> On Feb 12, 2025, at 10:07 PM, Emmanuel Lécharny <elecha...@gmail.com> wrote:
>
> I'm sad to have to cancel this release.
>
> Actually, the LDAP API itself works well, but when testing with the server, I
> get some breakage in some TLS tests. After a couple of days analysis the
> situation, it's worse than what I thought: it's goes down to MINA latest
> version (2.2.4) which has introduced some breakage. When I rolled back to
> 2.2.2, the Directory TLS tests are now passing green.
>
>
> I have two options here:
> - rollback to MINA 2.2.3 and start a new vote, assuming that the changes in
> MINA 2.2.4 were mainly to mitigate a potential CVE when using a feature we
> don't use
> - Or get MINA 2.2.5 out with a fix, then cut a new Apache LDAP API new
> release.
>
> The second path is probably the best, we can wait a couple more weeks...
>
> Let me know what you're thoughts on this.
>
Hi Emmanuel,
A couple weeks seems OK.
Let me know if there’s some way I can help here. I am wondering why I didn’t
catch this problem. Is it because I didn’t run the ApacheDS tests using the
latest API?
—
Shawn
> Thanks!
---------------------------------------------------------------------
To unsubscribe, e-mail: dev-unsubscr...@directory.apache.org
For additional commands, e-mail: dev-h...@directory.apache.org