Any successful SSL Implementation on Tomcat 9.0.69, Java 11, and Oracle ORDS 22.2?

2023-02-22 Thread James Boggs
Has anyone been able to complete a successful SSL Implementation on Tomcat 9.0.69, Java 11, and Oracle ORDS 22.2? We had SSL working with Tomcat 9.0.65, Java 8, and ORDS 21, on an Oracle 19c database with Oracle APEX 21 (on Windows Server 2012). Now ORDS requires Java 11 which does not have a

Re: Got a customer who's paranoid about Manager

2023-02-22 Thread Alex O'Ree
is removing the manager war an option for you? i don't think it's required for operation. you could also rename it so that it's in a different url path than the default On Wed, Feb 22, 2023 at 12:58 PM Mark Thomas wrote: > On 22/02/2023 17:49, James H. H. Lampert wrote: > > On 2/22/23 9:23 AM,

Re: Got a customer who's paranoid about Manager

2023-02-22 Thread Mark Thomas
On 22/02/2023 17:49, James H. H. Lampert wrote: On 2/22/23 9:23 AM, Mark Thomas wrote: Fire them and hire a security consultant with a proper understanding of risk? Pardon my Yiddish, but "Fun dayn moyl in Gots oyern." (From your mouth to God's ears. Such a colorful language.) But just

Re: Got a customer who's paranoid about Manager

2023-02-22 Thread James H. H. Lampert
On 2/22/23 9:23 AM, Mark Thomas wrote: Fire them and hire a security consultant with a proper understanding of risk? Pardon my Yiddish, but "Fun dayn moyl in Gots oyern." (From your mouth to God's ears. Such a colorful language.) But just because you're paranoid doesn't mean they're not out

Re: Database related performance degradation after upgrading from Tomcat 9.0.33 to Tomcat 9.0.69

2023-02-22 Thread Mark Thomas
On 22/02/2023 04:58, Konstantin Kolinko wrote: ср, 22 февр. 2023 г. в 01:31, Artur Tomusiak - Hannon Hill : After upgrading from Tomcat 9.0.33 to Tomcat 9.0.69, Note that using a binary search (bisection) one could limit the version range. Relevant version information is: 9.0.71 - DBCP

Re: Got a customer who's paranoid about Manager

2023-02-22 Thread Mark Thomas
On 22/02/2023 17:10, James H. H. Lampert wrote: We've got a customer -- the same one that was our first test of a working RemoteAddrValve -- whose security consultant is complaining that a potential intruder can confirm the *existence* of the manager context (because it returns a 403, as

Got a customer who's paranoid about Manager

2023-02-22 Thread James H. H. Lampert
We've got a customer -- the same one that was our first test of a working RemoteAddrValve -- whose security consultant is complaining that a potential intruder can confirm the *existence* of the manager context (because it returns a 403, as opposed to, say, a 404). Any ideas? -- JHHL