Your message dated Mon, 11 May 2015 11:35:17 +0000
with message-id <[email protected]>
and subject line Bug#737969: fixed in tomcat-native 1.1.33-1
has caused the Debian Bug report #737969,
regarding libtcnative-1 breaks Tomcat's 'SSLProtocols'
to be marked as done.

This means that you claim that the problem has been dealt with.
If this is not the case it is now your responsibility to reopen the
Bug report if necessary, and/or fix the problem forthwith.

(NB: If you are a system administrator and have no idea what this
message is talking about, this may indicate a serious mail system
misconfiguration somewhere. Please contact [email protected]
immediately.)


-- 
737969: http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=737969
Debian Bug Tracking System
Contact [email protected] with problems
--- Begin Message ---
Package: libtcnative-1
Version: 1.1.24-1
Severity: important

Symptoms:

  The Tomcat 'SSLProtocol' configuration attribute is documented
  as accepting several values, but on Debian 7/Wheezy (and
  presumably others) only the values "SSLv3" and "TLSv1" are
  accepted; notably the default value of "all" is rejected.

Cause:

  The Debian packaging of 'libtcnative-1' contains a patch that
  simply removes the 'SSL_PROTOCOL_SSLV2' bitmask constant and
  related code, but does not remove it from the matching Tomcat
  sources.

  So some other bitmask constants in the Tomcat sources contain
  that bitmask constant, and therefore will never match the
  supposedly equivalent bitmasks in 'libtcnative-1'.

Comments:

  Given that 'libtcnative-1' is essentially a Tomcat internal
  plugin, a native implementation of a Tomcat Java API,
  introducing an incompatibility between interface and
  implementation creates a surprising, undocumented,
  user-visible breakage.

  Anyhow it seems to me misguided to simply disable SSLv2 in
  'libtcnative-1' on other grounds:

  * The other role of 'libtcnative-1' is as wrapper around
    'libopenssl', and the maintainers of that, both upstream and
    Debian ones, have not felt any need to disable SSLv2 entirely
    within it. Just like the Tomcat ones, both upstream and
    Debian, have also felt no need to entirely disable SSLv2 in
    it either. It is amazing that a library that is a bit of glue
    between Tomcat and OpenSSL prevents the use of a feature that
    both explicitly support.

  * Some aspects of the SSLv2 protocol, in particular the SSLV2
    "hello", supported by the 'SSLv23*' OpenSSL functions, are
    widely used by clients, even when SSLv2 itself is not used.
    It also quite safe to use the 'SSLv23*' OpenSSL functions by
    setting the cipher suites to "HIGH:MEDIUM" as that disables
    all the SSLv2 ciphers, making SSLv2 native negotiation fail.

  * Perhaps it would be sufficient to print a warning message
    when SSLv2 is requested, but this should be done in Tomcat,
    not in a user-invisible glue layer between Tomcat and OpenSSL.

--- End Message ---
--- Begin Message ---
Source: tomcat-native
Source-Version: 1.1.33-1

We believe that the bug you reported is fixed in the latest version of
tomcat-native, which is due to be installed in the Debian FTP archive.

A summary of the changes between this version and the previous one is
attached.

Thank you for reporting the bug, which will now be closed.  If you
have further comments please address them to [email protected],
and the maintainer will reopen the bug report if appropriate.

Debian distribution maintenance software
pp.
Emmanuel Bourg <[email protected]> (supplier of updated tomcat-native package)

(This message was generated automatically at their request; if you
believe that there is a problem with it please contact the archive
administrators by mailing [email protected])


-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

Format: 1.8
Date: Mon, 11 May 2015 13:22:43 +0200
Source: tomcat-native
Binary: libtcnative-1
Architecture: source amd64
Version: 1.1.33-1
Distribution: unstable
Urgency: medium
Maintainer: Debian Java Maintainers 
<[email protected]>
Changed-By: Emmanuel Bourg <[email protected]>
Description:
 libtcnative-1 - Tomcat native library using the Apache Portable Runtime
Closes: 737969
Changes:
 tomcat-native (1.1.33-1) unstable; urgency=medium
 .
   * Team upload.
   * New upstream release
   * Removed the patch drop_sslv2_support.diff (Closes: #737969)
Checksums-Sha1:
 5d4cc0775f86258e88d3bea34a16121b23dcd8d4 2023 tomcat-native_1.1.33-1.dsc
 c7626c8e5144ee8e958175c4cd034cef90eab1ed 388787 
tomcat-native_1.1.33.orig.tar.gz
 fb3245dd4cc09784d3d3dec9a4a00443a36c5969 3708 
tomcat-native_1.1.33-1.debian.tar.xz
 9ef6d783e29d358d23598ff7f4f50ac870dd6c14 85492 libtcnative-1_1.1.33-1_amd64.deb
Checksums-Sha256:
 fb154d9bf6e7aa925a1f9862d267f4cf7598b9e0c2df39c3f912d92fd1f305f1 2023 
tomcat-native_1.1.33-1.dsc
 523dde7393c57307eedf4972ebbe19a9e9af6f7699e3b1ef6dabd7a11677866e 388787 
tomcat-native_1.1.33.orig.tar.gz
 144a2a04bae10ed412ea7bda2fbfa8e7a80c5532e5db7959009256f84757b8e8 3708 
tomcat-native_1.1.33-1.debian.tar.xz
 9e7f7ad981b76ede1a13851111df9f0aab1998103f4c0e217da5358fb09b6705 85492 
libtcnative-1_1.1.33-1_amd64.deb
Files:
 978c1a5e58007b2b4726aa30adcc28a3 2023 java extra tomcat-native_1.1.33-1.dsc
 04b66308560abf2f08c658eb1703546d 388787 java extra 
tomcat-native_1.1.33.orig.tar.gz
 ccbd9e9da51de954e0d379db4db1aae9 3708 java extra 
tomcat-native_1.1.33-1.debian.tar.xz
 1c57c8c3fe853aa80c62c759cc8d2cf4 85492 java extra 
libtcnative-1_1.1.33-1_amd64.deb

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1

iQIcBAEBAgAGBQJVUJFHAAoJEPUTxBnkudCsaqcP/3OezWbc4O1ZSx9N4cNd26Do
NlXpQQpD1x8FAyc0pKJ/LJggej9z70Q6jeXU4FSi0X8ZZTB4cUNdt2eCzBPRVXYJ
7bqxA3NRZCNCXXDqsS4oXvUK2o6TG4x6rkbfDS9pYJeQWB4+LokdauEj9Zbgde9P
+VjJ0sduCDCg3NYOMr63mmRMN6ZV/MMb4vlSPaLrnGkXaHWnPippvlfgTxMARZ7q
PikYq0/AvYAJE07qlwoW+J4McYNG4UctjpRsIJlDKKZlR4M3eVwc/qrEAQd5baJk
zU5JCSCT0G269lytraPUgsxKZ7CIA+HE80y4NXWgYuaF4C5P0bhks+Tn+Wg0wNo+
gvBcDyVT7vWZ22jBNGkZuafSvwRhzuj33TdDZZ5rblMdgAhm0wIKJ9gHtNaX7aGu
m+JWqwfy3tldXujMybx0YKInMINphv7p8UN/p42P3MgwbZHmODTpXqBXIKjqgGE3
oqAlSkSq1XsRoid3EhG4fL6mpuyx5ataPoaTdLDUzMEsB/u7qsDsRt1cCFHtdKhP
amJa//BO/qcpveUUDhEYgxlh+bSAUCr2EWJEaIk44YmGt+WGzPKbeA5L8XOjZbrc
rhz66V4P0KmoZHrtHmPkUcP88WpZDOPaTr0HH2JVd7bJZZAYvu/VCR3ujpMxswMr
4v6TuMN2UYwuNTWn1EKb
=m4MS
-----END PGP SIGNATURE-----

--- End Message ---

Reply via email to