DO NOT REPLY [Bug 37018] New: - Document how to use tomcat-SSL with a pkcs11 token

2005-10-11 Thread bugzilla
/show_bug.cgi?id=37018 Summary: Document how to use tomcat-SSL with a pkcs11 token Product: Tomcat 5 Version: 5.5.9 Platform: Other URL: http://java.sun.com/j2se/1.5.0/docs/guide/security/p11gu ide.html OS/Version: other

DO NOT REPLY [Bug 36735] New: - Problem with SSL - swf - Explorer

2005-09-20 Thread bugzilla
/show_bug.cgi?id=36735 Summary: Problem with SSL - swf - Explorer Product: Tomcat 5 Version: 5.0.28 Platform: Other OS/Version: other Status: NEW Severity: normal Priority: P2 Component: Catalina AssignedTo

DO NOT REPLY [Bug 36735] - Problem with SSL - swf - Explorer

2005-09-20 Thread bugzilla
DO NOT REPLY TO THIS EMAIL, BUT PLEASE POST YOUR BUG· RELATED COMMENTS THROUGH THE WEB INTERFACE AVAILABLE AT http://issues.apache.org/bugzilla/show_bug.cgi?id=36735. ANY REPLY MADE TO THIS MESSAGE WILL NOT BE COLLECTED AND· INSERTED IN THE BUG DATABASE.

DO NOT REPLY [Bug 27122] - IE plugins cannot access components through Tomcat 5 over SSL

2005-09-20 Thread bugzilla
DO NOT REPLY TO THIS EMAIL, BUT PLEASE POST YOUR BUG· RELATED COMMENTS THROUGH THE WEB INTERFACE AVAILABLE AT http://issues.apache.org/bugzilla/show_bug.cgi?id=27122. ANY REPLY MADE TO THIS MESSAGE WILL NOT BE COLLECTED AND· INSERTED IN THE BUG DATABASE.

DO NOT REPLY [Bug 35765] - make the SSL cipher config in server.xml fail safe, i.e. 128+ bit strength by default

2005-09-13 Thread bugzilla
DO NOT REPLY TO THIS EMAIL, BUT PLEASE POST YOUR BUG· RELATED COMMENTS THROUGH THE WEB INTERFACE AVAILABLE AT http://issues.apache.org/bugzilla/show_bug.cgi?id=35765. ANY REPLY MADE TO THIS MESSAGE WILL NOT BE COLLECTED AND· INSERTED IN THE BUG DATABASE.

DO NOT REPLY [Bug 36133] New: - Support JSS SSL implementation

2005-08-10 Thread bugzilla
/show_bug.cgi?id=36133 Summary: Support JSS SSL implementation Product: Tomcat 5 Version: 5.5.9 Platform: All OS/Version: All Status: NEW Severity: enhancement Priority: P2 Component: Unknown AssignedTo

Tomcat 5.5.10: APR-SSL doesn't work in chrooted UML

2005-08-09 Thread Markus Schönhaber
Hello! I'm trying to run Tomcat 5.5.10 [1] on user mode linux which is started in a chrooted environment but Tomcat hangs when initializing the SSL-Connector - i. e. the message org.apache.coyote.http11.Http11AprProtocol init does never show up in the log. When I try to connect to the SSL-port

How to do authentication and secure line HTTPS (SSL)

2005-07-20 Thread Abdullah Abdullah
Dear all Actually, I would like to ask you that how can I do authentication and secure line HTTPS (SSL) for my web pages ? It is worth mentioning that I am using JSP and Tomcat 5.5.9 . Thank you in advance. Regards Abdullah

Re: How to do authentication and secure line HTTPS (SSL)

2005-07-20 Thread Mark Thomas
Please post this, and any other requests relating to the usage of Tomcat rather than the development of Tomcat, to the tomcat-user list. Mark - To unsubscribe, e-mail: [EMAIL PROTECTED] For additional commands, e-mail:

DO NOT REPLY [Bug 35765] - make the SSL cipher config in server.xml fail safe, i.e. 128+ bit strength by default

2005-07-17 Thread bugzilla
/show_bug.cgi?id=35765 [EMAIL PROTECTED] changed: What|Removed |Added Summary|make the SSL cipher config |make the SSL cipher config |in web.xml fail safe, i.e

DO NOT REPLY [Bug 35765] New: - make the SSL cipher config in web.xml fail safe, i.e. 128+ bit strength by default

2005-07-16 Thread bugzilla
/show_bug.cgi?id=35765 Summary: make the SSL cipher config in web.xml fail safe, i.e. 128+ bit strength by default Product: Tomcat 5 Version: Nightly Build Platform: Other URL: http://java.sun.com/j2se/1.5.0/docs/guide/security

Re: Feature Request: Optional No Cert validation on SSL connector

2005-06-30 Thread Chad La Joie
Yep, this is a problem. And, as I said, we don't have keystores, so even if it did pick up the new cert it still wouldn't work for us. jean-frederic clere wrote: OK I have added a new CA using: +++ [EMAIL PROTECTED]:~ $JAVA_HOME/bin/keytool -import -trustcacerts -file

Re: Feature Request: Optional No Cert validation on SSL connector

2005-06-29 Thread jean-frederic clere
Chad La Joie wrote: jean-frederic clere wrote: Chad La Joie wrote: Yeah, I know what mod-ssl says, and for most cases it's probably right, however the optional_no_ca option is interesting to us because it provides exactly the functionality that we need; accepting the client cert, putting

Re: Feature Request: Optional No Cert validation on SSL connector

2005-06-28 Thread jean-frederic clere
for the SSL connector when client cert auth is used so that we can support a stand alone Tomcat set up too. Would this be possible? - To unsubscribe, e-mail: [EMAIL PROTECTED] For additional commands, e-mail: [EMAIL PROTECTED]

Re: Feature Request: Optional No Cert validation on SSL connector

2005-06-28 Thread jean-frederic clere
Chad La Joie wrote: Hey guys, I was wondering if there were any thoughts on this particular suggestion. I hadn't seen anything on the list. BTW: mod-ssl says: +++ In practice only levels none and require are really interesting, because level optional doesn't work with all browsers

Re: Feature Request: Optional No Cert validation on SSL connector

2005-06-28 Thread Chad La Joie
Yeah, I know what mod-ssl says, and for most cases it's probably right, however the optional_no_ca option is interesting to us because it provides exactly the functionality that we need; accepting the client cert, putting it in a standard place, and allowing our application to do the verification

Re: Feature Request: Optional No Cert validation on SSL connector

2005-06-28 Thread jean-frederic clere
Chad La Joie wrote: Yeah, I know what mod-ssl says, and for most cases it's probably right, however the optional_no_ca option is interesting to us because it provides exactly the functionality that we need; accepting the client cert, putting it in a standard place, and allowing our application

Re: Feature Request: Optional No Cert validation on SSL connector

2005-06-28 Thread Chad La Joie
jean-frederic clere wrote: Chad La Joie wrote: Yeah, I know what mod-ssl says, and for most cases it's probably right, however the optional_no_ca option is interesting to us because it provides exactly the functionality that we need; accepting the client cert, putting it in a standard

Re: Feature Request: Optional No Cert validation on SSL connector

2005-06-27 Thread Chad La Joie
the cert on to the Shibboleth server. This allows us to validate the certificate against the cert chains in the metadata files within the server code (a huge support boon for us). What we'd like to request is a similar option for the SSL connector when client cert auth is used so that we can

Re: Re: Feature Request: Optional No Cert validation on SSL connector

2005-06-27 Thread gerencia
su correo ha sido recepcionado. gracias - To unsubscribe, e-mail: [EMAIL PROTECTED] For additional commands, e-mail: [EMAIL PROTECTED]

Re: Re: Re: Feature Request: Optional No Cert validation on SSL connector

2005-06-27 Thread gerencia
su correo ha sido recepcionado. gracias - To unsubscribe, e-mail: [EMAIL PROTECTED] For additional commands, e-mail: [EMAIL PROTECTED]

Re: Re: Re: Re: Feature Request: Optional No Cert validation on SSL connector

2005-06-27 Thread gerencia
su correo ha sido recepcionado. gracias - To unsubscribe, e-mail: [EMAIL PROTECTED] For additional commands, e-mail: [EMAIL PROTECTED]

Re: Re: Re: Re: Re: Re: Feature Request: Optional No Cert validation on SSL connector

2005-06-27 Thread gerencia
su correo ha sido recepcionado. gracias - To unsubscribe, e-mail: [EMAIL PROTECTED] For additional commands, e-mail: [EMAIL PROTECTED]

Re: Re: Re: Re: Re: Re: Re: Feature Request: Optional No Cert validation on SSL connector

2005-06-27 Thread gerencia
su correo ha sido recepcionado. gracias - To unsubscribe, e-mail: [EMAIL PROTECTED] For additional commands, e-mail: [EMAIL PROTECTED]

Re: Re: Re: Re: Re: Re: Re: Re: Feature Request: Optional No Cert validation on SSL connector

2005-06-27 Thread gerencia
su correo ha sido recepcionado. gracias - To unsubscribe, e-mail: [EMAIL PROTECTED] For additional commands, e-mail: [EMAIL PROTECTED]

Re: Re: Re: Re: Re: Re: Re: Re: Re: Feature Request: Optional No Cert validation on SSL connector

2005-06-27 Thread gerencia
su correo ha sido recepcionado. gracias - To unsubscribe, e-mail: [EMAIL PROTECTED] For additional commands, e-mail: [EMAIL PROTECTED]

Re: Re: Re: Re: Re: Re: Re: Re: Re: Re: Feature Request: Optional No Cert validation on SSL connector

2005-06-27 Thread gerencia
su correo ha sido recepcionado. gracias - To unsubscribe, e-mail: [EMAIL PROTECTED] For additional commands, e-mail: [EMAIL PROTECTED]

Re: Re: Re: Re: Re: Re: Re: Re: Re: Re: Re: Feature Request: Optional No Cert validation on SSL connector

2005-06-27 Thread gerencia
su correo ha sido recepcionado. gracias - To unsubscribe, e-mail: [EMAIL PROTECTED] For additional commands, e-mail: [EMAIL PROTECTED]

AUTO {TOML#001-926-076}Feature Request: Optional No Cert validation on SSL connector

2005-06-27 Thread info
Dear Customer, Thank you for your interest in the services offered by TimesofMoney.com.We have received your email. Our Customer Relations Officer will get in touch with you shortly. Assuring you of our best services always. Warm Regards, Customer Relations TimesofMoney.com A Times Group

AUTO {TOML#001-926-078}Feature Request: Optional No Cert validation on SSL connector

2005-06-27 Thread info
Dear Customer, Thank you for your interest in the services offered by TimesofMoney.com.We have received your email. Our Customer Relations Officer will get in touch with you shortly. Assuring you of our best services always. Warm Regards, Customer Relations TimesofMoney.com A Times Group

Feature Request: Optional No Cert validation on SSL connector

2005-06-21 Thread Chad La Joie
support boon for us). What we'd like to request is a similar option for the SSL connector when client cert auth is used so that we can support a stand alone Tomcat set up too. Would this be possible? -- Chad La Joie 315Q St. Mary's Hall Project Sentinel 202.687.0124

Tomcat 5.x client SSL and CRL

2005-06-02 Thread Atul
Hi, I was trying to get tomcat 5.x (standalone) setup for mutual ssl for (only some service URLs) with CRL/OCSP validations. If I write my own CRL validator, how can I tell tomcat to invoke it for such requests? I tried various docs, lists but couldn'tfind any pointers. Any pointers are appeciated

Re: Hybrid (NIO+Multithread, SSL enabled) architecture for Coyote

2005-05-26 Thread Remy Maucherat
Vicenc Beltran Querol wrote: It has been a pleasure to post this information, and to receive constructive and technically-reasoned answers like yours. Deciding which parameters define the performance of a server is a great and never-ending discussion topic. Anyway, feel free to send my any

Re: Hybrid (NIO+Multithread, SSL enabled) architecture for Coyote

2005-05-25 Thread Vicenc Beltran Querol
Hi, The results of the AB benchmark configured with 20 concurrent clients are posted below, If somebody is interested in more configurations (from 20 to 1 concurrent clients) they are available at http://www.bsc.es/edragon/pdf/TestAb.tgz BTW, there is also available a comparison between

Re: Hybrid (NIO+Multithread, SSL enabled) architecture for Coyote

2005-05-25 Thread Peter Lin
Am I reading the results correctly? tomcat 5.5.9 - 16,331.81/sec hybrid - 7,085.54/sec that means the hybrid connector is 2x slower. If those results are accurate, I would say the APR connector is much better choice. peter lin On 5/25/05, Vicenc Beltran Querol [EMAIL PROTECTED] wrote: Hi,

Re: Hybrid (NIO+Multithread, SSL enabled) architecture for Coyote

2005-05-25 Thread Remy Maucherat
Peter Lin wrote: Am I reading the results correctly? tomcat 5.5.9 - 16,331.81/sec hybrid - 7,085.54/sec that means the hybrid connector is 2x slower. If those results are accurate, I would say the APR connector is much better choice. It's more complex than that. The APR connector has a

Re: Hybrid (NIO+Multithread, SSL enabled) architecture for Coyote

2005-05-25 Thread Vicenc Beltran Querol
Hi, The APR connector has a trick to optimize pipelining (where a client would do many requests on a single connection, but with a small delay between requests - typically, it would happen when getting lots of images from a website). What's the trick? Are you trying to do blocking read

Re: Hybrid (NIO+Multithread, SSL enabled) architecture for Coyote

2005-05-25 Thread Remy Maucherat
Vicenc Beltran Querol wrote: It's great to read your opinions... ;) Let's cut down on the broken record effect then: -1 for your code, it's not a clean implementation ;) (I end up with a smiley, since you did as well) Rémy

Re: Hybrid (NIO+Multithread, SSL enabled) architecture for Coyote

2005-05-25 Thread Peter Lin
On 5/25/05, Vicenc Beltran Querol [EMAIL PROTECTED] wrote: Hi, I'm absolutely disconcerted. In your previous answeryou agreed that the AB test is not good for comparing two different architectural approaches. And you still wanna compare the performance of the hybrid architecture using it.

Re: Hybrid (NIO+Multithread, SSL enabled) architecture for Coyote

2005-05-25 Thread Remy Maucherat
Peter Lin wrote: I'm not sure I agree with that statement. The reason for using apache AB for small files under 2K is that JMeter is unable to max out the server with tiny files. You can see the original number I produced here http://people.apache.org/~woolfel/tc_results.html. Since the bulk of

Re: Hybrid (NIO+Multithread, SSL enabled) architecture for Coyote

2005-05-25 Thread Peter Lin
I took a look at the AB and Rubis numbers. Honestly I don't understand the rubis graphs. From the AB results, it looks like the connect, processing and wait times are lower for the hybrid. That's a good achievement and congrats to you on that. I'm not convinced of the benefit of the hybrid

Re: Hybrid (NIO+Multithread, SSL enabled) architecture for Coyote

2005-05-25 Thread Mladen Turk
Remy Maucherat wrote: In my mind, the argument for tomcat supporting 1000 concurrent connections for an extended period of time isn't valid from my experience. - all the other APR features which are really useful and not provided by the core Java platform Actually I just read a perfect

Re: Hybrid (NIO+Multithread, SSL enabled) architecture for Coyote

2005-05-25 Thread Remy Maucherat
Mladen Turk wrote: Actually I just read a perfect use case scenario request for the new APR connector on [EMAIL PROTECTED] With only couple of threads all the 1000 connections could be handled without having 1000 threads. Actually, it seems a lot more a case of using the servlet API in a way

Re: Hybrid (NIO+Multithread, SSL enabled) architecture for Coyote

2005-05-25 Thread Vicenc Beltran Querol
Hi Peter, I took a look at the AB and Rubis numbers. Honestly I don't understand the rubis graphs. You can find an explanation about the httperf numbers on the man page of Httperf, or looking at http://www.hpl.hp.com/personal/David_Mosberger/httperf.html. Rubis is the dynamic application

RE: Hybrid (NIO+Multithread, SSL enabled) architecture for Coyote

2005-05-25 Thread Yoav Shapira
Hi, By the way, this is my last post about this topic. I've perfectly understood Remy's messages (in the list and in my personal address), so I will not waste your time anymore. It was far from a waste of time. Please don't hesitate to contribute again in performance tuning or other areas.

Re: Hybrid (NIO+Multithread, SSL enabled) architecture for Coyote

2005-05-24 Thread Vicenc Beltran Querol
Hi, I've repeated the tests on the hybrid architecture using the AB. You can find them attached to this mail. I've run the AB with several concurrency levels, ranging from 20 to 1. You can see all the results in a plot. Running a test with ab (ab -k -c 20 -n 2

Re: Hybrid (NIO+Multithread, SSL enabled) architecture for Coyote

2005-05-24 Thread Remy Maucherat
Vicenc Beltran Querol wrote: Hi, I've repeated the tests on the hybrid architecture using the AB. You can find them attached to this mail. I've run the AB with several concurrency levels, ranging from 20 to 1. You can see all the results in a plot. -c 20 -k is basically the only thing I

Re: Hybrid (NIO+Multithread, SSL enabled) architecture for Coyote

2005-05-24 Thread Remy Maucherat
Remy Maucherat wrote: I've repeated the tests on the hybrid architecture using the AB. You can find them attached to this mail. I've run the AB with several concurrency levels, ranging from 20 to 1. You can see all the results in a plot. Here are the results. Rémy

Re: Hybrid (NIO+Multithread, SSL enabled) architecture for Coyote

2005-05-24 Thread Remy Maucherat
Remy Maucherat wrote: Remy Maucherat wrote: I've repeated the tests on the hybrid architecture using the AB. You can find them attached to this mail. I've run the AB with several concurrency levels, ranging from 20 to 1. You can see all the results in a plot. Here are the results.

Re: Hybrid (NIO+Multithread, SSL enabled) architecture for Coyote

2005-05-23 Thread Vicenc Beltran Querol
On Fri, May 20, 2005 at 12:05:51PM +0200, Mladen Turk wrote: Vicenç Beltran wrote: Hi, attached you'll find a patch that changes the coyote multithreading model to a hybrid threading model (NIO+Mulithread). It's fully compatible with the existing Catalina code and is SSL enabled. diff

Re: Hybrid (NIO+Multithread, SSL enabled) architecture for Coyote

2005-05-23 Thread Remy Maucherat
from http://www.bsc.es/edragon/pdf/TestSurge.tgz As a summary, the throughput improvement I've observed is about a 25%, without breaking the response time. You can see all the results (original, patched and comparison) in the above file. I'm finishing the Dynamic content (plain and SSL

Hybrid (NIO+Multithread, SSL enabled) architecture for Coyote

2005-05-20 Thread Vicenç Beltran
Hi, attached you'll find a patch that changes the coyote multithreading model to a hybrid threading model (NIO+Mulithread). It's fully compatible with the existing Catalina code and is SSL enabled. The Hybrid model breaks the limitation of one thread per connection, thus you can have a higher

Re: Hybrid (NIO+Multithread, SSL enabled) architecture for Coyote

2005-05-20 Thread Mladen Turk
Vicenç Beltran wrote: Hi, attached you'll find a patch that changes the coyote multithreading model to a hybrid threading model (NIO+Mulithread). It's fully compatible with the existing Catalina code and is SSL enabled. diff -uprN jakarta-tomcat-5.5.9-src/jakarta-tomcat-connectors/http11/src

Re: Hybrid (NIO+Multithread, SSL enabled) architecture for Coyote

2005-05-20 Thread Remy Maucherat
Vicenç Beltran wrote: Hi, attached you'll find a patch that changes the coyote multithreading model to a hybrid threading model (NIO+Mulithread). It's fully compatible with the existing Catalina code and is SSL enabled. The Hybrid model breaks the limitation of one thread per connection, thus

Re: Hybrid (NIO+Multithread, SSL enabled) architecture for Coyote

2005-05-20 Thread Remy Maucherat
Mladen Turk wrote: Vicenç Beltran wrote: Can't you simply make two new files Http11NioProcessor and Http11NioProtocol. It definitely needs to be a (clean, this means no multiple /* */ in patch submissions ;) ) separate implementation. Actually it will also need a separate NioEndpoint (I would

Re: Hybrid (NIO+Multithread, SSL enabled) architecture for Coyote

2005-05-20 Thread Vicenc Beltran Querol
Hi guys, I'm not trying to be a Tomcat developer. I'm working on my PhD on web performance and just decided to share with you the experimental code I've developed after studying the performance obtained ;). Anyway, it's OK. I'll work on the new patch and resubmit it. Thanks for the comments,

Re: Hybrid (NIO+Multithread, SSL enabled) architecture for Coyote

2005-05-20 Thread Mladen Turk
Vicenc Beltran Querol wrote: Hi guys, I'm not trying to be a Tomcat developer. I'm working on my PhD on web performance and just decided to share with you the experimental code I've developed after studying the performance obtained ;). I've done some serious testings with HTTP server and NIO.

Re: Hybrid (NIO+Multithread, SSL enabled) architecture for Coyote

2005-05-20 Thread Jeanfrancois Arcand
Mladen Turk wrote: Vicenc Beltran Querol wrote: Hi guys, I'm not trying to be a Tomcat developer. I'm working on my PhD on web performance and just decided to share with you the experimental code I've developed after studying the performance obtained ;). I've done some serious testings with

Re: Hybrid (NIO+Multithread, SSL enabled) architecture for Coyote

2005-05-20 Thread Remy Maucherat
Jeanfrancois Arcand wrote: I disagree ;-) I would like to see your implementation, because from what I'm seeing/measuring, it is completely the inverse. I would be interested to see how you did implement your NIO connector. The problem with HTTP is not NIO, but the strategy to use for

Re: Hybrid (NIO+Multithread, SSL enabled) architecture for Coyote

2005-05-20 Thread Bill Barker
- Original Message - From: Jeanfrancois Arcand [EMAIL PROTECTED] To: Tomcat Developers List tomcat-dev@jakarta.apache.org Sent: Friday, May 20, 2005 6:56 AM Subject: Re: Hybrid (NIO+Multithread, SSL enabled) architecture for Coyote Mladen Turk wrote: Vicenc Beltran Querol wrote: Hi

Re: Hybrid (NIO+Multithread, SSL enabled) architecture for Coyote

2005-05-20 Thread Peter Lin
I'm not a committer, but I think evidence proves that native sockets + JNI is the way to go. To my knowledge, weblogic, websphere and Resin all use native sockets. having a pure Java approach sounds nice and all, but in the edge cases where high concurrent connection is needed, I much rather go

Re: Hybrid (NIO+Multithread, SSL enabled) architecture for Coyote

2005-05-20 Thread Mladen Turk
Jeanfrancois Arcand wrote: I've done some serious testings with HTTP server and NIO. The results were always bad for NIO. Blocking I/O is minimum 25% faster then NIO. Faster in what? Throughput and/or scalability? I disagree ;-) I would like to see your implementation, because from what I'm

Re: Hybrid (NIO+Multithread, SSL enabled) architecture for Coyote

2005-05-20 Thread Jeanfrancois Arcand
Remy Maucherat wrote: Jeanfrancois Arcand wrote: I disagree ;-) I would like to see your implementation, because from what I'm seeing/measuring, it is completely the inverse. I would be interested to see how you did implement your NIO connector. The problem with HTTP is not NIO, but the

Re: Hybrid (NIO+Multithread, SSL enabled) architecture for Coyote

2005-05-20 Thread Jeanfrancois Arcand
Mladen Turk wrote: Jeanfrancois Arcand wrote: I've done some serious testings with HTTP server and NIO. The results were always bad for NIO. Blocking I/O is minimum 25% faster then NIO. Faster in what? Throughput and/or scalability? I disagree ;-) I would like to see your implementation, because

Re: Hybrid (NIO+Multithread, SSL enabled) architecture for Coyote

2005-05-20 Thread Remy Maucherat
Jeanfrancois Arcand wrote: Well, the strategy you use is important. If you can predict the size of the stream (by let say discovering the content-length), you can make uploading task as fast as with blocking IO (OK, maybe a little slower since you parse the header, and the channel may not reads

How to redirect all ports to use SSL?

2005-05-04 Thread Donny R Rota
I want all my Tomcat requests to go through SSL. I want the URLs to look like https://this/ and not https://this:8443 I setup tomcat, and got ssl working on 8443. But I cannot redirect port 80 to 8443. I keep getting 'access denied'. Is there a way in Tomcat to redirect all port 80

Re: How to redirect all ports to use SSL?

2005-05-04 Thread Mark Thomas
This is a question for tomcat-user, not tomcat-dev Mark Donny R Rota wrote: I want all my Tomcat requests to go through SSL. I want the URLs to look like https://this/ and not https://this:8443 I setup tomcat, and got ssl working on 8443. But I cannot redirect port 80 to 8443. I keep

Re: [PATCH] Tomcat 5.X connectors SSL Accelerator proxy support

2005-04-06 Thread jean-frederic clere
[EMAIL PROTECTED] wrote: Dev Team, Attached is a patch to address the Tomcat 5.X inability to specify a secure proxy without an SSL connection. The goal is to specify secure=true, scheme=https, proxyPort=443, and proxyName=ssl-accelerator.domain.com on a plain HTTP Connector in server.xml. BTW

[PATCH] Tomcat 5.X connectors SSL Accelerator proxy support

2005-04-02 Thread watler
Dev Team, Attached is a patch to address the Tomcat 5.X inability to specify a secure proxy without an SSL connection. The goal is to specify secure=true, scheme=https, proxyPort=443, and proxyName=ssl-accelerator.domain.com on a plain HTTP Connector in server.xml. I am not sure

[PATCH] Tomcat 5.X connectors SSL Accelerator proxy support

2005-04-02 Thread watler
Dev Team, Attached is a patch to address the Tomcat 5.X inability to specify a secure proxy without an SSL connection. The goal is to specify secure=true, scheme=https, proxyPort=443, and proxyName=ssl-accelerator.domain.com on a plain HTTP Connector in server.xml. I am not sure

DO NOT REPLY [Bug 33883] - openssl pkcs12 -infile/-outfile bad options in SSL Configuration HOW-TO example

2005-03-24 Thread bugzilla
DO NOT REPLY TO THIS EMAIL, BUT PLEASE POST YOUR BUG· RELATED COMMENTS THROUGH THE WEB INTERFACE AVAILABLE AT http://issues.apache.org/bugzilla/show_bug.cgi?id=33883. ANY REPLY MADE TO THIS MESSAGE WILL NOT BE COLLECTED AND· INSERTED IN THE BUG DATABASE.

cvs commit: jakarta-tomcat-catalina/webapps/docs changelog.xml ssl-howto.xml

2005-03-23 Thread yoavs
yoavs 2005/03/23 08:31:41 Modified:webapps/docs changelog.xml ssl-howto.xml Log: Bugzilla 33883. Revision ChangesPath 1.253 +3 -0 jakarta-tomcat-catalina/webapps/docs/changelog.xml Index: changelog.xml

Re: tomcat 4.1.x with jdk1.4.2 ssl certificate(4096-key length) support - again

2005-03-10 Thread Matej Kafadar
Bruce, thanks for response. I know java has problem. Tomcat is here because I would like to have tomcat with SSL (with rsa key 4096 length support). I installed unlimited JCE strength and problem stil exist. Can anyone confirm does Java 1.4 support 4096 RSA key size or only 2048. Best regards

DO NOT REPLY [Bug 22701] - commons-logging and SSL in tomcat with struts

2005-03-10 Thread bugzilla
DO NOT REPLY TO THIS EMAIL, BUT PLEASE POST YOUR BUG· RELATED COMMENTS THROUGH THE WEB INTERFACE AVAILABLE AT http://issues.apache.org/bugzilla/show_bug.cgi?id=22701. ANY REPLY MADE TO THIS MESSAGE WILL NOT BE COLLECTED AND· INSERTED IN THE BUG DATABASE.

tomcat 4.1.x with jdk1.4.2 ssl certificate(4096-key length) support - again

2005-03-09 Thread Matej Kafadar
and have SSL with client authentication(client has certificate issued by CA which has certificate with public key length of 4096 bit)? Java 1.4 doesn't support rsa key size of 4096 (only to 2084). With keytool you aren't able to import certificate(4096) to cacerts. I instaled BouncyCastle

Re: tomcat 4.1.x with jdk1.4.2 ssl certificate(4096-key length) support - again

2005-03-09 Thread Bruce Keats
allready sent this question in user mail group, but there was no response, so I try lucky here. I would be happy if some expert or some who allready solved this problem, give me answer or hint about this. Repeted qouestion: is it possible to have tomcat 4.1.x running with jdk1.4.2 and have SSL

DO NOT REPLY [Bug 22701] - commons-logging and SSL in tomcat with struts

2005-03-08 Thread bugzilla
DO NOT REPLY TO THIS EMAIL, BUT PLEASE POST YOUR BUG· RELATED COMMENTS THROUGH THE WEB INTERFACE AVAILABLE AT http://issues.apache.org/bugzilla/show_bug.cgi?id=22701. ANY REPLY MADE TO THIS MESSAGE WILL NOT BE COLLECTED AND· INSERTED IN THE BUG DATABASE.

DO NOT REPLY [Bug 22701] - commons-logging and SSL in tomcat with struts

2005-03-08 Thread bugzilla
1.4.0_02-b02) Java HotSpot(TM) Client VM (build 1.4.0_02-b02, mixed mode) Tomcat Version Tomcat/4.1.18-LE-jdk14 Log4J version log4j-1.2.7.jar Struts version 1.1 NOTE: I haven't configured any SSL connector Although I have the following configuration under Standalone

DO NOT REPLY [Bug 33883] New: - openssl pkcs12 -infile/-outfile bad options in SSL Configuration HOW-TO example

2005-03-07 Thread bugzilla
/show_bug.cgi?id=33883 Summary: openssl pkcs12 -infile/-outfile bad options in SSL Configuration HOW-TO example Product: Tomcat 5 Version: Unknown Platform: All URL: http://jakarta.apache.org/tomcat/tomcat-5.5-doc/ssl

DO NOT REPLY [Bug 33413] - problem accessing ssl website...

2005-02-07 Thread bugzilla
DO NOT REPLY TO THIS EMAIL, BUT PLEASE POST YOUR BUG· RELATED COMMENTS THROUGH THE WEB INTERFACE AVAILABLE AT http://issues.apache.org/bugzilla/show_bug.cgi?id=33413. ANY REPLY MADE TO THIS MESSAGE WILL NOT BE COLLECTED AND· INSERTED IN THE BUG DATABASE.

DO NOT REPLY [Bug 33413] New: - problem accessing ssl website...

2005-02-06 Thread bugzilla
/show_bug.cgi?id=33413 Summary: problem accessing ssl website... Product: Tomcat 4 Version: 4.1.7 Platform: PC OS/Version: Windows XP Status: NEW Severity: normal Priority: P2 Component: Connector:Coyote HTTP/1.1

DO NOT REPLY [Bug 33413] - problem accessing ssl website...

2005-02-06 Thread bugzilla
DO NOT REPLY TO THIS EMAIL, BUT PLEASE POST YOUR BUG· RELATED COMMENTS THROUGH THE WEB INTERFACE AVAILABLE AT http://issues.apache.org/bugzilla/show_bug.cgi?id=33413. ANY REPLY MADE TO THIS MESSAGE WILL NOT BE COLLECTED AND· INSERTED IN THE BUG DATABASE.

DO NOT REPLY [Bug 33413] - problem accessing ssl website...

2005-02-06 Thread bugzilla
DO NOT REPLY TO THIS EMAIL, BUT PLEASE POST YOUR BUG· RELATED COMMENTS THROUGH THE WEB INTERFACE AVAILABLE AT http://issues.apache.org/bugzilla/show_bug.cgi?id=33413. ANY REPLY MADE TO THIS MESSAGE WILL NOT BE COLLECTED AND· INSERTED IN THE BUG DATABASE.

cvs commit: jakarta-tomcat-catalina/webapps/docs changelog.xml ssl-howto.xml

2005-02-01 Thread yoavs
yoavs 2005/02/01 13:04:30 Modified:webapps/docs Tag: TOMCAT_5_0 changelog.xml ssl-howto.xml Log: Bugzilla 33204. Revision ChangesPath No revision No revision 1.70.2.92 +3 -0 jakarta-tomcat-catalina/webapps/docs/changelog.xml

cvs commit: jakarta-tomcat-catalina/webapps/docs changelog.xml ssl-howto.xml

2005-02-01 Thread yoavs
yoavs 2005/02/01 13:07:29 Modified:webapps/docs changelog.xml ssl-howto.xml Log: Bugzilla 33204. Revision ChangesPath 1.230 +8 -0 jakarta-tomcat-catalina/webapps/docs/changelog.xml Index: changelog.xml

JNDIRealm via SSL

2005-01-19 Thread sudip shrestha
Current JNDIRealm does not support ldap with SSL and it's not a good idea to use simple authentication on production. I have raised this issue on discussion threads in the past, but never seem to get an answer from anybody, probably because genral users were not really familiar with the issue

DO NOT REPLY [Bug 22679] - how to access ssl session ID out of tomcat to prevent session hijacking and allow for phishing protection

2005-01-19 Thread bugzilla
01:23 --- good practice for such a anti-session-hijacking/anti-cross-site scripting is to implement a 2 out of 3 approach: i.e. SSL-session ID, remote IP and user-agent are compared between each http request and only if 2 out of 3 remain the same, the login-status is maintained. Not 3 out of 3

DO NOT REPLY [Bug 9702] - JNDIRealm StartTLS/SSL support request

2004-12-30 Thread bugzilla
DO NOT REPLY TO THIS EMAIL, BUT PLEASE POST YOUR BUG· RELATED COMMENTS THROUGH THE WEB INTERFACE AVAILABLE AT http://issues.apache.org/bugzilla/show_bug.cgi?id=9702. ANY REPLY MADE TO THIS MESSAGE WILL NOT BE COLLECTED AND· INSERTED IN THE BUG DATABASE.

DO NOT REPLY [Bug 9702] - JNDIRealm StartTLS/SSL support request

2004-12-29 Thread bugzilla
DO NOT REPLY TO THIS EMAIL, BUT PLEASE POST YOUR BUG· RELATED COMMENTS THROUGH THE WEB INTERFACE AVAILABLE AT http://issues.apache.org/bugzilla/show_bug.cgi?id=9702. ANY REPLY MADE TO THIS MESSAGE WILL NOT BE COLLECTED AND· INSERTED IN THE BUG DATABASE.

To Implement SSL!!

2004-12-14 Thread Rohit Kumar
Hi ALL, I need a help.. I have to implement SSL b/w two components one is Server and another is Agent...i have to authenticate both the server and the agent before communication between them .. i have implemented the SSL b/w GUI and Server ...where i have to only authenticate

Re: To Implement SSL!!

2004-12-14 Thread Bodhisatva N.
Fuck u and never mail me again. Rohit Kumar [EMAIL PROTECTED] wrote: Hi ALL, I need a help.. I have to implement SSL b/w two components one is Server and another is Agent...i have to authenticate both the server and the agent before communication between them .. i have implemented

cvs commit: jakarta-tomcat-catalina/webapps/docs changelog.xml ssl-howto.xml

2004-11-18 Thread yoavs
yoavs 2004/11/18 06:51:35 Modified:webapps/docs changelog.xml ssl-howto.xml Log: Bugzilla 22679: misc addition to SSL HowTo. Revision ChangesPath 1.171 +3 -0 jakarta-tomcat-catalina/webapps/docs/changelog.xml Index: changelog.xml

cvs commit: jakarta-tomcat-catalina/webapps/docs changelog.xml ssl-howto.xml

2004-11-18 Thread yoavs
yoavs 2004/11/18 07:01:03 Modified:webapps/docs Tag: TOMCAT_5_0 changelog.xml ssl-howto.xml Log: Bugzilla 22678: misc addition to SSL HowTo Revision ChangesPath No revision No revision 1.70.2.74 +3 -1 jakarta-tomcat-catalina

DO NOT REPLY [Bug 22679] - how to access ssl session ID out of tomcat to prevent session hijacking

2004-11-18 Thread bugzilla
DO NOT REPLY TO THIS EMAIL, BUT PLEASE POST YOUR BUG· RELATED COMMENTS THROUGH THE WEB INTERFACE AVAILABLE AT http://issues.apache.org/bugzilla/show_bug.cgi?id=22679. ANY REPLY MADE TO THIS MESSAGE WILL NOT BE COLLECTED AND· INSERTED IN THE BUG DATABASE.

DO NOT REPLY [Bug 22679] - how to access ssl session ID out of tomcat to prevent session hijacking and allow for phishing protection

2004-11-18 Thread bugzilla
/show_bug.cgi?id=22679 [EMAIL PROTECTED] changed: What|Removed |Added Summary|how to access ssl session ID|how to access ssl session ID |out of tomcat to prevent

DO NOT REPLY [Bug 29695] - regression in SSL cipher strength

2004-11-18 Thread bugzilla
DO NOT REPLY TO THIS EMAIL, BUT PLEASE POST YOUR BUG· RELATED COMMENTS THROUGH THE WEB INTERFACE AVAILABLE AT http://issues.apache.org/bugzilla/show_bug.cgi?id=29695. ANY REPLY MADE TO THIS MESSAGE WILL NOT BE COLLECTED AND· INSERTED IN THE BUG DATABASE.

DO NOT REPLY [Bug 32112] - SSL configuration attributes / security issue

2004-11-17 Thread bugzilla
DO NOT REPLY TO THIS EMAIL, BUT PLEASE POST YOUR BUG· RELATED COMMENTS THROUGH THE WEB INTERFACE AVAILABLE AT http://issues.apache.org/bugzilla/show_bug.cgi?id=32112. ANY REPLY MADE TO THIS MESSAGE WILL NOT BE COLLECTED AND· INSERTED IN THE BUG DATABASE.

IIS 6.0, SSL, and Tomcat 5.0 set up problem.

2004-11-12 Thread charles doweary
I am running IIS 6.0 with Tomcat 5.0 on Windows Server 2003, and I am having a problem getting SSL to work. The following instructions are a portion of the article titled TOMCAT and SSL, and I have a questions about Do: keytool -genkey -alias tomcat -keyalg RSA. Where is this command typed

DO NOT REPLY [Bug 32112] New: - SSL configuration attributes / security issue

2004-11-08 Thread bugzilla
/show_bug.cgi?id=32112 SSL configuration attributes / security issue Summary: SSL configuration attributes / security issue Product: Tomcat 5 Version: Unknown Platform: All OS/Version: All Status: NEW Severity: Enhancement

DO NOT REPLY [Bug 29907] - connector without accept thread (was: hanging during SSL negotiation)

2004-11-07 Thread bugzilla
/show_bug.cgi?id=29907 connector without accept thread (was: hanging during SSL negotiation) --- Additional Comments From [EMAIL PROTECTED] 2004-11-07 09:48 --- the same appears to have happened also with http://issues.apache.org/jira/browse/JAMES-324

  1   2   3   4   5   6   7   >