AW: AW: Logging web applications with log4j 1.2

2019-02-21 Thread Thomas Rohde
Hi Chris, > -BEGIN PGP SIGNED MESSAGE- > Hash: SHA256 > > Thomas, > > On 2/21/19 07:20, Thomas Rohde wrote: > > Hi Chris, > > > > -Ursprüngliche Nachricht- Von: Christopher Schultz > > [mailto:ch...@christopherschultz.net] Gesendet: Mittwoch, 20. > > Februar 2019 16:41 An: user

Re: Parallel Tomcat Instances On Same Server

2019-02-21 Thread TurboChargedDad .
The way I have done it in the past is to separate each tomcat instance by a local user on the machine. I use linux so I have no idea if this would work on windoze. This was done to separate powers and isolate permissions. I am actually looking for critique of this setup as well. So please feel

Parallel Tomcat Instances On Same Server

2019-02-21 Thread Jerry Malcolm
I need a bit of brainstorming.  I have a production Tomcat server that hosts several web sites.  A couple of these websites are high-availability sensitive.  Any downtime will cost the customer.  So obviously I want to minimize downtime.  On the other hand, I am always adding/removing/testing o

Re: [OT] Tomcat Apache 7.0.79 upgrade to Latest version

2019-02-21 Thread Nitin Kadam
Hello , Thanks for the reply. Yes having the plan to remediate same on weekend, ALready informed them about Challenges of upgrading and impact of any failure. Current vulnerability CVE detected in 7.0.79 is showing is taken care in 7.0.91 tomcat version So thinking of upgrading to the same famil

Re: AW: Logging web applications with log4j 1.2

2019-02-21 Thread Christopher Schultz
-BEGIN PGP SIGNED MESSAGE- Hash: SHA256 Thomas, On 2/21/19 07:20, Thomas Rohde wrote: > Hi Chris, > > -Ursprüngliche Nachricht- Von: Christopher Schultz > [mailto:ch...@christopherschultz.net] Gesendet: Mittwoch, 20. > Februar 2019 16:41 An: users@tomcat.apache.org Betreff: Re: L

Re: [OT] Tomcat Apache 7.0.79 upgrade to Latest version

2019-02-21 Thread Christopher Schultz
-BEGIN PGP SIGNED MESSAGE- Hash: SHA256 Nitin, On 2/21/19 07:47, Nitin Kadam wrote: > FOr backup - I will be taking Snapshot backup before doing the > upgrade but also going to take folder backup from C: programme > Files /Apache Tomcat folder. > > I am continuously getting emails from

Re: Logging web applications with log4j 1.2

2019-02-21 Thread John Dale
1 - DevOps can alleviate this issue .. implicit in the model. 2 - exploded directory deployment would allow you to change log4j assuming log4j is configured to reload its configuration on change I'm not sure how classpath contexts are assigned to war files .. but I'm sure there is way. Anyone els

Re: [OT] Tomcat Apache 7.0.79 upgrade to Latest version

2019-02-21 Thread John Dale
Are you going to try to do this on Friday night? You might forward some of our comments to your security team if they want you to change a tire on a moving vehicle .. it's possible, but not the best practice. Does your security team have the ability to allocate some more computing resources to yo

Re: [OT] Tomcat Apache 7.0.79 upgrade to Latest version

2019-02-21 Thread Nitin Kadam
FOr backup - I will be taking Snapshot backup before doing the upgrade but also going to take folder backup from C: programme Files /Apache Tomcat folder. I am continuously getting emails from the internal security team for upgrading the version 7.0.79 to the latest version need to figure out thi

AW: Logging web applications with log4j 1.2

2019-02-21 Thread Thomas Rohde
Hi Chris, -Ursprüngliche Nachricht- Von: Christopher Schultz [mailto:ch...@christopherschultz.net] Gesendet: Mittwoch, 20. Februar 2019 16:41 An: users@tomcat.apache.org Betreff: Re: Logging web applications with log4j 1.2 > > -BEGIN PGP SIGNED MESSAGE- > > Hash: SHA256 > > > >