Re: tomcat-embed 8.5.9 - runtime changes to SSLHostConfig objects

2017-01-05 Thread Jesse Schulman
On Thu, Jan 5, 2017 at 2:08 PM Mark Thomas wrote: > On 05/01/2017 21:05, Jesse Schulman wrote: > > We are using tomcat-embed 8.5.9, java8 and running on Centos7. Given > > Tomcat's new support for SNI, we wish to support adding/removing/updating > > certificates via our application at runtime wi

basic logging info

2017-01-05 Thread modjklist
Newbie Tomcat user here. I installed Tomcat 8.5.9 on CentOS 7 a few days ago and noticed the default log files for catalina, host-manager, localhost, and manager are created fresh each day with a date in their filename. Doesn't this fill up the directory over time? Wouldn't it be better to have

Re: Tomcat 8.5 - APR 1.2.10 SSL CPU issue ?

2017-01-05 Thread Mark Thomas
On 05/01/2017 22:01, David Oswell wrote: > After some more digging I've been able to further narrow down the problem > somewhat, but still not able to pin point the exact cause; > The issue is not load related, but rather seems to be related to the timing > of the TCP connection being closed. > Dep

Re: tomcat-embed 8.5.9 - runtime changes to SSLHostConfig objects

2017-01-05 Thread Mark Thomas
On 05/01/2017 21:05, Jesse Schulman wrote: > We are using tomcat-embed 8.5.9, java8 and running on Centos7. Given > Tomcat's new support for SNI, we wish to support adding/removing/updating > certificates via our application at runtime without restarting tomcat or > binding/unbinding the port. >

Re: Tomcat 8.5 - APR 1.2.10 SSL CPU issue ?

2017-01-05 Thread David Oswell
After some more digging I've been able to further narrow down the problem somewhat, but still not able to pin point the exact cause; The issue is not load related, but rather seems to be related to the timing of the TCP connection being closed. Depending on the timing the poller and exec appear to

tomcat-embed 8.5.9 - runtime changes to SSLHostConfig objects

2017-01-05 Thread Jesse Schulman
We are using tomcat-embed 8.5.9, java8 and running on Centos7. Given Tomcat's new support for SNI, we wish to support adding/removing/updating certificates via our application at runtime without restarting tomcat or binding/unbinding the port. Our configuration is very simple, we have a single se

Enable Debugging in Tomcat7 catalina.out file

2017-01-05 Thread Kaushal Shriyan
Hi, Is there a way to enable debugging tomcat catalina.out file. I did set it to FINEST in logging.properties file. Tomcat version :- 7.0.59 OS :- CentOS release 6.8 (Final) Java version :- java -version java version "1.7.0_80" Java(TM) SE Runtime Environment (build 1.7.0_80-b15) Java HotSpot(TM)

[SECURITY][UPDATE] CVE-2016-8745 Apache Tomcat Information Disclosure

2017-01-05 Thread Mark Thomas
CVE-2016-8745 Apache Tomcat Information Disclosure Severity: Important Vendor: The Apache Software Foundation Versions Affected: Apache Tomcat 9.0.0.M1 to 9.0.0.M13 Apache Tomcat 8.5.0 to 8.5.8 Apache Tomcat 8.0.0.RC1 to 8.0.39 (new) Apache Tomcat 7.0.0 to 7.0.73 (new) Apache Tomcat 6.0.16 to 6.