Re: AW: Publishing Tomcat webapp

2022-07-21 Thread Jasmin Ćatić
Hello again, I still didn't manage to configure SSL for my Tomcat. I tried a whole bunch of tutorials and solutions but nothing worked for me. Once again I will provide you with what I have, so if anybody can help me I would really appreciate it. If anyone has a free time I will provide you with

RE: QID 38863 - Cryptographically Weak Key Exchange Size

2022-07-21 Thread Saicharan.Burle
Hi Chriss Yeah kind of theoretical question. Recently a new Qualys QID vulnerability was released, QID: 38863 - Cryptographically Weak Key Exchange Size, which deals with weak cipher key exchange key values. So just checking if there is a way to specify a key size for the exchange? Thanks,

Re: *** Payara, GlassFish or Tomcat ***

2022-07-21 Thread Christopher Schultz
Zdenek, On 7/21/22 04:39, Zdeněk Henek wrote: Amn, Our application is tested with Weblogic and Tomcat. I was asked to port our application to any free application server or web container. I picked Tomcat 5.5, now we are on Tomcat 9. I have to say maintaining our app and its installer for

AW: AW: Publishing Tomcat webapp

2022-07-21 Thread Thomas Hoffmann (Speed4Trade GmbH)
> -Ursprüngliche Nachricht- > Von: Christopher Schultz > Gesendet: Donnerstag, 21. Juli 2022 14:11 > An: users@tomcat.apache.org > Betreff: Re: AW: Publishing Tomcat webapp > > Thomas, > > On 7/17/22 03:07, Thomas Hoffmann (Speed4Trade GmbH) wrote: > > Hello, > > > >>

Re: Publishing Tomcat webapp

2022-07-21 Thread Jasmin Ćatić
Hello again, I still didn't manage to configure SSL for my Tomcat. I tried a whole bunch of tutorials and solutions but nothing worked for me. Once again I will provide you with what I have, so if anybody can help me I would really appreciate it. If anyone has a free time I will provide you with

Re: Publishing Tomcat webapp

2022-07-21 Thread Christopher Schultz
Aryeh, On 7/18/22 09:08, Aryeh Friedman wrote: Here are the steps to installing a SSL cert (it varies slightly based on who your certificate authority [CA] is): Generate a CSR Stop. The OP already has a key, cert, and chain. None of this is necessary. [..] with keytool (it must be key tool

Re: AW: Publishing Tomcat webapp

2022-07-21 Thread Christopher Schultz
Thomas, On 7/17/22 03:07, Thomas Hoffmann (Speed4Trade GmbH) wrote: Hello, -Ursprüngliche Nachricht- Von: Aryeh Friedman Gesendet: Sonntag, 17. Juli 2022 08:43 An: Tomcat Users List Betreff: Re: Publishing Tomcat webapp On Sun, Jul 17, 2022 at 2:39 AM Aryeh Friedman wrote: Once

Re: Need remedy for the Vulnabilities

2022-07-21 Thread Christopher Schultz
Koustav, On 7/19/22 05:49, Naha, Koustav wrote: We have the below vulnerability in recent scan, mentioned below. Environment details: Apache - 2.4.25 version Tomcat - 8.5.5 version Can anyone take a look at the CVEs associated with the scan findings and see if there are workarounds,

Re: QID 38863 - Cryptographically Weak Key Exchange Size

2022-07-21 Thread Christopher Schultz
Saicharan, On 7/18/22 10:45, saicharan.bu...@wellsfargo.com.INVALID wrote: Hi All, A new vulnerability has surfaced regarding TLS and Key Exchange agreement (more specifically the key size.) "The SSL/TLS server supports key exchanges that are cryptographically weaker than recommended. Key

Re: SSL configuration for Tomcat 9

2022-07-21 Thread Christopher Schultz
Vince, On 7/15/22 19:56, Vince Stewart wrote: My system uses embedded Tomcat to connect to a HttpServlet instance. I have just uprgraded from Tomcat 8.0.2 to 9.0.64 I am implementing SSL for the first time. I created a keystore with no alias. Keytool gave it the alias "mykey". (2nd entry

Re: AW: [ANN] Apache Tomcat 9.0.65 available

2022-07-21 Thread Mark Thomas
21 Jul 2022 07:32:20 Thomas Hoffmann (Speed4Trade GmbH) : Hello, I saw just a little typo I think. In the changelog: jmvRoute --> jvmRoute Thanks. Should've fixed in git now. Mark Thanks! Thomas -Ursprüngliche Nachricht- Von: Rémy Maucherat Gesendet: Mittwoch, 20. Juli

Re: *** Payara, GlassFish or Tomcat ***

2022-07-21 Thread Zdeněk Henek
Amn, Our application is tested with Weblogic and Tomcat. I was asked to port our application to any free application server or web container. I picked Tomcat 5.5, now we are on Tomcat 9. I have to say maintaining our app and its installer for Tomcat is very easy. Very good backward compatibility

AW: [ANN] Apache Tomcat 9.0.65 available

2022-07-21 Thread Thomas Hoffmann (Speed4Trade GmbH)
Hello, I saw just a little typo I think. In the changelog: jmvRoute --> jvmRoute Thanks! Thomas > -Ursprüngliche Nachricht- > Von: Rémy Maucherat > Gesendet: Mittwoch, 20. Juli 2022 23:18 > An: Tomcat Developers List ; Tomcat Users List > ; annou...@tomcat.apache.org; >