Your message dated Mon, 11 May 2015 11:35:17 +0000 with message-id <[email protected]> and subject line Bug#737969: fixed in tomcat-native 1.1.33-1 has caused the Debian Bug report #737969, regarding libtcnative-1 breaks Tomcat's 'SSLProtocols' to be marked as done.
This means that you claim that the problem has been dealt with. If this is not the case it is now your responsibility to reopen the Bug report if necessary, and/or fix the problem forthwith. (NB: If you are a system administrator and have no idea what this message is talking about, this may indicate a serious mail system misconfiguration somewhere. Please contact [email protected] immediately.) -- 737969: http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=737969 Debian Bug Tracking System Contact [email protected] with problems
--- Begin Message ---Package: libtcnative-1 Version: 1.1.24-1 Severity: important Symptoms: The Tomcat 'SSLProtocol' configuration attribute is documented as accepting several values, but on Debian 7/Wheezy (and presumably others) only the values "SSLv3" and "TLSv1" are accepted; notably the default value of "all" is rejected. Cause: The Debian packaging of 'libtcnative-1' contains a patch that simply removes the 'SSL_PROTOCOL_SSLV2' bitmask constant and related code, but does not remove it from the matching Tomcat sources. So some other bitmask constants in the Tomcat sources contain that bitmask constant, and therefore will never match the supposedly equivalent bitmasks in 'libtcnative-1'. Comments: Given that 'libtcnative-1' is essentially a Tomcat internal plugin, a native implementation of a Tomcat Java API, introducing an incompatibility between interface and implementation creates a surprising, undocumented, user-visible breakage. Anyhow it seems to me misguided to simply disable SSLv2 in 'libtcnative-1' on other grounds: * The other role of 'libtcnative-1' is as wrapper around 'libopenssl', and the maintainers of that, both upstream and Debian ones, have not felt any need to disable SSLv2 entirely within it. Just like the Tomcat ones, both upstream and Debian, have also felt no need to entirely disable SSLv2 in it either. It is amazing that a library that is a bit of glue between Tomcat and OpenSSL prevents the use of a feature that both explicitly support. * Some aspects of the SSLv2 protocol, in particular the SSLV2 "hello", supported by the 'SSLv23*' OpenSSL functions, are widely used by clients, even when SSLv2 itself is not used. It also quite safe to use the 'SSLv23*' OpenSSL functions by setting the cipher suites to "HIGH:MEDIUM" as that disables all the SSLv2 ciphers, making SSLv2 native negotiation fail. * Perhaps it would be sufficient to print a warning message when SSLv2 is requested, but this should be done in Tomcat, not in a user-invisible glue layer between Tomcat and OpenSSL.
--- End Message ---
--- Begin Message ---Source: tomcat-native Source-Version: 1.1.33-1 We believe that the bug you reported is fixed in the latest version of tomcat-native, which is due to be installed in the Debian FTP archive. A summary of the changes between this version and the previous one is attached. Thank you for reporting the bug, which will now be closed. If you have further comments please address them to [email protected], and the maintainer will reopen the bug report if appropriate. Debian distribution maintenance software pp. Emmanuel Bourg <[email protected]> (supplier of updated tomcat-native package) (This message was generated automatically at their request; if you believe that there is a problem with it please contact the archive administrators by mailing [email protected]) -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 Format: 1.8 Date: Mon, 11 May 2015 13:22:43 +0200 Source: tomcat-native Binary: libtcnative-1 Architecture: source amd64 Version: 1.1.33-1 Distribution: unstable Urgency: medium Maintainer: Debian Java Maintainers <[email protected]> Changed-By: Emmanuel Bourg <[email protected]> Description: libtcnative-1 - Tomcat native library using the Apache Portable Runtime Closes: 737969 Changes: tomcat-native (1.1.33-1) unstable; urgency=medium . * Team upload. * New upstream release * Removed the patch drop_sslv2_support.diff (Closes: #737969) Checksums-Sha1: 5d4cc0775f86258e88d3bea34a16121b23dcd8d4 2023 tomcat-native_1.1.33-1.dsc c7626c8e5144ee8e958175c4cd034cef90eab1ed 388787 tomcat-native_1.1.33.orig.tar.gz fb3245dd4cc09784d3d3dec9a4a00443a36c5969 3708 tomcat-native_1.1.33-1.debian.tar.xz 9ef6d783e29d358d23598ff7f4f50ac870dd6c14 85492 libtcnative-1_1.1.33-1_amd64.deb Checksums-Sha256: fb154d9bf6e7aa925a1f9862d267f4cf7598b9e0c2df39c3f912d92fd1f305f1 2023 tomcat-native_1.1.33-1.dsc 523dde7393c57307eedf4972ebbe19a9e9af6f7699e3b1ef6dabd7a11677866e 388787 tomcat-native_1.1.33.orig.tar.gz 144a2a04bae10ed412ea7bda2fbfa8e7a80c5532e5db7959009256f84757b8e8 3708 tomcat-native_1.1.33-1.debian.tar.xz 9e7f7ad981b76ede1a13851111df9f0aab1998103f4c0e217da5358fb09b6705 85492 libtcnative-1_1.1.33-1_amd64.deb Files: 978c1a5e58007b2b4726aa30adcc28a3 2023 java extra tomcat-native_1.1.33-1.dsc 04b66308560abf2f08c658eb1703546d 388787 java extra tomcat-native_1.1.33.orig.tar.gz ccbd9e9da51de954e0d379db4db1aae9 3708 java extra tomcat-native_1.1.33-1.debian.tar.xz 1c57c8c3fe853aa80c62c759cc8d2cf4 85492 java extra libtcnative-1_1.1.33-1_amd64.deb -----BEGIN PGP SIGNATURE----- Version: GnuPG v1 iQIcBAEBAgAGBQJVUJFHAAoJEPUTxBnkudCsaqcP/3OezWbc4O1ZSx9N4cNd26Do NlXpQQpD1x8FAyc0pKJ/LJggej9z70Q6jeXU4FSi0X8ZZTB4cUNdt2eCzBPRVXYJ 7bqxA3NRZCNCXXDqsS4oXvUK2o6TG4x6rkbfDS9pYJeQWB4+LokdauEj9Zbgde9P +VjJ0sduCDCg3NYOMr63mmRMN6ZV/MMb4vlSPaLrnGkXaHWnPippvlfgTxMARZ7q PikYq0/AvYAJE07qlwoW+J4McYNG4UctjpRsIJlDKKZlR4M3eVwc/qrEAQd5baJk zU5JCSCT0G269lytraPUgsxKZ7CIA+HE80y4NXWgYuaF4C5P0bhks+Tn+Wg0wNo+ gvBcDyVT7vWZ22jBNGkZuafSvwRhzuj33TdDZZ5rblMdgAhm0wIKJ9gHtNaX7aGu m+JWqwfy3tldXujMybx0YKInMINphv7p8UN/p42P3MgwbZHmODTpXqBXIKjqgGE3 oqAlSkSq1XsRoid3EhG4fL6mpuyx5ataPoaTdLDUzMEsB/u7qsDsRt1cCFHtdKhP amJa//BO/qcpveUUDhEYgxlh+bSAUCr2EWJEaIk44YmGt+WGzPKbeA5L8XOjZbrc rhz66V4P0KmoZHrtHmPkUcP88WpZDOPaTr0HH2JVd7bJZZAYvu/VCR3ujpMxswMr 4v6TuMN2UYwuNTWn1EKb =m4MS -----END PGP SIGNATURE-----
--- End Message ---

