Return-Path: X-Original-To: apmail-activemq-dev-archive@www.apache.org Delivered-To: apmail-activemq-dev-archive@www.apache.org Received: from mail.apache.org (hermes.apache.org [140.211.11.3]) by minotaur.apache.org (Postfix) with SMTP id E0A5310CC2 for ; Fri, 17 Jan 2014 17:21:11 +0000 (UTC) Received: (qmail 12249 invoked by uid 500); 17 Jan 2014 17:21:10 -0000 Delivered-To: apmail-activemq-dev-archive@activemq.apache.org Received: (qmail 12156 invoked by uid 500); 17 Jan 2014 17:21:10 -0000 Mailing-List: contact dev-help@activemq.apache.org; run by ezmlm Precedence: bulk List-Help: List-Unsubscribe: List-Post: List-Id: Reply-To: dev@activemq.apache.org Delivered-To: mailing list dev@activemq.apache.org Received: (qmail 12147 invoked by uid 99); 17 Jan 2014 17:21:10 -0000 Received: from athena.apache.org (HELO athena.apache.org) (140.211.11.136) by apache.org (qpsmtpd/0.29) with ESMTP; Fri, 17 Jan 2014 17:21:10 +0000 X-ASF-Spam-Status: No, hits=0.6 required=5.0 tests=RCVD_IN_DNSWL_LOW,SPF_PASS,URI_HEX X-Spam-Check-By: apache.org Received-SPF: pass (athena.apache.org: domain of chris.mattmann@gmail.com designates 209.85.160.54 as permitted sender) Received: from [209.85.160.54] (HELO mail-pb0-f54.google.com) (209.85.160.54) by apache.org (qpsmtpd/0.29) with ESMTP; Fri, 17 Jan 2014 17:21:06 +0000 Received: by mail-pb0-f54.google.com with SMTP id uo5so717730pbc.41 for ; Fri, 17 Jan 2014 09:20:45 -0800 (PST) X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20130820; h=user-agent:date:subject:from:to:message-id:thread-topic:references :in-reply-to:mime-version:content-type:content-transfer-encoding; bh=gwqM+4uQz+BbOgg522zs4MekeVl/ztitaA+phA9bs9k=; b=QEAcOysemyCF39HbHmbo7zc3wDTVnux9JdMDQARKjVe5LPokQv58q8DBAxx+TWvQGj CC9CWO6W7ACAqkYpm8tRFEKYpg9P1Ng8z95ayT+rG1jppSWE71NrlMcn2BWKp4F6cbTu A4bljDb6dtKn9Ug6DyyUvr7LE2fhys/1Hb4yjLuQ8io2ap9Hye/uXkL9AEL5SXxoH4y6 t0fLq4ztFt/W0NyL8hJk1ulLoqHSfUV2Lov8jrNaMangcuzhvAYj2BTdacFHmccYDXPe /3AuY3pnJROWSq3w/jyb4LtD3olTlzwWWBwo9FQcxu4wG64G3NCwqgCSKlR7bsGlt2r1 WCyQ== X-Received: by 10.68.239.70 with SMTP id vq6mr3306615pbc.152.1389979245465; Fri, 17 Jan 2014 09:20:45 -0800 (PST) Received: from [137.79.16.80] ([137.79.16.80]) by mx.google.com with ESMTPSA id qq5sm24240311pbb.24.2014.01.17.09.20.33 for (version=TLSv1 cipher=RC4-SHA bits=128/128); Fri, 17 Jan 2014 09:20:44 -0800 (PST) User-Agent: Microsoft-MacOutlook/14.3.9.131030 Date: Fri, 17 Jan 2014 09:20:14 -0800 Subject: Re: [DISCUSS] Remove the old ActiveMQ Console From: Chris Mattmann To: Message-ID: Thread-Topic: [DISCUSS] Remove the old ActiveMQ Console References: <05AAA2FB-2982-4AA8-8CE2-4AC94DE2C708@gmail.com> <01D2C10F-0EC3-424F-A14E-241259EBFAE1@gmail.com> In-Reply-To: <01D2C10F-0EC3-424F-A14E-241259EBFAE1@gmail.com> Mime-version: 1.0 Content-type: text/plain; charset="ISO-8859-1" Content-transfer-encoding: quoted-printable X-Virus-Checked: Checked by ClamAV on apache.org Hi Everyone, I reported at the board meeting two days ago that you guys are making steps towards addressing this. The big issue that still remains is that hawtio in its current form unbranded as the default Apache ActiveMQ console must be fixed ASAP and addressed. *How* that is done is currently being discussed, but realize that discussion needs to conclude in a reasonable time frame, let's say before the next board meeting 3rd week of February 2014. Cheers, Chris -----Original Message----- From: Robert Davies Reply-To: Date: Friday, January 17, 2014 1:32 AM To: Subject: Re: [DISCUSS] Remove the old ActiveMQ Console >This discussion has been open a while - not exactly consensus but then >there=B9s not really much difference either. There does seem to be general >consensus amongst the poor folks who actually maintain the old console >(me included) it should die quickly, but I think we should keep it around >optionally for those users who can=B9t use anything else?. >We have to get this resolved quickly - so I=B9ll start a vote and hope to >gain some consensus, at least within the PMC. > >thanks, > >Rob >On 16 Jan 2014, at 22:21, Gary Tully wrote: > >> I think the web-console should die, letting it rot in a subproject >> will not make it more secure,usable nor maintainable. >>=20 >> Then we either - >> 1) skin hawtio with an Apache ActiveMQ brand and continue to ship it >> 2) document the extension points for third party consoles. >>=20 >> I think dropping needs to be contingent on either 1 or 2. >>=20 >> Imho, hawtio does it right with the jolokia jmx/http bridge and has >> some nice extension points so I am in favour of 1 >>=20 >> On 2 January 2014 09:59, Robert Davies wrote: >>> The old/original console is no longer fit for purpose, it is hard to >>>maintain, the source of a lot of security issues [1] over the last few >>>years. >>>=20 >>> There is another thread about using hawtio as the console going >>>forward, and without going into all the gory details it is probably >>>likely that there may be no web console shipped at all in future >>>releases of ActiveMQ. The JMX naming hierarchy was improved for >>>ActiveMQ 5.8, such that its easy to view the running status of an >>>ActiveMQ broker from 3rd party tools such as jconsole, visualvm or >>>hawtio. Regardless of the outcome of the other discussion [2] - It >>>doesn=B9t help the ActiveMQ project to try and maintain a static web >>>console any more. >>>=20 >>> I propose we remove the old web console from the ActiveMQ 5.10 release >>>- thoughts ? >>>=20 >>>=20 >>>=20 >>> [1]=20 >>>https://issues.apache.org/jira/browse/AMQ-2714?jql=3Dproject%20%3D%20AMQ%2 >>>0AND%20text%20~%20%22XSS%22 >>> [2]=20 >>>http://activemq.2283324.n4.nabble.com/Default-Web-Console-td4675705.html >>>=20 >>> Rob Davies >>> =8B=8B=8B=8B=8B=8B=8B=8B >>> Red Hat, Inc >>> http://hawt.io - #dontcha >>> Twitter: rajdavies >>> Blog: http://rajdavies.blogspot.com >>> ActiveMQ in Action: http://www.manning.com/snyder/ >>>=20 >>=20 >>=20 >>=20 >> --=20 >> http://redhat.com >> http://blog.garytully.com > >Rob Davies >=8B=8B=8B=8B=8B=8B=8B=8B >Red Hat, Inc >http://hawt.io - #dontcha >Twitter: rajdavies >Blog: http://rajdavies.blogspot.com >ActiveMQ in Action: http://www.manning.com/snyder/ >