Re: Changing the httpd security process

2020-08-20 Thread Ruediger Pluem
On 8/20/20 6:24 PM, Joe Orton wrote: > On Mon, Aug 17, 2020 at 12:08:35PM +0100, Joe Orton wrote: >> This roughly reverts the httpd process to what we used prior to adopting >> the Tomcat-esque policy for the whole ASF. We would have to document >> this and possibly need it approved by the AS

Re: Changing the httpd security process

2020-08-20 Thread Stefan Eissing
> Am 20.08.2020 um 18:24 schrieb Joe Orton : > > On Mon, Aug 17, 2020 at 12:08:35PM +0100, Joe Orton wrote: >> This roughly reverts the httpd process to what we used prior to adopting >> the Tomcat-esque policy for the whole ASF. We would have to document >> this and possibly need it approv

Re: Changing the httpd security process

2020-08-20 Thread Joe Orton
On Mon, Aug 17, 2020 at 12:08:35PM +0100, Joe Orton wrote: > This roughly reverts the httpd process to what we used prior to adopting > the Tomcat-esque policy for the whole ASF. We would have to document > this and possibly need it approved by the ASF security team. Thanks to those who have gi

Re: mod_http2 behavior in case of too many or too large request headers

2020-08-20 Thread Stefan Eissing
> Am 20.08.2020 um 11:35 schrieb Ruediger Pluem : > > > > On 8/20/20 10:47 AM, Stefan Eissing wrote: >> >> >>> Am 20.08.2020 um 10:01 schrieb Ruediger Pluem : >>> >>> >>> >>> On 8/19/20 12:18 PM, Stefan Eissing wrote: > Am 19.08.2020 um 12:08 schrieb Ruediger Pluem : > >

Re: mod_http2 behavior in case of too many or too large request headers

2020-08-20 Thread Ruediger Pluem
On 8/20/20 10:47 AM, Stefan Eissing wrote: > > >> Am 20.08.2020 um 10:01 schrieb Ruediger Pluem : >> >> >> >> On 8/19/20 12:18 PM, Stefan Eissing wrote: >>> >>> Am 19.08.2020 um 12:08 schrieb Ruediger Pluem : > > Understood. I do not see 2. descending from the heavens either and I mysel

Re: mod_http2 behavior in case of too many or too large request headers

2020-08-20 Thread Stefan Eissing
> Am 20.08.2020 um 10:01 schrieb Ruediger Pluem : > > > > On 8/19/20 12:18 PM, Stefan Eissing wrote: >> >> >>> Am 19.08.2020 um 12:08 schrieb Ruediger Pluem : >>> >>> If mod_http2 detects too many or too large request headers in >>> h2_stream_add_header or h2_stream_end_headers it does no

Re: mod_http2 behavior in case of too many or too large request headers

2020-08-20 Thread Ruediger Pluem
On 8/19/20 12:18 PM, Stefan Eissing wrote: > > >> Am 19.08.2020 um 12:08 schrieb Ruediger Pluem : >> >> If mod_http2 detects too many or too large request headers in >> h2_stream_add_header or h2_stream_end_headers it does not create a >> pseudo HTTP/1.1 request but directly responds back on