Re: Adding a custom configurations file globally and at web-app level for Apache Tomcat

2016-02-22 Thread Chiranga Alwis
Hi Chris, yeah as you said a decision was made to separate out properties which can be defined only at global level in one file reminiscent to Tomcat's server.xml and a web app descriptor file which can be defined at global level and can also be overridden at context level reminiscent to web.xml

RE: Tomcat memory

2016-02-22 Thread Gokul . Baskaran
Andre, Thanks for getting granular. Let me explain to the items which could have sounded to be confusing.. The JVM in discussion is Oracle JVM. OS is the 64bit Windows 2012. - OS has 6GB - OS should not impose a limit on memory (Only in this specific case, as OS is 64bit and total amount of

Re: tomcat7 installs to connect to ipv6:::8080 on Ubuntu 14.04

2016-02-22 Thread Christoph P.U. Kukulies
Being at the problem again since I would like to run haproxy against tomcat7. Here are my connectors: I added the address entry on each connector to no avail: # netstat -an Active Internet connections (servers and established) Proto Recv-Q Send-Q Local Address Foreign Address

Re: Update path of executeable of a tomcat windows service

2016-02-22 Thread Daniel Küppers
Am 22.02.2016 um 16:31 schrieb David kerber: On 2/22/2016 10:12 AM, Fabian Birk wrote: Hello, I am using tomcat as a windows service and want to update the path of executeable during my automated process via command line. The Reason why I dont want to deinstall / install the service is, that I

Re: Update path of executeable of a tomcat windows service

2016-02-22 Thread David kerber
On 2/22/2016 10:12 AM, Fabian Birk wrote: Hello, I am using tomcat as a windows service and want to update the path of executeable during my automated process via command line. The Reason why I dont want to deinstall / install the service is, that I want to keep the other informations like

Update path of executeable of a tomcat windows service

2016-02-22 Thread Fabian Birk
Hello, I am using tomcat as a windows service and want to update the path of executeable during my automated process via command line. The Reason why I dont want to deinstall / install the service is, that I want to keep the other informations like service user etc. I have a tomcat 7 service

Re: Tomcat memory

2016-02-22 Thread tomcat
On 22.02.2016 13:02, Gokul.Baskaran wrote: The answer I expected is the JVM grows as much as to the available system memory of there are m min and max set. Gokul, Well, no. And because these messages get archived and searched later by other people, they may get the wrong conclusion and

RE: Tomcat memory

2016-02-22 Thread Gokul . Baskaran
I meant the expectation as what I understood from the earlier posts. The hyperlink url was not formed correct, hyperlink url helped as well. Earlier I read it as the 1/64th and 1/4th applied only to the JSE5. Thanks to Olaf. -Gokul -Original Message- From: David kerber

Re: Tomcat memory

2016-02-22 Thread David kerber
On 2/22/2016 7:02 AM, Gokul.Baskaran wrote: The answer I expected is the JVM grows as much as to the available system memory of there are m min and max set. But if you go back and read what others have posted, you will find that that is not the case. Just because that's what you expect,

Re: Tomcat memory

2016-02-22 Thread Gokul . Baskaran
The answer I expected is the JVM grows as much as to the available system memory of there are m min and max set. -Gokul Sent from iPhone > On Feb 22, 2016, at 2:43 AM, André Warnier (tomcat) wrote: > >> On 22.02.2016 03:44, Gokul.Baskaran wrote: >> Thanks again, to make

[SECURITY] CVE-2016-0706 Apache Tomcat Security Manager bypass

2016-02-22 Thread Mark Thomas
-BEGIN PGP SIGNED MESSAGE- Hash: SHA256 CVE-2016-0706 Apache Tomcat Security Manager bypass Severity: Low Vendor: The Apache Software Foundation Versions Affected: - - Apache Tomcat 6.0.0 to 6.0.44 - - Apache Tomcat 7.0.0 to 7.0.67 - - Apache Tomcat 8.0.0.RC1 to 8.0.30 - - Apache

[SECURITY] CVE-2015-5345 Apache Tomcat Directory disclosure

2016-02-22 Thread Mark Thomas
-BEGIN PGP SIGNED MESSAGE- Hash: SHA256 CVE-2015-5345 Apache Tomcat Directory disclosure Severity: Low Vendor: The Apache Software Foundation Versions Affected: - - Apache Tomcat 6.0.0 to 6.0.44 - - Apache Tomcat 7.0.0 to 7.0.66 - - Apache Tomcat 8.0.0.RC1 to 8.0.29 - - Apache Tomcat

[SECURITY] CVE-2015-5346 Apache Tomcat Session fixation

2016-02-22 Thread Mark Thomas
-BEGIN PGP SIGNED MESSAGE- Hash: SHA256 CVE-2015-5346 Apache Tomcat Session fixation Severity: Low Vendor: The Apache Software Foundation Versions Affected: - - Apache Tomcat 7.0.5 to 7.0.65 - - Apache Tomcat 8.0.0.RC1 to 8.0.30 - - Apache Tomcat 9.0.0.M1 Description: When recycling

[SECURITY] CVE-2016-0714 Apache Tomcat Security Manager Bypass

2016-02-22 Thread Mark Thomas
-BEGIN PGP SIGNED MESSAGE- Hash: SHA256 CVE-2016-0714 Apache Tomcat Security Manager Bypass Severity: Moderate Vendor: The Apache Software Foundation Versions Affected: - - Apache Tomcat 6.0.0 to 6.0.44 - - Apache Tomcat 7.0.0 to 7.0.67 - - Apache Tomcat 8.0.0.RC1 to 8.0.30 - - Apache

[SECURITY] CVE-2016-0763 Apache Tomcat Security Manager Bypass

2016-02-22 Thread Mark Thomas
-BEGIN PGP SIGNED MESSAGE- Hash: SHA256 CVE-2016-0763 Apache Tomcat Security Manager Bypass Severity: Moderate Vendor: The Apache Software Foundation Versions Affected: - - Apache Tomcat 7.0.0 to 7.0.67 - - Apache Tomcat 8.0.0.RC1 to 8.0.30 - - Apache Tomcat 9.0.0.M1 to 9.0.0.M2

[SECURITY] CVE-2015-5174 Apache Tomcat Limited Directory Traversal

2016-02-22 Thread Mark Thomas
-BEGIN PGP SIGNED MESSAGE- Hash: SHA256 CVE-2015-5174 Apache Tomcat Limited Directory Traversal Severity: Low Vendor: The Apache Software Foundation Versions Affected: - - Apache Tomcat 6.0.0 to 6.0.44 - - Apache Tomcat 7.0.0 to 7.0.64 - - Apache Tomcat 8.0.0.RC1 to 8.0.26 - - Apache

[SECURITY] CVE-2015-5351 Apache Tomcat CSRF token leak

2016-02-22 Thread Mark Thomas
-BEGIN PGP SIGNED MESSAGE- Hash: SHA256 CVE-2015-5351 Apache Tomcat CSRF token leak Severity: Moderate Vendor: The Apache Software Foundation Versions Affected: - - Apache Tomcat 7.0.1 to 7.0.67 - - Apache Tomcat 8.0.0.RC1 to 8.0.31 - - Apache Tomcat 9.0.0.M1 Description: The index

Re: Tomcat7/8 - Leap year compliant

2016-02-22 Thread tomcat
On 22.02.2016 11:40, Shree, Shubha wrote: Hi , As 2016 is a Leap year, can you please confirm is Tomcat7 and Tomcat8 leap year compliant so that there should not be any impact on the applications running on tomcat 7/8 . Maybe you could define "leap year compliant" for us, so that we

Re: Tomcat7/8 - Leap year compliant

2016-02-22 Thread Mark Thomas
On 22/02/2016 10:40, Shree, Shubha wrote: > Hi , > > As 2016 is a Leap year, can you please confirm is Tomcat7 and Tomcat8 leap > year compliant so that there should not be any impact on the applications > running on tomcat 7/8 . First of all, don't cross-post. Tomcat does not do any direct

Tomcat7/8 - Leap year compliant

2016-02-22 Thread Shree, Shubha
Hi , As 2016 is a Leap year, can you please confirm is Tomcat7 and Tomcat8 leap year compliant so that there should not be any impact on the applications running on tomcat 7/8 . Regards, Shubha Shree Important : The information transmitted is intended for the person or entity to which it is

Re: context doesnt pick up

2016-02-22 Thread Mark Thomas
On 22/02/2016 08:53, Me Self wrote: >>> Hi All >>> >>> When I put the context in server.xml it works fine, but if I put the same >>> context tag in a xml file under /conf/Catalina/localhost/test.xml then >>> tomcat doesn't pick it up. I would rather want to use the latter. > >> You need to set

Re: context doesnt pick up

2016-02-22 Thread Me Self
>> Hi All >> >> When I put the context in server.xml it works fine, but if I put the same >> context tag in a xml file under /conf/Catalina/localhost/test.xml then >> tomcat doesn't pick it up. I would rather want to use the latter. >You need to set deployOnStartup="true" for that to work. And

Re: Tomcat memory

2016-02-22 Thread tomcat
On 22.02.2016 03:44, Gokul.Baskaran wrote: Thanks again, to make things clear. When I meant default, what is the default min and max that is given to an application if there nothing defined in the JVM ? In how many different ways do you need to be told this ? Re-read the previous answers