In what rhythm do you update the embedded Tomcat - currently outdated
Hi,
with the 9.8.0 release, I was happy to see that the embedded Tomcat was almost up to date (9.0.68). Our security team was very excited.
However, that has since changed. 6 months later, it is still the now outdated version 9.0.68. Security-wise, this is no longer permissible for us and we have a problem.
You don't support an own Tomcat, but you don't manage to keep the Tomcat halfway up to date - lose-lose for us as customers.
I have set up YF with my own Tomcat, actually no big deal and it works fine. You only have to put the war file into your own Tomcat and YF installs itself and works. Unfortunately your update idea doesn't fit to the war-file idea. Because during the update you replace single files instead of delivering a new war-file.
What can I do to meet the security requirements or when is a new TC coming from you?
;) Stefan
Hi Stefan,
That's certainly a good idea! I'll raise it as an enhancement request with the development team. We could see some changes due to your feedback and either include a Tomcat updater or ship new WAR files.
Kind regards,
Chris
Hi Stefan,
That's certainly a good idea! I'll raise it as an enhancement request with the development team. We could see some changes due to your feedback and either include a Tomcat updater or ship new WAR files.
Kind regards,
Chris
Hi Stefan,
Thanks for your question. Tomcat releases do come with full installs of Yellowfin but Yellowfin upgrades don't patch the currently installed version of Tomcat.
I'm glad you were able to set up Yellowfin with your own Tomcat. If you want to upgrade your current install, we have a KB article on upgrading Tomcat here:
https://community.yellowfinbi.com/knowledge-base/article/how-to-upgrade-tomcat
If you'd like to ensure that a new version of Tomcat comes with the next version of Yellowfin, I can put in a request with the developer team look into it.
Kind regards,
Chris
Hi Stefan,
Thanks for your question. Tomcat releases do come with full installs of Yellowfin but Yellowfin upgrades don't patch the currently installed version of Tomcat.
I'm glad you were able to set up Yellowfin with your own Tomcat. If you want to upgrade your current install, we have a KB article on upgrading Tomcat here:
https://community.yellowfinbi.com/knowledge-base/article/how-to-upgrade-tomcat
If you'd like to ensure that a new version of Tomcat comes with the next version of Yellowfin, I can put in a request with the developer team look into it.
Kind regards,
Chris
Hi Stefan,
Let me know if there's anything else on this topic you'd like to cover. I'll keep this open for a few more days until I hear from you.
Kind regards,
Chris
Hi Stefan,
Let me know if there's anything else on this topic you'd like to cover. I'll keep this open for a few more days until I hear from you.
Kind regards,
Chris
Replies have been locked on this page!