Bitnami apache tomcat cfm update#The issue is that the update puts a new "secret" into the CF configuration (the AJP line of the server.xml file), and the wsconfig upgrade puts that "secret" into the web connector (workers.properties) configuration file. First, you MUST "upgrade" any CF web server connector for IIS or Apache after applying the update.Here, briefly, is what to do and why ( update since original posting: I added the 3rd point): The issue(s) stem from important security fixes that Adobe has implemented (related to the "Ghostcat" Tomcat vulnerability), which apply to the "AJP connector" that is enabled by default for connections between web servers like IIS or Apache and CF.Īfter applying these latest Mar 2020 CF updates, web sites served from IIS or Apache will likely fail. There's also a fair bit of "screaming" in the CF community, and folks responding may not know the info that I (or Adobe) have shared, to get things "working again", so I hope this helps bring some calm, and most important the clear solution/s needed.įor those who favor brevity, here's my attempt at a "brief" explanation. Sadly, because many people don't bother to read the CF update technotes (linked to below), and they just apply the CF updates, they are not noticing this issue until they or their users start screaming because their sites are down. The good news is that these steps are both easy and documented by Adobe in the update technotes, but they do require that someone do them, if needed. Instead, it's that after applying it, your CF web sites served via IIS or Apache WILL likely break initially, until you take one at least and perhaps two extra steps. To be clear, I do not mean with this warning to suggest that you should NOT apply the update! It implements an important security fix. And readers in the future should note it will apply if and as you may update CF from any update BEFORE this one to any update AFTER this one. This is a critical warning to anyone who may apply the recent CF2018 Update 8 or CF2016 Update 14, released Tuesday of this week (on Mar 20, 2020).
0 Comments
Leave a Reply. |
AuthorWrite something about yourself. No need to be fancy, just an overview. ArchivesCategories |