Re: using cocoon 2.1 in the long-term, security concerns

Vincent Neyt <[email protected]> Tue, 20 Jul 2021 12:27:34 +0200
Newsgroups gmane.text.xml.cocoon.user
Message-ID <CAGbLPfYtqu5YFBw-f4dY4LE+OoPUNW=EzqwtREArZY6xWCbn_g@mail.gmail.com>
--00000000000036974205c78b8142
Content-Type: text/plain; charset="UTF-8"
Content-Transfer-Encoding: quoted-printable

Thank you very much Warrell, C=C3=A9dric, Greg and Chris.

I'm happy to hear that you believe Cocoon poses a very low security risk as
long as Tomcat and Java are up to date, and that Cocoon should continue to
work well with future versions of T & J as long as the dependency libraries
in Cocoon are updated. (At least until Tomcat 9 is no longer supported.)

best wishes,
Vincent





On Mon, Jul 19, 2021 at 6:35 PM Christopher Schultz <
[email protected]> wrote:

> Vincent,
>
> On 7/19/21 08:03, Vincent Neyt wrote:
> > Hi Cocoon users,
> >
> > I'd like to ask your opinion on the long-term security risks of running
> > Cocoon on a server. The colleague responsible for the servers at my
> > university is inquiring if the software I'm using for my website is up
> > to date and is concerned that I'm using outdated software that could in
> > the future pose a security risk.
> >
> > I'm using cocoon 2.1.11, which I could probably upgrade to 2.1.13
> > without many problems. But I'm concerned about the long-term, and
> > wondering if it would perhaps be better to reprogram the website I've
> > been working on for 10 years into eXist DB (which would be a huge time
> > investment). I like cocoon very much and would love to continue using i=
t
> > if it's possible.
> >
> > I'm curious to hear your thoughts about using Cocoon 2.1 for the long
> > term: will it still work well inside future versions of servlet
> > containers like Tomcat? What about the java dependencies? And will
> > cocoon 2.1 continue to put out updates when security risks are
> identified?
>
> I, like you, have been running Cocoon 2.1.x for years and would like to
> continue to rely on it for some important functions at $work.
>
> I don't see any reason it wouldn't run on current and future Tomcat
> versions. There are a few "current" versions of Tomcat, and the only one
> I would expect to have some issues would be the Tomcat 10.x series,
> which implement the "Jakarta EE" specifications instead of the "Java EE"
> specifications. For the most part, these specifications are simply
> package-renamed versions of the original Java EE specs. So, for example,
> javax.servlet.whatever becomes jakarta.servlet.whatever and so on.
>
> Tomcat has a migration tool which can migrate a binary web application
> (e.g. WAR file) from Java EE to Jakarta EE. It would be good to know if
> that tool works on a webapp which is Cocoon itself and/or
> Cocoon-bundled-with-your-application.
>
> I'm a Tomcat committer and if there are any problems, we could work
> together to make sure Cocoon has plenty of life left in it.
>
> With the semi-recent release of Cocoon 2.2, are there members of the
> community who would be interested in converting the project into a
> Jakarta EE-based project? There is no particular rush, and most of the
> conversion can be done essentially with a single sed script. But working
> that into the build process so you can say "build me a Java EE-based
> Cocoon" versus "build me a Jakarta EE-based Cocoon" would be really
> beneficial moving into the future.
>
> [As a Cocoon user, I'd love to know what is necessary to upgrade from
> Cocoon 2.1 to 2.2. We have an ant-based build process for our
> application which starts with a pre-built cocoon.war and customizes it
> with everything we need. So if e.g. Maven can build Cocoon into a WAR
> file, I might be all set.]
>
> -chris
>
> ---------------------------------------------------------------------
> To unsubscribe, e-mail: [email protected]
> For additional commands, e-mail: [email protected]
>
>

--00000000000036974205c78b8142
Content-Type: text/html; charset="UTF-8"
Content-Transfer-Encoding: quoted-printable

<div dir=3D"ltr">Thank you very much Warrell, C=C3=A9dric, Greg and Chris.<=
br><div><br></div><div>I&#39;m happy to hear that you believe Cocoon poses =
a very low security risk as long as Tomcat and Java are up to date, and tha=
t Cocoon should continue to work well with future versions of T &amp; J as =
long as the dependency libraries in Cocoon are updated. (At least until Tom=
cat 9 is no longer supported.)</div><div><br></div><div>best wishes,</div><=
div>Vincent</div><div><br></div><div><br></div><div><br></div><div><br></di=
v></div><br><div class=3D"gmail_quote"><div dir=3D"ltr" class=3D"gmail_attr=
">On Mon, Jul 19, 2021 at 6:35 PM Christopher Schultz &lt;<a href=3D"mailto=
:[email protected]" target=3D"_blank">[email protected]=
et</a>&gt; wrote:<br></div><blockquote class=3D"gmail_quote" style=3D"margi=
n:0px 0px 0px 0.8ex;border-left:1px solid rgb(204,204,204);padding-left:1ex=
">Vincent,<br>
<br>
On 7/19/21 08:03, Vincent Neyt wrote:<br>
&gt; Hi Cocoon users,<br>
&gt; <br>
&gt; I&#39;d like to ask your opinion on the long-term security risks of ru=
nning <br>
&gt; Cocoon on a server. The colleague responsible for the servers at my <b=
r>
&gt; university is inquiring if the software I&#39;m using for my website i=
s up <br>
&gt; to date and is concerned that I&#39;m using outdated software that cou=
ld in <br>
&gt; the future pose a security risk.<br>
&gt; <br>
&gt; I&#39;m using cocoon 2.1.11, which I could probably upgrade to 2.1.13 =
<br>
&gt; without many problems. But I&#39;m concerned about the long-term, and =
<br>
&gt; wondering if it would perhaps be better to reprogram the website I&#39=
;ve <br>
&gt; been working on for 10 years into eXist DB (which would be a huge time=
 <br>
&gt; investment). I like cocoon very=C2=A0much and would love to continue u=
sing it <br>
&gt; if it&#39;s possible.<br>
&gt; <br>
&gt; I&#39;m curious to hear your thoughts about using Cocoon 2.1 for the l=
ong <br>
&gt; term: will it still work well inside future versions of servlet <br>
&gt; containers like Tomcat? What about the java dependencies? And will <br=
>
&gt; cocoon 2.1 continue to put out updates when security risks are identif=
ied?<br>
<br>
I, like you, have been running Cocoon 2.1.x for years and would like to <br=
>
continue to rely on it for some important functions at $work.<br>
<br>
I don&#39;t see any reason it wouldn&#39;t run on current and future Tomcat=
 <br>
versions. There are a few &quot;current&quot; versions of Tomcat, and the o=
nly one <br>
I would expect to have some issues would be the Tomcat 10.x series, <br>
which implement the &quot;Jakarta EE&quot; specifications instead of the &q=
uot;Java EE&quot; <br>
specifications. For the most part, these specifications are simply <br>
package-renamed versions of the original Java EE specs. So, for example, <b=
r>
javax.servlet.whatever becomes jakarta.servlet.whatever and so on.<br>
<br>
Tomcat has a migration tool which can migrate a binary web application <br>
(e.g. WAR file) from Java EE to Jakarta EE. It would be good to know if <br=
>
that tool works on a webapp which is Cocoon itself and/or <br>
Cocoon-bundled-with-your-application.<br>
<br>
I&#39;m a Tomcat committer and if there are any problems, we could work <br=
>
together to make sure Cocoon has plenty of life left in it.<br>
<br>
With the semi-recent release of Cocoon 2.2, are there members of the <br>
community who would be interested in converting the project into a <br>
Jakarta EE-based project? There is no particular rush, and most of the <br>
conversion can be done essentially with a single sed script. But working <b=
r>
that into the build process so you can say &quot;build me a Java EE-based <=
br>
Cocoon&quot; versus &quot;build me a Jakarta EE-based Cocoon&quot; would be=
 really <br>
beneficial moving into the future.<br>
<br>
[As a Cocoon user, I&#39;d love to know what is necessary to upgrade from <=
br>
Cocoon 2.1 to 2.2. We have an ant-based build process for our <br>
application which starts with a pre-built cocoon.war and customizes it <br>
with everything we need. So if e.g. Maven can build Cocoon into a WAR <br>
file, I might be all set.]<br>
<br>
-chris<br>
<br>
---------------------------------------------------------------------<br>
To unsubscribe, e-mail: <a href=3D"mailto:[email protected]=
rg" target=3D"_blank">[email protected]</a><br>
For additional commands, e-mail: <a href=3D"mailto:[email protected]=
.org" target=3D"_blank">[email protected]</a><br>
<br>
</blockquote></div>

--00000000000036974205c78b8142--