<?xml version="1.0" encoding="UTF-8" ?>
<?xml-stylesheet type="text/xsl" href="http://blogs.msdn.com/utility/FeedStylesheets/rss.xsl" media="screen"?><rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:slash="http://purl.org/rss/1.0/modules/slash/" xmlns:wfw="http://wellformedweb.org/CommentAPI/"><channel><title>Important Team System Web Access update (updated)</title><link>http://blogs.msdn.com/bharry/archive/2009/02/02/important-team-system-web-access-update.aspx</link><description>Within the last couple of weeks, we released an important update to the Team System Web Access 2008 SP1 Power Tool. The update includes only one change and it fixes a significant security issue that we discovered. I'm not going to describe it in detail,</description><dc:language>en-US</dc:language><generator>CommunityServer 2.1 SP1 (Build: 61025.2)</generator><item><title>re: Important Team System Web Access update</title><link>http://blogs.msdn.com/bharry/archive/2009/02/02/important-team-system-web-access-update.aspx#9391377</link><pubDate>Mon, 02 Feb 2009 23:17:56 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:9391377</guid><dc:creator>Per</dc:creator><description>&lt;p&gt;Can't you provide a hotfix package instead or just zip the affected DLL. Uninstalling Web Access in production is too much work for a security update, what happens if you find another one next month.&lt;/p&gt;
</description></item><item><title>re: Important Team System Web Access update</title><link>http://blogs.msdn.com/bharry/archive/2009/02/02/important-team-system-web-access-update.aspx#9391785</link><pubDate>Tue, 03 Feb 2009 01:35:21 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:9391785</guid><dc:creator>B</dc:creator><description>&lt;p&gt;Can you refresh me on how we install this MSI can you install it right over the existing or do you have to remove the old first?&lt;/p&gt;
</description></item><item><title>re: Important Team System Web Access update</title><link>http://blogs.msdn.com/bharry/archive/2009/02/02/important-team-system-web-access-update.aspx#9392838</link><pubDate>Tue, 03 Feb 2009 10:45:47 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:9392838</guid><dc:creator>Oskar</dc:creator><description>&lt;p&gt;Hi, I am also interested in whether this update can be applied in production. Any stories to share on this? &lt;/p&gt;
</description></item><item><title>re: Important Team System Web Access update</title><link>http://blogs.msdn.com/bharry/archive/2009/02/02/important-team-system-web-access-update.aspx#9392865</link><pubDate>Tue, 03 Feb 2009 11:17:45 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:9392865</guid><dc:creator>b..</dc:creator><description>&lt;p&gt;Hi, we would also be helped a great deal with a hotfix ! More than 50 people are using it in production here + Management was just convinced to work with TFS and we wouldn't like to ask them already to take the system offline again .. Thank you&lt;/p&gt;
</description></item><item><title>re: Important Team System Web Access update</title><link>http://blogs.msdn.com/bharry/archive/2009/02/02/important-team-system-web-access-update.aspx#9393102</link><pubDate>Tue, 03 Feb 2009 15:25:03 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:9393102</guid><dc:creator>bharry</dc:creator><description>&lt;p&gt;I understand that uninstalling and installing is onerous. &amp;nbsp;It is, unfortunately one of our limitations for Power Tools. &amp;nbsp;The cost to setup up hotfix servicing for Power Tools is prohibitive. &amp;nbsp;However, Web Access is being incorporated into the shipping product for TFS 2010 and then is will become part of our normal hotfix capability. &amp;nbsp;This is the first time in the 2 years of delivering TSWA as a Power Tool that we had to deliver a security patch this way. &amp;nbsp;While I can't predict the future, I'm hopeful we won't have to do it again.&lt;/p&gt;
&lt;p&gt;I will look into the idea of providing a procedure to just replace the affected dll(s). &amp;nbsp;That may be practical.&lt;/p&gt;
&lt;p&gt;Thank you,&lt;/p&gt;
&lt;p&gt;Brian&lt;/p&gt;
</description></item><item><title>re: Important Team System Web Access update</title><link>http://blogs.msdn.com/bharry/archive/2009/02/02/important-team-system-web-access-update.aspx#9395592</link><pubDate>Wed, 04 Feb 2009 15:48:08 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:9395592</guid><dc:creator>b..</dc:creator><description>&lt;p&gt;Ok, thank you,&lt;/p&gt;
&lt;p&gt;we would appreciate that !&lt;/p&gt;
</description></item><item><title>re: Important Team System Web Access update (updated)</title><link>http://blogs.msdn.com/bharry/archive/2009/02/02/important-team-system-web-access-update.aspx#9395659</link><pubDate>Wed, 04 Feb 2009 16:28:58 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:9395659</guid><dc:creator>bharry</dc:creator><description>&lt;p&gt;OK, I have updated the post with instructions on how to perform the update manually. &amp;nbsp;Hopefully this will help some of you manage the update more easily.&lt;/p&gt;
&lt;p&gt;Thank you for the feedback,&lt;/p&gt;
&lt;p&gt;Brian&lt;/p&gt;
</description></item><item><title>Security Update for TSWA 2008 SP1</title><link>http://blogs.msdn.com/bharry/archive/2009/02/02/important-team-system-web-access-update.aspx#9395950</link><pubDate>Wed, 04 Feb 2009 18:33:21 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:9395950</guid><dc:creator>Visual Studio Team System (VSTS) Blog - by Neno Loje</dc:creator><description>&lt;p&gt;From Hakan Eskici&amp;amp;#39;s blog : A security issue has been identified with Team System Web Access 2008&lt;/p&gt;
</description></item><item><title>Security Update for TSWA 2008 SP1</title><link>http://blogs.msdn.com/bharry/archive/2009/02/02/important-team-system-web-access-update.aspx#9396266</link><pubDate>Wed, 04 Feb 2009 21:08:15 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:9396266</guid><dc:creator>Hakan Eskici</dc:creator><description>&lt;p&gt;A security issue has been identified with Team System Web Access 2008 SP1 and we have recently published&lt;/p&gt;
</description></item><item><title>re: Important Team System Web Access update (updated)</title><link>http://blogs.msdn.com/bharry/archive/2009/02/02/important-team-system-web-access-update.aspx#9396528</link><pubDate>Wed, 04 Feb 2009 22:54:13 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:9396528</guid><dc:creator>mskenny</dc:creator><description>&lt;p&gt;Hmmm...your command line didn't work. &amp;nbsp;It installed the files on my C: drive. &amp;nbsp;It looks like I'll have to uninstall/reinstall anyway.&lt;/p&gt;
&lt;p&gt;This is what I entered:&lt;/p&gt;
&lt;p&gt;msiexec /a TeamSystemWebAccess.msi /qb /TARGETDIR=d:\temp\tfswa&lt;/p&gt;
</description></item><item><title>re: Important Team System Web Access update (updated)</title><link>http://blogs.msdn.com/bharry/archive/2009/02/02/important-team-system-web-access-update.aspx#9396608</link><pubDate>Wed, 04 Feb 2009 23:32:03 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:9396608</guid><dc:creator>B</dc:creator><description>&lt;p&gt;The / in front of TargetDir is not needed.&lt;/p&gt;
</description></item><item><title>re: Important Team System Web Access update (updated)</title><link>http://blogs.msdn.com/bharry/archive/2009/02/02/important-team-system-web-access-update.aspx#9397811</link><pubDate>Thu, 05 Feb 2009 11:02:11 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:9397811</guid><dc:creator>prulifson</dc:creator><description>&lt;p&gt;I had the update installed and the downtime was only a few minutes. &lt;/p&gt;
&lt;p&gt;I understand the update requests, but it went so smoothly that it was not problem for us.&lt;/p&gt;
&lt;p&gt;It was simple, it worked and I'm done. cool.&lt;/p&gt;
</description></item><item><title>re: Important Team System Web Access update (updated)</title><link>http://blogs.msdn.com/bharry/archive/2009/02/02/important-team-system-web-access-update.aspx#9398444</link><pubDate>Thu, 05 Feb 2009 16:25:59 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:9398444</guid><dc:creator>bharry</dc:creator><description>&lt;p&gt;That's very good to hear, thank you.&lt;/p&gt;
&lt;p&gt;Brian&lt;/p&gt;
</description></item><item><title>re: Important Team System Web Access update (updated)</title><link>http://blogs.msdn.com/bharry/archive/2009/02/02/important-team-system-web-access-update.aspx#9404041</link><pubDate>Sat, 07 Feb 2009 11:29:12 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:9404041</guid><dc:creator>Per</dc:creator><description>&lt;p&gt;Thank you Brian for providing a manual way of patching! The TFS team has always been extremely responsive when it comes to customer feedback, I really appreciate your work.&lt;/p&gt;
</description></item><item><title>re: Important Team System Web Access update (updated)</title><link>http://blogs.msdn.com/bharry/archive/2009/02/02/important-team-system-web-access-update.aspx#9404953</link><pubDate>Sat, 07 Feb 2009 19:40:36 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:9404953</guid><dc:creator>bharry</dc:creator><description>&lt;p&gt;Happy to help :)&lt;/p&gt;
&lt;p&gt;Brian&lt;/p&gt;
</description></item><item><title>VSTS Links - 02/10/2009</title><link>http://blogs.msdn.com/bharry/archive/2009/02/02/important-team-system-web-access-update.aspx#9410517</link><pubDate>Tue, 10 Feb 2009 16:19:19 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:9410517</guid><dc:creator>Team System News</dc:creator><description>&lt;p&gt;New Site: Team System Live! Brian Harry on Important Team System Web Access update Willy-Peter Schaub&lt;/p&gt;
</description></item><item><title>manual deployment concerns</title><link>http://blogs.msdn.com/bharry/archive/2009/02/02/important-team-system-web-access-update.aspx#9411427</link><pubDate>Wed, 11 Feb 2009 01:10:27 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:9411427</guid><dc:creator>steve baker</dc:creator><description>&lt;p&gt;Brian,&lt;/p&gt;
&lt;p&gt;a diff of the original site vs an extracted copy of the patched one reveals that although the code changes made to resolve the vulnerability are small and isolated to the three dll's mentioned there are other significant changes that would deploy with an uninstall-reinstall.&lt;/p&gt;
&lt;p&gt;it appears that changes were made in web.config to integrate newer ajax functionality and ReportViewer. EditWorkItem.js has also been modified with what appears to be a significant change. the .docx mimetype mapping has been removed from MimeMap.xml.&lt;/p&gt;
&lt;p&gt;should any of these additional changes be deployed?&lt;/p&gt;
&lt;p&gt;TIA&lt;/p&gt;
</description></item><item><title>manual deployment concerns (update)</title><link>http://blogs.msdn.com/bharry/archive/2009/02/02/important-team-system-web-access-update.aspx#9411554</link><pubDate>Wed, 11 Feb 2009 02:26:05 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:9411554</guid><dc:creator>steve baker</dc:creator><description>&lt;p&gt;i just upgraded our tswa manually and tested to make sure the vulnerability was fixed. it was. &lt;/p&gt;
&lt;p&gt;however the EditWorkItem.js changes DID need to be copied over as well or a newly uploaded work item attachment (before you click the &amp;quot;Save&amp;quot; option for the work item) would not open, but would instead result in the following error:&lt;/p&gt;
&lt;p&gt;&amp;quot;Invalid URI: The format of the URI could not be determined.&amp;quot;&lt;/p&gt;
&lt;p&gt;the javascript updates were made to resolve that issue.&lt;/p&gt;
</description></item><item><title>manual deployment concerns (update)</title><link>http://blogs.msdn.com/bharry/archive/2009/02/02/important-team-system-web-access-update.aspx#9411651</link><pubDate>Wed, 11 Feb 2009 03:24:31 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:9411651</guid><dc:creator>steve baker</dc:creator><description>&lt;p&gt;after testing the Web application and making sure everything worked OK i then tested the Wiwa side of things and found that the same manual deployment has broken the site. &lt;/p&gt;
&lt;p&gt;Trying to download an attachment from a work item through wiwa now errors with &amp;quot;You are not authorized to access this page. Please contact your project administrator&amp;quot;&lt;/p&gt;
&lt;p&gt;The url requested for the attachment is the same with or without the patch. i can only guess, but would it have something to do with our configuration and the new impersonation code in DownloadAttachment::GetFile:&lt;/p&gt;
&lt;p&gt;Using WindowsIdentity.Impersonate(CommonUtility.ObtainProcessToken)&lt;/p&gt;
&lt;p&gt;tswa is installed on an application tier &amp;quot;mostly&amp;quot; configured to use FQDN's. we found we had to enable delegation in order for the site to authenticate correctly even though it is on the app tier.&lt;/p&gt;
&lt;p&gt;TIA&lt;/p&gt;
</description></item><item><title>re: Important Team System Web Access update (updated)</title><link>http://blogs.msdn.com/bharry/archive/2009/02/02/important-team-system-web-access-update.aspx#9413295</link><pubDate>Wed, 11 Feb 2009 22:55:03 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:9413295</guid><dc:creator>bharry</dc:creator><description>&lt;p&gt;Checking on it, thank you.&lt;/p&gt;
&lt;p&gt;Brian&lt;/p&gt;
</description></item><item><title>re: Important Team System Web Access update (updated)</title><link>http://blogs.msdn.com/bharry/archive/2009/02/02/important-team-system-web-access-update.aspx#9419715</link><pubDate>Fri, 13 Feb 2009 22:19:40 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:9419715</guid><dc:creator>Hakan Eskici</dc:creator><description>&lt;p&gt;Steve, &lt;/p&gt;
&lt;p&gt;RE: WIWA cannot download attachments&lt;/p&gt;
&lt;p&gt;We've looked into this and it's a bug in the current release, however there's a quick workarorund you can apply. See my blog post for details:&lt;/p&gt;
&lt;p&gt;&lt;a rel="nofollow" target="_new" href="http://blogs.msdn.com/hakane/archive/2009/02/13/fix-wiwa-cannot-download-attachments.aspx"&gt;http://blogs.msdn.com/hakane/archive/2009/02/13/fix-wiwa-cannot-download-attachments.aspx&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;Thanks,&lt;/p&gt;
&lt;p&gt;-Hakan&lt;/p&gt;
</description></item><item><title>re: Important Team System Web Access update (updated)</title><link>http://blogs.msdn.com/bharry/archive/2009/02/02/important-team-system-web-access-update.aspx#9484997</link><pubDate>Wed, 18 Mar 2009 01:26:55 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:9484997</guid><dc:creator>oberdan</dc:creator><description>&lt;p&gt;Hi Brian, after I installed the SP1 version of TSWA, I'm not able to access the document tab anymore.. &lt;/p&gt;
&lt;p&gt;I'm getting the following error message:&lt;/p&gt;
&lt;p&gt;&amp;quot;The permissions granted to user &amp;lt;user name&amp;gt; are insufficient to perform this operation.&lt;/p&gt;
&lt;p&gt;Have you seen this before?&lt;/p&gt;
&lt;p&gt;Best regards&lt;/p&gt;
&lt;p&gt;Oberdan&lt;/p&gt;
</description></item><item><title>re: Important Team System Web Access update (updated)</title><link>http://blogs.msdn.com/bharry/archive/2009/02/02/important-team-system-web-access-update.aspx#9508690</link><pubDate>Thu, 26 Mar 2009 01:16:24 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:9508690</guid><dc:creator>Greg</dc:creator><description>&lt;p&gt;Does TFSWA SP1 require VSTS/TFS 2008 SP1 to be installed?&lt;/p&gt;
</description></item><item><title>re: Important Team System Web Access update (updated)</title><link>http://blogs.msdn.com/bharry/archive/2009/02/02/important-team-system-web-access-update.aspx#9509048</link><pubDate>Thu, 26 Mar 2009 03:35:27 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:9509048</guid><dc:creator>buckh</dc:creator><description>&lt;p&gt;No, it works with 2005, and it works without SP1 for 2008 installed. &amp;nbsp;However, you must install Team Explorer 2008 in order to install TSWA 2008 or TSWA 2008 SP1.&lt;/p&gt;
&lt;p&gt;Buck&lt;/p&gt;
</description></item></channel></rss>