Re: Tomcat Native and OpenSSL 3.5.x

2025-05-22 Thread Mark Thomas
On 22/05/2025 15:27, Mark Thomas wrote: I'm making progress. I've built Tomcat Native 2.0.x with OpenSSL 3.5.0 but it looks like I've picked up too many dependencies. I'm looking at how to fix that now. Thank you Mladen. He had already made the necessary changes. I just needed to enabled t

Re: Tomcat Native and OpenSSL 3.5.x

2025-05-22 Thread Mark Thomas
On 22/05/2025 15:15, Christopher Schultz wrote: Mark, On 5/22/25 5:30 AM, Mark Thomas wrote: All, This isn't going to work for 3.5.x. We need to use a newer compiler than the one packaged with Mladen's custom Microsoft compiler bundle. I have been meaning to look at updating the Tomcat Nati

Re: Tomcat Native and OpenSSL 3.5.x

2025-05-22 Thread Rémy Maucherat
On Thu, May 22, 2025 at 4:09 PM Christopher Schultz wrote: > > Mark, > > On 5/22/25 3:13 AM, Mark Thomas wrote: > > All, > > > > The last Tomcat Native releases were in July 2024. The Windows binaries > > were built with 3.0.14. > > > > There are some low severity CVEs in 3.0.14 that we don't beli

Re: Tomcat Native and OpenSSL 3.5.x

2025-05-22 Thread Christopher Schultz
Mark, On 5/22/25 5:30 AM, Mark Thomas wrote: All, This isn't going to work for 3.5.x. We need to use a newer compiler than the one packaged with Mladen's custom Microsoft compiler bundle. I have been meaning to look at updating the Tomcat Native builds so we can use a standard Visual Studio

Re: Tomcat Native and OpenSSL 3.5.x

2025-05-22 Thread Christopher Schultz
Mark, On 5/22/25 3:13 AM, Mark Thomas wrote: All, The last Tomcat Native releases were in July 2024. The Windows binaries were built with 3.0.14. There are some low severity CVEs in 3.0.14 that we don't believe apply to Tomcat's usage of OpenSSL but that may trigger a security scanner. Th

Re: Tomcat Native and OpenSSL 3.5.x

2025-05-22 Thread Mark Thomas
All, This isn't going to work for 3.5.x. We need to use a newer compiler than the one packaged with Mladen's custom Microsoft compiler bundle. I have been meaning to look at updating the Tomcat Native builds so we can use a standard Visual Studio installation. I guess it is time to spend som

Re: Tomcat Native and OpenSSL 3.5.x

2025-05-22 Thread Rainer Jung
Am 22.05.25 um 09:13 schrieb Mark Thomas: All, The last Tomcat Native releases were in July 2024. The Windows binaries were built with 3.0.14. There are some low severity CVEs in 3.0.14 that we don't believe apply to Tomcat's usage of OpenSSL but that may trigger a security scanner. There

Re: Tomcat Native and OpenSSL 3.5.x

2025-05-22 Thread Michael Osipov
On 2025/05/22 07:13:49 Mark Thomas wrote: > All, > > The last Tomcat Native releases were in July 2024. The Windows binaries > were built with 3.0.14. > > There are some low severity CVEs in 3.0.14 that we don't believe apply > to Tomcat's usage of OpenSSL but that may trigger a security scanne

Re: Tomcat Native and OpenSSL 3.5.x

2025-05-22 Thread Rémy Maucherat
On Thu, May 22, 2025 at 9:13 AM Mark Thomas wrote: > > All, > > The last Tomcat Native releases were in July 2024. The Windows binaries > were built with 3.0.14. > > There are some low severity CVEs in 3.0.14 that we don't believe apply > to Tomcat's usage of OpenSSL but that may trigger a securit

Tomcat Native and OpenSSL 3.5.x

2025-05-22 Thread Mark Thomas
All, The last Tomcat Native releases were in July 2024. The Windows binaries were built with 3.0.14. There are some low severity CVEs in 3.0.14 that we don't believe apply to Tomcat's usage of OpenSSL but that may trigger a security scanner. There is a new OpenSSL LTS branch, 3.5.x, that in