Re: using cocoon 2.1 in the long-term, security concerns
Vincent Neyt <[email protected]> Tue, 20 Jul 2021 12:27:34 +0200
| Newsgroups | gmane.text.xml.cocoon.user |
|---|---|
| Message-ID | <CAGbLPfYtqu5YFBw-f4dY4LE+OoPUNW=EzqwtREArZY6xWCbn_g@mail.gmail.com> |
--00000000000036974205c78b8142 Content-Type: text/plain; charset="UTF-8" Content-Transfer-Encoding: quoted-printable Thank you very much Warrell, C=C3=A9dric, Greg and Chris. I'm happy to hear that you believe Cocoon poses a very low security risk as long as Tomcat and Java are up to date, and that Cocoon should continue to work well with future versions of T & J as long as the dependency libraries in Cocoon are updated. (At least until Tomcat 9 is no longer supported.) best wishes, Vincent On Mon, Jul 19, 2021 at 6:35 PM Christopher Schultz < [email protected]> wrote: > Vincent, > > On 7/19/21 08:03, Vincent Neyt wrote: > > Hi Cocoon users, > > > > I'd like to ask your opinion on the long-term security risks of running > > Cocoon on a server. The colleague responsible for the servers at my > > university is inquiring if the software I'm using for my website is up > > to date and is concerned that I'm using outdated software that could in > > the future pose a security risk. > > > > I'm using cocoon 2.1.11, which I could probably upgrade to 2.1.13 > > without many problems. But I'm concerned about the long-term, and > > wondering if it would perhaps be better to reprogram the website I've > > been working on for 10 years into eXist DB (which would be a huge time > > investment). I like cocoon very much and would love to continue using i= t > > if it's possible. > > > > I'm curious to hear your thoughts about using Cocoon 2.1 for the long > > term: will it still work well inside future versions of servlet > > containers like Tomcat? What about the java dependencies? And will > > cocoon 2.1 continue to put out updates when security risks are > identified? > > I, like you, have been running Cocoon 2.1.x for years and would like to > continue to rely on it for some important functions at $work. > > I don't see any reason it wouldn't run on current and future Tomcat > versions. There are a few "current" versions of Tomcat, and the only one > I would expect to have some issues would be the Tomcat 10.x series, > which implement the "Jakarta EE" specifications instead of the "Java EE" > specifications. For the most part, these specifications are simply > package-renamed versions of the original Java EE specs. So, for example, > javax.servlet.whatever becomes jakarta.servlet.whatever and so on. > > Tomcat has a migration tool which can migrate a binary web application > (e.g. WAR file) from Java EE to Jakarta EE. It would be good to know if > that tool works on a webapp which is Cocoon itself and/or > Cocoon-bundled-with-your-application. > > I'm a Tomcat committer and if there are any problems, we could work > together to make sure Cocoon has plenty of life left in it. > > With the semi-recent release of Cocoon 2.2, are there members of the > community who would be interested in converting the project into a > Jakarta EE-based project? There is no particular rush, and most of the > conversion can be done essentially with a single sed script. But working > that into the build process so you can say "build me a Java EE-based > Cocoon" versus "build me a Jakarta EE-based Cocoon" would be really > beneficial moving into the future. > > [As a Cocoon user, I'd love to know what is necessary to upgrade from > Cocoon 2.1 to 2.2. We have an ant-based build process for our > application which starts with a pre-built cocoon.war and customizes it > with everything we need. So if e.g. Maven can build Cocoon into a WAR > file, I might be all set.] > > -chris > > --------------------------------------------------------------------- > To unsubscribe, e-mail: [email protected] > For additional commands, e-mail: [email protected] > > --00000000000036974205c78b8142 Content-Type: text/html; charset="UTF-8" Content-Transfer-Encoding: quoted-printable <div dir=3D"ltr">Thank you very much Warrell, C=C3=A9dric, Greg and Chris.<= br><div><br></div><div>I'm happy to hear that you believe Cocoon poses = a very low security risk as long as Tomcat and Java are up to date, and tha= t Cocoon should continue to work well with future versions of T & J as = long as the dependency libraries in Cocoon are updated. (At least until Tom= cat 9 is no longer supported.)</div><div><br></div><div>best wishes,</div><= div>Vincent</div><div><br></div><div><br></div><div><br></div><div><br></di= v></div><br><div class=3D"gmail_quote"><div dir=3D"ltr" class=3D"gmail_attr= ">On Mon, Jul 19, 2021 at 6:35 PM Christopher Schultz <<a href=3D"mailto= :[email protected]" target=3D"_blank">[email protected]= et</a>> wrote:<br></div><blockquote class=3D"gmail_quote" style=3D"margi= n:0px 0px 0px 0.8ex;border-left:1px solid rgb(204,204,204);padding-left:1ex= ">Vincent,<br> <br> On 7/19/21 08:03, Vincent Neyt wrote:<br> > Hi Cocoon users,<br> > <br> > I'd like to ask your opinion on the long-term security risks of ru= nning <br> > Cocoon on a server. The colleague responsible for the servers at my <b= r> > university is inquiring if the software I'm using for my website i= s up <br> > to date and is concerned that I'm using outdated software that cou= ld in <br> > the future pose a security risk.<br> > <br> > I'm using cocoon 2.1.11, which I could probably upgrade to 2.1.13 = <br> > without many problems. But I'm concerned about the long-term, and = <br> > wondering if it would perhaps be better to reprogram the website I'= ;ve <br> > been working on for 10 years into eXist DB (which would be a huge time= <br> > investment). I like cocoon very=C2=A0much and would love to continue u= sing it <br> > if it's possible.<br> > <br> > I'm curious to hear your thoughts about using Cocoon 2.1 for the l= ong <br> > term: will it still work well inside future versions of servlet <br> > containers like Tomcat? What about the java dependencies? And will <br= > > cocoon 2.1 continue to put out updates when security risks are identif= ied?<br> <br> I, like you, have been running Cocoon 2.1.x for years and would like to <br= > continue to rely on it for some important functions at $work.<br> <br> I don't see any reason it wouldn't run on current and future Tomcat= <br> versions. There are a few "current" versions of Tomcat, and the o= nly one <br> I would expect to have some issues would be the Tomcat 10.x series, <br> which implement the "Jakarta EE" specifications instead of the &q= uot;Java EE" <br> specifications. For the most part, these specifications are simply <br> package-renamed versions of the original Java EE specs. So, for example, <b= r> javax.servlet.whatever becomes jakarta.servlet.whatever and so on.<br> <br> Tomcat has a migration tool which can migrate a binary web application <br> (e.g. WAR file) from Java EE to Jakarta EE. It would be good to know if <br= > that tool works on a webapp which is Cocoon itself and/or <br> Cocoon-bundled-with-your-application.<br> <br> I'm a Tomcat committer and if there are any problems, we could work <br= > together to make sure Cocoon has plenty of life left in it.<br> <br> With the semi-recent release of Cocoon 2.2, are there members of the <br> community who would be interested in converting the project into a <br> Jakarta EE-based project? There is no particular rush, and most of the <br> conversion can be done essentially with a single sed script. But working <b= r> that into the build process so you can say "build me a Java EE-based <= br> Cocoon" versus "build me a Jakarta EE-based Cocoon" would be= really <br> beneficial moving into the future.<br> <br> [As a Cocoon user, I'd love to know what is necessary to upgrade from <= br> Cocoon 2.1 to 2.2. We have an ant-based build process for our <br> application which starts with a pre-built cocoon.war and customizes it <br> with everything we need. So if e.g. Maven can build Cocoon into a WAR <br> file, I might be all set.]<br> <br> -chris<br> <br> ---------------------------------------------------------------------<br> To unsubscribe, e-mail: <a href=3D"mailto:[email protected]= rg" target=3D"_blank">[email protected]</a><br> For additional commands, e-mail: <a href=3D"mailto:[email protected]= .org" target=3D"_blank">[email protected]</a><br> <br> </blockquote></div> --00000000000036974205c78b8142--