ApacheCon @home CfP closes in 4 days

2020-07-09 Thread jean-frederic clere
Hi folks, The Call for Papers will close in 4 days, don't shy we are looking for topics about how you use Tomcat, so please submit. The conference will take place ONLINE the 29 September to 1 of October. Check: https://acna2020.jamhosted.net/ and remember NO travels you just need a webcam

small extension for Tomcat in ApacheConNA2019

2019-05-13 Thread jean-frederic clere
Hi, We have a small extension for The Tomcat track in ApacheConNA2019 CfP until Tuesday 23h59 GMT! Go and submit now ;-) -- Cheers Jean-Frederic - To unsubscribe, e-mail: users-unsubscr...@tomcat.apache.org For additional

ApacheCon call for presentations, httpd content

2019-05-08 Thread jean-frederic clere
Hi, folks. The call for presentations for ApacheCon North America closes in a little less than 6 days. The CFP is here - https://www.apachecon.com/acna19/cfp.html - and closes May 13th. Thanks! Jean-Frederic - To

[SECURITY] CVE-2018-8034 Apache Tomcat - Security Constraint Bypass

2018-07-22 Thread Jean-Frederic Clere
CVE-2018-8034 Apache Tomcat - Security Constraint Bypass Severity: Low Vendor: The Apache Software Foundation Versions Affected: Apache Tomcat 9.0.0.M1 to 9.0.9 Apache Tomcat 8.5.0 to 8.5.31 Apache Tomcat 8.0.0.RC1 to 8.0.52 Apache Tomcat 7.0.35 to 7.0.88 Description: The host name

[SECURITY] CVE-2018-8037 Apache Tomcat - Information Disclosure

2018-07-22 Thread Jean-Frederic Clere
CVE-2018-8037 Apache Tomcat - Information Disclosure Severity: Important Vendor: The Apache Software Foundation Versions Affected: Apache Tomcat 9.0.0.M9 to 9.0.9 Apache Tomcat 8.5.5 to 8.5.31 Description: A bug in the tracking of connection closures can lead to reuse of user sessions in a

[SECURITY] CVE-2018-1336 Apache Tomcat - Denial of Service

2018-07-22 Thread Jean-Frederic Clere
CVE-2018-1336 Apache Tomcat - Denial of Service Severity: Important Vendor: The Apache Software Foundation Versions Affected: Apache Tomcat 9.0.0.M9 to 9.0.7 Apache Tomcat 8.5.0 to 8.5.30 Apache Tomcat 8.0.0.RC1 to 8.0.51 Apache Tomcat 7.0.28 to 7.0.86 Description: An improper handing of

[SECURITY] CVE-2018-8020 Apache Tomcat Native Connector - Mishandled OCSP responses can allow clients to authenticate with revoked certificates

2018-07-21 Thread Jean-Frederic Clere
CVE-2018-8020 Apache Tomcat Native Connector - Mishandled OCSP responses can allow clients to authenticate with revoked certificates Severity: Important Vendor: The Apache Software Foundation Versions Affected: Apache Tomcat Native 1.2.0 to 1.2.16 Apache Tomcat Native 1.1.23 to 1.1.34

[SECURITY] CVE-2018-8019 Apache Tomcat Native Connector - Mishandled OCSP invalid response

2018-07-21 Thread Jean-Frederic Clere
CVE-2018-8019 Apache Tomcat Native Connector - Mishandled OCSP invalid response Severity: Moderate Vendor: The Apache Software Foundation Versions Affected: Apache Tomcat Native 1.2.0 to 1.2.16 Apache Tomcat Native 1.1.23 to 1.1.34 Description: When using an OCSP responder Tomcat Native did

[ANN] Apache Tomcat Native 1.2.17 released

2018-06-20 Thread Jean-Frederic Clere
The Apache Tomcat team announces the immediate availability of Apache Tomcat Native 1.2.17 stable. The key features of this release are: - Windows binaries built with APR 1.6.3 and OpenSSL 1.0.2o. - Fix Certificate verification using CRL. - Arrange OCSP response processing. Note that users

Re: TomcatCon @ ApacheCon

2017-01-12 Thread jean-frederic clere
On 01/10/2017 09:05 PM, Christopher Schultz wrote: > Mark, > > On 1/9/17 6:57 AM, Mark Thomas wrote: >> There is the opportunity (if we can pull it together as a >> community) to run a dedicated Tomcat conference alongside ApacheCon >> NA 2017. The dates are May 16 to 18. > > Interesting. > >>

Re: TomcatCon @ ApacheCon

2017-01-09 Thread jean-frederic clere
On 01/09/2017 12:57 PM, Mark Thomas wrote: > All, > > There is the opportunity (if we can pull it together as a community) to > run a dedicated Tomcat conference alongside ApacheCon NA 2017. The dates > are May 16 to 18. > > The call for papers closes on Feb 11 so we have around a month to get >

[ANN] Apache Tomcat 6.0.45 available

2016-02-12 Thread Jean-Frederic Clere
The Apache Tomcat team announces the immediate availability of Apache Tomcat 6.0.45. Apache Tomcat is an open source software implementation of the Java Servlet, JavaServer Pages and Java Expression Language technologies. This release contains a number of bug fixes and improvements compared to

Re: [ANN] Apache Tomcat Connectors 1.2.41 released

2015-08-19 Thread jean-frederic clere
On 08/17/2015 01:10 PM, Mark Thomas wrote: The Apache Tomcat Project is proud to announce the release of version 1.2.41 of the Apache Tomcat Connectors. This version fixes one security issue (CVE-2014-8111) and a number of bugs found in previous releases. Many thanks for the release and sorry

tomcat meetup during apachecon

2015-04-14 Thread jean-frederic clere
Hi, If you are @apachecon in Austin feel first to join: http://sched.co/35Hk Cheers Jean-Frederic - To unsubscribe, e-mail: users-unsubscr...@tomcat.apache.org For additional commands, e-mail: users-h...@tomcat.apache.org

[ANN] Apache Tomcat 6.0.37 released

2013-05-06 Thread jean-frederic clere
The Apache Tomcat team announces the immediate availability of Apache Tomcat 6.0.37 stable. Apache Tomcat 6.0.37 is primarily a security and bug fix release. All users of older versions of the Tomcat 6.0 family should upgrade to 6.0.37. Note that is version has 4 zip binaries: a generic one

[ANN] Apache Tomcat 6.0.36 released

2012-10-23 Thread jean-frederic clere
The Apache Tomcat team announces the immediate availability of Apache Tomcat 6.0.36 stable. Apache Tomcat 6.0.36 is primarily a security and bug fix release. All users of older versions of the Tomcat 6.0 family should upgrade to 6.0.36. Note that is version has 4 zip binaries: a generic one

[ANN] Apache Tomcat 6.0.35 released

2011-12-06 Thread jean-frederic clere
The Apache Tomcat team announces the immediate availability of Apache Tomcat 6.0.35 stable. Apache Tomcat 6.0.35 is primarily a security and bug fix release. All users of older versions of the Tomcat 6.0 family should upgrade to 6.0.35. Note that is version has 4 zip binaries: a generic one

Re: distributed session manager with infinispan

2011-11-28 Thread jean-frederic clere
On 11/27/2011 06:44 PM, Zdeněk Henek wrote: Hi, I have created prototype of distributed session manager which uses infinispan to distribute session state. The code is available here: https://github.com/zvrablik/tomcatInfinispanSessionManager Would anybody have time to discuss the prototype or

[ANN] Apache Tomcat 6.0.33 released

2011-08-18 Thread jean-frederic clere
The Apache Tomcat team announces the immediate availability of Apache Tomcat 6.0.33 stable. Apache Tomcat 6.0.33 is primarily a security and bug fix release. All users of older versions of the Tomcat 6.0 family should upgrade to 6.0.33. Note that is version has 4 zip binaries: a generic one

[ANN] Apache Tomcat 6.0.32 released

2011-02-03 Thread jean-frederic clere
The Apache Tomcat team announces the immediate availability of Apache Tomcat 6.0.32 stable. Apache Tomcat 6.0.32 is primarily a security and bug fix release. All users of older versions of the Tomcat 6.0 family should upgrade to 6.0.32. Note that is version has 4 zip binaries: a generic one

[ANN] Apache Tomcat 6.0.30 released

2011-01-13 Thread jean-frederic clere
The Apache Tomcat team announces the immediate availability of Apache Tomcat 6.0.30 stable. This release includes bug-fixes over Apache Tomcat 6.0.29. Note that is version has 4 zip binaries: a generic one and three bundled with Tomcat native binaries for different CPU architectures. Apache

Meetup during ApacheConNA2010

2010-10-14 Thread jean-frederic clere
Hi, We will have a meetup during the ApacheConNA2010 on Thursday 4th at 20h00. Meetups are free to attend and a opportunity to have short presentation and discussion about the new Tomcat 7 and the latest improvement done in the code. See http://wiki.apache.org/tomcat/TomcatAtApacheConNA2010 and

[ANN] Apache Tomcat 6.0.29 released

2010-07-23 Thread jean-frederic clere
The Apache Tomcat team announces the immediate availability of Apache Tomcat 6.0.29 stable. This release includes bug-fixes over Apache Tomcat 6.0.28. Apache Tomcat 6.0 includes new features over Apache Tomcat 5.5, including support for the new Servlet 2.5 and JSP 2.1 specifications, a refactored

Re: [ANN] Apache Tomcat 6.0.28 released

2010-07-09 Thread jean-frederic clere
The Apache Tomcat team announces the immediate availability of Apache Tomcat 6.0.28 stable. This release includes bug-fixes over Apache Tomcat 6.0.26. Apache Tomcat 6.0 includes new features over Apache Tomcat 5.5, including support for the new Servlet 2.5 and JSP 2.1 specifications, a refactored

Tomcat at the next ApacheCon

2010-03-18 Thread jean-frederic clere
Hi, We all want to see a Tomcat track at the ApacheConNA2010, don't we? I have created a wiki page to collect the presentation proposals. Fell free to add the stuff you would like to present at the ApacheCon. The tomcat PMC will review it and then propose it to the planners of conference. Note

[ANN] Apache Tomcat 6.0.26 released

2010-03-11 Thread jean-frederic clere
The Apache Tomcat team announces the immediate availability of Apache Tomcat 6.0.26 stable. This release includes bug-fixes over Apache Tomcat 6.0.24. Note that is version has 4 zip binaries: a generic one and three bundled with Tomcat native binaries for different CPU architectures. Apache

[ANN] Apache Tomcat 6.0.24 released

2010-01-21 Thread jean-frederic clere
The Apache Tomcat team announces the immediate availability of Apache Tomcat 6.0.24 stable. This release includes many bug-fixes over Apache Tomcat 6.0.20. Note that is version has 4 zip binaries: a generic one and three bundled with Tomcat native binaries for different CPU architectures. Apache

Re: [ANN] Apache Tomcat Native 1.1.18 released

2009-11-24 Thread jean-frederic clere
On 11/23/2009 10:49 PM, Tony Anecito wrote: Thanks Team for the fixes and any enhancements! So does one need to uninstall the older version before installing this one? The files of the new packages will overwrite the old ones, but that is good idea to uninstall the old package(s). Cheers

[ANN] Apache Tomcat Native 1.1.18 released

2009-11-23 Thread jean-frederic clere
The Apache Tomcat team announces the immediate availability of Apache Tomcat Native 1.1.18 stable. This release includes few bug fixes over Apache Tomcat Native 1.1.16 and fixes the client initiated part of cve-2009-3555, note that the server initiated renegociation was added in 1.1.17 (and is

Tomcat meetup at ApacheCon

2009-10-22 Thread jean-frederic clere
Hi everyone, There is a Tomcat meetup organized at the ApacheCon on Monday 2d of November at 20h00. To register http://spreadsheets.google.com/viewform?formkey=dEJLcHk3c1ZrRm8tWUNYeXZZckN0Vnc6MA For more information or add idem you want to present go to

Tomcat tracks at the ApacheConUS2009

2009-06-17 Thread jean-frederic clere
Hi, The Tomcat PMC has prepared the tracks of Tomcat for the ApacheCon US 2009. The first track is the official Tomcat Wednesday track the second one will be held in a small room (50) on Thursday after the main track. Drafts of the tracks are available at

Re: What Tomcat presentations / demos / discussions do you want to see at ApacheCon US 2009?

2009-04-22 Thread jean-frederic clere
Rainer Jung wrote: On 16.04.2009 12:44, Mark Thomas wrote: Gregor Schneider wrote: - Concerning how often questions regarding mod_jk are showing up in the list: mod_jk - HowTo / Best practices Any takers for presenting this? Not sure, whether this is too specific for ApacheCon, but yes, if

ApacheCon Europe 2009: Early Bird Deadline Extended until 13th of February

2009-02-10 Thread jean-frederic clere
Here's some great news for everyone who's thinking of traveling to Amsterdam for this year's ApacheCon Europe. The Early Bird deadline has been extended to Friday, February 13th - and remember, there is a discount of 150 Euro on registration for anyone staying at the Mövenpick Hotel. Register at

Want to learn Everything on Tomcat. 23/24 March in Amsterdam.

2009-02-07 Thread jean-frederic clere
Hi, A new tutorial has been added to the ApacheCon Web site: Everything Tomcat - Administering, Tuning, Troubleshooting and Develop. That is a 2 day tutorial given by Mark Thomas who is one of the greatest tomcat developers. Getting a tutorial during the ApacheCon is the oportunity to get more

[Fwd: [Urgent] Please help promote ApacheCon video streaming!]

2008-11-04 Thread jean-frederic clere
---BeginMessage--- Hi, please help promote the ApacheCon live video streaming by forwarding the email below to your PMC user and dev mailing lists, ASAP! Thank you Lars Eilebrecht - Subject: ApacheCon live video streaming available; keynotes and

[ANN] Apache Tomcat Native 1.1.15 released

2008-09-11 Thread jean-frederic clere
The Apache Tomcat team announces the immediate availability of Apache Tomcat Native 1.1.15 stable. This release includes few bug fixes over Apache Tomcat Native 1.1.14. Please refer to the change log for the list of changes: http://tomcat.apache.org/native-doc/miscellaneous/changelog.html

[ANN] Apache Tomcat Native 1.1.14 released

2008-07-04 Thread jean-frederic clere
The Apache Tomcat team announces the immediate availability of Apache Tomcat Native 1.1.14 stable. This release includes few bug fixes over Apache Tomcat Native 1.1.13. Please refer to the change log for the list of changes: http://tomcat.apache.org/native-doc/miscellaneous/changelog.html

[ANN] Apache Tomcat Native 1.1.13 released

2008-02-15 Thread jean-frederic clere
The Apache Tomcat team announces the immediate availability of Apache Tomcat Native 1.1.13 stable. This release includes many bugfixes over Apache Tomcat Native 1.1.12 and the first official release of Tomcat Native. Please refer to the change log for the list of changes: