So your advise is to run a *very* outdated version because the packagers haven't updated their software? Sounds like a great way to open up your system to hackers.
Martijn On 1/21/08, C. Bergström <[EMAIL PROTECTED]> wrote: > > > On Mon, 2008-01-21 at 11:31 +0100, Martijn Dashorst wrote: > > You might want to skip the packaged version (IMO linux packagers don't > > get the Java packaging), and just unzip a tarball > > in /opt/tomcat/tomcat-5.5.20 > > > > > > Then you are in complete control over how the server runs. > > > -1 > > Some distro packaging systems while admittedly are lacking in certain > areas are there for a reason. > > 1) Tomcat is not perfect software and thus may have some security issue > either in core or in the default context that's enabled by default and > thus not everyone follows such alerts/advisories for a living. (Trusting > that the distro will issue an update and the system is regularly > maintained.) > 2) I'm not sure this takes into account the install of tomcat native > libs and also any distro related changes there > > etc etc... > > > > Martijn > > > <snip /> > > > > > > Apparently the latest version ( 5.5.20-2etch1) has additional > > security headaches features which prevent wicket from > > functioning properly out-of-the-box: > > I consider this a positive thing as it means some forethought has > actually gone into this package. > > <snip /> > > > > > Any ideas on how to better configure Tomcat? > > Not at the moment. The best I can offer is give me about a week and > I'll see if I can get deb etch installed in vmware and have a look. > > > Good luck, > > ./C > > > --------------------------------------------------------------------- > To unsubscribe, e-mail: [EMAIL PROTECTED] > For additional commands, e-mail: [EMAIL PROTECTED] > > -- Buy Wicket in Action: http://manning.com/dashorst Apache Wicket 1.3.0 is released Get it now: http://www.apache.org/dyn/closer.cgi/wicket/1.3.0
