 PM, Walend, David wrote: > typesafe config's loader isn't picking up my subproject's > reference.conf from within a .jar file inside a .war file's > WEB_INF/lib/ . > > typesafe config finds the .jar file outside of tomcat. It

typesafe-config reference.conf file not found in a .jar in WEB_INF/lib

2015-05-05 Thread Walend, David
typesafe config's loader isn't picking up my subproject's reference.conf from within a .jar file inside a .war file's WEB_INF/lib/ . typesafe config finds the .jar file outside of tomcat. It works fine from the .war file's WEB_INF/classes (my hacky fix). Typesafe config is finding the reference.c

Re: tomcat-embed-jasper vs tomcat-jasper

2015-05-05 Thread Thusitha Thilina Dayaratne
Hi, > Hi > >> >> Could someone tell me what is the difference between tomcat-embed-jasper >> and tomcat-jasper? >> I have checked the both jars. tomcat-embed-jasper contains >> javax.servlet.jsp package. Is that the only difference between those 2? >>> Yes. > Thanks for quick reply. > 1. If so why

Re: tomcat-embed-jasper vs tomcat-jasper

2015-05-05 Thread Mark Thomas
On 05/05/2015 16:55, Thusitha Thilina Dayaratne wrote: > Hi > >> >> Could someone tell me what is the difference between tomcat-embed-jasper >> and tomcat-jasper? >> I have checked the both jars. tomcat-embed-jasper contains >> javax.servlet.jsp package. Is that the only difference between those 2

Re: tomcat-embed-jasper vs tomcat-jasper

2015-05-05 Thread Thusitha Thilina Dayaratne
Hi > > Could someone tell me what is the difference between tomcat-embed-jasper > and tomcat-jasper? > I have checked the both jars. tomcat-embed-jasper contains > javax.servlet.jsp package. Is that the only difference between those 2? >>Yes. Thanks for quick reply. 1. If so why there are 2 jars?

Re: tomcat-embed-jasper vs tomcat-jasper

2015-05-05 Thread Mark Thomas
On 05/05/2015 16:40, Thusitha Thilina Dayaratne wrote: > Hi, > > Could someone tell me what is the difference between tomcat-embed-jasper > and tomcat-jasper? > I have checked the both jars. tomcat-embed-jasper contains > javax.servlet.jsp package. Is that the only difference between those 2? Yes

tomcat-embed-jasper vs tomcat-jasper

2015-05-05 Thread Thusitha Thilina Dayaratne
Hi, Could someone tell me what is the difference between tomcat-embed-jasper and tomcat-jasper? I have checked the both jars. tomcat-embed-jasper contains javax.servlet.jsp package. Is that the only difference between those 2? Thanks --

Re: Does the securePort for Cluster/Channel/Receiver work yet?

2015-05-05 Thread pascal
Hi Chris 2015-05-04 22:13 GMT+02:00 Christopher Schultz : > Pascal, > > On 5/4/15 10:56 AM, pascal wrote: > > This was all done with tomcat-7.0.27 (sorry for being behind) > >> > > > > I just tried with 8.0.21 with the same result. I would even > > appreciate a "don't bother trying" response from

Re: Officially released Apache tomcat version with CVE-2014-0230

2015-05-05 Thread Mark Thomas
On 05/05/2015 11:27, Raghavendra Nilekani wrote: > Hi > > I have an application where I currently use 6.0.20 version of Apache tomcat > bundle from spring source. Now because of security vulnerabilities I have > to migrate to newer latest version of Apache tomcat. I saw the latest > version on Apa

RE: High cpu on Tomcat 8

2015-05-05 Thread Caldarale, Charles R
> From: Greg Huber [mailto:gregh3...@gmail.com] > Subject: Re: High cpu on Tomcat 8 > > Have you set a pollerThreadCount? > I have had a look and I cannot find where this is set. Is there any > documentation on this? The pollerThreadCount applies only to the HTTP version of the , not the AJP

Re: Officially released Apache tomcat version with CVE-2014-0230

2015-05-05 Thread André Warnier
Raghavendra Nilekani wrote: Hi I have an application where I currently use 6.0.20 version of Apache tomcat bundle from spring source. Now because of security vulnerabilities I have to migrate to newer latest version of Apache tomcat. I saw the latest version on Apace tomcat site is Apache Tomcat

Re: Issue while Configuring SSL in tomcat6

2015-05-05 Thread Daniel Mikusa
On Mon, May 4, 2015 at 8:35 PM, jairaj kamal wrote: First, please stop top posting. Reply inline or at the bottom. It's the convention followed on this list. Hello, when I checked with below command I find my keystore created type as > "JKS" and we are using tool "Keytool". Initially we receiv

Officially released Apache tomcat version with CVE-2014-0230

2015-05-05 Thread Raghavendra Nilekani
Hi I have an application where I currently use 6.0.20 version of Apache tomcat bundle from spring source. Now because of security vulnerabilities I have to migrate to newer latest version of Apache tomcat. I saw the latest version on Apace tomcat site is Apache Tomcat 6.0.43 where the highest CVE

Re: High cpu on Tomcat 8

2015-05-05 Thread Greg Huber
>Have you set a pollerThreadCount? If so, what is it? If not, you might >want to consider setting it to "2", but probably not any higher, and >see if it improves things. I have had a look and I cannot find where this is set. Is there any documentation on this? >When the CPU usage goes high, doe