So your advise is to run a *very* outdated version because the packagers
haven't updated their software?
Sounds like a great way to open up your system to hackers.

Martijn

On 1/21/08, C. Bergström <[EMAIL PROTECTED]> wrote:
>
>
> On Mon, 2008-01-21 at 11:31 +0100, Martijn Dashorst wrote:
> > You might want to skip the packaged version (IMO linux packagers don't
> > get the Java packaging), and just unzip a tarball
> > in /opt/tomcat/tomcat-5.5.20
> >
> >
> > Then you are in complete control over how the server runs.
> >
> -1
>
> Some distro packaging systems while admittedly are lacking in certain
> areas are there for a reason.
>
> 1) Tomcat is not perfect software and thus may have some security issue
> either in core or in the default context that's enabled by default and
> thus not everyone follows such alerts/advisories for a living. (Trusting
> that the distro will issue an update and the system is regularly
> maintained.)
> 2) I'm not sure this takes into account the install of tomcat native
> libs and also any distro related changes there
>
> etc etc...
> >
> > Martijn
> >
> <snip />
> >
> >
> >         Apparently the latest version ( 5.5.20-2etch1) has additional
> >         security headaches features which prevent wicket from
> >         functioning properly out-of-the-box:
>
> I consider this a positive thing as it means some forethought has
> actually gone into this package.
>
> <snip />
>
> >
> >         Any ideas on how to better configure Tomcat?
>
> Not at the moment.  The best I can offer is give me about a week and
> I'll see if I can get deb etch installed in vmware and have a look.
>
>
> Good luck,
>
> ./C
>
>
> ---------------------------------------------------------------------
> To unsubscribe, e-mail: [EMAIL PROTECTED]
> For additional commands, e-mail: [EMAIL PROTECTED]
>
>


-- 
Buy Wicket in Action: http://manning.com/dashorst
Apache Wicket 1.3.0 is released
Get it now: http://www.apache.org/dyn/closer.cgi/wicket/1.3.0

Reply via email to