Skip Headers
Oracle® iPlanet Web Server Release Notes
Release 6.1 SP21

E18788-09
Go to Table of Contents
Contents
Go to Feedback page
Contact Us

Go to previous page
Previous
Go to next page
Next
PDF · Mobi · ePub

A Features and Enhancements in Previous Oracle iPlanet Web Server 6.1 Releases

The features and enhancements in Oracle iPlanet Web Server 6.1 service pack releases prior to Oracle iPlanet Web Server 6.1 SP12 are described in the individual Release Notes documents specific to those releases, which are available at:

http://docs.oracle.com/cd/E19857-01/index.html

This chapter lists the features and enhancements in Oracle iPlanet Web Server 6.1 SP12 and later releases. It contains the following sections:

A.1 Features and Enhancements in 6.1 SP20

Oracle iPlanet Web Server 6.1 SP20 supports Network Security Services (NSS) 3.17.2.

A.2 Features and Enhancements in 6.1 SP19

There are no new features and enhancements in Oracle iPlanet Web Server 6.1 SP19. This release addresses security issues.

A.3 Features and Enhancements in 6.1 SP18

Oracle iPlanet Web Server 6.1 SP18 supports Network Security Services (NSS) 3.14.3.

A.4 Features and Enhancements in 6.1 SP17

There are no new features and enhancements in Oracle iPlanet Web Server 6.1 SP17. This release addresses security issues.

A.5 Features and Enhancements in 6.1 SP16

This section lists features and enhancements provided in Oracle iPlanet Web Server 6.1 SP16.

A.6 Features and Enhancements in 6.1 SP15

This section lists features and enhancements provided in Oracle iPlanet Web Server 6.1 SP15.

A.7 Features and Enhancements in 6.1 SP14

This section lists features and enhancements provided in Oracle iPlanet Web Server 6.1 SP14.

A.7.1 JDK Updated to 1.6.0_24

In Oracle iPlanet Web Server 6.1 SP14, the JDK 6 version that is packaged with the product has been changed to JDK 6 update 24. This change has been made to address security vulnerability CVE-2010-4476 (Java Runtime Environment hangs when converting "2.2250738585072012e-308" to a binary floating-point number).

For more information about security vulnerability CVE-2010-4476, see the Oracle Security Alert at:

http://www.oracle.com/technetwork/topics/security/alert-cve-2010-4476-305811.html

A.7.2 NSS Updated to 3.12.8

Oracle iPlanet Web Server 6.1 SP14 is integrated with NSS version 3.12.8.

For information about changes in this version, see the NSS 3.12.8 release notes at:

https://developer.mozilla.org/en/NSS_3.12.8_release_notes

A.8 Features and Enhancements in 6.1 SP13

This section lists features and enhancements provided in Oracle iPlanet Web Server 6.1 SP13.

A.8.1 Updated NSS and NSPR Versions, Resolving SSL/TLS Vulnerability

Web Server 6.1 SP12 included NSS 3.12.5, which provided relief, but not resolution, for the SSL/TLS renegotiation vulnerability http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2009-3555. Additionally, Web Server 6.1 SP12 disabled all use of SSL/TLS renegotiation in order to protect Web Server from attack. If either the client or Web Server attempted to trigger renegotiation on an existing SSL/TLS session, the connection would fail.

Web Server 6.1 SP13 includes NSS 3.12.7, which provides safe SSL/TLS renegotiation and so provides resolution of CVE-2009-3555. As a result, Web Server 6.1 SP13 re-enables use of SSL/TLS renegotiation. For more information about Web Server 6.1 SP13 support for NSS and NSPR, see Section 1.5.13, "NSS and NSPR Support."

A.8.2 HTTP Response-Splitting and XSS Vulnerability Resolved

As reported in issue 6957507, an HTTP response-splitting and XSS vulnerability was discovered in previous Web Server 6.1 versions. Web Server 6.1 SP13 corrects this vulnerability.

A.8.3 Updated Version of JDK

Web Server 6.1 SP13 includes JDK 1.6.0_21.

A.8.4 Support for 2048-Bit Key Size in CSR

In response to issue 6951364, the Web Server 6.1 SP13 Admin GUI supports specifying a 2048-bit key size when generating a CSR (Certificate Signing Request) when using Security ⇒ Request a Certificate.

A.8.5 Default Cryptographic Module Set to "Internal" in CSR

In response to issue 6922063, Web Server 6.1 SP13 sets the default value of Cryptographic Module in the Admin GUI Security ⇒ Request a Certificate to "internal". Additionally, the "NSS Generic Crypto Services" option has been removed.

A.8.6 Verisign Certificate Options Removed from Admin GUI

In response to issue 6972686, the "Request Verisign Certificate" and "Install Verisign Certificate" commands have been removed from the Security tab of the Admin GUI.

A.8.7 Documentation Corrections and Updates

Section 3.1, "Corrections and Updates to 6.1 SP12 Manuals" has been updated to address the following documentation issues.

Issue ID Description

6938886

Wrong information of supportable methods should be removed in the Setting Access Rights

6940796

net_read can set EAGAIN in errno when it times out.

6966631

Statement for PathCheck is not correct.

6973013

web 6.1 doc bug - need to remove the "-" in schedulerd command line stop - "- rm $PID_FILE"

6977268

web 6.1 and 7.0 doc RFE - all request header names are returned as lowercase


A.9 Features and Enhancements in 6.1 SP12