Re: How can I extend AceessLogValue

2023-02-03 Thread Christopher Schultz
Hello, On 2/2/23 08:00, shallowinggg wrote: traceId has in request header, but it is encrypted, I need to parse it. %{xxx}i can get header, but encrypted value How about writing a Filter which takes the value from the header, decrypts it, and then puts the unencrypted value into a request-at

Re: AW: AW: Having trouble with Tomcat crashes. Interesting memory numbers in Manager

2023-02-07 Thread Christopher Schultz
Thomas, James, On 2/6/23 17:00, Thomas Hoffmann (Speed4Trade GmbH) wrote: Hello James, -Ursprüngliche Nachricht- Von: James H. H. Lampert Gesendet: Montag, 6. Februar 2023 18:18 An: Tomcat Users List Betreff: Re: AW: Having trouble with Tomcat crashes. Interesting memory numbers in M

Re: Basic SSL Certificate Usage logging

2023-02-09 Thread Christopher Schultz
y 10, 2023 8:23 AM To: users@tomcat.apache.org Subject: Re: Basic SSL Certificate Usage logging On 10/01/2023 13:52, Christopher Schultz wrote: Jon, On 1/9/23 18:17, jonmcalexan...@wellsfargo.com.INVALID wrote: Yes Chris, It's just for during startup. For a particular instance I would

Re: AW: AW: Having trouble with Tomcat crashes. Interesting memory numbers in Manager

2023-02-09 Thread Christopher Schultz
James, On 2/7/23 20:35, James H. H. Lampert wrote: Monitored the thing all day, taking the CPU usage (via a WRKACTJOB) and the current heap size and heap-in-use (via option 5 of a WRKJVMJOB) every 15 minutes. Heap size was 4925.375M (out of a maximum of 5120M) at 08:45, and the OS took heap

Re: AW: AW: Having trouble with Tomcat crashes. Interesting memory numbers in Manager

2023-02-09 Thread Christopher Schultz
Shawn, On 2/9/23 17:18, Shawn Heisey wrote: On 2/9/23 12:54, Christopher Schultz wrote: It would be unusual for the OS to reclaim any of that memory from the JVM process. Are you looking at OS heap usage, or "JVM heap" usage? From your description above, it's tough to tell. The

Re: Tomcat 10.0.x

2023-02-21 Thread Christopher Schultz
PM To: Tomcat Users List Subject: Re: Tomcat 10.0.x 7 Feb 2023 18:38:31 jonmcalexan...@wellsfargo.com.INVALID: Hi Mark, Christopher, Remy, et-al, In regards to the Apache Tomcat(r) - End of life for Apache Tomcat 10.0.x< https://urldefense.com/v3/__https://tomcat.apache.org/tomcat- 10

[ANN] Apache Tomcat 8.5.86 available

2023-02-24 Thread Christopher Schultz
The Apache Tomcat team announces the immediate availability of Apache Tomcat 8.5.86. Apache Tomcat 8 is an open source software implementation of the Java Servlet, JavaServer Pages, Java Unified Expression Language, Java WebSocket and JASPIC technologies. Apache Tomcat 8.5.86 is a bugfix and fea

[ANN] Apache Tomcat 10.1.6 available

2023-02-24 Thread Christopher Schultz
The Apache Tomcat team announces the immediate availability of Apache Tomcat 10.1.6. Apache Tomcat 10 is an open source software implementation of the Jakarta Servlet, Jakarta Server Pages, Jakarta Expression Language, Jakarta WebSocket, Jakarta Authentication and Jakarta Annotations specificatio

Re: Database related performance degradation after upgrading from Tomcat 9.0.33 to Tomcat 9.0.69

2023-02-24 Thread Christopher Schultz
Artur, On 2/23/23 15:55, Artur Tomusiak - Hannon Hill wrote: Thanks everyone for the information and advice. Thanks to you we were able to track this down to a specific version of Tomcat and DBCP. Simply copying tomcat-dbcp.jar file from Tomcat 9.0.38 to Tomcat 9.0.33 and running Tomcat 9.0.33 r

Re: Tomcat V8.5.85

2023-02-28 Thread Christopher Schultz
Nitish, On 2/24/23 13:50, Nitish Khune wrote: Since I upgraded from 8.5.84 to 8.5.85 or later, Any REST API with below header throws a context mismatch exception It would be great if you are able to download the 8.5.87 release-candidate and test whether this problem is resolved for you. If

Re: Apache Tomcat 10.1.6 is giving me java.lang.ClassNotFoundException: jakarta.servlet.jsp.JspFactory

2023-03-01 Thread Christopher Schultz
Karen, On 3/1/23 09:09, Karen Goh wrote: Hello experts, I need desperate help to fix this java.lang.ClassNotFoundException: jakarta.servlet.jsp.JspFactory Here are my dependencies which I have installed but still Tomcat will still purge out the ClassNotFound error :                      com

Re: Apache Tomcat 10.1.6 is giving me java.lang.ClassNotFoundException: jakarta.servlet.jsp.JspFactory

2023-03-01 Thread Christopher Schultz
advise me now. Tks. If you are using jetty:run then you are probably not using Tomcat. >:| -chris On Wednesday, March 1, 2023 at 10:19:18 PM GMT+8, Christopher Schultz wrote: Karen, On 3/1/23 09:09, Karen Goh wrote: Hello experts, I need desperate help to fix t

Re: Apache Tomcat 10.1.6 is giving me java.lang.ClassNotFoundException: jakarta.servlet.jsp.JspFactory

2023-03-02 Thread Christopher Schultz
JSTL library and any of its dependencies (but not JSP-API, which is provided by Tomcat). -chris On Thursday, March 2, 2023 at 01:51:56 AM GMT+8, Christopher Schultz wrote: Karen, On 3/1/23 10:21 AM, Karen Goh wrote:   hi Chris, I am following advice from ClassNotFou

Re: Unpackwar

2023-03-02 Thread Christopher Schultz
Mark, On 3/2/23 09:39, Mark Thomas wrote: On 02/03/2023 14:20, Devatha Naga Puneeth wrote: Hi, I checked the documentation and only understood that if unpackwar enabled then contents of the application will be extracted in the appBase. What is the use of UnpackWar to false ? When to prefer tr

[ANN] Apache Tomcat 8.5.87 available

2023-03-04 Thread Christopher Schultz
The Apache Tomcat team announces the immediate availability of Apache Tomcat 8.5.87. Apache Tomcat 8 is an open source software implementation of the Java Servlet, JavaServer Pages, Java Unified Expression Language, Java WebSocket and JASPIC technologies. Apache Tomcat 8.5.87 is a bugfix and fea

[ANN] Apache Tomcat 10.1.7 available

2023-03-04 Thread Christopher Schultz
The Apache Tomcat team announces the immediate availability of Apache Tomcat 10.1.7. Apache Tomcat 10 is an open source software implementation of the Jakarta Servlet, Jakarta Server Pages, Jakarta Expression Language, Jakarta WebSocket, Jakarta Authentication and Jakarta Annotations specificatio

Re: Connector definitions, Re: Tomcat 8 impending EOL -- what's the minimum Java for Tomcat 9?

2023-03-07 Thread Christopher Schultz
James, On 3/7/23 03:35, Mark Thomas wrote: On 06/03/2023 23:58, James H. H. Lampert wrote: On 03/03/2023 17:44, I wrote: Ok, another question: will Tomcat 9 accept a "legacy" connector definition in the form as shown below? protocol="org.apache.coyote.http11.Http11Protocol" maxThreads="150"

Re: sslHostConfig and ciphers

2023-03-08 Thread Christopher Schultz
Jon, On 3/8/23 11:04, jonmcalexan...@wellsfargo.com.INVALID wrote: So, this is giving out this errors: javax.net.ssl|WARNING|01|main|2023-03-03 16:14:43.438 UTC|SSLSocketImpl.java:1468|handling exception ( "throwable" : { java.net.SocketException: Connection reset at java.net.Socket

Re: AW: sslHostConfig and ciphers

2023-03-08 Thread Christopher Schultz
Thomas, On 3/8/23 11:16, Thomas Hoffmann (Speed4Trade GmbH) wrote: the error messages when encryption/decryption fails are often not much helpful. I don't see any evience of encryption or decryption operations failing. -chris -Ursprüngliche Nachricht- Von: jonmcalexan...@wellsfargo.

Re: Tomcat 9.0.72 Firefox issue with 204 response (Empty Body)

2023-03-08 Thread Christopher Schultz
Bhavesh, On 3/7/23 22:07, Bhavesh Mistry wrote: Hi Mark Thomas and Tomcat Team, We have a strange issue with Tomcat 9.0.72.  All 204 response does not complete in firefox.  It works in the Chrome browser.  If we downgrade the tomcat version is less than .72. Everything works on all browsers.

Re: Connector definitions, Re: Tomcat 8 impending EOL -- what's the minimum Java for Tomcat 9?

2023-03-08 Thread Christopher Schultz
Mark, On 3/8/23 03:31, Mark Thomas wrote: On 07/03/2023 21:09, James H. H. Lampert wrote: Dear Mesrs. Thomas, Schultz, et al.: Changing it to "org.apache.coyote.http11.Http11NioProtocol" did the trick. The Tomcat 9 server launched, on our cloud Midrange box, and both it and the webapp contex

Re: Connector definitions, Re: Tomcat 8 impending EOL -- what's the minimum Java for Tomcat 9?

2023-03-08 Thread Christopher Schultz
James, On 3/7/23 16:09, James H. H. Lampert wrote: (I have the general impression that APR is not an option on IBM Midrange boxes, but I could be mistaken.) It might be. https://www.ibm.com/docs/en/ibm-http-server/9.0.5?topic=chs-apache-apr-apr-util-libraries-included-withibm-http-server Are

Re: sslHostConfig and ciphers

2023-03-08 Thread Christopher Schultz
cting to a Tomcat on the other end that you are trying to debug, here, then I think you are barking up the wrong tree. -chris -Original Message- From: Christopher Schultz Sent: Wednesday, March 8, 2023 10:23 AM To: users@tomcat.apache.org Subject: Re: sslHostConfig and ciphers

Re: catalina.out, was Re: Connector definitions

2023-03-08 Thread Christopher Schultz
James, On 3/8/23 17:05, James H. H. Lampert wrote: On 3/8/23 1:34 PM, Zerro wrote: On the Linux box Tomcat is probably started by systemd, therefore no catalina.out Very likely, but can you elaborate on that? I'm much more of a DOS (to the point of having gone to great lengths to set up a r

Re: Apache Tomcat wire logging does not show POST data payload

2023-03-09 Thread Christopher Schultz
Aditya, On 3/9/23 09:29, Aditya Kumar wrote: I edited my log4j2.xml to include these lines: Now in my defined serverlog I see the http wire traffic I am after. However there is one problem. For POST requests from my Tomcat server I can only see request/response HTTP headers. I cannot s

Re: HTTP Error 414. The request URL is too long.

2023-03-10 Thread Christopher Schultz
Stefan, On 3/10/23 02:27, Stefan Mayr wrote: Am 10.03.2023 um 07:58 schrieb Thomas Hoffmann (Speed4Trade GmbH): You should keep an eye on this log entry: this is a GET request as your SAMPLE POST already indicated. Maybe you can check back with your developers that they change their code to re

[OT] Issues with XMLDSIG

2023-03-13 Thread Christopher Schultz
All, I'm having a bit of trouble validating a SAML response which has been signed by Okta (who know a thing or two about signed XML), and the code I'm using was written by me using the basic Java XML security APIs, so I'm thinking there is something off with what I'm doing. If anyone has som

Re: [OT] Issues with XMLDSIG

2023-03-13 Thread Christopher Schultz
de we have is /mostly/ applicable. I'm having trouble tarcking-down why this particular provider's SAML responses are failing to validate. Thanks, -chris On Mon, Mar 13, 2023 at 3:27 PM Christopher Schultz < ch...@christopherschultz.net> wrote: All, I'm having a b

Re: How to configure and verified chain certificat

2023-03-14 Thread Christopher Schultz
Olivier, On 3/14/23 10:07, Olivier Studer wrote: I use Tomcat 9 version. I have configured the server.xml as following to use certificate signed. But I have an error with openssl command to verify it is correctly configured. Command and output: echo | openssl s_client -showcerts -connect se

Re: Quick Question with Tomcat 10.1x

2023-03-20 Thread Christopher Schultz
Jon, On 3/16/23 15:19, jonmcalexan...@wellsfargo.com.INVALID wrote: -Original Message- From: jonmcalexan...@wellsfargo.com.INVALID Sent: Thursday, March 16, 2023 1:54 PM To: users@tomcat.apache.org Subject: RE: Quick Question with Tomcat 10.1x -Original Message- From: Torste

Re: Unable to start application

2023-03-20 Thread Christopher Schultz
Kevin, On 3/18/23 19:04, Kevin Huntly wrote: I can't use tomcat 10 because of the switch to jakarta for the servlet container - I'd have to rewrite a lot of code. That being said, I got it fixed: All JDBC and JNDI lookups were prefixed with "java:comp/env/" and things worked. Clearly, IBM's Web

Re: GoDaddy SSL certificate not working with Tomcat9

2023-03-21 Thread Christopher Schultz
Ralph, On 3/21/23 06:38, Ralph Grove wrote: > [snip] > Alias name: tomcat Creation date: Mar 21, 2023 Entry type: trustedCertEntry You created a keystore with no keys. Where is the key you used to generate the CSR? That key needs to be in your keystore under the alias 'tomcat' alongside t

Re: Unable to start application

2023-03-21 Thread Christopher Schultz
't be going to production (our prod is db2) Sounds like: 1. This is dev, so you should fix your key+cert instead of hacking stunnel 2. You are using different databases in different environments. WTH? -chris On Mon, Mar 20, 2023, 20:09 Christopher Schultz < ch...@christopherschultz.ne

Re: Can't get RemoteIpValve to work

2023-03-25 Thread Christopher Schultz
Leon, On 3/24/23 10:09, Leon Rosenberg wrote: Full log output (dumping out headers, without the valve): 6049752 2023-03-24 14:07:59,749 [http-apr-8080-exec-13] INFO n.a.c.extapi.ping.PingResource:38 - key: host; value: api.myhost.net 6049752 2023-03-24 14:07:59,749 [http-apr-8080-exec-13] INFO

Re: Requirements to support HTTPS

2023-03-25 Thread Christopher Schultz
Blake, On 3/25/23 10:16, Blake McBride wrote: I wanted to confirm my suspicions regarding packages needed in tomcat to support HTTPS. You don't need anything except the core Tomcat and a reasonably recent JVM to support HTTPS. You may have some other requirements you'd like to place on top o

Re: Logging

2023-04-03 Thread Christopher Schultz
Kevin, On 4/2/23 09:08, Kevin Huntly wrote: Couple questions: 1. Is there a way to change the default "stdout" to a different name? e.g. SystemOut.log (and by extension, can syserr be printed to something SystemErr.log?) How are you launching Tomcat? 2. When verbose:gc is turned on it logs

Re: DBAs?

2023-04-03 Thread Christopher Schultz
Kevin, On 4/2/23 16:39, Kevin Huntly wrote: Are there any DBAs in here? If so, are you aware of a MySQL user mailing list? I'm having an issue with some stored procedures and need some help dba.stackexchange.com is fairly decent in my experience. -chris --

Re: [org.apache.jasper.JasperException: Unable to compile class for JSP] with root cause

2023-04-03 Thread Christopher Schultz
Kesavan, On 4/3/23 10:53, Kesavan, Suresh Prabhu (Fed) wrote: Thanks, can you tell me how to enable all security in tomcat Catalina.policy. Just turn off the security manager if you are going to allow all privilieges. Having it enabled without any enforcement means you get zero security cont

Re: Logging

2023-04-03 Thread Christopher Schultz
-- PS+ PE Y(+) PGP++(+++) t+ 5-- X-- R+ tv+ b++ DI++ D++ G++ e(+) h--- r+++ y+++* --END GEEK CODE BLOCK-- On Mon, Apr 3, 2023 at 10:03 AM Christopher Schultz < ch...@christopherschultz.net> wrote: Kevin, On 4/2/23 09:08, Kevin Huntly wrote: Couple questions: 1. Is there a wa

Re: Logging

2023-04-03 Thread Christopher Schultz
R+ tv+ b++ DI++ D++ G++ e(+) h--- r+++ y+++* --END GEEK CODE BLOCK-- On Mon, Apr 3, 2023 at 10:03 AM Christopher Schultz < ch...@christopherschultz.net> wrote: Kevin, On 4/2/23 09:08, Kevin Huntly wrote: Couple questions: 1. Is there a way to change the default "stdout"

Re: Logging

2023-04-03 Thread Christopher Schultz
ay be serving other purposes. I have some personal thoughts about things like what should be done on OOMEs but again those are very environment-specific. -chris On Mon, Apr 3, 2023 at 11:57 AM Christopher Schultz < ch...@christopherschultz.net> wrote: Kevin, On 4/3/23 10:07, Kevin Huntly

Re: Logging

2023-04-05 Thread Christopher Schultz
in my experience, OOME -> script to ping a management system is fairly reliable. -chris On Mon, Apr 3, 2023 at 12:31 PM Christopher Schultz mailto:ch...@christopherschultz.net>> wrote: Kevin, On 4/3/23 12:10, Kevin Huntly wrote: > idk why i add the typeset, but I do every

Re: Accessing Tomcat Sessions

2023-04-05 Thread Christopher Schultz
Mark and Chew Kok, On 4/3/23 12:47, Mark Thomas wrote: On 02/04/2023 13:44, Chew Kok Hoor wrote: Hi, As part of a way to prevent concurrent login, and to re-assign a session back to a request based on JWT token (for clients that cannot pass us cookies), we need to access to the 'findSes

Re: [OT] Access Log Valve

2023-04-05 Thread Christopher Schultz
Jon, On 4/4/23 15:01, jonmcalexan...@wellsfargo.com.INVALID wrote: Hi everybody, I'm trying to understand the Logging Valve better for the Access Logs. I saw in there that the Apache HTTPD Logging format is supported, but not entirely sure on how to implement. Is something like this kosher? W

Re: [OT] Apache Tomcat 10.0.26 Shortcut issue in our environment - Need Help

2023-04-05 Thread Christopher Schultz
Sriharikumar, On 4/5/23 07:04, P M, SRIHARIKUMAR (Consultant) wrote: While validating source for Apache Tomcat 10.0.26, The shortcut is throwing error while launching. Please find the results below Tomcat Version : 10.0.26 End of life: https://tomcat.apache.org/tomcat-10.0-eol.html Operati

Re: Accessing Tomcat Sessions

2023-04-06 Thread Christopher Schultz
use the JMXProxyServlet, which is a part of the Manager web application, you can use HTTP to make JMX calls via HTTP to other servers. So for example if you want to expire an HttpSession on another server, you can do it via HTTP. Hope that helps, -chris On Thu, Apr 6, 2023, 1:56 AM Christopher

Re: tomcat shared classloader

2023-04-06 Thread Christopher Schultz
Kevin, On 4/6/23 16:26, Kevin Huntly wrote: I've placed a utility jar in ${catalina.home}/shared/app for use across all my webapps. However, I'm getting ClassNotFound exceptions when trying to use the shared stuff. Any ideas? What version of Tomcat? Have you changed the configuration from th

Re: Database connection pooling ..

2023-04-11 Thread Christopher Schultz
John, On 4/10/23 00:40, John Dale (DB2DOM) wrote: Has anyone tried using the Tomcat 10 DBCP from a standalone java app? I have not, but there isn't really anything Tomcat-specific about it. -chris - To unsubscribe, e-mail: u

Re: Database connection pooling ..

2023-04-11 Thread Christopher Schultz
Bruno, On 4/11/23 12:51, BRUNO MELLONI wrote: I used org.apache.commons.dbcp2.BasicDataSource as my default DataSource for over a decade in both Tomcat and standalone apps. Very reliable. Note that you are talking about commons-dbcp2 and John was asking about tomcat-pool (which is a different p

Getting started with Websocket

2023-04-12 Thread Christopher Schultz
All, I'm finally dipping my toes into Websocket-based communication with my Tomcat-based applications. Is it possible to do everything with "real" code and not any annotations? I was looking for something like the Servlet Async model where you take an existing request and put it into async m

Re: Getting started with Websocket

2023-04-12 Thread Christopher Schultz
Mark, On 4/12/23 15:21, Mark Thomas wrote: On 12/04/2023 19:31, Christopher Schultz wrote: All, I'm finally dipping my toes into Websocket-based communication with my Tomcat-based applications. Is it possible to do everything with "real" code and not any annotations? I

Re: Tomcat 9.0.73 - Exception while accessing application

2023-04-13 Thread Christopher Schultz
Jon, On 4/12/23 17:38, jonmcalexan...@wellsfargo.com.INVALID wrote: And another app, different stack-trace, same java.lang.NoSuchFieldError: EMPTY_CHAR_ARRAY What version of Java are you using? -chris 11-Apr-2023 12:38:44.264 SEVERE [https-jsse-nio-0.0.0.0-23601-exec-11] org.apa

Re: Clustering issue

2023-04-13 Thread Christopher Schultz
Kevin, On 4/12/23 19:20, Kevin Huntly wrote: I setup a quick and dirty cluster following https://tomcat.apache.org/tomcat-9.0-doc/cluster-howto.html I am seeing the following: 12-Apr-2023 19:18:00.369 WARNING [main] org.apache.catalina.ha.tcp.SimpleTcpCluster.registerManager Manager [Persisten

Re: Redirect appends port number?

2023-04-13 Thread Christopher Schultz
Kevin, On 4/12/23 19:35, Kevin Huntly wrote: I'm seeing some odd behavior - my servlet filter is redirecting with port 10943 attached to the redirect Are you the author of the filter? If so, can you post the code that is determining what URL to use for the redirect? > - that port is the por

Re: Java Heap Space Error

2023-04-13 Thread Christopher Schultz
Pratik, On 4/13/23 05:35, pratik.kulka...@shell.com.INVALID wrote: This email concerns an error I encountered while using Oracle Apex with ORDS 3.0.9 and Tomcat 9. Specifically, I receive a "Java heap space" error when accessing the application. To troubleshoot the issue, I have tried to incr

Re: Java Heap Space Error

2023-04-17 Thread Christopher Schultz
Pratik, On 4/13/23 22:55, pratik.kulka...@shell.com.INVALID wrote: Chris - I see. So we already have installed a service and I tried to set the environment variable after we got the error. Is there a way for Tomcat to read the variables we set after installation? If you are running the Windows S

Re: Tomcat 9.0.73 - Exception while accessing application

2023-04-17 Thread Christopher Schultz
Tomcat installation. -chris From: Christopher Schultz Sent: Thursday, April 13, 2023 1:11:15 PM To: users@tomcat.apache.org Subject: Re: Tomcat 9.0.73 - Exception while accessing application Jon, On 4/12/23 17:38, jonmcalexan...@wellsfargo.com.INVALID wrote

[ANN] Apache Tomcat 8.5.88 available

2023-04-19 Thread Christopher Schultz
The Apache Tomcat team announces the immediate availability of Apache Tomcat 8.5.88. Apache Tomcat 8 is an open source software implementation of the Java Servlet, JavaServer Pages, Java Unified Expression Language, Java WebSocket and JASPIC technologies. Apache Tomcat 8.5.88 is a bugfix and fea

[ANN] Apache Tomcat 10.1.8 available

2023-04-19 Thread Christopher Schultz
The Apache Tomcat team announces the immediate availability of Apache Tomcat 10.1.8. Apache Tomcat 10 is an open source software implementation of the Jakarta Servlet, Jakarta Server Pages, Jakarta Expression Language, Jakarta WebSocket, Jakarta Authentication and Jakarta Annotations specificatio

Re: Java Heap Space Error

2023-04-20 Thread Christopher Schultz
Pratik, On 4/20/23 03:35, pratik.kulka...@shell.com.INVALID wrote: I guess you're right, Tomcat 9 allocates less default memory compared to Tomcat 8; I checked our logs and below are the memory parameters which seem to be passed in, Tomcat 9 - 14-Apr-2023 02:47:55.567 INFO [main] org.apache

Re: OT: Tomcat and TLS

2023-04-20 Thread Christopher Schultz
Jon, On 4/20/23 10:12, jonmcalexan...@wellsfargo.com.INVALID wrote: Since TLS 1.2 and 1.3 don't/can't play well with each other (no mixed mode) What do you mean by this? [...] is it best to have a TLS 1.2 connector and a separate TLA 1.3 connector on a different port, or just go to a TLS 1.3

Re: ServletFileUpload not available in Tomcat 10.1

2023-04-20 Thread Christopher Schultz
Thomas, On 4/20/23 10:26, Thomas Hoffmann (Speed4Trade GmbH) wrote: we are upgrading from Tomcat 10 to Tomcat 10.1 We are currently using ServletFileUpload.isMultipartContent(request) (from org.apache.tomcat.util.http.fileupload.servlet.ServletFileUpload) It seems that the whole Servlet was re

Re: [ANN] Apache Tomcat 9.0.74 available

2023-04-20 Thread Christopher Schultz
Konstantin, On 4/18/23 09:39, Konstantin Kolinko wrote: You can also download from Maven Central. Tomcat releases are also published there. This is the "correct" answer for anything Maven-related IMO. -chris - To unsubscribe

Re: java.lang.InternalError: Unexpected CryptoAPI failure generating seed

2023-04-20 Thread Christopher Schultz
Harri, On 4/18/23 07:43, Harri Pesonen wrote: Hello, we have: Tomcat/8.5.83 Windows Server 2016 java.version=11.0.12 java.vendor=Azul Systems, Inc. sun.arch.data.model=64 Sometimes Tomcat fails to start our application because of this error: 06:45:58.230 ERR> (Catalina-startStop-1) (org.apac

Re: [OT] Cluster Manager not working

2023-04-20 Thread Christopher Schultz
Kevin, On 4/19/23 07:07, Kevin Huntly wrote: I'm guessing its not possible to have the cluster setup with a session database? Yeah, you usually pick one: database or cluster. If you pick cluster, then the cluster is your database (don't let all the nodes go down!). If you pick database, ther

Re: Tips on identifying the DB connection leaks leading to the "Pool empty" error

2023-04-20 Thread Christopher Schultz
Torsten, On 4/17/23 19:31, Torsten Krah wrote: Use logAbandoned as a boolean parameter +1 remoteAbandoned is only a band-aid; you need to fix your application. In development, I always run with maxTotal="1" and logAbandoned="true" and maxWaitMillis="1". This will help you find connectio

Re: ClassNotFound after upgrade to tomcat 10

2023-04-20 Thread Christopher Schultz
Kevin, On 4/17/23 17:56, Kevin Huntly wrote: I'm getting the following exception when I try to access my webapp: 17-Apr-2023 17:52:55.982 SEVERE [catalina-exec-1] org.apache.catalina.core.ApplicationDispatcher.invoke Servlet.service() for servlet [jsp] threw exception java.lang.ClassNo

Re: Tomcat 8.5.85 and above - Issue with file uploads

2023-04-20 Thread Christopher Schultz
William, On 4/20/23 13:56, William L. Cunningham wrote: Unfortunately, I'm not privy to the developer side of things. I'm infrastructure trying to help the development side. So I'm not sure how to provide what you're asking for. I'll see if I can get some assistance on that though. Point your

Re: java.lang.InternalError: Unexpected CryptoAPI failure generating seed

2023-04-21 Thread Christopher Schultz
re. -chris -Original Message- From: Christopher Schultz Sent: torstai 20. huhtikuuta 2023 19.35 To: users@tomcat.apache.org Subject: Re: java.lang.InternalError: Unexpected CryptoAPI failure generating seed Harri, On 4/18/23 07:43, Harri Pesonen wrote: Hello, we have: Tomcat/8.5.

Re: [OT] MySQL Connection settings

2023-04-21 Thread Christopher Schultz
Kevin, On 4/21/23 09:35, Kevin Huntly wrote: I'm not a DBA nor do I pretend to be, so I'm asking what everyone's thoughts are on MySQL connection string settings? What are the best options to use, what options are absolutely required, etc? Just ... in general? Or do you have a specific use-cas

Re: OT: hsts in Tomcat 9.0.73

2023-04-21 Thread Christopher Schultz
Jon, On 4/21/23 11:47, jonmcalexan...@wellsfargo.com.INVALID wrote: Thank you Olaf, however, the connection was made over https directly to Tomcat on port 8443. Sample curl with secrets removed? -chris -Original Message- From: Olaf Kock Sent: Friday, April 21, 2023 1:48 AM To: users

Re: [OT] MySQL Connection settings

2023-04-25 Thread Christopher Schultz
Kevin, On 4/21/23 14:19, Kevin Huntly wrote: in general. something all purpose to get started with On Fri, Apr 21, 2023, 14:17 Christopher Schultz < ch...@christopherschultz.net> wrote: Kevin, On 4/21/23 09:35, Kevin Huntly wrote: I'm not a DBA nor do I pretend to be, so I&#x

Re: OT: hsts in Tomcat 9.0.73

2023-04-25 Thread Christopher Schultz
Jon, On 4/20/23 16:39, jonmcalexan...@wellsfargo.com.INVALID wrote: Hellow again. I hae another app team that is getting hit with a QID 11827 stating that the hsts Security header is missing. We have reviewed the web.xml and the appropriate section and filter are present. hstsEnabled is set t

Re: OT: hsts in Tomcat 9.0.73

2023-04-25 Thread Christopher Schultz
Jon, On 4/25/23 10:15, Christopher Schultz wrote: Jon, On 4/20/23 16:39, jonmcalexan...@wellsfargo.com.INVALID wrote: Hellow again. I hae another app team that is getting hit with a QID 11827 stating that the hsts Security header is missing. We have reviewed the web.xml and the appropriate

Re: java.lang.InternalError: Unexpected CryptoAPI failure generating seed

2023-04-25 Thread Christopher Schultz
java.security.egd should not affect it. I can't recall if the format of that string is the same in Windows, but it should be similar. It doesn't matter. -chris On Fri, Apr 21, 2023 at 2:15 PM Christopher Schultz < ch...@christopherschultz.net> wrote: Harri, On 4/21/23 0

Re: Tomcat Native 1.2.30 -- Windows 2016 TLSv1.3 support?

2023-04-25 Thread Christopher Schultz
Vincent, On 4/25/23 05:14, Mark Thomas wrote: On 24/04/2023 20:15, Ragosta, Vincent wrote: Hello all, We have an application packaged with Tomcat Native 1.2.30, which, per the following, the Windows binaries were built using OpenSSL 1.1.1k: https://www.mail-archive.com/dev@tomcat.apache.org

Re: OT: hsts in Tomcat 9.0.73

2023-04-25 Thread Christopher Schultz
T and your own application and you are all good. What does your look like for port 8443? -chris -Original Message- From: Christopher Schultz Sent: Tuesday, April 25, 2023 9:15 AM To: users@tomcat.apache.org Subject: Re: OT: hsts in Tomcat 9.0.73 Jon, On 4/20/23 16:39, jonmcalexan...@wellsfa

Re: OT: hsts in Tomcat 9.0.73

2023-04-25 Thread Christopher Schultz
configuration in ROOT/WEB-INF/web.xml and nowhere else. -chris -Original Message- From: Christopher Schultz Sent: Tuesday, April 25, 2023 10:04 AM To: users@tomcat.apache.org Subject: Re: OT: hsts in Tomcat 9.0.73 Jon, On 4/25/23 10:31, jonmcalexan...@wellsfargo.com.INVALID wrote: It'

Re: OT: hsts in Tomcat 9.0.73

2023-04-25 Thread Christopher Schultz
Olaf, On 4/22/23 03:13, Olaf Kock wrote: Am 22.04.23 um 00:48 schrieb jonmcalexan...@wellsfargo.com.INVALID: Thanks Peter, I still do not see the hsts header. I'm wondering if this is causing it. SSL certificate verify result: self signed certificate in certificate chain (19), continuing an

Re: OT: hsts in Tomcat 9.0.73

2023-04-25 Thread Christopher Schultz
GIN X-XSS-Protection 1 (Although the documentation suggests that the value for X-XSS-Protection should be "1; mode=block" and it isn't in the above header value.) Are you able to change the configuration and/or add some code/config? -chris -Original Message- From

Re: How to setup client certificate based authentication in Tomcat 9

2023-04-26 Thread Christopher Schultz
Parkar, On 4/26/23 10:34, Patkar Omkar Anant wrote: I am a bit newbie to this domain of client certificate-based authentication. We have two applications … A(server) and B(client). Web application A runs on Apache Tomcat 9.0.52. (it’s a REST API based application). Application B invokes the res

Re: OT: hsts in Tomcat 9.0.73

2023-04-27 Thread Christopher Schultz
that level, just at the server level. It should be the same as what you put into conf/web.xml: just define the and add /*. -chris -----Original Message- From: Christopher Schultz Sent: Tuesday, April 25, 2023 4:40 PM To: users@tomcat.apache.org Subject: Re: OT: hsts in Tomcat 9.0.73 Jon,

Re: OT: hsts in Tomcat 9.0.73

2023-04-27 Thread Christopher Schultz
ou'll have to follow Olaf's suggestion of running it under a debugger if you want immediate clarity on what's happening. -chris -Original Message----- From: Christopher Schultz Sent: Thursday, April 27, 2023 10:16 AM To: Tomcat Users List Subject: Re: OT: hsts in Tomcat 9

Re: WebappClassLoaderBase error when upgrading Tomcat 8 to 8.5

2023-05-01 Thread Christopher Schultz
Jeremy, On 5/1/23 14:22, Jeremy Nguyen wrote: I'm trying to upgrade Tomcat 8 to 8.5 and I'm getting a nullpointerexception within WebappClassLoaderBase.CombinedEnumeration.inc. It seems to occur when it's trying to initialize commons-logging LogFactory for any class specified in Web.xml, and it'

Re: WebappClassLoaderBase error when upgrading Tomcat 8 to 8.5

2023-05-02 Thread Christopher Schultz
Rob, On 5/1/23 17:12, Rob Sargent wrote: => On 5/1/23 14:36, Christopher Schultz wrote: Jeremy, On 5/1/23 14:22, Jeremy Nguyen wrote: I'm trying to upgrade Tomcat 8 to 8.5 and I'm getting a nullpointerexception within WebappClassLoaderBase.CombinedEnumeration.inc. It seems to oc

Re: WebappClassLoaderBase error when upgrading Tomcat 8 to 8.5

2023-05-02 Thread Christopher Schultz
ng a breakpoint in WebappClassLoaderBase.getResources and just inspecting the situation at that point -- you should be able to see what the parent ClassLoader is, and even see what getParent().getResources() returns. -chris On Mon, May 1, 2023 at 2:12 PM Rob Sargent wrote: On 5/1/23 14:

Re: WebappClassLoaderBase error when upgrading Tomcat 8 to 8.5

2023-05-03 Thread Christopher Schultz
6) ~[pac4j-core-1.9.1.jar:?] ... 34 more On Tue, May 2, 2023 at 5:23 AM Christopher Schultz < ch...@christopherschultz.net> wrote: Jeremy, On 5/1/23 17:46, Jeremy Nguyen wrote: I noticed this change was introduced: https://bz.apache.org/bugzilla/show_bug.cgi?id=62868 https://github.

Re: WebappClassLoaderBase error when upgrading Tomcat 8 to 8.5

2023-05-03 Thread Christopher Schultz
from the parent ClassLoader). No warranty, you accept all responsibility, etc. -chris On May 3, 2023, at 7:05 AM, Christopher Schultz wrote:  Jeremy, On 5/2/23 22:27, Jeremy Nguyen wrote: I was able to retrieve some logs that might shed some insight on the parent classloader when running 8

Re: WebappClassLoaderBase error when upgrading Tomcat 8 to 8.5

2023-05-03 Thread Christopher Schultz
Jeremy, On 5/3/23 12:27, Jeremy Nguyen wrote: Thanks Chris! That works for me now. Okay. I'll ask the rest of the team if it's an acceptable workaround. Honestly, that parent ClassLoader is violating The Rules. Only issue I have left is failing to compile/validate JSP. Caused by: java.lan

Re: Supporting Proxy Protocol in Tomcat

2023-05-08 Thread Christopher Schultz
Amit, On 5/4/23 16:07, Amit Pande wrote: We have a similar requirement as mentioned in the below enhancement request. https://bz.apache.org/bugzilla/show_bug.cgi?id=57830 Is there any plan to add this support in Tomcat in future releases? Nothing at the moment that I know of. I thought that

Re: Apache httpd as reverse proxy in front of Tomcat 10.1 - Different Connectors vs. HTTP request smuggling

2023-05-08 Thread Christopher Schultz
Reg, On 5/5/23 23:48, r.barc...@habmalnefrage.de wrote: I have some questions about HTTP request smuggling in the context of Tomcat with Apache httpd as its reverse proxy. First of all, a few words about my current setup: At the moment I have a few applications that are deployed this way: I u

Re: Jakarta - Sources you'd recommend

2023-05-08 Thread Christopher Schultz
Amn, On 5/8/23 10:20, Amn Ojee Uw wrote: I am trying to learn how to program web pages using Java, but I am having serious difficulties understanding the how to. So, is there a source [books, web sites, etc.] anyone here can recommend me. How much do you want to read, and how much do you want

Re: Question in regards to the Connector allowHostHeaderMismatch when it is set to "false"

2023-05-08 Thread Christopher Schultz
Alvaro, On 5/8/23 10:39, Mark Thomas wrote: On 08/05/2023 13:52, Alvaro Garay wrote: Hi Mark, In the example above...the port remains the same (8143). How is it different? GET http://myhostname.company.com/api/v1/endpoint  HTTP/1.1 The host is "myhostname.company.com" Host: myhostname.com

Fwd: Call for Presentations, Community Over Code 2023

2023-05-10 Thread Christopher Schultz
All, Please see below for the Call for Presentations (CFP) for the upcoming Community Over Code (formerly ApacheCon) Conference. While it's great to hear from committers and PMC members from Tomcat, I prefer to see presentations that come from *outside* of that group. So if you are doing so

Re: [External] Re: Supporting Proxy Protocol in Tomcat

2023-05-10 Thread Christopher Schultz
ot just s dumb pass-through. Hope that helps, -chris -Original Message- From: Christopher Schultz Sent: Monday, May 8, 2023 3:40 PM To: users@tomcat.apache.org Subject: [External] Re: Supporting Proxy Protocol in Tomcat Amit, On 5/4/23 16:07, Amit Pande wrote: We have a similar

Re: Best Practice to Upgrade Apache Tomcat from 9.0.56 to 9.0.74

2023-05-12 Thread Christopher Schultz
André, On 5/11/23 14:49, Andr? van der Lugt wrote: Hi Meltron, -Original Message- From: Meltron Kendrick Sent: 11 May, 2023 19:09 To: users@tomcat.apache.org Subject: Best Practice to Upgrade Apache Tomcat from 9.0.56 to 9.0.74 I have NOT been able to locate clear HOW TO steps for th

[ANN] Apache Tomcat 8.5.89 available

2023-05-19 Thread Christopher Schultz
The Apache Tomcat team announces the immediate availability of Apache Tomcat 8.5.89. Apache Tomcat 8 is an open source software implementation of the Java Servlet, JavaServer Pages, Java Unified Expression Language, Java WebSocket and JASPIC technologies. Apache Tomcat 8.5.89 is a bugfix and fea

Re: AW: Too many certificates in chain?!? Help!

2023-05-23 Thread Christopher Schultz
James, On 5/18/23 16:01, James H. H. Lampert wrote: On 5/18/23 12:18 AM, Thomas Hoffmann (Speed4Trade GmbH) wrote: Which version of tomcat do you use? Is the stack trace truncated in your mail? Is there a "caused by ..." further down the stacktrace? It looks like the error is thrown deeper i

Re: How to setup client certificate based authentication in Tomcat 9

2023-05-23 Thread Christopher Schultz
Omkar, On 5/3/23 00:28, Patkar Omkar Anant wrote: The server A where tomcat is running... it hosts a REST based application (BPMN based called Camunda ... it’s a 3rd party application). For e.g., when an application wants to trigger a workflow or BPMN deployed in Camunda, then they will fire t

Re: WebdavServlet protected resources cannot be opened in Word

2023-05-25 Thread Christopher Schultz
All, On 5/24/23 07:17, Mark Thomas wrote: On 24/05/2023 08:03, Кирилл Бубович wrote: We use webdav servlet to enable editing docx documents. We also use the |ms-word:ofe|u|https://www.example.com/d

<    5   6   7   8   9   10   11   12   13   14   >