Re: Apache_1.3.26-Mod_SSL_2.8.10-OpenSSL_0.9.6g-Win32.zip

2002-09-17 Thread Jim Lee

Hi,

Since i am a windows user, i am looking for an already compiled file:
Apache_1.3.26-Mod_SSL_2.8.10-OpenSSL_0.9.6g-Win32.zip

Since i do not have any compilers installed, i would really appreciate if 
any of our UNIX friends could help our WINDOWS collegues and post the 
Apache_1.3.26-Mod_SSL_2.8.10-OpenSSL_0.9.6g-Win32.zip file in the following 
location: http://www.modssl.org/contrib/ftp/contrib/

Thanks,

Bye,
-Jim.

>From: Horst To: Jim Lee <[EMAIL PROTECTED]>
>Subject: Re: Apache_1.3.26-Mod_SSL_2.8.10-OpenSSL_0.9.6g-Win32.zip
>Date: Tue, 17 Sep 2002 20:42:08 -0700 (PDT)
>
>Hi Jim,
>I didn't read all the previous messages and the reference to
>http://www.modssl.org/contrib/ftp/contrib/
>  but I'd guess you can google for the 3 independent files.
>That's how I found Apache_1.3.26 and Mod_SSL_2.8.10 recently.
>
>  - Horst (ohh, just realizing you are on Win - I am on linux and got the
>RPMs with no problem)
>
>
>On Wed, 18 Sep 2002, Jim Lee wrote:
>
> > I have been unable to find the file:
> >
> > Apache_1.3.26-Mod_SSL_2.8.10-OpenSSL_0.9.6g-Win32.zip
> >
> > at the following location:
> >
> > http://www.modssl.org/contrib/ftp/contrib/
> >
> > Any help from our fellow members in the group would be higly appreciated 
>in
> > view of the recent openSSL worm virus alerts.
> >
> > Thanks and Regards,
> >
> > Bye,
> > -Jim.
> >
> >
> > >From: Paul
To: [EMAIL PROTECTED]
> > >Subject: Re: Apache_1.3.26-Mod_SSL_2.8.10-OpenSSL_0.9.6g-Win32.zip
> > >Date: Wed, 18 Sep 2002 09:02:41 +1200
> > >
> > > > Hi,
> > > >
> > > > I am looking for the following file:
> > > >
> > > >
> > > > Apache_1.3.26-Mod_SSL_2.8.10-OpenSSL_0.9.6g-Win32.zip
> > > >
> > > >
> > > > in the http://www.modssl.org/contrib/ftp/contrib/   folder.
> > > >
> > > >
> > > > If anyone could contribute this file, i would highly appreciate it.
> > > >
> > >
> > >Hi Jim,
> > >
> > >I'm looking for that file too!  Did you have any luck.
> > >
> > >Cheers, Paul.
> > >--
> >
> >
> >
> >
> > _





_
MSN Photos is the easiest way to share and print your photos: 
http://photos.msn.com/support/worldwide.aspx

__
Apache Interface to OpenSSL (mod_ssl)   www.modssl.org
User Support Mailing List  [EMAIL PROTECTED]
Automated List Manager[EMAIL PROTECTED]



Re: Apache_1.3.26-Mod_SSL_2.8.10-OpenSSL_0.9.6g-Win32.zip

2002-09-17 Thread Jim Lee

I have been unable to find the file:

Apache_1.3.26-Mod_SSL_2.8.10-OpenSSL_0.9.6g-Win32.zip

at the following location:

http://www.modssl.org/contrib/ftp/contrib/

Any help from our fellow members in the group would be higly appreciated in 
view of the recent openSSL worm virus alerts.

Thanks and Regards,

Bye,
-Jim.


>From: Paul  To: [EMAIL PROTECTED]
>Subject: Re: Apache_1.3.26-Mod_SSL_2.8.10-OpenSSL_0.9.6g-Win32.zip
>Date: Wed, 18 Sep 2002 09:02:41 +1200
>
> > Hi,
> >
> > I am looking for the following file:
> >
> >
> > Apache_1.3.26-Mod_SSL_2.8.10-OpenSSL_0.9.6g-Win32.zip
> >
> >
> > in the http://www.modssl.org/contrib/ftp/contrib/   folder.
> >
> >
> > If anyone could contribute this file, i would highly appreciate it.
> >
>
>Hi Jim,
>
>I'm looking for that file too!  Did you have any luck.
>
>Cheers, Paul.
>--




_
Join the world’s largest e-mail service with MSN Hotmail. 
http://www.hotmail.com

__
Apache Interface to OpenSSL (mod_ssl)   www.modssl.org
User Support Mailing List  [EMAIL PROTECTED]
Automated List Manager[EMAIL PROTECTED]



Jonathan Cloots/Utimaco/BE is out of the office.

2002-09-17 Thread jonathan . cloots

I will be out of the office starting  16/09/2002 and will not return until
01/01/3000.

I will be out of the office starting  04/09/2002 and will not return until
31/12/3000.

Please call our general number +32/(0)16/44.01.35 or our general e-mail
address: [EMAIL PROTECTED]

Kind regards,
   Jonathan

__
Apache Interface to OpenSSL (mod_ssl)   www.modssl.org
User Support Mailing List  [EMAIL PROTECTED]
Automated List Manager[EMAIL PROTECTED]



RE: Apache + VirtualHost + WebDAV + mod_ssl

2002-09-17 Thread Thierry Cabuzel

Hi,

I have tried it well enough to encounter a big problem with it :-(
SSL work well, but there is not all the PHP extensions I could except.
Especially PHP_IMAP, PHP_GD with GIF support, and PHP_XSLT for the more
important for me :-(( And PHP does some check on the interface version, then
I can't take them from another more complete PHP build :-((

I think I will take this probem to the level 2: Format my 2nd computer,
install Linux and do it all 'a la mano' with a C compiler...


> -Message d'origine-
> De : [EMAIL PROTECTED]
> [mailto:[EMAIL PROTECTED]]De la part de Martin Dickau
> Envoyé : jeudi 5 septembre 2002 14:16
> À : [EMAIL PROTECTED]
> Objet : Re: Apache + VirtualHost + WebDAV + mod_ssl
>
>
> You should try OpenSA (http://www.opensa.org).  V1.0.3 is
> available, and it
> has Apache 1.3.26 + mod_ssl 2.8.10 + OpenSSL 0.9.6g, built for
> Windows, with
> a Windows installer.  The release notes/download page is here:
> http://www.opensa.org/download/100.html
>
> - Original Message -
> From: "Thierry Cabuzel" <[EMAIL PROTECTED]>
> To: <[EMAIL PROTECTED]>
> Sent: Thursday, September 05, 2002 2:45 AM
> Subject: RE: Apache + VirtualHost + WebDAV + mod_ssl
>
>
> > I have no probem to update apache. but for mod_ssl, I have
> bigger problem
> as
> > the contrib page of modssl.org seems out of order and the ftp
> folder is a
> > bit messy and OpenSSL_0.9.6c seems to be the older I can find in it.
> Source
> > is not a good solution as I have no C compiler and I don't want to mess
> with
> > one (at a point that I prefer to take the risk of a backdoored mod_ssl
> found
> > via google on an unknow server than to have to compile it from source).
>
> The OpenSA 1.0.3 kit also includes mod_ColdFusion (4.5.x), mod_DAV 1.0.3,
> PHP 4.2.2, mod_ASP, mod_GZIP, and mod_AuthMysql 2.22.
>
> Regards,
>
> Martin Dickau, ByAllAccounts
> [EMAIL PROTECTED]


__
Apache Interface to OpenSSL (mod_ssl)   www.modssl.org
User Support Mailing List  [EMAIL PROTECTED]
Automated List Manager[EMAIL PROTECTED]



SSL error

2002-09-17 Thread Estrade Matthieu

Hi,

I am running apache 2.0.40 + SSL + mod_proxy
I have many error when i benchmark my server with stress tools 
(silkperformer):

[Tue Sep 17 19:36:03 2002] [error] SSL Library Error: 336151568 
error:14094410:lib(20):func(148):reason(1040)
[Tue Sep 17 19:36:03 2002] [error] SSL error on reading data

If someone have an idea,

best regards,

Estrade Matthieu



Etudiant: Wanadoo t'offre le Pack eXtense Haut Débit soit 150,92 euros d'économies !
Et pour 1 euro de plus, reçois le CD-ROM du jeu Dark Age of Camelot
+ 1 mois de jeu en réseau offert ! 
Clique ici : http://www.ifrance.com/_reloc/mail.etudiant 

__
Apache Interface to OpenSSL (mod_ssl)   www.modssl.org
User Support Mailing List  [EMAIL PROTECTED]
Automated List Manager[EMAIL PROTECTED]



Intermediate Certificates

2002-09-17 Thread Robert Lagana
Title: Intermediate Certificates






Hi,


Can you put more than one intermediate signer certificate for chaining in Apache?
Meaning having two lines in the apache config file.


SSLCertificateChainFile /usr/local/apache/conf/ssl.crt/ca.crt
SSLCertificateChainFile /usr/local/apache/conf/ssl.crt/ca1.crt


or 1 line pointing to the file but have both intermediate certs together..


such as 


-Begin Certificate-
code
-Begin Certificate-
-Begin Certificate-
code
-Begin Certificate-



SSLCertificateChainFile /usr/local/apache/conf/ssl.crt/ca.crt (containing both)



Thanks,
Rob





apache and client certificates

2002-09-17 Thread Jose Correia (J)

Hi all

Is anyone aware of Apache version 1.3.20 having problems with client
authentication??

I've created my own CA created using openssl (vs 0.9.6a). I then
created and signed my server certificate with the CA using openssl.
(apache is on a RH Linux 6.2 machine)

I then created a client public key using Java's keytool (from my
Win2000 client machine). I then took this key and signed it with my CA
using openssl which I duly converted into DER format. I then imported
my CA's certificate in my JSSE keystore plus the now created client
certificate which replaces the previous public key.

In my Apache I mention these (I have mod-ssl vs 2.8.4):
SSLCertificateFile /jose/CA2/server.crt
SSLCertificateKeyFile /jose/CA2/server.key
SSLCACertificateFile /jose/CA2/demoCA/cacert.pem
SSLVerifyClient require
SSLVerifyDepth  10

When I connect, I'm getting the following on ssl_engine.log

"[17/Sep/2002 15:20:22 28388] [error] SSL handshake failed (server
155.239.48.43:443, client 165.148.59.202) (OpenSSL library error
follows)
[17/Sep/2002 15:20:22 28388] [error] OpenSSL: error:14094416:SSL
routines:SSL3_READ_BYTES:sslv3 alert certificate unknown"

and from my Java client I'm getting:

"main, SEND SSL v3.1 ALERT:  fatal, description = certificate_unknown
main, WRITE:  SSL v3.1 Alert, length = 2
javax.net.ssl.SSLPeerUnverifiedException: peer not authenticated"

Hence my confusion since I know my client certificate was signed by
the CA mentioned in apache httpd.conf... :-(

Anyone got a clue? I've searched extensevily...

Thanks a lot
Jose Correia
__
Apache Interface to OpenSSL (mod_ssl)   www.modssl.org
User Support Mailing List  [EMAIL PROTECTED]
Automated List Manager[EMAIL PROTECTED]



Re: Apache 1.3.9 make fails with mod_ssl 2.4.10 and openssl 0.9.5a

2002-09-17 Thread Mads Toftum

On Tue, Sep 17, 2002 at 02:24:35AM -0700, hiren mehta wrote:
> Hi,
> 
>   I am getting the error as below
> when making apache .I am using Apache 1.3.9+mod_ssl
> 2.4.10 with openssl 0.9.5 .I also tried with openssl
> 0.9.5a without success .
> 
IIRC you would need an even older version of openssl for this to work -
something in the early 0.9.4 series. But you should not do that, as there
are well known exploits for all of these. You really should be using
openssl-0.9.6g, apache-1.3.26 and mod_ssl-2.8.10.

vh

Mads Toftum
-- 
`Darn it, who spiked my coffee with water?!' - lwall

__
Apache Interface to OpenSSL (mod_ssl)   www.modssl.org
User Support Mailing List  [EMAIL PROTECTED]
Automated List Manager[EMAIL PROTECTED]



Apache 1.3.9 make fails with mod_ssl 2.4.10 and openssl 0.9.5a

2002-09-17 Thread hiren mehta

Hi,

  I am getting the error as below
when making apache .I am using Apache 1.3.9+mod_ssl
2.4.10 with openssl 0.9.5 .I also tried with openssl
0.9.5a without success .

   Error below appears
when making apache
  
 
---
   ssl_util_ssl.c:145:
conflicting types for
  `d2i_PrivateKey_bio'
  
 
/usrhome/ryoussef/openssl-0.9.5a/include/openssl/x509.h:696:
  previous declaration of
`d2i_PrivateKey_bio'
   *** Error code 1
   make: Fatal error:
Command failed for target
  `ssl_util_ssl.lo'
   Current working
directory
 
/usrhome/ryoussef/apache_1.3.9/src/modules/ssl
   *** Error code 1
   make: Fatal error:
Command failed for target
  `all'
   Current working
directory
 
/usrhome/ryoussef/apache_1.3.9/src/modules
   *** Error code 1
   make: Fatal error:
Command failed for target
  `subdirs'
   Current working
directory
 
/usrhome/ryoussef/apache_1.3.9/src
   *** Error code 1
   make: Fatal error:
Command failed for target
  `build-std'
   Current working
directory
  /usrhome/ryoussef/apache_1.3.9
   *** Error code 1
   make: Fatal error:
Command failed for target
  `build'
   

Any help how to resolve this is appreciated.

  Thanks in advance.

  Regards,
  Hiren



__
Do you Yahoo!?
Yahoo! News - Today's headlines
http://news.yahoo.com
__
Apache Interface to OpenSSL (mod_ssl)   www.modssl.org
User Support Mailing List  [EMAIL PROTECTED]
Automated List Manager[EMAIL PROTECTED]