Author: kkolinko Date: Sat Nov 14 23:11:07 2009 New Revision: 836290 URL: http://svn.apache.org/viewvc?rev=836290&view=rev Log: propose installer patch
Modified: tomcat/tc5.5.x/trunk/STATUS.txt Modified: tomcat/tc5.5.x/trunk/STATUS.txt URL: http://svn.apache.org/viewvc/tomcat/tc5.5.x/trunk/STATUS.txt?rev=836290&r1=836289&r2=836290&view=diff ============================================================================== --- tomcat/tc5.5.x/trunk/STATUS.txt (original) +++ tomcat/tc5.5.x/trunk/STATUS.txt Sat Nov 14 23:11:07 2009 @@ -186,6 +186,17 @@ http://svn.apache.org/viewvc?rev=834047&view=rev +1: markt, mturk -1: + kkolinko: It cannot be applied cleanly, because manager and + host-manager are at different paths in TC5.5. + + Alternative patch: + Fix CVE-2009-3548 - Windows installer uses insecure default password + Also removes some old commented-out code and changes some message strings. + This patch file is a backport of revs. 834047, 836036, 836045, 836209 + http://people.apache.org/~kkolinko/patches/2009-11-14_Installer_password_tc55.patch + +1: kkolinko + -1: + * Disable TLS renegotiation be default with an option to re-enable it Based on Costin's patch for trunk with Mark's modifications --------------------------------------------------------------------- To unsubscribe, e-mail: dev-unsubscr...@tomcat.apache.org For additional commands, e-mail: dev-h...@tomcat.apache.org