Re: DH params and multiple certificates in one VHost

2014-04-21 Thread Kaspar Brand
On 19.04.2014 09:37, Falco Schwarz wrote: I successfully tested your attached patch with the latest 1.0.2 branch. The DH temp key now has the bit length of the used RSA key, regardless of SSLCertificate[Key]File order. Thanks for testing. Committed to trunk with r1588851 and proposed for

Re: SSL_CTX_get_{first,next}_certificate

2014-04-21 Thread Kaspar Brand
On 05.02.2014 14:05, Kaspar Brand wrote: On 03.02.2014 12:21, Dr Stephen Henson wrote: On 02/02/2014 13:45, Kaspar Brand wrote: Yes, this sounds like a useful extension - not only for the issue at hand (i.e. SSL_CONF and stapling initialisation), but as a general mechanism for retrieving all

Re: svn commit: r1587607 - in /httpd/httpd/trunk: ./ include/ modules/ssl/

2014-04-21 Thread Kaspar Brand
On 15.04.2014 17:25, traw...@apache.org wrote: Author: trawick Date: Tue Apr 15 15:25:03 2014 New Revision: 1587607 URL: http://svn.apache.org/r1587607 Log: mod_ssl: Add hooks to allow other modules to perform processing at several stages of initialization and connection handling. See

Re: svn commit: r1587607 - in /httpd/httpd/trunk: ./ include/ modules/ssl/

2014-04-21 Thread Jeff Trawick
On Mon, Apr 21, 2014 at 4:01 AM, Kaspar Brand httpd-dev.2...@velox.chwrote: On 15.04.2014 17:25, traw...@apache.org wrote: Author: trawick Date: Tue Apr 15 15:25:03 2014 New Revision: 1587607 URL: http://svn.apache.org/r1587607 Log: mod_ssl: Add hooks to allow other modules to

Re: mod_cache thundering herd bug

2014-04-21 Thread Graham Leggett
On 19 Apr 2014, at 10:26 PM, Eric Covener cove...@gmail.com wrote: Graham -- related subject brought up either in Denver or in the bug. It seems that when we serve a stale file while the cache is locked, the age headers are small instead of large. I got totally lost trying to track down the

SSLUserName - mod_auth_user

2014-04-21 Thread Graham Leggett
Hi all, Right now, we have the SSLUserName directive, which takes an arbitrary SSL variable and turns it into a username for the benefit of the request. This has the downside that only SSL variables (and some CGI variables) are usable as usernames, and it combines with FakeBasicAuth to create

Re: SSLUserName - mod_auth_user

2014-04-21 Thread Eric Covener
On Mon, Apr 21, 2014 at 7:38 AM, Graham Leggett minf...@sharp.fm wrote: Hi all, Right now, we have the SSLUserName directive, which takes an arbitrary SSL variable and turns it into a username for the benefit of the request. This has the downside that only SSL variables (and some CGI

Re: SSLUserName - mod_auth_user

2014-04-21 Thread Tim Bannister
On 21 Apr 2014, at 12:38, Graham Leggett minf...@sharp.fm wrote: Hi all, Right now, we have the SSLUserName directive, which takes an arbitrary SSL variable and turns it into a username for the benefit of the request. This has the downside that only SSL variables (and some CGI variables)

Re: mod_cache thundering herd bug

2014-04-21 Thread Jim Riggs
On 21 Apr 2014, at 06:38, Graham Leggett minf...@sharp.fm wrote: On 19 Apr 2014, at 10:26 PM, Eric Covener cove...@gmail.com wrote: Graham -- related subject brought up either in Denver or in the bug. It seems that when we serve a stale file while the cache is locked, the age headers are

Re: mod_cache thundering herd bug

2014-04-21 Thread Eric Covener
Covener - Are you talking about my comments in #16 on the ticket? (https://issues.apache.org/bugzilla/show_bug.cgi?id=50317#c16) If so, do either you or Graham have thoughts on the Age header getting returned with stale content? In my testing, when stale content is getting returned, no

Re: Problem of URL in bugzilla

2014-04-21 Thread Rainer Jung
On 21.04.2014 23:15, Mark Thomas wrote: On 20/04/2014 20:11, Mark Thomas wrote: On 20/04/2014 18:51, Rainer Jung wrote: CCing Mark our Bugzilla (and much more) champion, hoping he knows more or at least needs the info. @Mark: I think the transform svn revision to link feature is a Bugzilla