NOTICE: This version of the NSF Unidata web site (archive.unidata.ucar.edu) is no longer being updated.
Current content can be found at unidata.ucar.edu.

To learn about what's going on, see About the Archive Site.

Re: [thredds] Problem - Re: Announce: security enhancements to TDS - please read

Hi Roy,

Sorry about that. I added a note in our release notes but didn't get
that into the announcement.

You need to add the following to your threddsConfig.xml:

  <CatalogServices>
    <allowRemote>true</allowRemote>
  </CatalogServices>

Similarly to allow the WCS server to serve remote dataset, you will need
to add an allowRemote line as follows:

  <WCS>
    <allow>true</allow>
    <allowRemote>true</allowRemote>
    ...
  </WCS>

Ethan

Roy Mendelssohn wrote:
> Hi John:
> 
> I replaced our present thredds in the webapps directory with this one,  
> on restart our remote catalog access failed.  I switched back and it  
> works ago.  Has there been changes in the settings that allow this to  
> work - we depend on it.
> 
> -Roy
> On Jan 20, 2009, at 2:19 PM, John Caron wrote:
> 
>> A new, stable release of the THREDDS Data Server (3.17) is now
>> available at
>>
>> http://www.unidata.ucar.edu/projects/THREDDS/tech/TDS.html
>>
>> This release includes enhancements that give TDS more layers of
>> security, developed in close consultation with NOAA security experts.
>>
>> While there are no known security vulnerabilities with TDS, Tomcat, or
>> Java, multiple layers of security are necessary to protect against
>> future possible exploits.
>>
>> As part of your security process, you must keep both Java and Tomcat
>> up-to-date, as security fixes are ongoing. We recommend Java 1.6 for
>> performance; the current version is 1.6.0_11. If you are constrained
>> to stay with Java 1.5, go to the Java download page and make sure that
>> you are using the latest released version. The current Tomcat version
>> is 6.0.18.
>>
>> While there is no immediate threat, we recommend that you upgrade to
>> current releases of TDS, Tomcat, and Java as soon as practical, and
>> that you make it a practice to keep production systems current.
>> _______________________________________________
>> thredds mailing list
>> thredds@xxxxxxxxxxxxxxxx
>> For list information or to unsubscribe,  visit: 
>> http://www.unidata.ucar.edu/mailing_lists/
> 
> **********************
> "The contents of this message do not reflect any position of the U.S.  
> Government or NOAA."
> **********************
> Roy Mendelssohn
> Supervisory Operations Research Analyst
> NOAA/NMFS
> Environmental Research Division
> Southwest Fisheries Science Center
> 1352 Lighthouse Avenue
> Pacific Grove, CA 93950-2097
> 
> e-mail: Roy.Mendelssohn@xxxxxxxx (Note new e-mail address)
> voice: (831)-648-9029
> fax: (831)-648-8440
> www: http://www.pfeg.noaa.gov/
> 
> "Old age and treachery will overcome youth and skill."
> "From those who have been given much, much will be expected"
> 
> _______________________________________________
> thredds mailing list
> thredds@xxxxxxxxxxxxxxxx
> For list information or to unsubscribe,  visit: 
> http://www.unidata.ucar.edu/mailing_lists/ 

-- 
Ethan R. Davis                                Telephone: (303) 497-8155
Software Engineer                             Fax:       (303) 497-8690
UCAR Unidata Program Center                   E-mail:    edavis@xxxxxxxx
P.O. Box 3000
Boulder, CO  80307-3000                       http://www.unidata.ucar.edu/
---------------------------------------------------------------------------


  • 2009 messages navigation, sorted by:
    1. Thread
    2. Subject
    3. Author
    4. Date
    5. ↑ Table Of Contents
  • Search the thredds archives: