You are viewing a plain text version of this content. The canonical link for it is here.
Posted to users@tomcat.apache.org by "Mark G. Franz" <mg...@pe.net> on 2000/11/18 14:00:46 UTC

VIRUS ALERT! Re: using SSL on standalone Tomcat - Urgent !

DO NOT OPEN THIS ATTACHMENT!

-----Original Message-----
From: Craig R. McClanahan <Cr...@eng.sun.com>
To: tomcat-user@jakarta.apache.org <to...@jakarta.apache.org>
Date: Friday, November 17, 2000 10:26 PM
Subject: Re: using SSL on standalone Tomcat - Urgent !


>"Lacerda, Wellington (AFIS)" wrote:
>
>> Craig,
>>
>> Can you send me a piece of example of the configuration ? I can't see
what
>> I'm doing wrong. I've already tested both suggestions and I didn't get
that
>> message back in any case.
>>
>> Thanks,
>>
>> Wellington
>>
>
>Attached is the simplest web-app I can create that illustrates this thing
>working correctly.  Put "secure-only.war" in your webapps directory,
restart
>Tomcat, and try:
>
>    http://localhost:8080/secure-only
>
>You should get a message stating "SSL required to access this page".  I
tested
>this with the most recent code from CVS, but I do not believe anything has
>changed (that would affect this) since beta 7.
>
>Craig
>
>PS:  It also works if you change the transport guarantee from CONFIDENTIAL
to
>INTEGRAL.
>
>


Re: VIRUS ALERT! Re: using SSL on standalone Tomcat - Urgent !

Posted by Kurt Bernhard Pruenner <le...@gmx.at>.
"Mark G. Franz" wrote:
> DO NOT OPEN THIS ATTACHMENT!

Jeeez... you've got to be kidding me - that file was just over 1kB in size,
and contained 2 xml and 1 html file... just because your virus scanner is
paranoid doesn't mean you have to be too... and there's no way you're gonna
fit a JavaScript-Virus into 163 bytes of HTML, think about it, much less find
an XML-virus...

Just to cite some other paranoid firewall...

<quote>
Antigen virus protection for Exchange found secure-only.war infected with
CorruptedCompressedFile virus.  The file is currently Deleted.  The message,
"Re: using SSL on standalone Tomcat - Urgent !", was
sent from Craig R. McClanahan  and was discovered in IMC Queues\Inbound
located at Genelco.
</quote>

Now, if you also got the "corrupted compressed file" virus warning - blame
your virus scanner for not being able to correctly read WAR-files, a feat even
WinRAR here pulls off without problems... :/

Okay people, you _can_ open this attachment alright, move along, move along,
nothing to see here...

Sorry, I just had to get this off my chest...

-- 
Kurt Pruenner - Haendelstrasse 17, 4020 Linz, Austria | Briareos at Olymp BBS:
http://www.mp3.com/Leak http://www.ssw.uni-linz.ac.at | ssh bbs@138.232.112.32
...........It might be written "Mindfuck", but it's spelt "L-A-I-N"...........
np: Leak - Turbs (Leaked)

Re: VIRUS ALERT! Re: using SSL on standalone Tomcat - Urgent !

Posted by "Craig R. McClanahan" <Cr...@eng.sun.com>.
"Mark G. Franz" wrote:

> DO NOT OPEN THIS ATTACHMENT!
>

The "Antigen for Exchange" virus scanner is broken, as you will discover if you
scan this file with any other virus scanner.  Apparently it does not know what a
Java JAR file looks like.

Craig McClanahan