[Bug 61773] When more than 10000 times of HTTPS websocket, Tomcat cannot respond to requesting HTTPS requests

2024-06-08 Thread bugzilla
https://bz.apache.org/bugzilla/show_bug.cgi?id=61773 Chuck Caldarale changed: What|Removed |Added URL|https://acuantoday.com | -- You are receiving this mail bec

[Bug 69129] New: Upgrade to Tomcat 10.1 breaks deployments with reverse proxies

2024-06-08 Thread bugzilla
https://bz.apache.org/bugzilla/show_bug.cgi?id=69129 Bug ID: 69129 Summary: Upgrade to Tomcat 10.1 breaks deployments with reverse proxies Product: Tomcat 10 Version: 10.1.24 Hardware: PC OS: Linux

[Bug 61773] When more than 10000 times of HTTPS websocket, Tomcat cannot respond to requesting HTTPS requests

2024-06-08 Thread bugzilla
https://bz.apache.org/bugzilla/show_bug.cgi?id=61773 Masel changed: What|Removed |Added URL||https://acuantoday.com Keywords|

Re: [PROPOSAL] Enable SecureLifecycleListener by default

2024-06-08 Thread Rémy Maucherat
On Thu, Jun 6, 2024 at 4:46 PM Christopher Schultz wrote: > > All, > > I'd like to remove the around the SecureLifecycleListener > in conf/server.xml that we bundle with Tomcat distributions. > > Before I do so, are there any objections to making this change? +1 Having something commented out in

Re: [PROPOSAL] Remove JSP file from ROOT web application

2024-06-08 Thread Rémy Maucherat
On Thu, Jun 6, 2024 at 4:44 PM Christopher Schultz wrote: > > All, > > I'd like to change the existing webapps/ROOT/index.jsp to index.html and > remove the dynamic elements. Currently, the only truly dynamic element > in the whole file is this: > > " > Copyright ©1999-${year} Apache Software > Fo

Re: [PROPOSAL] Tomcat 10: Remove CGI Servlet

2024-06-08 Thread Rémy Maucherat
On Thu, Jun 6, 2024 at 4:40 PM Christopher Schultz wrote: > > All, > > Resurrecting this thread from 2019. > > I will be proceeding with this 4.5-year-old plan to extract the CGI > servlet to a separate JAR file to make it easy to "remove" from Tomcat > if operators would prefer to do such things.

Re: Security mechanisms to counter spam

2024-06-08 Thread Rémy Maucherat
On Fri, Jun 7, 2024 at 12:23 PM Dimitris Soumis wrote: > > Hi All, > > Due to the surge in spam BZs today, I propose implementing a security > mechanism to counter this issue and prevent further disruption to the > mailing list. > > A potential solution could include a honeypot to identify and blo

Re: [PROPOSAL] Tomcat 10: Remove Server-Side Includes (SSI)

2024-06-08 Thread Rémy Maucherat
On Mon, Oct 7, 2019 at 4:46 PM Christopher Schultz wrote: > > -BEGIN PGP SIGNED MESSAGE- > Hash: SHA256 > > All, > > I recently gave a presentation on locking-down Apache Tomcat[1] and I > briefly discussed the "sharp edges" present in Tomcat. Some of them > are unnecessarily sharp and may