Re: [VOTE] Release Apache Tomcat Native 1.1.20

2010-02-11 Thread jean-frederic clere
vote. > It will be closed in about 72 hours > (or sooner if enough votes are encountered) > > > Apache Tomcat Native 1.1.20 is: > > [X] Stable - no major issues, no regressions Builds/Tests on all plaforms I am able to test. Cheers Jean-Frederic --

Re: Timing for 6.0.25?

2010-02-16 Thread jean-frederic clere
On 02/16/2010 12:52 PM, Mark Thomas wrote: > Mainly a question for Jean-Frederic, but what are the thoughts on aiming > for a 6.0.25 release quite soon? There were a handful of regressions in > 6.0.24 it would be good to fix. > +1 on my side :-) Cheers J

Re: Timing for 6.0.25?

2010-02-16 Thread jean-frederic clere
On 02/16/2010 05:15 PM, Mark Thomas wrote: > On 16/02/2010 14:03, jean-frederic clere wrote: >> On 02/16/2010 12:52 PM, Mark Thomas wrote: >>> Mainly a question for Jean-Frederic, but what are the thoughts on aiming >>> for a 6.0.25 release quite soon? There were

Re: jk/cluster - intelligent systems load

2010-02-18 Thread jean-frederic clere
ng SPDY implementation in tomcat, > inter-operable > with chrome/mod_spdy/google. If we start with this we'll probably make > more progress than by discussing protocols :-) Yep, I have noted that people are preparing an implementation for httpd so at some point it will just "porting" that code to TC. Cheers Jean-Frederic - To unsubscribe, e-mail: dev-unsubscr...@tomcat.apache.org For additional commands, e-mail: dev-h...@tomcat.apache.org

Re: jk/cluster - intelligent systems load

2010-02-19 Thread jean-frederic clere
is all that is needed thought. > Some of those are even displayed on status page > when it's loaded in inside the Tomcat. Additionally JAVA6 provide stats information on the JVM. Cheers Jean-Frederic - To unsubscribe, e-mail: dev-unsubscr...@tomcat.apache.org For additional commands, e-mail: dev-h...@tomcat.apache.org

Re: Prepping for a 6.0.25 release

2010-02-24 Thread jean-frederic clere
enough votes is the fix for > https://issues.apache.org/bugzilla/show_bug.cgi?id=48627 I have voted for this one. I will wait a while and then go for the release. Cheers Jean-Frederic - To unsubscribe, e-mail: dev-unsubscr...@tom

[VOTE] Release build 6.0.25

2010-02-24 Thread jean-frederic clere
The candidates binaries are available here: http://people.apache.org/~jfclere/tomcat-6/v6.0.25/ According to the release process, the 6.0.25 tag is: [ ] Broken [ ] Alpha [ ] Beta [ ] Stable Cheers Jean-Frederic - To

Re: [VOTE] Release Tomcat Connectors 1.2.29

2010-02-25 Thread jean-frederic clere
On 02/23/2010 04:06 PM, Mladen Turk wrote: > [X] Stable - no major issues, no regressions Looks ok in all my builds. Cheers Jean-Frederic - To unsubscribe, e-mail: dev-unsubscr...@tomcat.apache.org For additional commands

Re: [VOTE] Release build 6.0.25

2010-02-25 Thread jean-frederic clere
On 02/25/2010 01:07 PM, Tim Funk wrote: > So far all looks OK - but due to the version issue - I vote: > [X] Broken > > I believe rebuilding with an updated properties (no retag needed) should > fix the issue. Yep it is just a packaging problem. Cheers

Re: svn commit: r917921 - in /tomcat/native/branches/1.1.x: java/org/apache/tomcat/jni/SSL.java native/include/ssl_private.h native/src/ssl.c native/src/sslcontext.c xdocs/miscellaneous/changelog.xml

2010-03-02 Thread jean-frederic clere
che.org/viewvc?rev=881179&view=rev ? Cheers Jean-Frederic - To unsubscribe, e-mail: dev-unsubscr...@tomcat.apache.org For additional commands, e-mail: dev-h...@tomcat.apache.org

Re: svn commit: r917921 - in /tomcat/native/branches/1.1.x: java/org/apache/tomcat/jni/SSL.java native/include/ssl_private.h native/src/ssl.c native/src/sslcontext.c xdocs/miscellaneous/changelog.xml

2010-03-02 Thread jean-frederic clere
On 03/02/2010 05:47 PM, Mladen Turk wrote: > On 03/02/2010 05:43 PM, jean-frederic clere wrote: >> On 03/02/2010 09:51 AM, mt...@apache.org wrote: >>> Author: mturk >>> Date: Tue Mar 2 08:51:46 2010 >>> New Revision: 917921 >>> >>> URL: ht

Re: Tomcat 5.5 release

2010-03-02 Thread jean-frederic clere
On 03/02/2010 08:54 PM, Filip Hanik - Dev Lists wrote: > Time for another one folks? Should I tag end of this week? +1 Cheers Jean-Frederic - To unsubscribe, e-mail: dev-unsubscr...@tomcat.apache.org For additional commands

[RESULTS][VOTE] Release build 6.0.25

2010-03-02 Thread jean-frederic clere
Stable [3] Broken [2] So we go for a 6.0.26. Please commit the stuff voted in STATUS.txt Comments? Cheers Jean-Frederic - To unsubscribe, e-mail: dev-unsubscr...@tomcat.apache.org For additional commands, e-mail: dev-h

Re: [RESULTS][VOTE] Release build 6.0.25

2010-03-03 Thread jean-frederic clere
On 03/04/2010 04:04 AM, Rex Wang wrote: > Hi, any plan when will 6.0.26 released? Our project has a dependency on it.. There is still a regression to vote (and test): bug 48827. If no other problems the release should happen early next week. Cheers Jean-Frederic > > Thanks > >

[GSoC Projects Available] Issue Navigator - ASF JIRA

2010-03-04 Thread jean-frederic clere
Hi, Just that JIRA stuff has been created for the GSoC. Should we move our entries there? Cheers Jean-Frederic https://issues.apache.org/jira/secure/IssueNavigator.jspa?mode=hide&requestId=12314021 - To unsubscribe, e-

Re: svn commit: r919515 - /tomcat/tc6.0.x/trunk/STATUS.txt

2010-03-05 Thread jean-frederic clere
related to the actual change proposed here? Oops that should just fix the examples. Mark already fixed the part that broke all the application. Cheers Jean-Frederic > > > > - &g

Re: svn commit: r919515 - /tomcat/tc6.0.x/trunk/STATUS.txt

2010-03-05 Thread jean-frederic clere
yDirectory SEVERE: Erreur lors du d?ploiement du r?pertoire erablex de l'application web Throwable occurred: java.lang.NoClassDefFoundError: org.apache.catalina.session.StandardManager (initialization failure) at java.lang.J9VMInternals.initialize(J9VMInternals.java:140)

Re: LocalProperties

2010-03-05 Thread jean-frederic clere
On 03/05/2010 09:24 PM, Henri Gomez wrote: > Hi to all, > > I sent some patches to Jean-Fred about the LocalString_fr.properties. I have noticed it is in fact fix in trunk but not in tc6.0.x I have submitted a new proposal. Please double check... It is not my day today :-/ Cheers Jean

tagging 6.0.26

2010-03-05 Thread jean-frederic clere
Hi, I plan to tag 6.0.26 on Sunday evening (Neuchatel time) and release on Monday. Comments? Cheers Jean-Frederic - To unsubscribe, e-mail: dev-unsubscr...@tomcat.apache.org For additional commands, e-mail: dev-h

Re: tagging 6.0.26

2010-03-08 Thread jean-frederic clere
On 03/06/2010 10:55 AM, Mark Thomas wrote: > On 06/03/2010 06:54, jean-frederic clere wrote: >> Hi, >> >> I plan to tag 6.0.26 on Sunday evening (Neuchatel time) and release on >> Monday. >> Comments? > > +1. Do you really mean release on Monday? hm... Star

Re: tagging 6.0.26

2010-03-08 Thread jean-frederic clere
On 03/08/2010 09:35 AM, Mark Thomas wrote: > On 08/03/2010 08:09, jean-frederic clere wrote: >> On 03/06/2010 10:55 AM, Mark Thomas wrote: >>> On 06/03/2010 06:54, jean-frederic clere wrote: >>>> Hi, >>>> >>>> I plan to tag 6.0.26 on Sund

Re: tagging 6.0.26

2010-03-08 Thread jean-frederic clere
On 03/08/2010 12:01 PM, Konstantin Kolinko wrote: > 2010/3/8 jean-frederic clere : >> On 03/08/2010 09:35 AM, Mark Thomas wrote: >>> On 08/03/2010 08:09, jean-frederic clere wrote: >>>> On 03/06/2010 10:55 AM, Mark Thomas wrote: >>>>> On 06/03/201

Re: [VOTE] C-T-R for any translation fixes

2010-03-08 Thread jean-frederic clere
e manner, RTC has > worked well for that That is also what I am thinking, more eyes to spot errors warrants a more stable tomcat. Cheers Jean-Frederic - To unsubscribe, e-mail: dev-unsubscr...@tomcat.apache.org For additional c

Re: tagging 6.0.26

2010-03-09 Thread jean-frederic clere
On 03/09/2010 04:58 PM, Konstantin Kolinko wrote: > 2010/3/9 Konstantin Kolinko : >> Do not forget to update both >> version.minor >> version.suffix > > I meant > version.build > version.suffix Yep. I will double check that. - T

Re: tagging 6.0.26

2010-03-09 Thread jean-frederic clere
On 03/09/2010 04:59 PM, Henri Gomez wrote: > And to include french translations fixes :) those are r920841 - To unsubscribe, e-mail: dev-unsubscr...@tomcat.apache.org For additional commands, e-mail: dev-h...@tomcat.apache.org

[VOTE] Release build 6.0.26

2010-03-09 Thread jean-frederic clere
The candidates binaries are available here: http://people.apache.org/~jfclere/tomcat-6/v6.0.26/ According to the release process, the 6.0.26 tag is: [ ] Broken [ ] Alpha [ ] Beta [ ] Stable Cheers Jean-Frederic - To

Re: Reusing instances

2010-03-10 Thread jean-frederic clere
er mpm. > > That was on of the reasons we kill JK2. > JNI inproc connector simply didn't work. One of the big problem is that the prefork and worker models may use several process for the same session and you can't fix a session to a JVM process... At the end you needed a flat clu

Re: svn commit: r921464 - in /tomcat/trunk/java/org/apache/jasper: JspCompilationContext.java servlet/JspServletWrapper.java

2010-03-11 Thread jean-frederic clere
JSPs in production are something we need to handle > then we could make this dependent on the setting of the development mode. > > Thoughts? Or have an additional switch for that. Cheers Jean-Frederic - To unsubscribe, e-mail: dev-unsubscr...@tomcat.apache.org For additional commands, e-mail: dev-h...@tomcat.apache.org

[RESULTS][VOTE] Release build 6.0.26

2010-03-11 Thread jean-frederic clere
Stable [6] So I will go on with the release process. Comments? Cheers Jean-Frederic - To unsubscribe, e-mail: dev-unsubscr...@tomcat.apache.org For additional commands, e-mail: dev-h...@tomcat.apache.org

Re: Tomcat 6.0.26 docs on the site - not replicated

2010-03-11 Thread jean-frederic clere
e I was modifying the files in people.apache.org. The download is also broken and there the permissions are ok. > > cd tomcat-6.0-doc > chmod -R g+w * > would fix that Done Cheers Jean-Frederic - To unsubscribe, e-m

Re: Reusing instances

2010-03-11 Thread jean-frederic clere
On 03/11/2010 05:27 PM, Mladen Turk wrote: > More important one is to use the web server connectors directly. > It's not about speed, but about eliminating connector as a > point of failure. > hm You still have to move the data for httpd (in C) to Tomcat (in JAVA) so you still have a connector, n

[ANN] Apache Tomcat 6.0.26 released

2010-03-11 Thread jean-frederic clere
The Apache Tomcat team announces the immediate availability of Apache Tomcat 6.0.26 stable. This release includes bug-fixes over Apache Tomcat 6.0.24. Note that is version has 4 zip binaries: a generic one and three bundled with Tomcat native binaries for different CPU architectures. Apache Tomca

Re: [Tomcat Wiki] Update of "SummerOfCode2010" by JeanFredericClere

2010-03-12 Thread jean-frederic clere
The JIRA are needed just for http://tinyurl.com/asfgsoc Cheers Jean-Frederic - To unsubscribe, e-mail: dev-unsubscr...@tomcat.apache.org For additional commands, e-mail: dev-h...@tomcat.apache.org

Re: [RESULT] (Was: [VOTE] C-T-R for any translation fixes)

2010-03-17 Thread jean-frederic clere
l > 0: Filip > > RESULT: Passes > >> 6. Require some indication in the commit message for code that usually is >> covered by RTC, that this commit was done using C-T-R rule. > > +1: Mladen, Rainer, Bi

Tomcat at the next ApacheCon

2010-03-18 Thread jean-frederic clere
Note we have until the Sunday, March 21st to collect that information. Cheers Jean-Frederic - To unsubscribe, e-mail: dev-unsubscr...@tomcat.apache.org For additional commands, e-mail: dev-h...@tomcat.apache.org

Re: Tomcat at the next ApacheCon

2010-03-18 Thread jean-frederic clere
On 03/18/2010 05:05 PM, Mladen Turk wrote: > On 03/18/2010 05:00 PM, jean-frederic clere wrote: >> >> Note we have until the Sunday, March 21st to collect that information. >> > > I'm always amazed with the fact that each conference > planner need your prop

Re: Tomcat at the next ApacheCon

2010-03-18 Thread jean-frederic clere
On 03/18/2010 05:33 PM, Mladen Turk wrote: > On 03/18/2010 05:19 PM, jean-frederic clere wrote: >>> >>> I'm always amazed with the fact that each conference >>> planner need your proposals by yesterday. >> >> Well they were asking that the 16th,

Re: [GSoC] Regarding JSR 196 implementation project idea

2010-03-22 Thread jean-frederic clere
e org/apache/coyote/spdy (like we already have the org/apache/coyote/http11 and org/apache/coyote/ajp). There is already mod_spdy for httpd in http://code.google.com/p/mod-spdy/wiki/Design so you can have a look there to see how a SPDY server should work. Cheers Jean-Frederic --

Re: Interested in GSOC ideas

2010-04-01 Thread jean-frederic clere
; mentor in above links. > I like the 'SPDY connector' idea too...but because it's still draft > version, will it become a problem to qualify? No. > I mean will it get approved when i make a proposal? > I hope it will. Che

Re: GSoC Tomcat SPDY Connectors

2010-04-06 Thread jean-frederic clere
On 04/05/2010 06:11 AM, Costin Manolache wrote: > next protocol negotiation http://tools.ietf.org/html/draft-agl-tls-nextprotoneg-00.html Cheers Jean-Frederic - To unsubscribe, e-mail: dev-unsubscr...@tomcat.apache.org

Re: [VOTE] Release Tomcat 7.0.0 based on Tomcat 7.0.0 RC1

2010-04-14 Thread jean-frederic clere
oken - do not release > [ ] Alpha - go ahead and release 7.0.0 Stable based on 7.0.0-RC1 > [X] Beta - go ahead and release 7.0.0 Beta based on 7.0.0-RC1 The APR gives some errors for example Address already in use :8080 on my Linux box. All other test/plaforms look ok. Cheers Jean-

Re: [VOTE] Release Tomcat 7.0.0 based on Tomcat 7.0.0 RC1

2010-04-14 Thread jean-frederic clere
On 04/14/2010 03:50 PM, Mark Thomas wrote: > On 14/04/2010 14:35, jean-frederic clere wrote: >> On 04/14/2010 12:34 PM, Mark Thomas wrote: > >>> The 7.0.0-RC1 tag is >>> [ ] Broken - do not release >>> [ ] Alpha - go ahead and release 7.0.0 Stable based on

Re: [VOTE] Release Tomcat 7.0.0 based on Tomcat 7.0.0 RC1

2010-04-14 Thread jean-frederic clere
On 04/14/2010 04:13 PM, Mladen Turk wrote: > On 04/14/2010 03:35 PM, jean-frederic clere wrote: >> On 04/14/2010 12:34 PM, Mark Thomas wrote: >> >> The APR gives some errors for example Address already in use:8080 >> on my Linux box. All other test/plaforms look ok. >

Re: [VOTE] Release Tomcat 7.0.0 based on Tomcat 7.0.0 RC1

2010-04-15 Thread jean-frederic clere
to work on java/org/apache/coyote/http11/Http11AprProcessor.java ... The missing code is already in the Bio connector some how it is a kind of copy + paste + fix. Cheers Jean-Frederic - To unsubscribe, e-mail: dev-unsubscr...@tomcat.apache.org For additional commands, e-mail: dev-h...@tomcat.apache.org

Re: Tomcat Job Opportunities at SpringSource

2010-04-27 Thread jean-frederic clere
On 04/28/2010 05:14 AM, Karl San Gabriel wrote: > Is this valid for non-US citizens? There is a list j...@apache.org for ASF related jobs, please use that one for this topic. Cheers Jean-Frederic - To unsubscribe, e-mail:

Re: AJP Protocol enhancements

2015-09-25 Thread jean-frederic clere
out the contents once upgraded). So adding upgrade to AJP won't help much. Additionally I think websockets via upgrade is dead, there won't be new developments there. I would just let AJP dying in peace. Cheers Jean-Frederic

Re: svn commit: r1706858 - /tomcat/trunk/java/org/apache/coyote/http2/Http2UpgradeHandler.java

2015-10-06 Thread jean-frederic clere
demo from the ApacheCon now the status of http/2 is: FF : apr OK, nio NOTOK and nio2 NOTOK. Chrome: apr OK nio OK and nio2 NOTOK (chrome still gives an error with nio2, something like a timeout). Cheers Jean-Frederic

Re: Plan for 9.0.0.RC1

2015-10-19 Thread jean-frederic clere
list. Cool but note it requires a quite new openssl I would like to see how it can work without APR. Cheers Jean-Frederic - To unsubscribe, e-mail: dev-unsubscr...@tomcat.apache.org For additional commands, e-mail: dev-h...@tomcat.apache.org

Re: Plan for 9.0.0.RC1

2015-10-22 Thread jean-frederic clere
opportunity to test >> the tcnative binaries) and I see what looks to be the same problem with >> Chrome + NIO2 in that no images are displayed. Even a simple HTTP/2 page >> fails. >> > > That's what I get. Nice test since I had never tried the OpenSSL engin

Re: Plan for 9.0.0.RC1

2015-10-23 Thread jean-frederic clere
. Cool. My demo is now working for all connectors. > > I have put in a work-around but I'm not sure it is in the right place. > This feels like something that should be fixed at a lower level > (tcnative?) so a call to unwrap unwarps as much as possible. Well the

Re: [VOTE] Release Apache Tomcat Native 1.2.0

2015-10-27 Thread jean-frederic clere
The Apache Tomcat Native 1.2.0 is > [X] Stable, go ahead and release We need to get more people using it ;-) Cheers Jean-Frederic - To unsubscribe, e-mail: dev-unsubscr...@tomcat.apache.org For additional commands, e-mail: dev-h...@tomcat.apache.org

Re: Tomcat 9.0.x, tc-native and itanium support

2015-10-27 Thread jean-frederic clere
On 10/22/2015 12:31 PM, Mark Thomas wrote: > how do folks feel about dropping the Itanium build from > the binary packages for tcnative 1.2.x and Tomcat 9.0.x? DROP IT!!! Cheers Jean-Frederic - To unsubscribe, e-mai

Re: [VOTE] Switch 6.0.x from RTC to CTR

2015-10-29 Thread jean-frederic clere
On 10/28/2015 11:42 PM, Mark Thomas wrote: > [X] Switch 6.0.x to CTR Basically there are so few fixes in 6.0.x that the RTC blocks any move in 6.0.x Cheers Jean-Frederic - To unsubscribe, e-mail: dev-unsub

Re: [VOTE][RESULT] Release Apache Tomcat Native 1.2.0

2015-10-30 Thread jean-frederic clere
lib/jvm/java-1.8.0-openjdk-1.8.0.60-14.b27.fc22.x86_64 --with-ssl=$HOME/OPENSSL-1.0.2c make clean make Well I tested the tag as I am rebuild always from svn repo. Cheers Jean-Frederic > > Regards > > 2015-10-28 3:33 GMT+01:00 Mark Thomas : > >> The following votes were

Re: Tomcat Native 1.2.2

2015-11-04 Thread jean-frederic clere
he day. I am trying some small changes to allow to use the keystore with the openssl engine, I need a few days more, do you want to wait or should we add that later. Cheers Jean-Frederic > > Mark > > - > T

Re: svn commit: r1715414 - in /tomcat/trunk: java/org/apache/catalina/ java/org/apache/catalina/core/ java/org/apache/catalina/mapper/ java/org/apache/catalina/mbeans/ java/org/apache/catalina/storeco

2015-11-22 Thread jean-frederic clere
threw exception java.lang.NoSuchMethodException: org.apache.catalina.core.StandardService setContainer at org.apache.tomcat.util.IntrospectionUtils.callMethod1(IntrospectionUtils.java:360) at org.apache.tomcat.util.digester.SetNextRule.end(SetNextRule.java:145) +++ Cheers Jean-Fr

Re: svn commit: r1715414 - in /tomcat/trunk: java/org/apache/catalina/ java/org/apache/catalina/core/ java/org/apache/catalina/mapper/ java/org/apache/catalina/mbeans/ java/org/apache/catalina/storeco

2015-11-22 Thread jean-frederic clere
On 11/22/2015 01:25 PM, Mark Thomas wrote: > On 22 November 2015 10:40:07 GMT+00:00, jean-frederic clere > wrote: >> On 11/20/2015 09:28 PM, ma...@apache.org wrote: >>> -public void setContainer(Container container) { >>> -setContainer((Engine) con

Re: svn commit: r1715414 - in /tomcat/trunk: java/org/apache/catalina/ java/org/apache/catalina/core/ java/org/apache/catalina/mapper/ java/org/apache/catalina/mbeans/ java/org/apache/catalina/storeco

2015-11-22 Thread jean-frederic clere
On 11/22/2015 05:03 PM, Mark Thomas wrote: > I've fixed the digester rules in trunk so you shouldn't need your patch > any more. Thanks Jean-Frederic - To unsubscribe, e-mail: dev-unsubscr...@tomcat.apache.or

Re: svn commit: r1715732 - /tomcat/trunk/java/org/apache/tomcat/util/net/openssl/OpenSSLUtil.java

2015-11-23 Thread jean-frederic clere
ill fix the code later today. Cheers Jean-Frederic - To unsubscribe, e-mail: dev-unsubscr...@tomcat.apache.org For additional commands, e-mail: dev-h...@tomcat.apache.org

Re: svn commit: r1715732 - /tomcat/trunk/java/org/apache/tomcat/util/net/openssl/OpenSSLUtil.java

2015-11-23 Thread jean-frederic clere
On 11/23/2015 03:35 PM, Rémy Maucherat wrote: > 2015-11-23 15:31 GMT+01:00 jean-frederic clere : > >> On 11/23/2015 01:56 PM, Konstantin Kolinko wrote: >>> TW, a changelog, documentation =? >> >> Here I have a small question. In fact it possible to mix ope

Re: Time for a 6.0.x release in January?

2015-12-22 Thread jean-frederic clere
On 12/22/2015 10:23 AM, Mark Thomas wrote: > All, > > It has been over 6 months since the last 6.0.x release. The changelog > for 6.0.x is reasonably long so it is looks like time for a release. > > Jean-Frederic or I have done the last few releases. Are there any > volun

[ANN] Apache Tomcat Native 1.2.17 released

2018-06-19 Thread Jean-Frederic Clere
The Apache Tomcat team announces the immediate availability of Apache Tomcat Native 1.2.17 stable. The key features of this release are: - Windows binaries built with APR 1.6.3 and OpenSSL 1.0.2o. - Fix Certificate verification using CRL. - Arrange OCSP response processing. Note that users shoul

[SECURITY] CVE-2018-8019 Apache Tomcat Native Connector - Mishandled OCSP invalid response

2018-07-21 Thread Jean-Frederic Clere
CVE-2018-8019 Apache Tomcat Native Connector - Mishandled OCSP invalid response Severity: Moderate Vendor: The Apache Software Foundation Versions Affected: Apache Tomcat Native 1.2.0 to 1.2.16 Apache Tomcat Native 1.1.23 to 1.1.34 Description: When using an OCSP responder Tomcat Native did not

[SECURITY] CVE-2018-8020 Apache Tomcat Native Connector - Mishandled OCSP responses can allow clients to authenticate with revoked certificates

2018-07-21 Thread Jean-Frederic Clere
CVE-2018-8020 Apache Tomcat Native Connector - Mishandled OCSP responses can allow clients to authenticate with revoked certificates Severity: Important Vendor: The Apache Software Foundation Versions Affected: Apache Tomcat Native 1.2.0 to 1.2.16 Apache Tomcat Native 1.1.23 to 1.1.34 Descript

[SECURITY] CVE-2018-1336 Apache Tomcat - Denial of Service

2018-07-22 Thread Jean-Frederic Clere
CVE-2018-1336 Apache Tomcat - Denial of Service Severity: Important Vendor: The Apache Software Foundation Versions Affected: Apache Tomcat 9.0.0.M9 to 9.0.7 Apache Tomcat 8.5.0 to 8.5.30 Apache Tomcat 8.0.0.RC1 to 8.0.51 Apache Tomcat 7.0.28 to 7.0.86 Description: An improper handing of overf

[SECURITY] CVE-2018-8037 Apache Tomcat - Information Disclosure

2018-07-22 Thread Jean-Frederic Clere
CVE-2018-8037 Apache Tomcat - Information Disclosure Severity: Important Vendor: The Apache Software Foundation Versions Affected: Apache Tomcat 9.0.0.M9 to 9.0.9 Apache Tomcat 8.5.5 to 8.5.31 Description: A bug in the tracking of connection closures can lead to reuse of user sessions in a new

[SECURITY] CVE-2018-8034 Apache Tomcat - Security Constraint Bypass

2018-07-22 Thread Jean-Frederic Clere
CVE-2018-8034 Apache Tomcat - Security Constraint Bypass Severity: Low Vendor: The Apache Software Foundation Versions Affected: Apache Tomcat 9.0.0.M1 to 9.0.9 Apache Tomcat 8.5.0 to 8.5.31 Apache Tomcat 8.0.0.RC1 to 8.0.52 Apache Tomcat 7.0.35 to 7.0.88 Description: The host name verification

https://repository.apache.org/content/repositories/snapshots/org/apache/tomcat/tomcat-dbcp/9.0-SNAPSHOT

2018-08-06 Thread jean-frederic clere
Hi, I have a question about using those snapshots: How are they produced? -- Cheers Jean-Frederic - To unsubscribe, e-mail: dev-unsubscr...@tomcat.apache.org For additional commands, e-mail: dev-h...@tomcat.apache.org

Re: https://repository.apache.org/content/repositories/snapshots/org/apache/tomcat/tomcat-dbcp/9.0-SNAPSHOT

2018-08-06 Thread jean-frederic clere
On 06/08/18 16:34, Mark Thomas wrote: > On 06/08/18 15:26, jean-frederic clere wrote: >> Hi, >> >> I have a question about using those snapshots: How are they produced? > > The buidlbot jobs that run after every commit generate and upload them. > It is only configu

DBCP2 in Tomcat

2018-08-07 Thread jean-frederic clere
Hi, I just want to ask what is the process, we pick all changes after commons-dbcp releases a version, or could I pick the actual code? -- Cheers Jean-Frederic - To unsubscribe, e-mail: dev-unsubscr...@tomcat.apache.org For

Re: DBCP2 in Tomcat

2018-08-07 Thread jean-frederic clere
On 07/08/18 10:10, Mark Thomas wrote: > On 07/08/18 08:55, jean-frederic clere wrote: >> Hi, >> >> I just want to ask what is the process, we pick all changes after >> commons-dbcp releases a version, or could I pick the actual code? > > Generally, I keep an e

ant problems

2018-08-09 Thread jean-frederic clere
Hi, I have problems while building trunk: /home/jfclere/TMP/tomcat/build.xml:693: javac doesn't support the "release" attribute Is that expected I have tried java11 and java8 (openjdk)? -- Cheers Jean-Frederic -

tomcat-native trunk

2018-09-03 Thread jean-frederic clere
Hi, I am working on a jar to laod the libraries in tomcat-native. I have noted that the examples don't compile and that the test directory is empty. I am planning to clean that and go for maven build for the new jar. Comments? -- Cheers Jean-Fre

Re: tomcat-native trunk

2018-09-03 Thread jean-frederic clere
On 03/09/18 12:31, Rainer Jung wrote: > Am 03.09.2018 um 11:41 schrieb Mark Thomas: >> On 03/09/18 09:38, jean-frederic clere wrote: >>> Hi, >>> >>> I am working on a jar to laod the libraries in tomcat-native. I have >>> noted that the examples

Re: [VOTE] Release Apache Tomcat 9.0.12

2018-09-06 Thread jean-frederic clere
On 05/09/18 00:32, Mark Thomas wrote: > [X] Stable - go ahead and release as 9.0.12 Tested on fedora 28. -- Cheers Jean-Frederic - To unsubscribe, e-mail: dev-unsubscr...@tomcat.apache.org For additional commands, e-mail:

Re: [VOTE] Release Apache Tomcat 8.5.0

2016-03-18 Thread jean-frederic clere
On 03/18/2016 03:47 PM, Mark Thomas wrote: > On 18/03/2016 14:44, jean-frederic clere wrote: >> On 03/17/2016 09:00 PM, Mark Thomas wrote: >>> [x] Alpha - go ahead and release as 8.5.0 >> >> I have failure in the following tests:

Re: [VOTE] Release Apache Tomcat 8.5.0

2016-03-18 Thread jean-frederic clere
as openssl might not have the cipher we have in JSSE and I don't think that should be considered as an issue. I need to have a closer look but the results seem to depend on openssl version. Cheers Jean-Frederic - To unsubs

Re: Time for tc-native 1.2.6

2016-04-18 Thread jean-frederic clere
SSL > example/apps code and it could well be, that we should replace a bigger > part of that code with some pre-cooked cert validation function (call) > in OpenSSL. Is mod_ssl also affected by those API changes? Cheers Jean-Frederic - To unsubscribe, e-mail: dev-unsubscr...@tomcat.apache.org For additional commands, e-mail: dev-h...@tomcat.apache.org

Re: svn commit: r1741984 - in /tomcat/trunk: java/org/apache/coyote/ java/org/apache/coyote/ajp/ java/org/apache/coyote/http11/ java/org/apache/coyote/http11/upgrade/ java/org/apache/coyote/http2/ web

2016-05-02 Thread jean-frederic clere
unning configured as: +++ +++ thanks Jean-Frederic - To unsubscribe, e-mail: dev-unsubscr...@tomcat.apache.org For additional commands, e-mail: dev-h...@tomcat.apache.org

Re: Timescale for 8.0.x EOL

2016-06-15 Thread jean-frederic clere
be security supported at least until the Debian 9 >>> release (~April/May 2017) it would allow users following the stable >>> distribution to remain on a supported version of Tomcat (Debian 9 will >>> include Tomcat 8.5). >> >> That is unlikely unless someone

Re: Timescale for 8.0.x EOL

2016-06-20 Thread jean-frederic clere
at > point > - security fixes will probably be back-ported > - further releases will depend on circumstances but are unlikely to be > more frequent that 6 monthly +1 I will try to find the cycles to be the RM from September on

Re: OpenSSL without APR experiment

2016-06-27 Thread jean-frederic clere
huge difference in latest tests between the native connector and the NIO/NIO2 with openssl basically APR looked to have a problem with tomcat 8.5.x I didn't had to investigate. I am planning to redo tests soon... And put my slides online :D Cheers Jean-Frederic > >> >> If the

Re: svn commit: r1750514 - in /tomcat/native/trunk: native/src/ssl.c xdocs/miscellaneous/changelog.xml

2016-06-28 Thread jean-frederic clere
quite where I excepted it. Cheers Jean-Frederic - To unsubscribe, e-mail: dev-unsubscr...@tomcat.apache.org For additional commands, e-mail: dev-h...@tomcat.apache.org

Re: [VOTE] Release Apache Tomcat Native 1.2.8

2016-06-30 Thread jean-frederic clere
ease artefacts can be found at [1], > and the build was done using tag [2]. > > The Apache Tomcat Native 1.2.8 is > [X] Stable, go ahead and release According to my tests there is an improvement with the apr connector (See http://www.slideshare.net/jfclere/n

Re: JSSE-based crypto performance

2016-09-30 Thread jean-frederic clere
, I complained and got a patch. I never had a real hardware accelerator to try so I can't tell, we have customers using hardware accelerators but that is through tomcat-native and openssl. Cheers Jean-Frederic signature.asc Description: OpenPGP digital signature

try to release taglibs-standard-1.2.6

2017-04-30 Thread jean-frederic clere
Hi, I will try to tag and propose taglibs-standard-1.2.6 for release tomorrow, any comments? Cheers Jean-Frederic - To unsubscribe, e-mail: dev-unsubscr...@tomcat.apache.org For additional commands, e-mail: dev-h

http://svn.apache.org/viewvc/tomcat/taglibs/standard/ in git?

2016-11-08 Thread jean-frederic clere
Hi, Anyone knows we have a git mirror of the taglibs? What would be the process to get it? Ticket to infra? Cheers Jean-Frederic - To unsubscribe, e-mail: dev-unsubscr...@tomcat.apache.org For additional commands, e-mail: dev

Re: TomcatCon @ ApacheCon

2017-01-09 Thread jean-frederic clere
hat makes sense since the ApacheCon I have done 2 JUGs on tomcat-8.5, got a bunch of questions and requests to do more of the same. Cheers Jean-Frederic > > I've started a discussion on the users list. > > All help, support, ideas etc. welc

Re: [POLL] Will you be at ApacheCon NA 2017?

2017-01-27 Thread jean-frederic clere
ion at TomcatCon: > > [ X ] Yes > [ ] Maybe > [ ] No > > If you have an idea / some ideas about potential session topics please > feel free to suggest them. The ideas so far are summarized on the wiki > [1]. Both new suggestions and amendments to existing ideas

Re: [VOTE-RESTARTED] Release Apache Tomcat Native 1.2.4

2016-01-08 Thread jean-frederic clere
On 01/06/2016 01:56 PM, Mark Thomas wrote: > On 05/01/2016 15:46, Mark Thomas wrote: >> Version 1.2.4 includes the following change: >> >> - Renegotiation improvements >> >> The proposed release artefacts can be found at [1], >> and the build was done using tag [2]. >> >> The Apache Tomcat Native 1

Re: [VOTE-RESTARTED] Release Apache Tomcat Native 1.2.4

2016-01-08 Thread jean-frederic clere
t across from 1.2.3 if > people think it is essential. It is probably better to have it as building on windows is a challenge for a lot of people. Cheers Jean-Frederic - To unsubscribe, e-mail: dev-unsubscr...@tomcat.apache.org For additional commands, e-mail: dev-h...@tomcat.apache.org

tagging tomcat 6.0.45

2016-01-08 Thread jean-frederic clere
Hi, I am planning to test and tag tomcat 6.0.45 during the week-end. Any objections? Cheers Jean-Frederic - To unsubscribe, e-mail: dev-unsubscr...@tomcat.apache.org For additional commands, e-mail: dev-h...@tomcat.apache.org

Re: tagging tomcat 6.0.45

2016-01-10 Thread jean-frederic clere
On 01/08/2016 11:28 PM, Mark Thomas wrote: > On 08/01/2016 14:21, jean-frederic clere wrote: >> Hi, >> >> I am planning to test and tag tomcat 6.0.45 during the week-end. >> >> Any objections? > > I'm working on some session stuff that really should

Re: tagging tomcat 6.0.45

2016-01-10 Thread jean-frederic clere
On 01/08/2016 07:27 PM, Konstantin Kolinko wrote: > 2016-01-08 17:21 GMT+03:00 jean-frederic clere : >> Hi, >> >> I am planning to test and tag tomcat 6.0.45 during the week-end. > > 1) A bug in a new feature: > https://bz.apache.org/bugzilla/show_bug.cgi?id=5

dropping windows ia64 in Tomcat6

2016-01-10 Thread jean-frederic clere
Hi, I would like to drop Itanium support in the windows binaries, we have dropped it in native 1.1.34 so we can't have a complete Itanium in Tomcat 6.0.45. Comments? Cheers Jean-Frederic - To unsubscribe, e-mail

Re: [VOTE-RESTARTED] Release Apache Tomcat Native 1.2.4

2016-01-11 Thread jean-frederic clere
On 01/11/2016 03:10 PM, Giorgio Zoppi wrote: > Jean, > trying to move to CMake for making portable? That might be something to look at my previous tries with CMake weren't successful but feel free to contribute. Cheers Je

Re: openssl 1.0.2f released

2016-01-28 Thread jean-frederic clere
; So I think we don't *need* a new tcnative. More eyes/thoughts welcome. > > Having reviewed the OpenSSL announcement and the tomcta-native code, I > agree with your assessment. So I will process with the tomcat6 release process during the week-end to get a release during next wee

tagging tomcat 6.0.45 (try2)

2016-01-29 Thread jean-frederic clere
Hi, I am planning to test and tag tomcat 6.0.45 during the week-end. Mark has fixed his session stuff and the openssl we use isn't affected with the latest vulnerability. Any objections? Cheers Jean-Frederic - To unsubs

Re: tagging tomcat 6.0.45 (try2)

2016-01-31 Thread jean-frederic clere
On 01/31/2016 07:47 PM, Konstantin Kolinko wrote: > 2016-01-30 15:54 GMT+03:00 Konstantin Kolinko : >> 2016-01-29 18:50 GMT+03:00 jean-frederic clere : >>> Hi, >>> >>> I am planning to test and tag tomcat 6.0.45 during the week-end. >>> >>> M

[VOTE] Release Apache Tomcat 6.0.45

2016-02-01 Thread jean-frederic clere
/repos/asf/tomcat/tc6.0.x/tags/TOMCAT_6_0_45/ The proposed 6.0.45 release is: [ ] Broken - do not release [ ] Stable - go ahead and release as 6.0.45 Stable Cheers Jean-Frederic - To unsubscribe, e-mail: dev-unsubscr

<    1   2   3   4   5   6   7   8   9   >