Tomcat Security Issues
Author: knut.dybendahl@gmail.com (Knut)
Hi all, I'm not sure which forum this belongs to - but since it's starting with the development of secure web applications I thought I'd drop it in here. There are a number of security alerts and warnings associated with the version of Tomcat shipped with the latest version of Uniface - up to and including version 9.6.06 - with 1 security hole and 11 security warnings on a PCI check from Comodo - causing sites to be PCI non-compliant (which is NOT good).
From what I can tell, all of the issues have been resolved with the latest version of Tomcat, version 7.0.55. 1) Are there any issues with upgrading the Tomcat server to 7.0.55 since we'd break the long-standing "the Lab hasn't tested that specific configuration - hence it's unsupported" mantra? 2) Does the Lab / others in the Uniface community have a best practices method to stay on top of Tomcat issues? 3) Would I be able to shield these issues by using IIS as a frontend to the Tomcat engine as IIS would have to deal with the SSL / TSL issues? 4) Should we have a 'Security' sub forum? Knut




