Re: Reject HTTP protocols >= 2.0 in ap_parse_request_line?

2020-06-18 Thread Ruediger Pluem
On 6/18/20 10:37 AM, Stefan Eissing wrote: > > Stefan Eissing > > bytes GmbH > Hafenweg 16 > 48155 Münster > www.greenbytes.de > >> Am 18.06.2020 um 09:48 schrieb Ruediger Pluem : >> >> >> >> On 6/18/20 12:09 AM, Roy T. Fielding wrote: On Jun 8, 2020, at 12:56 AM, Ruediger Pluem wrote:

Re: Reject HTTP protocols >= 2.0 in ap_parse_request_line?

2020-06-18 Thread Stefan Eissing
> Am 18.06.2020 um 11:49 schrieb Ruediger Pluem : > > > > On 6/18/20 10:37 AM, Stefan Eissing wrote: >> >> Stefan Eissing >> >> bytes GmbH >> Hafenweg 16 >> 48155 Münster >> www.greenbytes.de >> >>> Am 18.06.2020 um 09:48 schrieb Ruediger Pluem : >>> >>> >>> >>> On 6/18/20 12:09 AM, Roy

Re: Reject HTTP protocols >= 2.0 in ap_parse_request_line?

2020-06-18 Thread Ruediger Pluem
On 6/18/20 12:21 PM, Stefan Eissing wrote: >> Am 18.06.2020 um 11:49 schrieb Ruediger Pluem : >> >> >> >> On 6/18/20 10:37 AM, Stefan Eissing wrote: >>> >>> Stefan Eissing >>> >>> bytes GmbH >>> Hafenweg 16 >>> 48155 Münster >>> www.greenbytes.de >>> Am 18.06.2020 um 09:48 schrieb Ruediger

Re: Reject HTTP protocols >= 2.0 in ap_parse_request_line?

2020-06-18 Thread William A Rowe Jr
> On 6/18/20 12:09 AM, Roy T. Fielding wrote: > >> On Jun 8, 2020, at 12:56 AM, Ruediger Pluem > wrote: > >> > >> I came across the question if we should not reject HTTP protocols > >= 2.0 in the request line when we parse it > >> in ap_parse_request_line. > >> This does

Re: Reject HTTP protocols >= 2.0 in ap_parse_request_line?

2020-06-18 Thread Stefan Eissing
Stefan Eissing bytes GmbH Hafenweg 16 48155 Münster www.greenbytes.de > Am 18.06.2020 um 16:51 schrieb William A Rowe Jr : > > > On 6/18/20 12:09 AM, Roy T. Fielding wrote: > >> On Jun 8, 2020, at 12:56 AM, Ruediger Pluem wrote: > >> > >> I came across the question if we

Re: hardening mod_write and mod_proxy like mod_jk with servletnormalize

2020-06-18 Thread jean-frederic clere
On 17/06/2020 13:26, Yann Ylavic wrote: On Sat, Jun 13, 2020 at 11:18 AM jean-frederic clere wrote: On 11/06/2020 13:50, Yann Ylavic wrote: On Thu, Jun 11, 2020 at 1:22 PM Yann Ylavic wrote: On Thu, Jun 11, 2020 at 9:57 AM Yann Ylavic wrote: On Thu, Jun 11, 2020 at 9:50 AM Yann Ylavic

Re: Reject HTTP protocols >= 2.0 in ap_parse_request_line?

2020-06-18 Thread Roy T. Fielding
> On Jun 18, 2020, at 9:03 AM, Stefan Eissing > wrote: >> Am 18.06.2020 um 16:51 schrieb William A Rowe Jr : >> >> >> On 6/18/20 12:09 AM, Roy T. Fielding wrote: On Jun 8, 2020, at 12:56 AM, Ruediger Pluem wrote: I came across the question if we should not

Re: Reject HTTP protocols >= 2.0 in ap_parse_request_line?

2020-06-18 Thread Ruediger Pluem
On 6/18/20 8:55 PM, Roy T. Fielding wrote: >> On Jun 18, 2020, at 9:03 AM, Stefan Eissing > > wrote: >>> Am 18.06.2020 um 16:51 schrieb William A Rowe Jr >> >: >>> >>> >>> On 6/18/20 12:09 AM, Roy T. Fielding wrote: >

Re: Reject HTTP protocols >= 2.0 in ap_parse_request_line?

2020-06-18 Thread Ruediger Pluem
On 6/18/20 12:09 AM, Roy T. Fielding wrote: >> On Jun 8, 2020, at 12:56 AM, Ruediger Pluem wrote: >> >> I came across the question if we should not reject HTTP protocols >= 2.0 in >> the request line when we parse it >> in ap_parse_request_line. >> This does not affect mod_http2 if loaded as

Re: Broken: apache/httpd#804 (trunk - 97bc128)

2020-06-18 Thread Stefan Eissing
> Am 17.06.2020 um 21:19 schrieb Ruediger Pluem : > > > > On 6/17/20 3:11 PM, Ruediger Pluem wrote: >> >> >> On 6/17/20 11:52 AM, Yann Ylavic wrote: >>> On Wed, Jun 17, 2020 at 10:43 AM Joe Orton wrote: > And yes this makes me think if this kind of fake really makes sense. The

Re: Reject HTTP protocols >= 2.0 in ap_parse_request_line?

2020-06-18 Thread Stefan Eissing
Stefan Eissing bytes GmbH Hafenweg 16 48155 Münster www.greenbytes.de > Am 18.06.2020 um 09:48 schrieb Ruediger Pluem : > > > > On 6/18/20 12:09 AM, Roy T. Fielding wrote: >>> On Jun 8, 2020, at 12:56 AM, Ruediger Pluem wrote: >>> >>> I came across the question if we should not reject