On Thursday, September 10, 2026, Coty Sutherland <[email protected]> wrote:
> > > On Wednesday, September 9, 2026, Mark Thomas <[email protected]> wrote: > >> The proposed Apache Tomcat 11.0.26 release is now available for voting. >> >> The notable changes compared to 11.0.25 include: >> >> - Update Tomcat Native to 2.0.16 (built with OpenSSL 3.5.8 for Windows) >> and make 2.0.16b the minimum required version. >> >> - Various improvements to the RewriteValve >> >> - Various TLS improvements including more robust OCSP and ALPN handling >> >> - Ensure that WebSocket write timeouts apply to the complete message and >> are not lost if two writes have the same timeout. >> >> >> For full details, see the change log: >> https://nightlies.apache.org/tomcat/tomcat-11.0.x/docs/changelog.html >> >> Applications that run on Tomcat 9 and earlier will not run on Tomcat 11 >> without changes. Java EE applications designed for Tomcat 9 and earlier may >> be placed in the $CATALINA_BASE/webapps-javaee directory and Tomcat will >> automatically convert them to Jakarta EE and copy them to the webapps >> directory. Applications using deprecated APIs may require further changes. >> >> It can be obtained from: >> https://dist.apache.org/repos/dist/dev/tomcat/tomcat-11/v11.0.26/ >> >> The Maven staging repo is: >> https://repository.apache.org/content/repositories/orgapachetomcat-1604 >> The tag is: >> https://github.com/apache/tomcat/tree/11.0.26 >> 3592f2541fe608f78bf755e6e79140768b8d07ae >> >> The proposed 11.0.26 release is: >> [ ] -1 Broken - do not release >> [x] +1 Stable - go ahead and release as 11.0.26 >> > > My testing pipeline is having problems with the new xrl tests but other > than that lgtm. > Closing the loop on this: I confirmed the env issue on my test box. The CRL is being rejected (so all of the tests in the new class are failing) by Fedora’s OpenJDK certificate-path validation because it is signed with SHA-1, which is disabled by the default crypto policy. I've updated the pipeline to skip the test for now, but if it's bothering anyone else then we should reissue the CRL using a stronger signature algorithm (SHA-256). > >> >> --------------------------------------------------------------------- >> To unsubscribe, e-mail: [email protected] >> For additional commands, e-mail: [email protected] >> >>
