Re: [thredds] Problem - Re: Announce: security enhancements to TDS - please read

Hi Roy,

Sorry about that. I added a note in our release notes but didn't get
that into the announcement.

You need to add the following to your threddsConfig.xml:

  <CatalogServices>
    <allowRemote>true</allowRemote>
  </CatalogServices>

Similarly to allow the WCS server to serve remote dataset, you will need
to add an allowRemote line as follows:

  <WCS>
    <allow>true</allow>
    <allowRemote>true</allowRemote>
    ...
  </WCS>

Ethan

Roy Mendelssohn wrote:
> Hi John:
> 
> I replaced our present thredds in the webapps directory with this one,  
> on restart our remote catalog access failed.  I switched back and it  
> works ago.  Has there been changes in the settings that allow this to  
> work - we depend on it.
> 
> -Roy
> On Jan 20, 2009, at 2:19 PM, John Caron wrote:
> 
>> A new, stable release of the THREDDS Data Server (3.17) is now
>> available at
>>
>> http://www.unidata.ucar.edu/projects/THREDDS/tech/TDS.html
>>
>> This release includes enhancements that give TDS more layers of
>> security, developed in close consultation with NOAA security experts.
>>
>> While there are no known security vulnerabilities with TDS, Tomcat, or
>> Java, multiple layers of security are necessary to protect against
>> future possible exploits.
>>
>> As part of your security process, you must keep both Java and Tomcat
>> up-to-date, as security fixes are ongoing. We recommend Java 1.6 for
>> performance; the current version is 1.6.0_11. If you are constrained
>> to stay with Java 1.5, go to the Java download page and make sure that
>> you are using the latest released version. The current Tomcat version
>> is 6.0.18.
>>
>> While there is no immediate threat, we recommend that you upgrade to
>> current releases of TDS, Tomcat, and Java as soon as practical, and
>> that you make it a practice to keep production systems current.
>> _______________________________________________
>> thredds mailing list
>> thredds@xxxxxxxxxxxxxxxx
>> For list information or to unsubscribe,  visit: 
>> http://www.unidata.ucar.edu/mailing_lists/
> 
> **********************
> "The contents of this message do not reflect any position of the U.S.  
> Government or NOAA."
> **********************
> Roy Mendelssohn
> Supervisory Operations Research Analyst
> NOAA/NMFS
> Environmental Research Division
> Southwest Fisheries Science Center
> 1352 Lighthouse Avenue
> Pacific Grove, CA 93950-2097
> 
> e-mail: Roy.Mendelssohn@xxxxxxxx (Note new e-mail address)
> voice: (831)-648-9029
> fax: (831)-648-8440
> www: http://www.pfeg.noaa.gov/
> 
> "Old age and treachery will overcome youth and skill."
> "From those who have been given much, much will be expected"
> 
> _______________________________________________
> thredds mailing list
> thredds@xxxxxxxxxxxxxxxx
> For list information or to unsubscribe,  visit: 
> http://www.unidata.ucar.edu/mailing_lists/ 

-- 
Ethan R. Davis                                Telephone: (303) 497-8155
Software Engineer                             Fax:       (303) 497-8690
UCAR Unidata Program Center                   E-mail:    edavis@xxxxxxxx
P.O. Box 3000
Boulder, CO  80307-3000                       http://www.unidata.ucar.edu/
---------------------------------------------------------------------------


  • 2009 messages navigation, sorted by:
    1. Thread
    2. Subject
    3. Author
    4. Date
    5. ↑ Table Of Contents
  • Search the thredds archives: