Re: [VOTE] Release Apache Tomcat 11.0.0-M24

2024-08-06 Thread Coty Sutherland
Chris, On Mon, Aug 5, 2024 at 5:10 PM Christopher Schultz < ch...@christopherschultz.net> wrote: > Coty, > > On 8/5/24 14:56, Coty Sutherland wrote: > > On Mon, Aug 5, 2024 at 2:43 PM Rainer Jung > wrote: > > > >> Am 05.08.24 um 20:18 schrieb Coty Sutherl

Re: [VOTE] Release Apache Tomcat 11.0.0-M24

2024-08-05 Thread Coty Sutherland
On Mon, Aug 5, 2024 at 2:43 PM Rainer Jung wrote: > Am 05.08.24 um 20:18 schrieb Coty Sutherland: > > I'm testing and see an issue with o.a.c.http2.TestStreamProcessor getting > > some unexpected result: > > > > Testcase: testPrepareHeaders[0: loop [0], use

Re: [VOTE] Release Apache Tomcat 11.0.0-M24

2024-08-05 Thread Coty Sutherland
I'm testing and see an issue with o.a.c.http2.TestStreamProcessor getting some unexpected result: Testcase: testPrepareHeaders[0: loop [0], useAsyncIO[false]] took 0.061 sec FAILED expected:<...-Header-[etag]-[W/"9[34]-1447269522000"] 3-H...> but was:<...-Header-[etag]-[W/"9[57]-1447269522000"

Re: [VOTE] Release Apache Tomcat 11.0.0-M23

2024-08-01 Thread Coty Sutherland
On Mon, Jul 29, 2024 at 2:27 PM Mark Thomas wrote: > The proposed Apache Tomcat 11.0.0-M23 release is now available for > voting. > > Apache Tomcat 11.0.0-M23 is a milestone release of the 11.0.x branch and > has been made to provide users with early access to the new features in > Apache Tomcat

Re: [VOTE] Release Apache Tomcat 10.1.27

2024-08-01 Thread Coty Sutherland
On Tue, Jul 30, 2024 at 11:57 AM Christopher Schultz < ch...@christopherschultz.net> wrote: > The proposed Apache Tomcat 10.1.27 release is now available for > voting. > > All committers and PMC members are kindly requested to provide a vote if > possible. ANY TOMCAT USER MAY VOTE, though only PMC

Re: [VOTE] Release Apache Tomcat 9.0.92

2024-07-31 Thread Coty Sutherland
On Mon, Jul 29, 2024 at 11:33 PM Rémy Maucherat wrote: > The proposed Apache Tomcat 9.0.92 release is now available for voting. > > The notable changes compared to 9.0.91 are: > > - Align HTTP/2 with HTTP/1.1 and recycle the container internal request >and response processing objects by defau

Re: [VOTE] Release Apache Tomcat 10.1.26

2024-07-12 Thread Coty Sutherland
On Sun, Jul 7, 2024 at 6:07 PM Christopher Schultz < ch...@christopherschultz.net> wrote: > The proposed Apache Tomcat 10.1.26 release is now available for > voting. > > All committers and PMC members are kindly requested to provide a vote if > possible. ANY TOMCAT USER MAY VOTE, though only PMC m

Re: [PROPOSAL] Enable SecureLifecycleListener by default

2024-06-07 Thread Coty Sutherland
On Fri, Jun 7, 2024 at 10:33 AM Tim Funk wrote: > Somewhat related and tangential to the other conversations > > Is it worth introducing a system property like > "-Dtomcat.security.harden=true". (Personally not sold yet on the idea) > I think I'm +0 on this. Implementing something like this

Re: [PROPOSAL] Remove JSP file from ROOT web application

2024-06-07 Thread Coty Sutherland
On Fri, Jun 7, 2024 at 8:52 AM Christopher Schultz < ch...@christopherschultz.net> wrote: > Konstantin, > > On 6/6/24 11:26, Konstantin Kolinko wrote: > > чт, 6 июн. 2024 г. в 17:44, Christopher Schultz < > ch...@christopherschultz.net>: > >> > >> All, > >> > >> I'd like to change the existing web

Re: Notes from Tomcat security day

2024-06-07 Thread Coty Sutherland
Looks like a very productive day! Thanks for sharing the notes, Mark. On Friday, June 7, 2024, Mark Thomas wrote: > Hi all, > > I have added the notes from yesterday's security day to the wiki. > > https://cwiki.apache.org/confluence/display/TOMCAT/Security+Day+EU+2024 > > We discussed lots of th

Re: [PROPOSAL] Enable SecureLifecycleListener by default

2024-06-06 Thread Coty Sutherland
On Thu, Jun 6, 2024 at 10:46 AM Christopher Schultz < ch...@christopherschultz.net> wrote: > All, > > I'd like to remove the around the SecureLifecycleListener > in conf/server.xml that we bundle with Tomcat distributions. > > Before I do so, are there any objections to making this change? > No

Re: [VOTE] Release Apache Tomcat 9.0.82

2023-10-11 Thread Coty Sutherland
On Wed, Oct 11, 2023 at 9:38 AM Rémy Maucherat wrote: > The proposed Apache Tomcat 9.0.82 release is now available for voting. > > The notable changes compared to 9.0.81 are: > > - Correct a regression in 9.0.81 that broke the Tomcat JBDC >connection pool > > - Correct a regression in 9.0.81

Re: [VOTE] Release Apache Tomcat 9.0.81

2023-10-09 Thread Coty Sutherland
On Mon, Oct 9, 2023 at 5:36 PM Rémy Maucherat wrote: > The proposed Apache Tomcat 9.0.81 release is now available for voting. > > The notable changes compared to 9.0.80 are: > > - Provide a lifecycle listener that will automatically > reload TLS configurations a set time before the certificate

Re: [VOTE] Release Apache Tomcat 11.0.0-M12

2023-10-09 Thread Coty Sutherland
On Mon, Oct 9, 2023 at 9:22 PM Coty Sutherland wrote: > > > On Mon, Oct 9, 2023 at 5:42 PM Mark Thomas wrote: > >> The proposed Apache Tomcat 11.0.0-M12 release is now available for >> voting. >> >> Apache Tomcat 11.0.0-M12 is a milestone release of the 1

Re: [VOTE] Release Apache Tomcat 10.1.14

2023-10-09 Thread Coty Sutherland
On Mon, Oct 9, 2023 at 6:19 PM Christopher Schultz < ch...@christopherschultz.net> wrote: > The proposed Apache Tomcat 10.1.14 release is now available for > voting. > > The notable changes compared to 10.1.13 are: > > - Update Tomcat Native to 1.2.39 to pick up Windows binaries built with >Op

Re: [VOTE] Release Apache Tomcat 11.0.0-M12

2023-10-09 Thread Coty Sutherland
On Mon, Oct 9, 2023 at 5:42 PM Mark Thomas wrote: > The proposed Apache Tomcat 11.0.0-M12 release is now available for > voting. > > Apache Tomcat 11.0.0-M12 is a milestone release of the 11.0.x branch and > has been made to provide users with early access to the new features in > Apache Tomcat 1

Re: Tomcat's fork of Commons File Upload

2023-09-15 Thread Coty Sutherland
On Fri, Sep 15, 2023 at 8:43 AM Rémy Maucherat wrote: > On Fri, Sep 15, 2023 at 2:38 PM Mark Thomas wrote: > > > > All, > > > > Since the introduction of multi-part upload support in Servlet 3 (Tomcat > > 7), Tomcat has used a package renamed fork of Commons FileUpload to > > provide that suppor

Re: [VOTE] Release Apache Tomcat 9.0.76

2023-06-06 Thread Coty Sutherland
On Mon, Jun 5, 2023 at 3:49 AM Rémy Maucherat wrote: > The proposed Apache Tomcat 9.0.76 release is now available for voting. > > The notable changes compared to 9.0.75 are: > > - Add support for virtual threads. (Java 21+ only) > > - Update HTTP/2 to use the RFC-9218 prioritization scheme. > > -

Re: Java 21 and virtual threads

2023-05-05 Thread Coty Sutherland
On Thu, May 4, 2023 at 8:37 AM Mark Thomas wrote: > Hi all, > > The latest Java 21 EA build has moved virtual threads (from project > Loom) out of preview. How do we want to handle this in Tomcat 11? Recall > that Jakarta EE 11 has set Java 21 as the minimum version. > > I think we have the follo

Re: tomcat-native v2.0+ breaks unix domain socket support on java16-

2023-03-07 Thread Coty Sutherland
Hi there, On Mon, Mar 6, 2023 at 6:01 PM Graham Leggett wrote: > Hi all, > > A while back I added unix domain socket support to tomcat-native, and > patched tomcat to use it until java16 is available. > > Unfortunately unix domain socket support was removed from tomcat-native > 2.0+, and now tom

Re: Regarding IDE configuration files

2023-02-06 Thread Coty Sutherland
On Sat, Feb 4, 2023 at 5:21 AM Mark Thomas wrote: > > 4 Feb 2023 04:17:29 Bailey Brownie : > > > Hi all, > > > > Recently, when setting up Tomcat for development with the Eclipse IDE, > > I noticed that the configuration files that come with Tomcat had > > multiple hard-coded (and outdated) refer

Re: [DISCUSS] EOL date for 8.5.x

2022-10-20 Thread Coty Sutherland
On Fri, Oct 7, 2022 at 5:28 AM Mark Thomas wrote: > Hi all, > > I don't think there is a need to make a decision on this quickly, but > based on past experience and the current discussions about Jakarta EE 11 > I think this is something we need to start thinking about. > > Some key facts: > > - T

Re: [VOTE] Release Apache Tomcat 10.1.1

2022-10-11 Thread Coty Sutherland
On Mon, Oct 3, 2022 at 9:26 AM Mark Thomas wrote: > The proposed Apache Tomcat 10.1.1 release is now available for > voting. > > Applications that run on Tomcat 9 and earlier will not run on Tomcat 10 > without changes. Java EE applications designed for Tomcat 9 and earlier > may be placed in the

Re: [VOTE] Release Apache Tomcat 9.0.65

2022-07-20 Thread Coty Sutherland
On Thu, Jul 14, 2022 at 9:17 AM Rémy Maucherat wrote: > The proposed Apache Tomcat 9.0.65 release is now available for voting. > > The notable changes compared to 9.0.64 are: > > - Implement support for repeatable builds. > > - Update the packaged version of the Tomcat Native Library to 1.2.35. >

Re: [VOTE] Release Apache Tomcat Native 2.0.1

2022-07-12 Thread Coty Sutherland
On Wed, Jul 6, 2022 at 6:32 AM Mark Thomas wrote: > This is the first release of the Tomcat Native 2.0.x branch. The major > differences compared to the 1.2.x branch are: > > - JNI API has been reduced to just that required to support Tomcat's >OpenSSL based TLS implementation. The APR/native

Re: [ANN] ApacheCon NA 2022 in New Orleans, 3-6 Oct 2022, CFP is OPEN!

2022-05-23 Thread Coty Sutherland
On Fri, Apr 29, 2022 at 2:53 PM Christopher Schultz < ch...@christopherschultz.net> wrote: > All, > > Please remember that the ApacheCon North American conference is still > accepting presentations until 23 May 2022. > > The Tomcat track currently has *zero* proposals, and we were hoping to > fill

Re: Plans for Tomcat Native

2022-05-23 Thread Coty Sutherland
On Mon, May 23, 2022 at 6:52 AM Mark Thomas wrote: > Hi all, > > A question on the users list about Tomcat Native, OpenSSL 3.0 FIPs > caused me to take a look at the current state of supported versions. > > The detail is here: > https://github.com/apache/tomcat-native/blob/main/native/srclib/VERS

Re: [VOTE] Release Apache Tomcat 9.0.62

2022-03-31 Thread Coty Sutherland
On Thu, Mar 31, 2022 at 10:57 AM Rémy Maucherat wrote: > The proposed Apache Tomcat 9.0.62 release is now available for voting. > > The notable changes compared to 9.0.60 are: > > - Update the packaged version of the Tomcat Native Library to 1.2.32 to >pick up Windows binaries built with Open

Re: [VOTE] Release Apache Tomcat 9.0.61

2022-03-31 Thread Coty Sutherland
On Wed, Mar 30, 2022 at 4:22 AM Rémy Maucherat wrote: > The proposed Apache Tomcat 9.0.61 release is now available for voting. > > The notable changes compared to 9.0.60 are: > > - Fix a potential thread-safety issue that could cause HTTP/1.1 request >processing to pause, and potentially time

Re: Tomcat Native and minimum OpenSSL version

2022-03-16 Thread Coty Sutherland
On Wed, Mar 16, 2022 at 11:21 AM Christopher Schultz < ch...@christopherschultz.net> wrote: > Mark, > > On 3/15/22 16:40, Mark Thomas wrote: > > Hi all, > > > > We currently have the following text in the VERSIONS file for Tomcat > > Native: > > > > = > > The current minimum versions a

Re: [VOTE] Release Apache Tomcat 9.0.59

2022-02-25 Thread Coty Sutherland
On Mon, Feb 21, 2022 at 4:21 PM Rémy Maucherat wrote: > The proposed Apache Tomcat 9.0.59 release is now available for voting. > > The notable changes compared to 9.0.58 are: > > - Add support for additional user attributes to TomcatPrincipal and >GenericPrincipal > > - Correct a regression i

Re: [VOTE] Release Apache Tomcat 9.0.58

2022-01-20 Thread Coty Sutherland
On Sat, Jan 15, 2022 at 9:51 AM Rémy Maucherat wrote: > The proposed Apache Tomcat 9.0.58 release is now available for voting. > > The notable changes compared to 9.0.56 are: > > - Add recycling check in the input and output stream isReady to try to >give a more informative ISE when the facad

Re: [VOTE] Release Apache Tomcat 10.1.0-M10

2022-01-17 Thread Coty Sutherland
On Sat, Jan 15, 2022 at 7:49 AM Mark Thomas wrote: > The proposed Apache Tomcat 10.1.0-M10 release is now available for > voting. > > Applications that run on Tomcat 9 and earlier will not run on Tomcat 10 > without changes. Java EE applications designed for Tomcat 9 and earlier > may be placed i

Re: [VOTE] Release Apache Tomcat 10.1.0-M8

2021-12-06 Thread Coty Sutherland
On Thu, Dec 2, 2021 at 9:45 AM Mark Thomas wrote: > The proposed Apache Tomcat 10.1.0-M8 release is now available for > voting. > > Applications that run on Tomcat 9 and earlier will not run on Tomcat 10 > without changes. Java EE applications designed for Tomcat 9 and earlier > may be placed in

Re: [VOTE] Release Apache Tomcat 9.0.56

2021-12-06 Thread Coty Sutherland
On Fri, Dec 3, 2021 at 3:50 AM Rémy Maucherat wrote: > The proposed Apache Tomcat 9.0.56 release is now available for voting. > > The notable changes compared to 9.0.56 are: > > - Provide protection against a known OS bug that causes the acceptor to >report an incoming connection more than on

Re: [VOTE] Release Apache Tomcat 9.0.56

2021-12-06 Thread Coty Sutherland
On Mon, Dec 6, 2021 at 10:57 AM Rémy Maucherat wrote: > On Mon, Dec 6, 2021 at 4:42 PM jean-frederic clere > wrote: > > > > On 06/12/2021 15:19, jean-frederic clere wrote: > > > On 03/12/2021 09:49, Rémy Maucherat wrote: > > >> [X] Stable - go ahead and release as 9.0.56 (stable) > > > > > > Tes

Re: [VOTE] Release Apache Tomcat 10.1.0-M6

2021-09-30 Thread Coty Sutherland
On Tue, Sep 28, 2021 at 8:31 AM Mark Thomas wrote: > The proposed Apache Tomcat 10.1.0-M6 release is now available for > voting. > > Applications that run on Tomcat 9 and earlier will not run on Tomcat 10 > without changes. Java EE applications designed for Tomcat 9 and earlier > may be placed in

Re: [VOTE] Release Apache Tomcat 9.0.54

2021-09-30 Thread Coty Sutherland
On Tue, Sep 28, 2021 at 10:25 AM Rémy Maucherat wrote: > The proposed Apache Tomcat 9.0.54 release is now available for voting. > > The notable changes compared to 9.0.54 are: > > - Further robustness improvements to HTTP/2 flow control window >management > > - Improvements to the DataSourceU

Re: [VOTE] Release Apache Tomcat 9.0.53

2021-09-09 Thread Coty Sutherland
On Mon, Sep 6, 2021 at 3:22 PM Rémy Maucherat wrote: > The proposed Apache Tomcat 9.0.53 release is now available for voting. > > The notable changes compared to 9.0.53 are: > > - Add a UserDatabase implementation as a superset of the DataSourceRealm >functionality. > > - Update the internal

Re: Update "developers" list

2021-07-08 Thread Coty Sutherland
On Thu, Jul 8, 2021 at 11:17 AM Mark Thomas wrote: > On 08/07/2021 15:28, Christopher Schultz wrote: > > All, > > > > The Apache Tomcat web site has a few places where people are > > specifically listed by name. One is under "Who We Are"[1], and it's > > fairly up-to-date. (Reasonable people can

Re: [VOTE] Release Apache Tomcat 9.0.50

2021-06-30 Thread Coty Sutherland
On Mon, Jun 28, 2021 at 4:57 AM Rémy Maucherat wrote: > The proposed Apache Tomcat 9.0.50 release is now available for voting. > > The notable changes compared to 9.0.50 are: > > - Re-work the HTTP/2 overhead protection to reduce the likelihood of >false positives. Note that the default overh

Re: [VOTE] Release Apache Tomcat 10.0.8

2021-06-30 Thread Coty Sutherland
On Fri, Jun 25, 2021 at 7:27 PM Mark Thomas wrote: > The proposed Apache Tomcat 10.0.8 release is now available for > voting. > > Apache Tomcat 10.x implements Jakarta EE 9 and, as such, the primary > package for all the specification APIs has changed from javax.* to > jakarta.* > > Applications

Re: Time to create Tomcat 10.1.x and master->main migration

2021-05-18 Thread Coty Sutherland
On Tue, May 18, 2021 at 7:34 AM Mark Thomas wrote: > All, > > Things are starting to move forward for Jakarta EE 10 so I think it is > time for us to create the 10.1.x branch. At the same time, I'd like to > switch our primary development branches from master to main for all our > repos. > > We w

Re: [VOTE] Release Apache Tomcat Native 1.2.28

2021-04-05 Thread Coty Sutherland
On Thu, Apr 1, 2021 at 9:57 AM Mark Thomas wrote: > Version 1.2.28 includes the following changes compared to 1.2.27 > > - Correct regression in previous fix for BZ 65181 > > The proposed release artefacts can be found at [1], > and the build was done using tag [2]. > > The Apache Tomcat Native 1

Re: [VOTE] Release Apache Tomcat 9.0.38

2020-09-14 Thread Coty Sutherland
On Thu, Sep 10, 2020 at 5:03 AM Mark Thomas wrote: > The proposed Apache Tomcat 9.0.38 release is now available for voting. > > The notable changes compared to the 9.0.37 release are: > > - For requests containing the Expect: 100-continue header, optional > support has been added to delay sendi

Re: [VOTE] Release Apache Tomcat 10.0.0-M8

2020-09-14 Thread Coty Sutherland
On Wed, Sep 9, 2020 at 10:57 AM Mark Thomas wrote: > The proposed Apache Tomcat 10.0.0-M8 release is now available for > voting. > > Apache Tomcat 10.x implements Jakarta EE 9 and, as such, the primary > package for all the specification APIs has changed from javax.* to > jakarta.* > Applications

Re: security.txt

2020-09-01 Thread Coty Sutherland
On Tue, Sep 1, 2020 at 1:01 PM Christopher Schultz < ch...@christopherschultz.net> wrote: > -BEGIN PGP SIGNED MESSAGE- > Hash: SHA256 > > All, > > I'd like to propose that we publish a security.txt[1] file on our web > site under /.well-known/security.txt and /security.txt > > This file co

Re: [PROPOSAL] Remove the functional specs from docs webapp

2020-08-12 Thread Coty Sutherland
On Mon, Aug 10, 2020 at 11:46 AM Mark Thomas wrote: > Hi all, > > I'd like to propose removing all the functional spec pages from the > documentation web application. > > My reasoning for this proposal is, in short, that we aren't using or > maintaining these pages. > > I don't recall any discuss

Re: [tomcat] 01/02: Fix BZ 64540 - switch from bndwrap task to bnd task, begin generating a better manifest and make sure the resulting jar contents are correct.

2020-07-21 Thread Coty Sutherland
s are > actually used externally and I had some changes coming to deal with those > (but presently I'm on vacation so thanks for handling some of those those > Mark.) > > Sincerely, > - Ray > > On Tue, Jul 21, 2020 at 9:51 AM Coty Sutherland > wrote: > >

Re: [tomcat] 01/02: Fix BZ 64540 - switch from bndwrap task to bnd task, begin generating a better manifest and make sure the resulting jar contents are correct.

2020-07-21 Thread Coty Sutherland
That looks like an issue that will need fixing in Fedora's build system. > Annotation scanning and the multipart upload API will be broken if those > packages are missing. > Hm, OK. I'll look into that and I guess other changes to ensure the Fedora build isn't breaking stuff. I need to figure ou

Re: [tomcat] 01/02: Fix BZ 64540 - switch from bndwrap task to bnd task, begin generating a better manifest and make sure the resulting jar contents are correct.

2020-07-21 Thread Coty Sutherland
On Tue, Jul 21, 2020 at 9:15 AM Mark Thomas wrote: > On 21/07/2020 14:06, Coty Sutherland wrote: > > > > > Oh yeah, you're right. They were included in the ASF binaries, but > > Fedora (and Debian I guess) built their own bits and that's where the > > c

Re: [tomcat] 01/02: Fix BZ 64540 - switch from bndwrap task to bnd task, begin generating a better manifest and make sure the resulting jar contents are correct.

2020-07-21 Thread Coty Sutherland
On Tue, Jul 21, 2020 at 7:52 AM Mark Thomas wrote: > On 21/07/2020 12:43, Coty Sutherland wrote: > > Hi Mark, > > > > On Tue, Jul 21, 2020 at 4:48 AM Mark Thomas > <mailto:ma...@apache.org>> wrote: > > > > On 20/07/2020 18:20, Coty Sutherlan

Re: [tomcat] 01/02: Fix BZ 64540 - switch from bndwrap task to bnd task, begin generating a better manifest and make sure the resulting jar contents are correct.

2020-07-21 Thread Coty Sutherland
Hi Mark, On Tue, Jul 21, 2020 at 4:48 AM Mark Thomas wrote: > On 20/07/2020 18:20, Coty Sutherland wrote: > > This commit is problematic :( It's broken some projects that depend on > > Tomcat because now the tomcat-coyote.jar doesn't contain the > > org

Re: [tomcat] 01/02: Fix BZ 64540 - switch from bndwrap task to bnd task, begin generating a better manifest and make sure the resulting jar contents are correct.

2020-07-20 Thread Coty Sutherland
This commit is problematic :( It's broken some projects that depend on Tomcat because now the tomcat-coyote.jar doesn't contain the org.apache.tomcat.util.net.jsse or org.apache.tomcat.util.modeler.modules packages which results in ClassNotFoundExceptions. I haven't seen any issues with other jars

Re: [VOTE] Release Apache Tomcat 7.0.105

2020-07-07 Thread Coty Sutherland
On Thu, Jul 2, 2020 at 9:08 AM Violeta Georgieva wrote: > The proposed Apache Tomcat 7.0.105 release is now available for voting. > > It can be obtained from: > https://dist.apache.org/repos/dist/dev/tomcat/tomcat-7/v7.0.105/ > The Maven staging repo is: > https://repository.apache.org/content/re

Re: [ANN] New committer: Raymond Augé

2020-07-02 Thread Coty Sutherland
Congrats and welcome! On Thu, Jul 2, 2020 at 10:40 AM Mark Thomas wrote: > On behalf of the Tomcat committers I am pleased to announce that > Raymond Augé (rotty3000) has been voted in as a new Tomcat committer. > > Please join me in welcoming him. > > Kind regards, > > Mark > >

Re: [VOTE] Release Apache Tomcat 8.5.57

2020-07-01 Thread Coty Sutherland
On Tue, Jun 30, 2020 at 6:14 PM Mark Thomas wrote: > The proposed Apache Tomcat 8.5.57 release is now available for voting. > > The notable changes compared to the 8.5.56 release are: > > - Implement a significant portion of the TLS environment variables > for the rewrite valve. > > - Reduce me

Re: [VOTE] Release Apache Tomcat 10.0.0-M7

2020-07-01 Thread Coty Sutherland
On Tue, Jun 30, 2020 at 2:16 PM Mark Thomas wrote: > The proposed Apache Tomcat 10.0.0-M7 release is now available for > voting. > > Apache Tomcat 10.x implements Jakarta EE 9 and, as such, the primary > package for all the specification APIs has changed from javax.* to > jakarta.* > Applications

Re: [VOTE] Release Apache Tomcat 9.0.37

2020-07-01 Thread Coty Sutherland
On Tue, Jun 30, 2020 at 4:41 PM Mark Thomas wrote: > The proposed Apache Tomcat 9.0.37 release is now available for voting. > > The notable changes compared to the 9.0.36 release are: > > - Implement a significant portion of the TLS environment variables > for the rewrite valve. > > - Improveme

Re: Changing the name of the default branch in our git repos

2020-06-16 Thread Coty Sutherland
On Tue, Jun 16, 2020 at 4:02 AM Mark Thomas wrote: > All, > > You may have seen the recent discussions both inside and outside the ASF > about the user of "master" as the name of the default git branch. If you > haven't, the short version is that the name can be traced back to > master/slave and

Re: [VOTE] Release Apache Tomcat 9.0.36

2020-06-04 Thread Coty Sutherland
On Wed, Jun 3, 2020 at 2:06 PM Mark Thomas wrote: > The proposed Apache Tomcat 9.0.36 release is now available for voting. > > The notable changes compared to the 9.0.35 release are: > > - Add support for ALPN on recent OpenJDK 8 releases. > > - Add support for the CATALINA_OUT_CMD environment va

Re: [VOTE] Release Apache Tomcat 7.0.104

2020-05-15 Thread Coty Sutherland
On Thu, May 7, 2020 at 4:18 PM Violeta Georgieva wrote: > The proposed Apache Tomcat 7.0.104 release is now available for voting. > > It can be obtained from: > https://dist.apache.org/repos/dist/dev/tomcat/tomcat-7/v7.0.104/ > The Maven staging repo is: > https://repository.apache.org/content/re

Re: [tomcat] branch 7.0.x updated: Use parametric replacement to ensure the proper version of wsdl4j is written to Eclipse's .classpath file.

2020-05-15 Thread Coty Sutherland
On Fri, May 15, 2020 at 10:20 AM Christopher Schultz < ch...@christopherschultz.net> wrote: > -BEGIN PGP SIGNED MESSAGE- > Hash: SHA256 > > All, > > I'd like to talk about this. > > First, this is a patch to Tomcat 7 where a single version number > (wsdl4j) wasn't updated in all the places

Re: [VOTE] Release Apache Tomcat 10.0.0-M5

2020-05-06 Thread Coty Sutherland
On Tue, May 5, 2020 at 3:34 PM Mark Thomas wrote: > The proposed Apache Tomcat 10.0.0-M5 release is now available for > voting. > > Apache Tomcat 10.x implements Jakarta EE 9 and, as such, the primary > package for all the specification APIs has changed from javax.* to > jakarta.* > Applications

Re: [VOTE] Release Apache Tomcat 9.0.35

2020-05-06 Thread Coty Sutherland
On Tue, May 5, 2020 at 5:41 PM Mark Thomas wrote: > The proposed Apache Tomcat 9.0.35 release is now available for voting. > > The major changes compared to the 9.0.34 release are: > > - Improve the handling of requests that use an expectation. Do not > disable keep-alive where the response has

Re: [VOTE] Release Apache Tomcat 8.5.55

2020-05-06 Thread Coty Sutherland
On Tue, May 5, 2020 at 6:38 PM Mark Thomas wrote: > The proposed Apache Tomcat 8.5.55 release is now available for voting. > > The major changes compared to the 8.5.54 release are: > > - Improve the handling of requests that use an expectation. Do not > disable keep-alive where the response has

Re: Remove org.apache.catalina.tribes.transport.bio

2020-04-28 Thread Coty Sutherland
On Tue, Apr 28, 2020 at 12:30 PM Rémy Maucherat wrote: > Hi, > > I'm still looking at things to remove or refactor in 10 following the > rearchitecting failure for the Connector. One candidate could be the Tribes > transport, since NIO is the default and BIO is probably never used. > > Can it be

Re: git-fu is (still) weak

2020-04-28 Thread Coty Sutherland
On Tue, Apr 28, 2020 at 10:58 AM Christopher Schultz < ch...@christopherschultz.net> wrote: > -BEGIN PGP SIGNED MESSAGE- > Hash: SHA256 > > Coty, > > On 4/28/20 10:45, Coty Sutherland wrote: > > > > > > On Tue, Apr 28, 2020 at 10:2

Re: git-fu is (still) weak

2020-04-28 Thread Coty Sutherland
On Tue, Apr 28, 2020 at 10:21 AM Christopher Schultz < ch...@christopherschultz.net> wrote: > -BEGIN PGP SIGNED MESSAGE- > Hash: SHA256 > > Rémy, > > On 4/27/20 18:41, Rémy Maucherat wrote: > > On Tue, Apr 28, 2020 at 12:21 AM Christopher Schultz > > >

Re: [VOTE] Release Apache Tomcat 9.0.34

2020-04-06 Thread Coty Sutherland
On Fri, Apr 3, 2020 at 8:49 AM Mark Thomas wrote: > The proposed Apache Tomcat 9.0.34 release is now available for voting. > > The major changes compared to the 9.0.34 release are: > > - Add support for default values when using ${...} property replacement > in configuration files. Based on a p

Re: [VOTE] Release Apache Tomcat 10.0.0-M4

2020-04-06 Thread Coty Sutherland
On Fri, Apr 3, 2020 at 7:28 AM Mark Thomas wrote: > The proposed Apache Tomcat 10.0.0-M4 release is now available for > voting. > > Apache Tomcat 10.x implements Jakarta EE 9 and, as such, the primary > package for all the specification APIs has changed from javax.* to > jakarta.* > Applications

Re: [VOTE] Release Apache Tomcat 7.0.103

2020-03-19 Thread Coty Sutherland
On Mon, Mar 16, 2020 at 5:13 AM Violeta Georgieva wrote: > The proposed Apache Tomcat 7.0.103 release is now available for voting. > > It can be obtained from: > https://dist.apache.org/repos/dist/dev/tomcat/tomcat-7/v7.0.103/ > The Maven staging repo is: > https://repository.apache.org/content/r

Re: [VOTE] Release Apache Tomcat 10.0.0-M1

2020-02-14 Thread Coty Sutherland
On Fri, Feb 14, 2020 at 9:49 AM Mark Thomas wrote: > The proposed Apache Tomcat 10.0.0-M1 release is now available for > voting. This is the first release of 10.0.x and is based on 9.0.31. > > The major changes compared to 9.0.31 are: > > - Complete the javax to jakarta package rename > > - Remo

Re: [VOTE] Release Apache Tomcat 7.0.100

2020-02-13 Thread Coty Sutherland
On Tue, Feb 11, 2020 at 4:08 AM Violeta Georgieva wrote: > The proposed Apache Tomcat 7.0.100 release is now available for voting. > > It can be obtained from: > https://dist.apache.org/repos/dist/dev/tomcat/tomcat-7/v7.0.100/ > The Maven staging repo is: > https://repository.apache.org/content/r

Re: Numbering schemes for future releases

2020-02-10 Thread Coty Sutherland
On Mon, Feb 10, 2020 at 4:48 AM Mark Thomas wrote: > Hi, > > I thought it would be useful to re-open the discussion on this. If there > is a better plan that the one we currently have I'd like to try and find > it. > > I'm happy to hold off on the current 10.0.0.0-M1 release for a few days > to g

Re: [PROPOSAL] Tomcat 10: change default certificateKeystoreType and truststoreType from JKS to PKCS12

2020-01-29 Thread Coty Sutherland
On Tue, Jan 28, 2020 at 12:07 PM Christopher Schultz < ch...@christopherschultz.net> wrote: > -BEGIN PGP SIGNED MESSAGE- > Hash: SHA256 > > All, > > The subject says it all. > > Java 9 is changing the default keystore type from JKS to PKCS12 and > deprecating the use of JKS. > > Do we know

Re: Tomcat 7.0.x end of life

2020-01-15 Thread Coty Sutherland
On Tue, Jan 14, 2020 at 3:56 PM Mark Thomas wrote: > Hi all, > > This has been mentioned several times as we have figured out our > approach to Jakarta EE 9 and Tomcat 10. I'd like to formally propose > that we announce end of life for Tomcat 7.0.x as 31 March 2021. > > Thoughts? > +1 > > Mark

Re: [VOTE] Release Apache Tomcat 8.5.50

2019-12-09 Thread Coty Sutherland
On Sat, Dec 7, 2019 at 2:54 PM Mark Thomas wrote: > The proposed Apache Tomcat 8.5.50 release is now available for voting. > > The major changes compared to the 8.5.49 release are: > > - Correct multiple regressions in the static resource caching related to > using URLs provided for cached reso

Re: [VOTE] Release Apache Tomcat 9.0.30

2019-12-09 Thread Coty Sutherland
On Sat, Dec 7, 2019 at 12:24 PM Mark Thomas wrote: > The proposed Apache Tomcat 9.0.30 release is now available for voting. > > The major changes compared to the 9.0.29 release are: > > - Correct multiple regressions in the static resource caching related to > using URLs provided for cached res

Re: [VOTE] Release Apache Tomcat 8.5.49

2019-11-18 Thread Coty Sutherland
On Sun, Nov 17, 2019 at 2:01 PM Mark Thomas wrote: > The proposed Apache Tomcat 8.5.49 release is now available for voting. > > The major changes compared to the 8.5.47 release are: > > - Improvements to Async error handling > > - Stricter processing of HTTP headers when looking for specific toke

Re: [VOTE] Release Apache Tomcat 9.0.29

2019-11-18 Thread Coty Sutherland
On Sat, Nov 16, 2019 at 1:56 PM Mark Thomas wrote: > The proposed Apache Tomcat 9.0.29 release is now available for voting. > > The major changes compared to the 9.0.27 release are: > > - Improvements to Async error handling > > - Stricter processing of HTTP headers when looking for specific toke

Re: [VOTE] Release Apache Tomcat 9.0.27

2019-10-07 Thread Coty Sutherland
On Mon, Oct 7, 2019 at 7:51 AM Mark Thomas wrote: > The proposed Apache Tomcat 9.0.27 release is now available for voting. > > The major changes compared to the 9.0.26 release are: > > - Update to Commons Daemon 1.2.2 to pick up the fix for a regression in > Commons Daemon 1.2.0 and 1.2.1 that

Re: [PROPOSAL] Tomcat 10: Remove Server-Side Includes (SSI)

2019-10-07 Thread Coty Sutherland
On Mon, Oct 7, 2019 at 10:46 AM Christopher Schultz < ch...@christopherschultz.net> wrote: > -BEGIN PGP SIGNED MESSAGE- > Hash: SHA256 > > All, > > I recently gave a presentation on locking-down Apache Tomcat[1] and I > briefly discussed the "sharp edges" present in Tomcat. Some of them >

Re: [PROPOSAL] Tomcat 10: Remove CGI Servlet

2019-10-07 Thread Coty Sutherland
On Mon, Oct 7, 2019 at 11:00 AM Christopher Schultz < ch...@christopherschultz.net> wrote: > -BEGIN PGP SIGNED MESSAGE- > Hash: SHA256 > > All, > > I recently gave a presentation on locking-down Apache Tomcat[1] and I > briefly discussed the "sharp edges" present in Tomcat. Some of them >

Re: [PROPOSAL] Tomcat 10: Drop APR Connector

2019-10-07 Thread Coty Sutherland
On Mon, Oct 7, 2019 at 10:39 AM Christopher Schultz < ch...@christopherschultz.net> wrote: > -BEGIN PGP SIGNED MESSAGE- > Hash: SHA256 > > All, > > I recently gave a presentation on locking-down Apache Tomcat[1] and I > briefly discussed the "sharp edges" present in Tomcat. Some of them >

Re: Tomcat-Native - Time to move to git?

2019-06-17 Thread Coty Sutherland
On Mon, Jun 17, 2019 at 12:56 PM Mark Thomas wrote: > Hi, > > I'm starting to look at OCSP stapling for our OpenSSL based connectors > and I suspect a Tomcat Native release will be required. Even if it isn't > for this, it has been a while since the last Tomcat Native release so I > expect we'll

Re: [VOTE] Release Apache Tomcat 8.5.42

2019-06-05 Thread Coty Sutherland
On Tue, Jun 4, 2019 at 5:06 PM Mark Thomas wrote: > The proposed Apache Tomcat 8.5.42 release is now available for voting. > > The major changes compared to the 8.5.41 release are: > > - Fix various concurrency and stability issues for HTTP/2. > > - Add support for same-site cookie attribute. Pat

Re: [VOTE] Release Apache Tomcat 9.0.21

2019-06-05 Thread Coty Sutherland
On Tue, Jun 4, 2019 at 4:50 PM Mark Thomas wrote: > The proposed Apache Tomcat 9.0.21 release is now available for voting. > > The major changes compared to the 9.0.20 release are: > > - Fix various concurrency and stability issues for HTTP/2. > > - Add support for same-site cookie attribute. Pat

Are we interested in using any the GitHub features?

2019-05-28 Thread Coty Sutherland
Hi, Are we interested in utilizing any of the GitHub integration for Travis CI , Coverity Scan , LGTM , etc? We could at least set them up for testing PRs since we already have the Apac

Re: Proposal for TLS config sanity check

2019-05-23 Thread Coty Sutherland
On Tue, May 21, 2019 at 5:43 PM Mark Thomas wrote: > On 21/05/2019 21:46, Christopher Schultz wrote: > > All, > > > > Looking at the legacy-versus-modern TLS configuration (Connector vs > > SSLHostConfig), it seems easy for an admin to create a configuration > > that looks like this (paraphrasing

Re: [tomcat] branch master updated: Use https instead of http

2019-05-21 Thread Coty Sutherland
anch master > >> in repository https://gitbox.apache.org/repos/asf/tomcat.git > >> > >> > >> The following commit(s) were added to refs/heads/master by this push: > >> new beb2dca Use https instead of http > >> beb2dca is described be

Re: The migration guide configuration file difference feature is broken

2019-05-08 Thread Coty Sutherland
On Wed, May 8, 2019 at 11:17 AM Mark Thomas wrote: > On 08/05/2019 15:35, Coty Sutherland wrote: > > Hi, > > > > Someone on freenode (CiscoEagle) pointed out to me that the migration > > guide's file comparison feature doesn't work :( Looking at the "

The migration guide configuration file difference feature is broken

2019-05-08 Thread Coty Sutherland
Hi, Someone on freenode (CiscoEagle) pointed out to me that the migration guide's file comparison feature doesn't work :( Looking at the "configure file differences" section on the 9.0 migration guide ( http://tomcat.apache.org/migration-9.html#Tomcat_9.0.x_configuration_file_differences), if you

Re: Finally getting around to switching to Git

2019-04-26 Thread Coty Sutherland
On Fri, Apr 26, 2019 at 3:13 AM Mark Thomas wrote: > On 25/04/2019 20:07, Christopher Schultz wrote: > > On 4/25/19 14:03, Igal Sapir wrote: > > > > >> In some projects it's easy to maintain a single repository and > >> switch between branches, but I find the differences between 7.0.x > >> and m

Re: Finally getting around to switching to Git

2019-04-25 Thread Coty Sutherland
On Thu, Apr 25, 2019 at 2:06 PM Igal Sapir wrote: > On 4/25/2019 10:56 AM, Coty Sutherland wrote: > > On Thu, Apr 25, 2019 at 1:32 PM Christopher Schultz < > > ch...@christopherschultz.net> wrote: > > > >> -BEGIN PGP SIGNED MESSAGE- > >> Hash

Re: Finally getting around to switching to Git

2019-04-25 Thread Coty Sutherland
On Thu, Apr 25, 2019 at 1:32 PM Christopher Schultz < ch...@christopherschultz.net> wrote: > -BEGIN PGP SIGNED MESSAGE- > Hash: SHA256 > > Igal, > > On 4/23/19 12:52, Igal Sapir wrote: > > Another thing that I have changed in my workflow based on Mark's > > past suggestion, is that I keep

Re: Finally getting around to switching to Git

2019-04-23 Thread Coty Sutherland
On Tue, Apr 23, 2019 at 10:33 AM Rémy Maucherat wrote: > On Tue, Apr 23, 2019 at 4:29 PM Christopher Schultz < > ch...@christopherschultz.net> wrote: > > > -BEGIN PGP SIGNED MESSAGE- > > Hash: SHA256 > > > > Rémy, > > > > On 4/23/19 10:07, Rémy Maucherat wrote: > > > On Tue, Apr 23, 2019

Re: SSLv2Hello "Protocol" Support

2019-04-17 Thread Coty Sutherland
On Wed, Apr 17, 2019 at 2:18 PM Christopher Schultz < ch...@christopherschultz.net> wrote: > -BEGIN PGP SIGNED MESSAGE- > Hash: SHA256 > > Coty, > > On 4/16/19 07:28, Coty Sutherland wrote: > > Hi, > > > > It appears that the IBM JDK (version 8)

Re: SSLv2Hello "Protocol" Support

2019-04-17 Thread Coty Sutherland
If we haven't tried to remove it in 5 years it might be worth another look :) On Wed, Apr 17, 2019 at 3:49 AM jean-frederic clere wrote: > On 16/04/2019 13:28, Coty Sutherland wrote: > > Hi, > > > > It appears that the IBM JDK (version 8) has dropped support for &g

SSLv2Hello "Protocol" Support

2019-04-16 Thread Coty Sutherland
Hi, It appears that the IBM JDK (version 8) has dropped support for SSLv2Hello so when you startup tomcat with the IBM JDK you get a warning saying that the protocol is being skipped. OpenJDK seems to have dropped it in version 12 or 13 (I haven't tested, just noticed a user list thread about it)

  1   2   3   >