IBM's response to a question about this which supports Rob's comment below (see the " --> ")
The newest bulletin release is sharing that Heritage Navigator for i (running on Admin2 and ports 2004 or 2005) is no longer secure because of the use of log4j 1.x.
The bulletin also shares that this log4j version cannot be updated at any release and suggestion is to manually end Admin2. Yes you can still use Heritage Navigator at your own risk but IBM's stance is to no longer use it.
The PTFs mentioned in the bulletin will be to turn off Admin2 from auto-starting by default. Heritage Navigator is not being pulled from any releases as of right now.
At 7.2 there currently is no other option for Navigator so your customer is looking at continuing use of Navigator while aware of the vulnerability or upgrade to 7.3 or 7.4 to introduce New Nav.
Very Respectfully,
Michael Mayer
IBM i on Power System Admin.
IT Operations.
The Florida Bar
651 E. Jefferson St
Tallahassee, Florida 32399-2300
mmayer@xxxxxxxxxxxxxx
https://www.floridabar.org
Office: 850.561.5761
Cell: 518.641.8906
Today's Topics:
3. RE: IBM planning to disable heritage web navigator [PRIVATE
REPLY] (Rob Berendt)
----------------------------------------------------------------------
message: 3
date: Mon, 10 Jan 2022 21:11:57 +0000
from: Rob Berendt <rob@xxxxxxxxx>
subject: RE: IBM planning to disable heritage web navigator [PRIVATE
REPLY]
Oopsie. Your private reply was not quite so private.
Basically I don't think IBM wants to spend the dollars upgrading the old Navigator when the new one is available.
And it makes some sense to me.
Sure, one may lament some feature not being in the new which was in the old, like Database. IBM has said that iACS should be used for Database instead. I can see how a one stop shopping mentality might like everything on the same web origin though.
---> So how do they address the log4j issue in 7.2 with the Navigator? Come out with a ptf which disables it and requires you to manually turn it back on? Sort of like when they changed Navigator from https to http to get around all the browsers having conniptions with self signed certificates?
Rob Berendt
--
IBM Certified System Administrator - IBM i 6.1 Group Dekko Dept 1600 Mail to: 7310 Innovation Blvd, Suite 104
Ft. Wayne, IN 46818
Ship to: 7310 Innovation Blvd, Dock 9C
Ft. Wayne, IN 46818
http://www.dekko.com
________________________________
Please note: Florida has very broad public records laws. Many written communications to or from The Florida Bar regarding Bar business may be considered public records, which must be made available to anyone upon request. Your e-mail communications may therefore be subject to public disclosure.
As an Amazon Associate we earn from qualifying purchases.