[Bug 61448] Cluster StaticMember (McastService:Required property "tcpListenPort" is missing)

2017-08-21 Thread bugzilla
https://bz.apache.org/bugzilla/show_bug.cgi?id=61448 --- Comment #2 from Keiichi Fujino --- If you want to use static cluster membership, you do not need to use McastService. So you should set channelStartOptions = "3". -- You are receiving this mail because: You are the

Regression with PKCS11 KeyStores?

2017-08-21 Thread Daniel Ruggeri
Hello, Tomcat devs; I have detected what appears to be a regression in 8.5.20 with JSSE keystores since 8.5.16. With my limited understanding I'm unable to pinpoint the exact cause to a certainty after poking around a bit, so I thought I'd pass what info I have along and get some thoughts.

Re: Config warning when using OpenSSL config items and useOpenSSL=true

2017-08-21 Thread Rainer Jung
Am 21.08.2017 um 20:01 schrieb Mark Thomas: On 19/08/17 22:44, Rainer Jung wrote: Assume tcantive and OpenSSL is available. When using the AprLifecycleListener with useOpenssl="true" (default) and useAprConnector="false" (also default) with a Java NIO or NIO2 connector and *not* setting the

Re: Config warning when using OpenSSL config items and useOpenSSL=true

2017-08-21 Thread Mark Thomas
On 19/08/17 22:44, Rainer Jung wrote: > Assume tcantive and OpenSSL is available. > > When using the AprLifecycleListener with useOpenssl="true" (default) and > useAprConnector="false" (also default) with a Java NIO or NIO2 connector > and *not* setting the sslImplementationName one gets warnings

[Bug 48655] Active multipart downloads prevent tomcat shutdown.

2017-08-21 Thread bugzilla
https://bz.apache.org/bugzilla/show_bug.cgi?id=48655 Mark Thomas changed: What|Removed |Added Resolution|--- |FIXED

svn commit: r1805655 - in /tomcat/tc7.0.x/trunk: ./ java/org/apache/tomcat/util/net/AprEndpoint.java webapps/docs/changelog.xml

2017-08-21 Thread markt
Author: markt Date: Mon Aug 21 17:03:28 2017 New Revision: 1805655 URL: http://svn.apache.org/viewvc?rev=1805655=rev Log: Fix https://bz.apache.org/bugzilla/show_bug.cgi?id=48655 Enable Tomcat to shutdown cleanly when using sendfile, the APR/native connector and a multi-part download is in

svn commit: r1805654 - in /tomcat/tc8.0.x/trunk: ./ java/org/apache/tomcat/util/net/AprEndpoint.java webapps/docs/changelog.xml

2017-08-21 Thread markt
Author: markt Date: Mon Aug 21 17:01:24 2017 New Revision: 1805654 URL: http://svn.apache.org/viewvc?rev=1805654=rev Log: Fix https://bz.apache.org/bugzilla/show_bug.cgi?id=48655 Enable Tomcat to shutdown cleanly when using sendfile, the APR/native connector and a multi-part download is in

svn commit: r1805653 - in /tomcat/tc8.5.x/trunk: ./ java/org/apache/tomcat/util/net/AprEndpoint.java webapps/docs/changelog.xml

2017-08-21 Thread markt
Author: markt Date: Mon Aug 21 17:00:48 2017 New Revision: 1805653 URL: http://svn.apache.org/viewvc?rev=1805653=rev Log: Fix https://bz.apache.org/bugzilla/show_bug.cgi?id=48655 Enable Tomcat to shutdown cleanly when using sendfile, the APR/native connector and a multi-part download is in

svn commit: r1805652 - in /tomcat/trunk: java/org/apache/tomcat/util/net/AprEndpoint.java webapps/docs/changelog.xml

2017-08-21 Thread markt
Author: markt Date: Mon Aug 21 16:59:56 2017 New Revision: 1805652 URL: http://svn.apache.org/viewvc?rev=1805652=rev Log: Fix https://bz.apache.org/bugzilla/show_bug.cgi?id=48655 Enable Tomcat to shutdown cleanly when using sendfile, the APR/native connector and a multi-part download is in

[Bug 61448] Cluster StaticMember (McastService:Required property "tcpListenPort" is missing)

2017-08-21 Thread bugzilla
https://bz.apache.org/bugzilla/show_bug.cgi?id=61448 --- Comment #1 from Carlos --- How to reproduce: Set up a cluster with one static member. #server.xml: -- You are

[Bug 61448] New: Cluster StaticMember (McastService:Required property "tcpListenPort" is missing)

2017-08-21 Thread bugzilla
https://bz.apache.org/bugzilla/show_bug.cgi?id=61448 Bug ID: 61448 Summary: Cluster StaticMember (McastService:Required property "tcpListenPort" is missing) Product: Tomcat 7 Version: 7.0.70 Hardware: All

[Bug 48655] Active multipart downloads prevent tomcat shutdown.

2017-08-21 Thread bugzilla
https://bz.apache.org/bugzilla/show_bug.cgi?id=48655 Mark Thomas changed: What|Removed |Added Status|NEEDINFO|NEW --- Comment #2

[Bug 61437] 8.0.46: Websockets examples failure with AccessControlException "accessClassInPackage.org.apache.catalina.webresources"

2017-08-21 Thread bugzilla
https://bz.apache.org/bugzilla/show_bug.cgi?id=61437 Mark Thomas changed: What|Removed |Added Resolution|--- |FIXED

svn commit: r1805649 - in /tomcat/tc8.0.x/trunk: java/org/apache/catalina/security/SecurityClassLoad.java webapps/docs/changelog.xml

2017-08-21 Thread markt
Author: markt Date: Mon Aug 21 16:02:15 2017 New Revision: 1805649 URL: http://svn.apache.org/viewvc?rev=1805649=rev Log: Fix https://bz.apache.org/bugzilla/show_bug.cgi?id=61437 Fix a possible AccessControlException accessing the WebSocket examples when running under a SecurityManager.

[Bug 61447] Link is 404

2017-08-21 Thread bugzilla
https://bz.apache.org/bugzilla/show_bug.cgi?id=61447 --- Comment #2 from Mark Thomas --- Reported to the infra team: https://issues.apache.org/jira/browse/INFRA-14921 -- You are receiving this mail because: You are the assignee for the bug.

[Bug 61447] Link is 404

2017-08-21 Thread bugzilla
https://bz.apache.org/bugzilla/show_bug.cgi?id=61447 Mark Thomas changed: What|Removed |Added OS||All

[Bug 61424] Obtaining a StackOverflowError when running Tomcat 8.5 or 9 with SecurityManager, a javax.management.remote.JMXPrincipal entry is present in catalina.policy file and Subject.doAs method is

2017-08-21 Thread bugzilla
https://bz.apache.org/bugzilla/show_bug.cgi?id=61424 Mark Thomas changed: What|Removed |Added Resolution|--- |FIXED

svn commit: r1805647 - in /tomcat/tc8.0.x/trunk: ./ java/org/apache/catalina/loader/WebappClassLoaderBase.java webapps/docs/changelog.xml

2017-08-21 Thread markt
Author: markt Date: Mon Aug 21 15:27:48 2017 New Revision: 1805647 URL: http://svn.apache.org/viewvc?rev=1805647=rev Log: Fix https://bz.apache.org/bugzilla/show_bug.cgi?id=61424 The trick to avoid the relatively slow ClassNotFoundException has another (possible) edge case that can trigger a

svn commit: r1805646 - in /tomcat/tc8.5.x/trunk: ./ java/org/apache/catalina/loader/WebappClassLoaderBase.java webapps/docs/changelog.xml

2017-08-21 Thread markt
Author: markt Date: Mon Aug 21 15:25:31 2017 New Revision: 1805646 URL: http://svn.apache.org/viewvc?rev=1805646=rev Log: Fix https://bz.apache.org/bugzilla/show_bug.cgi?id=61424 The trick to avoid the relatively slow ClassNotFoundException has another edge case that can trigger a

svn commit: r1805645 - in /tomcat/trunk: java/org/apache/catalina/loader/WebappClassLoaderBase.java webapps/docs/changelog.xml

2017-08-21 Thread markt
Author: markt Date: Mon Aug 21 15:24:42 2017 New Revision: 1805645 URL: http://svn.apache.org/viewvc?rev=1805645=rev Log: Fix https://bz.apache.org/bugzilla/show_bug.cgi?id=61424 The trick to avoid the relatively slow ClassNotFoundException has another edge case that can trigger a

[Bug 61447] New: Link is 404

2017-08-21 Thread bugzilla
https://bz.apache.org/bugzilla/show_bug.cgi?id=61447 Bug ID: 61447 Summary: Link is 404 Product: Tomcat 9 Version: 9.0.0.M26 Hardware: PC URL: https://tomcat.apache.org/download-90.cgi Status: NEW

[Bug 58244] two way SSL loses client certificate after a few requests

2017-08-21 Thread bugzilla
https://bz.apache.org/bugzilla/show_bug.cgi?id=58244 Mark Thomas changed: What|Removed |Added Resolution|--- |FIXED

svn commit: r1805640 - in /tomcat/tc7.0.x/trunk: ./ java/org/apache/coyote/http11/Http11AprProcessor.java webapps/docs/changelog.xml

2017-08-21 Thread markt
Author: markt Date: Mon Aug 21 14:15:37 2017 New Revision: 1805640 URL: http://svn.apache.org/viewvc?rev=1805640=rev Log: Fix https://bz.apache.org/bugzilla/show_bug.cgi?id=58244 Handle the case when OpenSSL resumes a TLS session using a ticket and the full client certificate chain is not

svn commit: r1805639 - in /tomcat/tc8.0.x/trunk: ./ java/org/apache/coyote/http11/Http11AprProcessor.java webapps/docs/changelog.xml webapps/docs/config/http.xml

2017-08-21 Thread markt
Author: markt Date: Mon Aug 21 14:11:14 2017 New Revision: 1805639 URL: http://svn.apache.org/viewvc?rev=1805639=rev Log: Fix https://bz.apache.org/bugzilla/show_bug.cgi?id=58244 Handle the case when OpenSSL resumes a TLS session using a ticket and the full client certificate chain is not

svn commit: r1805638 - in /tomcat/tc8.5.x/trunk: ./ java/org/apache/tomcat/util/net/AprSSLSupport.java webapps/docs/changelog.xml webapps/docs/config/http.xml

2017-08-21 Thread markt
Author: markt Date: Mon Aug 21 14:03:53 2017 New Revision: 1805638 URL: http://svn.apache.org/viewvc?rev=1805638=rev Log: Fix https://bz.apache.org/bugzilla/show_bug.cgi?id=58244 Handle the case when OpenSSL resumes a TLS session using a ticket and the full client certificate chain is not

svn commit: r1805637 - in /tomcat/trunk: java/org/apache/tomcat/util/net/AprSSLSupport.java webapps/docs/changelog.xml webapps/docs/config/http.xml

2017-08-21 Thread markt
Author: markt Date: Mon Aug 21 14:00:32 2017 New Revision: 1805637 URL: http://svn.apache.org/viewvc?rev=1805637=rev Log: Handle the case when OpenSSL resumes a TLS session using a ticket and the full client certificate chain is not available. In this case the client certificate without the

[Bug 58263] Crash during TLS handshake

2017-08-21 Thread bugzilla
https://bz.apache.org/bugzilla/show_bug.cgi?id=58263 Mark Thomas changed: What|Removed |Added Resolution|--- |WONTFIX

[Bug 59811] TLS Session ID not available if session tickets are used

2017-08-21 Thread bugzilla
https://bz.apache.org/bugzilla/show_bug.cgi?id=59811 Mark Thomas changed: What|Removed |Added Status|NEW |RESOLVED

[Bug 61422] Feature requests for tc-native based on forked netty-tcnative

2017-08-21 Thread bugzilla
https://bz.apache.org/bugzilla/show_bug.cgi?id=61422 Mark Thomas changed: What|Removed |Added OS||All

[Bug 61210] When using the Security Manager, Tomcat prints warning about a non-existent file

2017-08-21 Thread bugzilla
https://bz.apache.org/bugzilla/show_bug.cgi?id=61210 Mark Thomas changed: What|Removed |Added Resolution|--- |FIXED

svn commit: r1805616 - in /tomcat/tc8.0.x/trunk: ./ java/org/apache/catalina/loader/ java/org/apache/catalina/security/ java/org/apache/juli/ webapps/docs/

2017-08-21 Thread markt
Author: markt Date: Mon Aug 21 09:52:01 2017 New Revision: 1805616 URL: http://svn.apache.org/viewvc?rev=1805616=rev Log: Fix https://bz.apache.org/bugzilla/show_bug.cgi?id=61210 When running under a SecurityManager, do not print a warning about not being able to read a logging configuration

svn commit: r1805614 - in /tomcat/tc8.5.x/trunk: ./ java/org/apache/catalina/loader/ java/org/apache/catalina/security/ java/org/apache/juli/ webapps/docs/

2017-08-21 Thread markt
Author: markt Date: Mon Aug 21 09:49:47 2017 New Revision: 1805614 URL: http://svn.apache.org/viewvc?rev=1805614=rev Log: Fix https://bz.apache.org/bugzilla/show_bug.cgi?id=61210 When running under a SecurityManager, do not print a warning about not being able to read a logging configuration

svn commit: r1805613 - in /tomcat/trunk: java/org/apache/catalina/loader/ java/org/apache/catalina/security/ java/org/apache/juli/ webapps/docs/

2017-08-21 Thread markt
Author: markt Date: Mon Aug 21 09:48:09 2017 New Revision: 1805613 URL: http://svn.apache.org/viewvc?rev=1805613=rev Log: Fix https://bz.apache.org/bugzilla/show_bug.cgi?id=61210 When running under a SecurityManager, do not print a warning about not being able to read a logging configuration

svn commit: r1805612 - in /tomcat/trunk: java/org/apache/tomcat/util/net/openssl/OpenSSLConf.java test/org/apache/tomcat/util/net/TesterSupport.java

2017-08-21 Thread markt
Author: markt Date: Mon Aug 21 09:44:16 2017 New Revision: 1805612 URL: http://svn.apache.org/viewvc?rev=1805612=rev Log: Fix IDE nags Modified: tomcat/trunk/java/org/apache/tomcat/util/net/openssl/OpenSSLConf.java tomcat/trunk/test/org/apache/tomcat/util/net/TesterSupport.java

[Bug 61415] SSL protocol error with Chrome, client certificates and OpenSSL/NIO in Tomcat 8.5

2017-08-21 Thread bugzilla
https://bz.apache.org/bugzilla/show_bug.cgi?id=61415 Mark Thomas changed: What|Removed |Added OS||All --- Comment #1

svn commit: r1805607 - in /tomcat/site/trunk/docs/native-doc: index.html news/2008.html news/2009.html news/2010.html news/2011.html news/2012.html news/2013.html news/2014.html news/2015.html news/20

2017-08-21 Thread markt
Author: markt Date: Mon Aug 21 08:32:53 2017 New Revision: 1805607 URL: http://svn.apache.org/viewvc?rev=1805607=rev Log: Belatedly update site for 1.2.12 release Added: tomcat/site/trunk/docs/native-doc/news/2017.html (with props) Modified: tomcat/site/trunk/docs/native-doc/index.html

svn commit: r1805606 - in /tomcat/native/trunk: native/src/sslnetwork.c xdocs/miscellaneous/changelog.xml

2017-08-21 Thread markt
Author: markt Date: Mon Aug 21 08:22:17 2017 New Revision: 1805606 URL: http://svn.apache.org/viewvc?rev=1805606=rev Log: Fix renegotiation to obtain a client certificate from a user agent. Modified: tomcat/native/trunk/native/src/sslnetwork.c

svn commit: r1805605 - in /tomcat/trunk: java/org/apache/tomcat/util/net/AprEndpoint.java webapps/docs/changelog.xml

2017-08-21 Thread markt
Author: markt Date: Mon Aug 21 08:20:06 2017 New Revision: 1805605 URL: http://svn.apache.org/viewvc?rev=1805605=rev Log: Ensure that the APR/native connector uses blocking I/O for TLS renegotiation. Modified: tomcat/trunk/java/org/apache/tomcat/util/net/AprEndpoint.java