Content Security policy for Tomcat 8.5

2019-10-03 Thread Nitin Kadam
Hell All, Internal security team recommended to set *Content security policy* header for Web server as same is not complaint with security standard. can you please help me setting CSP filters for my Tomcat application hosted on windows server. -- Regards Nitin Kadam

closedChannelException from time to time

2019-10-03 Thread Helena Carbajo
Hi, I'm using Tomcat versiĆ³n 8.5.23 with http2 and from time to time I get some ClosedChannelException: {"message":"Failed to register socket with selector from poller","timestamp":"2019-10-02T02:23:32+02:00","level":"ERROR","networkFunction":"UDR","serviceId":"eric-udr-nudrfe","exception":"java

Re: Apache SSI breaks with tomcat-connectors-1.2.43 or newer

2019-10-03 Thread Ezsra McDonald
Mark, Thanks for taking a look. I will try the SVN build and let you know. --Ez On Wed, Oct 2, 2019 at 10:02 AM Mark Thomas wrote: > On 02/10/2019 15:39, Mark Thomas wrote: > > On 02/10/2019 14:51, Mark Thomas wrote: > > > > > > There is a work-around. Use virtual="..." in the SSI includes.

Re: Security issue involving HTTP response headers

2019-10-03 Thread Christopher Schultz
-BEGIN PGP SIGNED MESSAGE- Hash: SHA256 James, On 10/2/19 01:34, jam...@touchtonecorp.com wrote: > We have a customer who is particularly concerned about security. > > We just updated their Tomcat, which solved all the issues coming up > in their security scan, except for one involving th

Re: Content Security policy for Tomcat 8.5

2019-10-03 Thread Christopher Schultz
-BEGIN PGP SIGNED MESSAGE- Hash: SHA256 Nitin, On 10/3/19 09:54, Nitin Kadam wrote: > Hell All, > > Internal security team recommended to set *Content security policy* > header for Web server as same is not complaint with security > standard. can you please help me setting CSP filters for

Re: Security issue involving HTTP response headers

2019-10-03 Thread jamesl
Thanks to all who have responded (especially Mr. Schultz), and thanks in advance to anybody else who responds. It will be a few more days before I can act on the information. I'm not ignoring any of you; I'm gathering information so I can solve the problem ASAP upon my return to work from my vac