On 23/09/2026 16:54, James H. H. Lampert via users wrote:
On 9/23/26 3:01 AM, Mark Thomas wrote:
- Remove the examples web application
My, this was an awful lot of security-related mitigation announcements.
Better get used to it. It is looking like this is the new normal. At
least for now.
First, please refresh my memory: on an IBM Midrange box, do connectors
in the general form
<Connector port="443"
protocol="org.apache.coyote.http11.Http11Protocol"
keystoreFile="<REDACTED Java keystore pathname>"
maxThreads="150" SSLEnabled="true" scheme="https" secure="true"
clientAuth="false" sslProtocol="TLSv1.2" />
(some of our more security-conscious customers have things a bit
tighter, like limits on acceptable ciphers) use OpenSSL in Tomcat 9?
It depends. If the AprLifecyleListener or OpenSSLLifecycleListener is
present they might. Check the logs. The connector name will be something
like https-jsse-nio-443 if it is using JSSE and https-openssl-nio-443 if
using OpenSSL (that example is for Tomcat Native).
Second, by "the examples web application" do you mean the default ROOT
context, or perhaps one of the other bundled webapp? Because we
routinely strip out every bundled webapp other than Manager, simply
because our own webapp is so enormous (we also have to expand the upload
limit in Manager by a full order of magnitude), and Manager is the only
bundled webapp that's of any practical use in the installations we manage.
I mean the web application with context path "/examples" that is
normally found at $CATALINA_BASE/webapps/examples.
Mark
---------------------------------------------------------------------
To unsubscribe, e-mail: [email protected]
For additional commands, e-mail: [email protected]