tomcat-users mailing list archives

Site index · List index
Message view « Date » · « Thread »
Top « Date » · « Thread »
From Anand Gundanna <Anand.Gunda...@Norwich-union.co.uk>
Subject Re: Fw: Tomcat Patch Management
Date Thu, 11 Sep 2008 17:22:47 GMT
Chris,

Thanks for your response.. 

Currently we are managing Windows Patch management through a application 
called "BIGFIX". But that will not be used to manage for any other 
application purpose. 

So, do you think Automatic windows patch management and manual tomcat 
patch management would ideal as patch releases from Tomcat is very rare?

Best Regards,
Anand G
NU UK ITS Architecture and Design
Floor 7, Norfolk Tower, Norwich
Phone - 01603 838398



Christopher Schultz <chris@christopherschultz.net> 
11/09/2008 18:09
Please respond to
"Tomcat Users List" <users@tomcat.apache.org>


To
Tomcat Users List <users@tomcat.apache.org>
cc

Subject
Re: Fw: Tomcat Patch Management






-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

Anand,

Anand Gundanna wrote:
> We have installed and configured an Tomcat web server on windows server
> platform for an application called Business Objects XI.

Yikes. Patching Microsoft Windows will be more important than patching
Tomcat from the vulnerabilities I've seen from both.

> 1) What is the best procedure/practice to keep Tomcat up-to-date with
> patches?

That depends on your existing patching procedures.

> 2) How frequently does Tomcat releases patches/updates and how critical
> it is for an internal application?

Tomcat rarely releases patches per se. New versions are sometimes
released to fix non-security-related as well as security-related bugs.
These are also relatively rare.

> 3) Does Tomcat have any built in tool/feature to download and update
> patches automatically?

No. You'll have to watch the lists for updates and then test and deploy
them yourself.

> Please let me know if you know any other easy option/solution for Tomcat
> Patch Management.

I would ask your NOC what they do for Microsoft Windows updates.

- -chris
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.9 (MingW32)
Comment: Using GnuPG with Mozilla - http://enigmail.mozdev.org

iEYEARECAAYFAkjJULUACgkQ9CaO5/Lv0PBDDgCcCmhu5/tsnOmv4loCbBzmWjpc
diwAn18ybgLsKg1ivtJNOfGcJTIcs8wy
=0/ND
-----END PGP SIGNATURE-----

---------------------------------------------------------------------
To start a new topic, e-mail: users@tomcat.apache.org
To unsubscribe, e-mail: users-unsubscribe@tomcat.apache.org
For additional commands, e-mail: users-help@tomcat.apache.org



Mime
View raw message