Re: httpd and letsencrypt

2016-08-29 Thread Leif Hedstrom
> On Aug 29, 2016, at 5:17 PM, William A Rowe Jr wrote: > > On Mon, Aug 29, 2016 at 2:52 PM, Jim Jagielski > wrote: > Also, and this is personal, I don't tend to "trust" entities > with non-public membership: > >

Re: httpd and letsencrypt

2016-08-29 Thread William A Rowe Jr
On Mon, Aug 29, 2016 at 2:52 PM, Jim Jagielski wrote: > Also, and this is personal, I don't tend to "trust" entities > with non-public membership: > > https://github.com/orgs/letsencrypt/people > > FWIW, looking through letskencrypt git commits, it seems to consist of only

Re: httpd and letsencrypt

2016-08-29 Thread William A Rowe Jr
On Aug 29, 2016 14:50, "Jim Jagielski" wrote: > > Key, of course (no pun intended) is a client impl with a suitable > and acceptable license. > > There is https://kristaps.bsd.lv/letskencrypt/, but last I looked > it required, iirc, LibreSSL as well as it still being somewhat >

Re: httpd and letsencrypt

2016-08-29 Thread Jim Jagielski
Also, and this is personal, I don't tend to "trust" entities with non-public membership: https://github.com/orgs/letsencrypt/people > On Aug 29, 2016, at 3:49 PM, Jim Jagielski wrote: > > Key, of course (no pun intended) is a client impl with a suitable > and acceptable

Re: httpd and letsencrypt

2016-08-29 Thread Jim Jagielski
Key, of course (no pun intended) is a client impl with a suitable and acceptable license. There is https://kristaps.bsd.lv/letskencrypt/, but last I looked it required, iirc, LibreSSL as well as it still being somewhat instable. I am hoping we can get pointers to alternatives :) > On Aug 29,

Re: Backporting HttpProtocolOptions survey

2016-08-29 Thread Ruediger Pluem
On 08/29/2016 06:25 PM, William A Rowe Jr wrote: > Thanks all for the feedback. Status and follow-up questions inline > > On Thu, Aug 25, 2016 at 10:02 PM, William A Rowe Jr > wrote: > > A couple key questions now that the full

Re: Backporting HttpProtocolOptions survey

2016-08-29 Thread William A Rowe Jr
Thanks all for the feedback. Status and follow-up questions inline On Thu, Aug 25, 2016 at 10:02 PM, William A Rowe Jr wrote: > A couple key questions now that the full refactoring of legacy vs. strict > is mostly complete (there remain potential issues with some of the 3-4

Re: Unbounded memory usage in mod_dav + mod_headers/mod_deflate/...

2016-08-29 Thread Evgeny Kotkov
Evgeny Kotkov writes: > It might be possible to rework mod_dav_svn, although it's going to take > some time. Currently, every top-level handler receives an `ap_filter_t *` > and passes it further, and all these places would have to be updated so > that the actual

Re: httpd and letsencrypt

2016-08-29 Thread William A Rowe Jr
Hi Rich, some thoughts inline... On Aug 29, 2016 10:09, "Josh Aas" wrote: > > Thanks for the intro Rich. > > I think it's important that we make HTTPS as easy as possible with > Apache httpd. I don't have a particular architecture in mind, my not > being an Apache dev, but

Re: httpd and letsencrypt

2016-08-29 Thread Josh Aas
Thanks for the intro Rich. I think it's important that we make HTTPS as easy as possible with Apache httpd. I don't have a particular architecture in mind, my not being an Apache dev, but I do have a user experience in mind -- the simplest config option possible, without having to fetch/install

Re: Backporting HttpProtocolOptions survey

2016-08-29 Thread Jim Jagielski
+1 > On Aug 26, 2016, at 7:10 AM, Ruediger Pluem wrote: > > > Debug > > We should ban it unequivocally. > > Only a single toggle. > > Default should be strict. >

Re: mod_http2 - h2_session(): connections get's closed on graceful restart

2016-08-29 Thread Stefan Priebe - Profihost AG
Am 29.08.2016 um 15:52 schrieb Stefan Eissing: > >> Am 29.08.2016 um 15:43 schrieb Stefan Priebe - Profihost AG >> : >> >> Am 29.08.2016 um 15:31 schrieb Stefan Eissing: >>> Am 26.08.2016 um 20:02 schrieb Stefan Priebe - Profihost AG :

Re: mod_http2 - h2_session(): connections get's closed on graceful restart

2016-08-29 Thread Stefan Eissing
> Am 29.08.2016 um 15:43 schrieb Stefan Priebe - Profihost AG > : > > Am 29.08.2016 um 15:31 schrieb Stefan Eissing: >> >>> Am 26.08.2016 um 20:02 schrieb Stefan Priebe - Profihost AG >>> : >>> >>> [Fri Aug 26 19:54:05.321979 2016] [http2:debug]

Re: mod_http2 - h2_session(): connections get's closed on graceful restart

2016-08-29 Thread Stefan Priebe - Profihost AG
Am 29.08.2016 um 15:31 schrieb Stefan Eissing: > >> Am 26.08.2016 um 20:02 schrieb Stefan Priebe - Profihost AG >> : >> >> [Fri Aug 26 19:54:05.321979 2016] [http2:debug] [pid 13222:tid >> 139700320794368] h2_stream.c(205): [client 1.2.3.4:38822] AH03082: >>

Re: mod_http2 - h2_session(): connections get's closed on graceful restart

2016-08-29 Thread Stefan Eissing
> Am 26.08.2016 um 20:02 schrieb Stefan Priebe - Profihost AG > : > > [Fri Aug 26 19:54:05.321979 2016] [http2:debug] [pid 13222:tid > 139700320794368] h2_stream.c(205): [client 1.2.3.4:38822] AH03082: > h2_stream(212-45): opened > [Fri Aug 26 19:54:05.322017 2016]