Hi,

>So what I've brought up is not a critical security fix, but instead a
>critical functionality fix, with a workaround that is quite annoying
for
>end users.
>How does that rate?

Below a critical security fix.  Personally, I wouldn't rate the
JNDIRealm as a critical piece of functionality either, but that's a
simple and subjective opinion based solely on its rarity as an issue on
the tomcat-user list.

>Yes, Tomcat 5.x is the way to go, but for instance on "support packs"
>for NetWare we are not at liberty to make such a big move, but instead
>need to make the smaller upgrade of 4.1.29 to 4.1.30.  I will pull in
>whatever additional fixes I need(JNDIRealm, the Connector to make the
>admin work), but the story of "Move to 5.x" does not fit everybody's
>case.

I understand completely, and I further imagine there are other people
who can't move to 5.x for other reasons (support contracts, 3rd party
library lock-in, 4.x-specific code, etc).  What I said earlier holds
just the same.

Your fix will not be ignored forever: it will be bundled into the next
4.x release.  But because there is no established frequency on releases
for a maintenance-phase branch, if you need your fix now you have to do
a custom build.

This policy is not dramatically different from other products, both in
the open-source and in the commercial software realms.  If you found a
functionality (not security) bug in Excel 97, you'd be told to upgrade
as that's in maintenance-mode.  In fact I think we've been pretty good
in maintaining 4.x and doing a couple of releases even after 5.x stable
came out.

>But, the next major release vehicle of NetWare and our Novell Linux
>Services will do that move to the 5.x code of course.

Cool.

Yoav Shapira




This e-mail, including any attachments, is a confidential business communication, and 
may contain information that is confidential, proprietary and/or privileged.  This 
e-mail is intended only for the individual(s) to whom it is addressed, and may not be 
saved, copied, printed, disclosed or used by anyone else.  If you are not the(an) 
intended recipient, please immediately delete this e-mail from your computer system 
and notify the sender.  Thank you.


---------------------------------------------------------------------
To unsubscribe, e-mail: [EMAIL PROTECTED]
For additional commands, e-mail: [EMAIL PROTECTED]

Reply via email to