RE: OT: hsts in Tomcat 9.0.73

2023-04-21 Thread jonmcalexander
Thanks Peter, I still do not see the hsts header. I'm wondering if this is causing it. SSL certificate verify result: self signed certificate in certificate chain (19), continuing anyway. I don't know why it's complaining as the certificate for Tomcat is not a self-signed certificate. Thanks,

Re: OT: hsts in Tomcat 9.0.73

2023-04-21 Thread logo
Jon, Oh, I see there is a redirect. I do see a similar behavior on redirects (302) or auth (401 eg. on the manager app). But HSTS on 200, 404 or 403. What happens if you call "/c/portal/license" ? Peter > Am 21.04.2023 um 23:05 schrieb jonmcalexan...@wellsfargo.com.invalid > : > > Here is t

RE: OT: hsts in Tomcat 9.0.73

2023-04-21 Thread jonmcalexander
Here is the output from a powershell command: Invoke-WebRequest -Uri https://ldvwa00a0010.wellsfargo.com:8443 -MaximumRedirection 0 | Select-Object -ExpandProperty Headers KeyValue ---- X-Content-Type-Options nosniff X-Frame-OptionsSAMEORIGIN X

RE: OT: hsts in Tomcat 9.0.73

2023-04-21 Thread jonmcalexander
Hey Peter, Yes, the context is ROOT as this app does have a ROOT component. Dream * Excel * Explore * Inspire Jon McAlexander Senior Infrastructure Engineer Asst. Vice President He/His Middleware Product Engineering Enterprise CIO | EAS | Middleware | Infrastructure Solutions 8080 Cobblestone R

Re: java.lang.InternalError: Unexpected CryptoAPI failure generating seed

2023-04-21 Thread Thomas Worster
That document is mostly about a corrupted install in Weblogic, but after that, it suggests making sure you are using the urandom (non-blocking) random number generator. If you're using the blocking RNG, it would explain why the issue is not easily repeatable. -Djava.security.egd=file:/dev/./urand

Re: OT: hsts in Tomcat 9.0.73

2023-04-21 Thread logo
Jon, again, the Qualys Scanner usually does not know any other webcontexts than root, manager and examples. So if you don't have a root context, it may well end up in the woods and the result will not have a HSTS-Header. Can you verify the requested resource? Best regards Peter > Am 21.04.20

Re: [OT] MySQL Connection settings

2023-04-21 Thread Kevin Huntly
in general. something all purpose to get started with On Fri, Apr 21, 2023, 14:17 Christopher Schultz < ch...@christopherschultz.net> wrote: > Kevin, > > On 4/21/23 09:35, Kevin Huntly wrote: > > I'm not a DBA nor do I pretend to be, so I'm asking what everyone's > > thoughts are on MySQL connect

Re: OT: hsts in Tomcat 9.0.73

2023-04-21 Thread Christopher Schultz
Jon, On 4/21/23 11:47, jonmcalexan...@wellsfargo.com.INVALID wrote: Thank you Olaf, however, the connection was made over https directly to Tomcat on port 8443. Sample curl with secrets removed? -chris -Original Message- From: Olaf Kock Sent: Friday, April 21, 2023 1:48 AM To: users

Re: [OT] MySQL Connection settings

2023-04-21 Thread Christopher Schultz
Kevin, On 4/21/23 09:35, Kevin Huntly wrote: I'm not a DBA nor do I pretend to be, so I'm asking what everyone's thoughts are on MySQL connection string settings? What are the best options to use, what options are absolutely required, etc? Just ... in general? Or do you have a specific use-cas

Re: java.lang.InternalError: Unexpected CryptoAPI failure generating seed

2023-04-21 Thread Christopher Schultz
Harri, On 4/21/23 04:39, Harri Pesonen wrote: No, I think that I have seen this only once now, but of course it might have happened more than once. Googling says that other people have seen this as well, but very randomly. Apparently the problem happens in Windows function, but JNI call does no

RE: OT: hsts in Tomcat 9.0.73

2023-04-21 Thread jonmcalexander
Thank you Olaf, however, the connection was made over https directly to Tomcat on port 8443. Thanks, Dream * Excel * Explore * Inspire Jon McAlexander Senior Infrastructure Engineer Asst. Vice President He/His Middleware Product Engineering Enterprise CIO | EAS | Middleware | Infrastructure Sol

MySQL Connection settings

2023-04-21 Thread Kevin Huntly
Hi Everyone, I'm not a DBA nor do I pretend to be, so I'm asking what everyone's thoughts are on MySQL connection string settings? What are the best options to use, what options are absolutely required, etc? Kevin Huntly Email: kmhun...@gmail.com C

RE: java.lang.InternalError: Unexpected CryptoAPI failure generating seed

2023-04-21 Thread Harri Pesonen
No, I think that I have seen this only once now, but of course it might have happened more than once. Googling says that other people have seen this as well, but very randomly. Apparently the problem happens in Windows function, but JNI call does not tell the reason for failure. This happened in