This updates includes a rebase from tomcat 8.0.36 up to 8.0.38 which resolves multiple CVEs and a problem that 8.0.37 introduces to freeipa:
and includes two additional CVE fixes along with one bug fix:
Updates may require up to 24 hours to propagate to mirrors. If the following command doesn't work, please retry later:
sudo dnf upgrade --refresh --advisory=FEDORA-2016-c1b01b9278
Please login to add feedback.
This update has been submitted for testing by csutherl.
This update has been pushed to testing.
This update broke Dogtag PKI setup during FreeIPA server installation:
See also the following cornucopia of stack traces in the pki-tomcat service journal log: https://paste.fedoraproject.org/460589/77394029
giving negative karma until the issue is fixed either on tomcat or dogtag side.
After upgrade a restart of FreeIPA fails. In catalina log I can see there is a missing java class that cannot be found:
Note that the only java packages upgraded were from tomcat:
Corresponding Apache bug: https://bz.apache.org/bugzilla/show_bug.cgi?id=60101
So we need to get 8.0.38 packaged.
Thanks for pinning that down @abbra; I'll rebase to 8.0.38 asap.
csutherl edited this update.
New build(s):
Removed build(s):
This update has been submitted for testing by csutherl.
Is it possible to remove the tomcat-8.0.37-3.fc24 package from updates-testing?
I was under the impression that adding a new build would remove the old one, but maybe that isn't the case. I do see that this update is pending the push to testing, so maybe when that happens the old build will be removed. I'm going to wait and see what happens when this update is pushed to testing. If it doesn't resolve it, I'll try untagging the 8.0.37-3 build.
This update has been pushed to testing.
csutherl edited this update.
This update has reached 7 days in testing and can be pushed to stable now if the maintainer wishes
This update has been submitted for stable by csutherl.
This update has been pushed to stable.