Re: Bug 35083 - SSL error trapping

2007-01-10 Thread Marc Stern - Approach
Hi Joe 1. The current idea is to trap validation-related errors, like certificate expiration/revocation. Shouldn't we also trap negotiation errors, like incompatible ciphersuites and protocols between browser and server ? Maybe other ones ? I would not try to solve everything at once;

FW: unsubscribe

2007-01-10 Thread Zhao, Jing
Learn more about Chase Paymentech Solutions,LLC payment processing services at www.chasepaymentech.com. THIS MESSAGE IS CONFIDENTIAL. This e-mail message and any attachments are proprietary and confidential information intended only for the use of the recipient(s) named above. If you

Re: mod_authn_dbd and apr_password_validate

2007-01-10 Thread Patrick Welche
On Mon, Jan 08, 2007 at 09:10:52PM +, Nick Kew wrote: On Mon, 8 Jan 2007 16:08:51 + Patrick Welche [EMAIL PROTECTED] wrote: so what sort of password does apr_password_validate accept? Those created with htpasswd is a simple answer. Would the following patch be acceptable? (So

mod_mbox patches

2007-01-10 Thread Bernard Buri
Hi! Here are some patches for mod_mbox to correcly display binary mime-parts. Please review; --- module-2.0/mod_mbox.h.orig Tue Jan 9 15:06:24 2007 +++ module-2.0/mod_mbox.h Tue Jan 9 15:06:01 2007 @@ -130,6 +130,7 @@ mbox_mime_message_t *mbox_mime_decode_multipart(apr_pool_t *p, char

[Announce] Apache HTTP Server 2.2.4 Released

2007-01-10 Thread William A. Rowe, Jr.
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 Apache HTTP Server 2.2.4 Released The Apache Software Foundation and the Apache HTTP Server Project are pleased to announce the release of version 2.2.4 of the Apache HTTP Server (Apache). This version of Apache is principally a

Re: [VOTE] httpd-2.2.4 release candidate for review

2007-01-10 Thread William A. Rowe, Jr.
William A. Rowe, Jr. wrote: http://httpd.apache.org/dev/dist/ will soon (within the hour, upon resync) contain the following tarballs for approval httpd-2.2.4.tar.bz2 [.asc|.md5] httpd-2.2.4.tar.gz [.asc|.md5] httpd-2.2.4-win32-src.zip [.asc|.md5] I counted 7+1, 0-1. Thanks everyone.

2.2.4 windows binary w/ssl?

2007-01-10 Thread William A. Rowe, Jr.
I'd like to propose we ship apache_2.2.4-win32-x86-openssl-0.9.8d.msi with this release. Couple of notes... Roy has started the details spelled out at http://www.apache.org/dev/crypto.html and I'm certain he will complete them sometime shortly, here. That's a red flag that prevents us from

Re: 2.2.4 windows binary w/ssl?

2007-01-10 Thread Justin Erenkrantz
On 1/10/07, William A. Rowe, Jr. [EMAIL PROTECTED] wrote: A final question for all, do we wish to install an arbitrary, on the fly self signed default.crt/default.key? Do we want to help them fill out the details or use stock details? Or do we want them to use openssl.exe to generate one for

Re: 2.2.4 windows binary w/ssl?

2007-01-10 Thread Issac Goldstand
I think the MSI should autogenerate a self-signed cert at least (last thing we need is for people to deploy a static pre-distributed cert which would make it that much easier to do man-in-the-middle attacks). Would be great if the MSI had a choice to use an existing cert, or generate a new one

Re: 2.2.4 windows binary w/ssl?

2007-01-10 Thread Jorge Schrauwen
Do note that not all users that will chose the SSL package will know how to correctly fill in the fields. My experience tells me if there is a package with XYZ and without most chose it with XYZ even if they don't need it. So if there is a dialog in the installer that would ask for the

Re: 2.2.4 windows binary w/ssl?

2007-01-10 Thread William A. Rowe, Jr.
Jorge Schrauwen wrote: Do note that not all users that will chose the SSL package will know how to correctly fill in the fields. s/not all/a small minority of/ They can't figure out what Domain Name means, let's be serious :) On 1/10/07, *Issac Goldstand* [EMAIL PROTECTED] mailto:[EMAIL

Re: 2.2.4 windows binary w/ssl?

2007-01-10 Thread Jorge Schrauwen
On 1/10/07, William A. Rowe, Jr. [EMAIL PROTECTED] wrote: Jorge Schrauwen wrote: Do note that not all users that will chose the SSL package will know how to correctly fill in the fields. s/not all/a small minority of/ Do not underestimate user stupidity ;) ok maybe the number won't be

Re: 2.2.4 windows binary w/ssl?

2007-01-10 Thread Ruediger Pluem
On 01/10/2007 10:40 PM, William A. Rowe, Jr. wrote: Does this sound sane? +1 Regards RĂ¼diger

ap_get_module_config() questions...

2007-01-10 Thread Drew Bertola
Hi everyone, I have a couple quick questions regarding ap_get_module_config(). First, how do I return valuable information if there's a config error? For example, if my config has the directive MyFile conf/foo.txt and the file doesn't exist, how can I report this when I run httpd -t?

[STATUS] (httpd-2.0) Wed Jan 10 23:49:37 2007

2007-01-10 Thread Rodent of Unusual Size
APACHE 2.0 STATUS: -*-text-*- Last modified at [$Date: 2007-01-05 22:48:09 -0500 (Fri, 05 Jan 2007) $] The current version of this file can be found at: * http://svn.apache.org/repos/asf/httpd/httpd/branches/2.0.x/STATUS Documentation status is

[STATUS] (httpd-trunk) Wed Jan 10 23:49:08 2007

2007-01-10 Thread Rodent of Unusual Size
APACHE 2.3 STATUS: -*-text-*- Last modified at [$Date: 2006-08-22 16:41:03 -0400 (Tue, 22 Aug 2006) $] The current version of this file can be found at: * http://svn.apache.org/repos/asf/httpd/httpd/trunk/STATUS Documentation status is maintained