You are viewing a plain text version of this content. The canonical link for it is here.
Posted to users@tomcat.apache.org by Vladimir Mikhelson <vl...@hollebcons.com> on 2009/04/17 19:07:34 UTC

Installing mod_jk 1.2.27 on NetWare 6.5 SP8

Hi,

I have tried to install mod_jk 1.2.27 on Netware 6.5 per CVE-2008-5519:
Apache Tomcat mod_jk information disclosure vulnerability.

I downloaded the binary mod_jk-1.2.27-httpd-2.0.63-nw.zip
<http://archive.apache.org/dist/tomcat/tomcat-connectors/jk/binaries/netware/jk-1.2.27/mod_jk-1.2.27-httpd-2.0.63-nw.zip>
from
http://archive.apache.org/dist/tomcat/tomcat-connectors/jk/binaries/netware/jk-1.2.27/
and tried to use it.

Unfortunately I was getting the following in the httpd message screen:

Syntax error on line 638 of SYS:/apache2/conf/httpd.conf:
JkWorkersFile only allowed once

Here is the part of the httpd.conf where the loader failed:
Line 636   #  TABLE: (4)
Line 637   <IfModule mod_jk.c>
Line 638   JkWorkersFile "sys:/adminsrv/conf/mod_jk/workers.properties"
Line 639   JkLogFile "logs/mod_jk.log"
Line 640   JkLogLevel error
Line 641   </IfModule>

NetWare loads httpd in the Admin and then in the OS memory spaces.  The
problem is observed on the second load.

Do you think that it is something that Tomcat people can take care of or
is something where Novell should make their special binary?

Thank you,
Vladimir


---------------------------------------------------------------------
To unsubscribe, e-mail: users-unsubscribe@tomcat.apache.org
For additional commands, e-mail: users-help@tomcat.apache.org


Re: Installing mod_jk 1.2.27 on NetWare 6.5 SP8

Posted by Vladimir Mikhelson <vl...@hollebcons.com>.
Christopher,

I have received an off-line reply from Rainer Jung who suggested to
discuss the issue with Gunter Knauf, the person responsible for NetWare
binaries compilation.

According to Rainer, "The check for multiple JkWorkersFile directives in
the config has been added in revision 580793, so between 1.2.25 and 1.2.26."

It seems to me the mod_jk developers overlooked the NetWare specifics
where the same process can run independently in different memory
spaces.  JkWorkersFile is instantiated once per httpd instance. There
are potentially multiple instances of the same process allowed in
NetWare. Apparently that causes some problem with new version of mod_jk.
FYI, version 1.2.23 runs fine on the same .conf files.

Thank you,
Vladimir



Christopher Schultz wrote:
> Vladimir,
>
> On 4/17/2009 1:07 PM, Vladimir Mikhelson wrote:
> > I downloaded the binary mod_jk-1.2.27-httpd-2.0.63-nw.zip
>
> > Unfortunately I was getting the following in the httpd message screen:
>
> > Syntax error on line 638 of SYS:/apache2/conf/httpd.conf:
> > JkWorkersFile only allowed once
>
> Could you post more of your httpd.conf file? The error message is pretty
> self-explanatory.... line 638 is probably the /second/ place
> JkWorkersFile is mentioned in httpd.conf, so you should look for other
> places.
>
> > Here is the part of the httpd.conf where the loader failed:
> > Line 636   #  TABLE: (4)
> > Line 637   <IfModule mod_jk.c>
> > Line 638   JkWorkersFile "sys:/adminsrv/conf/mod_jk/workers.properties"
> > Line 639   JkLogFile "logs/mod_jk.log"
> > Line 640   JkLogLevel error
> > Line 641   </IfModule>
>
> > NetWare loads httpd in the Admin and then in the OS memory spaces.  The
> > problem is observed on the second load.
>
> Hmm.... I'm not familiar enough with netware to know what you mean when
> you say that you load it in the Admin and OS memory spaces. Why are you
> running httpd more than once?
>
> > Do you think that it is something that Tomcat people can take care of or
> > is something where Novell should make their special binary?
>
> While mod_jk is pretty much a product to support Tomcat (or other Java
> web application servers), the code itself is separate from Tomcat and
> maintained by different people. Two of the mod_jk developers lurk on
> this list and may be able to help, but I suspect your problem is
> configuration-related and not a problem with mod_jk itself.
>
> -chris

---------------------------------------------------------------------
To unsubscribe, e-mail: users-unsubscribe@tomcat.apache.org
For additional commands, e-mail: users-help@tomcat.apache.org




---------------------------------------------------------------------
To unsubscribe, e-mail: users-unsubscribe@tomcat.apache.org
For additional commands, e-mail: users-help@tomcat.apache.org


Re: Installing mod_jk 1.2.27 on NetWare 6.5 SP8

Posted by Christopher Schultz <ch...@christopherschultz.net>.
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

Vladimir,

On 4/17/2009 1:07 PM, Vladimir Mikhelson wrote:
> I downloaded the binary mod_jk-1.2.27-httpd-2.0.63-nw.zip
>
> Unfortunately I was getting the following in the httpd message screen:
> 
> Syntax error on line 638 of SYS:/apache2/conf/httpd.conf:
> JkWorkersFile only allowed once

Could you post more of your httpd.conf file? The error message is pretty
self-explanatory.... line 638 is probably the /second/ place
JkWorkersFile is mentioned in httpd.conf, so you should look for other
places.

> Here is the part of the httpd.conf where the loader failed:
> Line 636   #  TABLE: (4)
> Line 637   <IfModule mod_jk.c>
> Line 638   JkWorkersFile "sys:/adminsrv/conf/mod_jk/workers.properties"
> Line 639   JkLogFile "logs/mod_jk.log"
> Line 640   JkLogLevel error
> Line 641   </IfModule>
> 
> NetWare loads httpd in the Admin and then in the OS memory spaces.  The
> problem is observed on the second load.

Hmm.... I'm not familiar enough with netware to know what you mean when
you say that you load it in the Admin and OS memory spaces. Why are you
running httpd more than once?

> Do you think that it is something that Tomcat people can take care of or
> is something where Novell should make their special binary?

While mod_jk is pretty much a product to support Tomcat (or other Java
web application servers), the code itself is separate from Tomcat and
maintained by different people. Two of the mod_jk developers lurk on
this list and may be able to help, but I suspect your problem is
configuration-related and not a problem with mod_jk itself.

- -chris
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.9 (MingW32)
Comment: Using GnuPG with Mozilla - http://enigmail.mozdev.org/

iEYEARECAAYFAknuJlMACgkQ9CaO5/Lv0PBqqgCgnuXZblKZMs0fKuSr55k77Lht
P/4An1p9z5Hy3txuVeNwqul/Q98wKANh
=Vgxp
-----END PGP SIGNATURE-----

---------------------------------------------------------------------
To unsubscribe, e-mail: users-unsubscribe@tomcat.apache.org
For additional commands, e-mail: users-help@tomcat.apache.org