Bug#492130: apache2.2-common: HTTP Trace enabled in default configuration

2008-07-24 Thread Thom May
no, since that would imply having mod_rewrite enabled out of the box.
http://www.apacheweek.com/issues/03-01-24#news



-- 
To UNSUBSCRIBE, email to [EMAIL PROTECTED]
with a subject of unsubscribe. Trouble? Contact [EMAIL PROTECTED]



Bug#492130: apache2.2-common: HTTP Trace enabled in default configuration

2008-07-24 Thread Dario Griffo

Thom May wrote:

no, since that would imply having mod_rewrite enabled out of the box.
http://www.apacheweek.com/issues/03-01-24#news



What if using TraceEnable directive?
http://httpd.apache.org/docs/2.0/mod/core.html#traceenable
I'm testing it in my server wich i've installed few days ago, just to 
try some stuff, didn't enabled anithing else, but this directive and 
TRACE request are disallowed.




--
To UNSUBSCRIBE, email to [EMAIL PROTECTED]
with a subject of unsubscribe. Trouble? Contact [EMAIL PROTECTED]



Bug#492130: apache2.2-common: HTTP Trace enabled in default configuration

2008-07-23 Thread Dario Griffo
Package: apache2.2-common
Version: 2.2.9-5
Severity: minor

default site available doesn't disable HTTP Trace method. Should it?

-- Package-specific info:
List of enabled modules from 'apache2 -M':
  alias auth_basic authn_file authz_default authz_groupfile
  authz_host authz_user autoindex cgi dir env jk mime negotiation
  php5 setenvif status

-- System Information:
Debian Release: lenny/sid
  APT prefers testing
  APT policy: (500, 'testing')
Architecture: i386 (i686)

Kernel: Linux 2.6.25-2-686 (SMP w/2 CPU cores)
Locale: LANG=en_US.UTF-8, LC_CTYPE=en_US.UTF-8 (charmap=UTF-8)
Shell: /bin/sh linked to /bin/bash

Versions of packages apache2.2-common depends on:
ii  apache2-utils  2.2.9-5   utility programs for webservers
ii  libapr11.2.12-4  The Apache Portable Runtime Librar
ii  libaprutil11.2.12+dfsg-7 The Apache Portable Runtime Utilit
ii  libc6  2.7-10GNU C Library: Shared libraries
ii  libmagic1  4.24-4File type determination library us
ii  libssl0.9.80.9.8g-10.1   SSL shared libraries
ii  lsb-base   3.2-12Linux Standard Base 3.2 init scrip
ii  mime-support   3.44-1MIME files 'mime.types'  'mailcap
ii  net-tools  1.60-19   The NET-3 networking toolkit
ii  perl   5.10.0-11 Larry Wall's Practical Extraction 
ii  procps 1:3.2.7-8 /proc file system utilities
ii  zlib1g 1:1.2.3.3.dfsg-12 compression library - runtime

Versions of packages apache2.2-common recommends:
ii  ssl-cert  1.0.21 simple debconf wrapper for OpenSSL

Versions of packages apache2.2-common is related to:
pn  apache2-mpm-event none (no description available)
pn  apache2-mpm-itk   none (no description available)
ii  apache2-mpm-prefork   2.2.9-5Apache HTTP Server - traditional n
pn  apache2-mpm-workernone (no description available)

-- no debconf information



-- 
To UNSUBSCRIBE, email to [EMAIL PROTECTED]
with a subject of unsubscribe. Trouble? Contact [EMAIL PROTECTED]