Re: CVE-2021-25329, was Re: Most recent security-related update to 8.5

2021-07-02 Thread Mark Thomas
On 02/07/2021 16:44, James H. H. Lampert wrote: On 7/2/21 12:02 AM, Mark Thomas wrote: It is an alternative session manager that persists session data via a configured Store. There are two Store implementations provided by default - File and DataSource. You would know if you were using it as

Re: CVE-2021-25329, was Re: Most recent security-related update to 8.5

2021-07-02 Thread Christopher Schultz
James, On 7/2/21 11:44, James H. H. Lampert wrote: On 7/2/21 12:02 AM, Mark Thomas wrote: It is an alternative session manager that persists session data via a configured Store. There are two Store implementations provided by default - File and DataSource. You would know if you were using i

Re: Question about directory listing sorting ..

2021-07-02 Thread Christopher Schultz
Konstantin, On 7/2/21 05:28, Konstantin Kolinko wrote: пт, 2 июл. 2021 г. в 04:04, John Dale (DB2DOM) : Doesn't seem to work for me on 9.0.41 (it's an older development box). I found these interesting: ow with patch v3: 1. "s=NA" name=asc 2. "s=ND" name=dsc 3. "s=SA" size=asc 4. "s=SD" size=d

Re: JSESSION ID

2021-07-02 Thread Christopher Schultz
Mohan, On 7/1/21 07:27, Mohan T wrote: Dear All, We are using tomcat 8.5.35 on Linux. We are getting two session ID for the same Http request.. Similar session ID is marked in yellow This is the session ID in startup JSESSIONID=FFE8F98C012CDB4461FC8E68C109298E This is the session ID in dispa

Re: Strange error with JSP

2021-07-02 Thread Christopher Schultz
Konstantin, On 7/1/21 04:17, Konstantin Kolinko wrote: вт, 29 июн. 2021 г. в 19:35, Christopher Schultz : Konstantin, On 6/29/21 10:21, Konstantin Kolinko wrote: ср, 2 июн. 2021 г. в 23:16, Christopher Schultz : [...] Has the page been compiled once, or its modification time is being check

Re: CVE-2021-25329, was Re: Most recent security-related update to 8.5

2021-07-02 Thread James H. H. Lampert
On 7/2/21 12:02 AM, Mark Thomas wrote: It is an alternative session manager that persists session data via a configured Store. There are two Store implementations provided by default - File and DataSource. You would know if you were using it as it requires explicit configuration. Thanks for

Re: Possible bug in http2 window size handling in tomcat 9.0.45

2021-07-02 Thread Erik Nilsson
Perfect, glad to see a release after the vacation :) Thanks again and happy vacationing. /Erik Den fre 2 juli 2021 kl 14:06 skrev Mark Thomas : > On 02/07/2021 12:46, Erik Nilsson wrote: > > Great!! With tomcat-9.0-20210701.191821-3270 in our environment it seems > to > > be stable without any RS

Re: Possible Http11NioProtocol regression since 9.0.48?

2021-07-02 Thread Mark Thomas
On 02/07/2021 12:43, André van der Lugt wrote: I finally managed to create a decrypted Wireshark capture with injected TLS session keys, will send it in a direct message due to size. I hope it provides the information needed. Thanks. I have the file. I'll hopefully have time to look at this

Re: Possible bug in http2 window size handling in tomcat 9.0.45

2021-07-02 Thread Mark Thomas
On 02/07/2021 12:46, Erik Nilsson wrote: Great!! With tomcat-9.0-20210701.191821-3270 in our environment it seems to be stable without any RST_STREAMs. Excellent. Thanks for confirming the fix. When will you release this version? Releases happen ~monthly. We aim for early in the month and t

Re: Possible bug in http2 window size handling in tomcat 9.0.45

2021-07-02 Thread Erik Nilsson
Great!! With tomcat-9.0-20210701.191821-3270 in our environment it seems to be stable without any RST_STREAMs. When will you release this version? /Erik Den fre 2 juli 2021 kl 10:28 skrev Mark Thomas : > On 01/07/2021 08:57, Mark Thomas wrote: > > On 01/07/2021 08:41, Erik Nilsson wrote: > >> >

RE: Possible Http11NioProtocol regression since 9.0.48?

2021-07-02 Thread André van der Lugt
> -Original Message- > From: Mark Thomas > Sent: Wednesday, June 30, 2021 15:22 > To: users@tomcat.apache.org > Subject: Re: Possible Http11NioProtocol regression since 9.0.48? > > On 30/06/2021 13:57, André van der Lugt wrote: > > Hi, > > > > Since upgrading our Tomcat 9.0.x installati

Re: Question about directory listing sorting ..

2021-07-02 Thread Konstantin Kolinko
пт, 2 июл. 2021 г. в 04:04, John Dale (DB2DOM) : > > Doesn't seem to work for me on 9.0.41 (it's an older development box). > > I found these interesting: > ow with patch v3: > 1. "s=NA" name=asc > 2. "s=ND" name=dsc > 3. "s=SA" size=asc > 4. "s=SD" size=dsc > 5. "s=MA" modify=asc > 6. "s=MD" modif

Re: Possible bug in http2 window size handling in tomcat 9.0.45

2021-07-02 Thread Mark Thomas
On 01/07/2021 08:57, Mark Thomas wrote: On 01/07/2021 08:41, Erik Nilsson wrote: protocol="org.apache.coyote.http11.Http11NioProtocol"     connectionTimeout="2" compression="on" useAsyncIO="false" compressibleMimeType="text/html,text/xml,text/css,text/javascript,text/pla

Re: What is "h2c"? What is CVE-2021-25329? Re: Most recent security-related update to 8.5

2021-07-02 Thread Mark Thomas
On 01/07/2021 22:24, James H. H. Lampert wrote: Also, I've got somebody complaining about CVE-2021-25329. I'm not sure I understand what CVE-2021-25329 is, or what the underlying CVE-2020-9484 is. If the person complaining about CVE-2021-25329 can't explain (or demonstrate) why it is an is