Versions Compared

Key

  • This line was added.
  • This line was removed.
  • Formatting was changed.

...

Info

MAINTENANCE NOTIFICATION

22-12-21; OpenStack upgrades finished, Log4J vulnerability patched

We have completed our OpenStack upgrades. We are now running on the latest version of OpenStack and can confirm that our systems are running smoothly.

Log4J update
In the past weeks a new priority has been added to our attention list; the Log4J vulnerabilities.

You might have been reading about this vulnerability in the press or on security blogs like the one from Google; Understanding the Impact of Apache Log4j Vulnerability  

Onetrail uses this software in various places and has extensively reviewed and researched this issue.

IN SHORT: Details about upcoming maintenance window:

  • The maintenance window of Monday the 28th will be extended until 23:00 hours. 

Dear customer, 

We are updating the TPN platform on a regular base with the recommended software patches.
Based on the time we spent on the acceptance environment we calculate a longer downtime for patching the production environment. This will take place:

Monday the 28th of March from 19:30 – 23:00 CET.

During this update, we will shut down the entire platform including the high available servicesAs a solution we updated all the relevant projects to the latest Log4J version 2.17. In addition, we have implemented a proxy rule to scan and if required block incoming traffic from the Internet.