Re: Rename apachectl prior to 2.4.1 tag?

2012-01-30 Thread Rainer Jung
On 30.01.2012 22:53, William A. Rowe Jr. wrote: On 1/30/2012 3:12 PM, Stefan Fritsch wrote: And there is apachectl, not httpdctl. Would anyone else like to see this changed, now, for the 2.4 releases? -0.5 Rainer

Re: [PATCH] trunk/2.4 core output filter is broken

2012-01-30 Thread Rainer Jung
On 31.01.2012 00:36, Daniel Ruggeri wrote: On 1/30/2012 7:51 AM, Jim Jagielski wrote: Anyone with Windows willing to sign up to review/test? I don't have a build environment to create something based on the diff, but if someone can create a build , I'll happily do the testing. What's you ru

Re: [Vote] httpd 2.2.22 release

2012-01-30 Thread Rainer Jung
On 30.01.2012 19:10, William A. Rowe Jr. wrote: On 1/30/2012 4:02 AM, Rainer Jung wrote: We add apu-1-confg --includes to CPPFLAGS and then use CPP and apu_version.h to detect which version we have. That works for most gcc versions, but recent gcc chokes, because apu_version.h includes

Re: who is working on getting security patches proposed for 2.0.65?

2012-01-30 Thread Rainer Jung
On 25.01.2012 14:00, Jeff Trawick wrote: I'll start with the patch for CVE-2011-4317. I removed CVE-2011-3348 from STATUS (does not apply to 2.0.x) and added a comment for CVE-2010-2068, which IMHO does not apply either. Regards, Rainer

Re: [Vote] httpd 2.2.22 release

2012-01-30 Thread Rainer Jung
On 30.01.2012 03:16, William A. Rowe Jr. wrote: On 1/29/2012 3:18 PM, Rainer Jung wrote: Overview: Minor problem (not a regression): config.guess and config.sub are a bit old (2008) due to buildconf in the released apr overwriting the config.* in our svn by the system config.*. This is fixed

Re: [Vote] httpd 2.2.22 release

2012-01-29 Thread Rainer Jung
On 25.01.2012 23:59, William A. Rowe Jr. wrote: Candidate binaries are available from http://httpd.apache.org/dev/dist/ - these do not yet constitute ASF releases. Win32 specific artifacts (x86 binary distribution and -win32-src.zip) will follow shortly, once I fix the release.sh breakage. Ther

Re: [Vote] httpd 2.2.22 release

2012-01-25 Thread Rainer Jung
On 25.01.2012 23:59, William A. Rowe Jr. wrote: Candidate binaries are available from http://httpd.apache.org/dev/dist/ - these do not yet constitute ASF releases. Win32 specific artifacts (x86 binary distribution and -win32-src.zip) will follow shortly, once I fix the release.sh breakage. Ple

Re: svn commit: r1234336 - in /httpd/httpd/branches/2.4.x: include/ap_release.h server/util_expr_parse.c server/util_expr_parse.h

2012-01-21 Thread Rainer Jung
On 21.01.2012 15:38, j...@apache.org wrote: Author: jim Date: Sat Jan 21 14:38:25 2012 New Revision: 1234336 URL: http://svn.apache.org/viewvc?rev=1234336&view=rev Log: Update copyrights for externally visible and changed code Modified: httpd/httpd/branches/2.4.x/include/ap_release.h

Re: [VOTE] Release Apache httpd 2.4.0

2012-01-19 Thread Rainer Jung
On 16.01.2012 18:50, Jim Jagielski wrote: The 2.4.0 (prerelease) tarballs are available for download and test: http://httpd.apache.org/dev/dist/ I'm calling a VOTE on releasing these as Apache httpd 2.4.0 GA. Vote will last the normal 72 hours... Can I get a w00t w00t! +1 for GA. I

Re: [VOTE] Release Apache httpd 2.4.0

2012-01-19 Thread Rainer Jung
On 19.01.2012 07:14, Kaspar Brand wrote: On 19.01.2012 03:28, Rainer Jung wrote: OpenSSL should be 1.0.0f and the strange thing is, that the same tests succeed on Solaris 10 using the same OpenSSL version. Something must be different between my Linux systems, which all fail, and the Solaris box

Re: [VOTE] Release Apache httpd 2.4.0

2012-01-18 Thread Rainer Jung
On 16.01.2012 18:50, Jim Jagielski wrote: The 2.4.0 (prerelease) tarballs are available for download and test: http://httpd.apache.org/dev/dist/ I'm calling a VOTE on releasing these as Apache httpd 2.4.0 GA. Vote will last the normal 72 hours... Can I get a w00t w00t! Intermediate r

Re: Time for 2.4.0 GA??

2012-01-13 Thread Rainer Jung
and a bad response. The name "Stefan" was a typo at that type and was corrected shortly after on the same thread to be meant as "Steffen" ;) I think Stefan doesn't have a Win build and environment to reproduce. Regards, Rainer Op 12 jan. 2012 om 18:11 heeft R

Re: Time for 2.4.0 GA??

2012-01-12 Thread Rainer Jung
On 12.01.2012 19:10, Jim Jagielski wrote: On monday (Jan 16th), I plan to T&R 2.4.0... +1

Re: Time for 2.4.0 GA??

2012-01-12 Thread Rainer Jung
On 12.01.2012 11:24, Steffen wrote: We have at least 4 hard bugs in 2.3.16. Known for a long time, and no need to exposure more for these. Fine a GA, with a big note that it is not ready for Windows and advising to run 2.2.21 as proven stable. So not happy with 2.4. Understood, but we rep

Re: Fwd: svn commit: r1228700 - in /httpd/httpd/trunk/docs: STATUS manual/mod/mod_heartbeat.xml manual/mod/mod_heartmonitor.xml manual/mod/mod_watchdog.xml manual/mod/mod_watchdog.xml.meta

2012-01-07 Thread Rainer Jung
On 07.01.2012 20:22, Sander Temme wrote: Folks, I've put in some updates to the mod_heart* modules, taken from the README supplied with the modules and some perusal of the source code. I have not run these as I'm too lazy to set up the servers. Review would be appreciated, especially by the

Re: Build-Warnings httpd 2.4.x Visual Studio 10, 32 Bit

2012-01-04 Thread Rainer Jung
Hi Eric, On 04.01.2012 16:07, Eric Covener wrote: Any fresh hints/pointers about setting up a windows sandbox so I can try to look at the LDAP stuff? Here's what I did. Some of it is a bit complex, because I used Visual Studio 10 and the Windows build files are not really optimal for that (m

Build-Warnings httpd 2.4.x Visual Studio 10, 32 Bit

2012-01-04 Thread Rainer Jung
During the Build for Windows 32 Bit I get the following warnings: mod_data.c(112): warning C4244: 'function' : conversion from 'apr_off_t' to 'int', possible loss of data mod_filter.c(596): warning C4090: 'function' : different 'const' qualifiers mod_substitute.c(250): warning C4018: '<=' : s

Re: Win 2.3.16 :: Server Status Entries

2012-01-04 Thread Rainer Jung
gging status in server-status for a long time for the winnt MPM? This bug is still there in 2.3.16, have "L" entries for more then a week ! They are occupying workers all the time, so the busyorkers are far high: L__L_L___LL_L__L___L_L_L__ Happy (2.4) new year to all, Ste

Re: Win 2.3.16 :: SSL and AcceptFilter

2012-01-04 Thread Rainer Jung
On 04.01.2012 06:00, William A. Rowe Jr. wrote: On 1/3/2012 9:19 PM, Rainer Jung wrote: On 30.12.2011 22:04, Gregg L. Smith wrote: On 12/27/2011 10:40 AM, Steffen wrote: Gregg reported it also: I've also found AcceptFilter https none to be problematic. First time you hit a site via htt

Re: Win 2.3.16 :: SSL and AcceptFilter

2012-01-03 Thread Rainer Jung
On 30.12.2011 22:04, Gregg L. Smith wrote: On 12/27/2011 10:40 AM, Steffen wrote: Gregg reported it also: I've also found AcceptFilter https none to be problematic. First time you hit a site via https it usually comes up with a blank white nothing. Hitting reload and it comes up proper. That

Re: Win 2.3.15 :: Server Status Entries

2011-12-06 Thread Rainer Jung
ave the Logging status in server-status for a long time for the winnt MPM? -Original Message- From: Rainer Jung Sent: Tuesday, November 22, 2011 11:32 AM To: dev@httpd.apache.org Subject: Re: Win 2.3.15 :: Server Status Entries On 22.11.2011 10:28, Steffen wrote: Seeing a huge number of hang

Re: svn commit: r1210287 [6/12] - in /httpd/httpd/branches/2.4.x: ./ modules/aaa/ modules/arch/netware/ modules/arch/unix/ modules/arch/win32/ modules/cache/ modules/cluster/ modules/core/ modules/dat

2011-12-05 Thread Rainer Jung
Hi Bill, On 05.12.2011 07:50, William A. Rowe Jr. wrote: On 12/4/2011 6:08 PM, s...@apache.org wrote: -ap_log_error(APLOG_MARK, APLOG_ERR, rc, s, +ap_log_error(APLOG_MARK, APLOG_ERR, rc, s, APLOGNO(00654) Did you really mean for these to be in octal? APLOGNO is the f

Re: Windows Laundry List pt3, mod_watchdog

2011-12-04 Thread Rainer Jung
Picking up this old discussion: On 03.07.2011 19:40, William A. Rowe Jr. wrote: On 7/1/2011 12:26 AM, Mladen Turk wrote: On 07/01/2011 06:31 AM, Gregg L. Smith wrote: Hi folks, Well, this is the same chunk of Win32 specific debugging code causing this module to crash yet again. Gregg: Can

Re: svn commit: r1203859 [2/2] - in /httpd/httpd/trunk/modules/proxy: mod_proxy.c ...

2011-12-04 Thread Rainer Jung
On 04.12.2011 15:38, Jim Jagielski wrote: On Dec 1, 2011, at 8:35 PM, Gregg L. Smith wrote: @@ -551,7 +546,7 @@ static int scgi_handler(request_rec *r, cleanup: if (backend) { backend->close = 1; /* always close the socket */ -ap_proxy_release_connection(PROXY_FUNCTION

Re: svn commit: r1207721 - in /httpd/httpd/branches/2.4.x: ./ build/rpm/httpd.spec.in

2011-12-04 Thread Rainer Jung
On 04.12.2011 14:15, Rainer Jung wrote: On 29.11.2011 13:12, Graham Leggett wrote: On 29 Nov 2011, at 11:55, Igor Galić wrote: OpenSSL (and cascading deps to it) mod_ssl mod_session mod_session_crypto Neither mod_session nor mod_session_crypto have any hard coded links to openssl (or any

Re: Stray svn:mergeinfo on files

2011-12-04 Thread Rainer Jung
On 30.11.2011 01:02, Graham Leggett wrote: Hi all, While merging I am getting a lot of stray svn:mergeinfo changes on arbitrary files, for example: M modules/core/mod_watchdog.c M modules/core/mod_so.c M modules/core/Makefile.in M modules/core/config.m4 M mod

Re: svn commit: r1207721 - in /httpd/httpd/branches/2.4.x: ./ build/rpm/httpd.spec.in

2011-12-04 Thread Rainer Jung
On 29.11.2011 13:12, Graham Leggett wrote: On 29 Nov 2011, at 11:55, Igor Galić wrote: OpenSSL (and cascading deps to it) mod_ssl mod_session mod_session_crypto Neither mod_session nor mod_session_crypto have any hard coded links to openssl (or any other library), it's all abstracted away. m

Re: Icons for 2.4

2011-11-27 Thread Rainer Jung
Hi Gregg, In 28.11.2011 01:12, Gregg L. Smith wrote: I did this a couple weeks ago, it's close, but not perfect. Best on white/light background. Which font did you use for the digits? Is it a freely avaiable font? Regards, Rainer

Re: Icons for 2.4

2011-11-27 Thread Rainer Jung
On 27.11.2011 10:50, Stefan Fritsch wrote: Hi, docs/icons/apache_pb2* contain the version number (2.2), in the case of docs/icons/apache_pb2_ani.gif it's even an animation. Any volunteers for changing these to 2.4? Anyone knows the right or at least a similar font? Regards, Rainer

Re: [RFC] further proxy/rewrite URL validation security issue (CVE-2011-4317)

2011-11-24 Thread Rainer Jung
On 23.11.2011 15:23, Joe Orton wrote: Prutha Parikh from Qualys reported a variant on the CVE-2011-3368 attack against certain mod_proxy/mod_rewrite configurations. A new CVE name, CVE-2011-4317, has been assigned to this variant. The configurations in question are the same as affected by -3368

Re: Win 2.3.15 :: New log entries

2011-11-22 Thread Rainer Jung
On 22.11.2011 22:42, Stefan Fritsch wrote: [core:error] [pid 3800:tid 2216] [client 220.134.192.77:42107] Handler for type-map returned invalid result code 620018, referer: . This message denotes that there is a bug in the handler (maybe in mod_negotiation). The log message itself is new, t

Re: Win 2.3.15 :: Server Status Entries

2011-11-22 Thread Rainer Jung
On 22.11.2011 10:28, Steffen wrote: Seeing a huge number of hanging entries in the Server Status, already for 20 hours and looks they are staying there forever. The requests are invalid, not sure since I do not keep the raw logs. ... ... 0-0 3800 0/177/177 _ 64980 1 0.0 0.09 0.09 94.76.244.212

Re: Win 2.3.15 :: The timeout specified has expired

2011-11-22 Thread Rainer Jung
On 21.11.2011 11:59, "Plüm, Rüdiger, VF-Group" wrote: -Original Message- From: Steffen [mailto:i...@apachelounge.com] Sent: Montag, 21. November 2011 11:50 To: dev@httpd.apache.org Subject: Win 2.3.15 :: The timeout specified has expired Observing that the error.log is filling with [

Re: Improving SSL config

2011-11-18 Thread Rainer Jung
On 18.11.2011 18:20, Kaspar Brand wrote: On 18.11.2011 13:09, Rainer Jung wrote: You might want to drop the -SSLv2 from our SSLCipherSuite in docs/conf/extra/httpd-ssl.conf.in then as well. You're right, yes. As there were no objections to the changes I proposed on the list a few days a

Re: Improving SSL config

2011-11-18 Thread Rainer Jung
On 18.11.2011 06:32, Kaspar Brand wrote: As I can't think of any good reason why a new major version of an HTTPS server released in late 2011 should still support insecure SSL protocol cruft from the 1990s (v2 was superseded about 15 years ago, when SSLv3 was introduced), I went for the first opt

Re: svn commit: r1202255 - /httpd/httpd/trunk/modules/filters/mod_reqtimeout.c

2011-11-16 Thread Rainer Jung
On 15.11.2011 20:57, Jeff Trawick wrote: On Tue, Nov 15, 2011 at 2:32 PM, William A. Rowe Jr. wrote: On 11/15/2011 12:33 PM, Stefan Fritsch wrote: On Tuesday 15 November 2011, Paul Querna wrote: On Tue, Nov 15, 2011 at 9:17 AM, Stefan Fritsch wrote: On Tue, 15 Nov 2011, pque...@apache.

Re: setting TZ env var

2011-11-16 Thread Rainer Jung
On 15.11.2011 17:06, Paul Querna wrote: So, I was looking at all the system calls we make in a single request, and comparing it to nginx. We were actually pretty close, baring supporting our features like htaccess, there was only one thing that stood out. Glibc is opening, calling fstat twice,

Re: Changes in mod_ssl

2011-11-15 Thread Rainer Jung
Hello Moran, On 15.11.2011 14:54, Moran Jacuel wrote: Hello Rainer, I found out that the patch that I used in order to connect apache server with SSL using our HSM to hold the Private RSA and Certificate already exists in bugzilla at: https://issues.apache.org/bugzilla/show_bug.cgi?id=42687

Re: Changes in mod_ssl

2011-11-14 Thread Rainer Jung
Hello, On 14.11.2011 05:59, Moran Jacuel wrote: Hello, Our company is an HSM manufacturer (See link for http://www.arx.com/products/private-server-hsm PrivateServer product) We wanted to connect apache server with SSL using our HSM to hold the Private RSA and Certificate. We downloaded apache

Re: [Discuss] [VOTE] Formal deprecation of 2.0.x branch

2011-11-11 Thread Rainer Jung
On 11.11.2011 13:04, André Malo wrote: * William A. Rowe Jr. wrote: So isn't it enough to say that "The project will choose to publish further releases only for significant security fixes, or will choose instead to publish patches for less significant security fixes for 12 months from the date

Re: [VOTE] Release 2.3.15-dev as beta

2011-11-11 Thread Rainer Jung
On 08.11.2011 15:16, Jim Jagielski wrote: The 2.3.15-dev (prerelease) tarballs are available for download at test: http://httpd.apache.org/dev/dist/ I'm calling a VOTE on releasing these as 2.3.15-dev BETA and, with luck, this will be our last beta and the next release in ~2weeks or les

Re: BRANCHED : httpd 2.4.x

2011-11-11 Thread Rainer Jung
On 11.11.2011 09:42, Jim Jagielski wrote: The 2.4.x httpd branch was created from the r1200449 point of trunk… I've tried to backport pretty much all non-apreq patches from trunk. I guess we are still on CTR on that branch? Rainer

Re: Lua state reuse does not work

2011-11-11 Thread Rainer Jung
On 11.11.2011 02:16, Rainer Jung wrote: I did a few lua tests and currently the reuse of lua states does not work. Unfortunately I don't yet see the root cause. We are constantly creating new lua states, saving them to the pool and on the next request retrieve null and create a new state.

Lua state reuse does not work

2011-11-11 Thread Rainer Jung
I did a few lua tests and currently the reuse of lua states does not work. Unfortunately I don't yet see the root cause. We are constantly creating new lua states, saving them to the pool and on the next request retrieve null and create a new state. When the server is shutdown, all of the stat

Re: [users@httpd] 2.3.15-beta: module proxy_balancer requires the not automatically loaded module slotmem_shm

2011-11-09 Thread Rainer Jung
On 09.11.2011 21:20, William A. Rowe Jr. wrote: On 11/9/2011 4:53 PM, Jim Jagielski wrote: Isn't the point different? If someone enables mod_proxy then the configure script needs to ensure that mod_slotmem is also built… Reporter suggests that *NOT* loading mod_slotmem_shm caused the server to

Re: Fwd: [users@httpd] 2.3.15-beta: module proxy_balancer requires the not automatically loaded module slotmem_shm

2011-11-09 Thread Rainer Jung
On 09.11.2011 14:48, William A. Rowe Jr. wrote: On 11/9/2011 3:53 PM, Stefan Fritsch wrote: Hi, On Wed, 9 Nov 2011, William A. Rowe Jr. wrote: This one in from the users@ list. It sounds vaguely familiar to the issue previously mentioned about win32 defaults and some strange dependency failure

Re: Small things to do

2011-11-09 Thread Rainer Jung
On 08.11.2011 13:10, Stefan Fritsch wrote: - Rainer wanted to check some pcre linking issues, but I don't remember the exact details The problem is mainly gone with trunk. It concerns dependency libs, which are likely used by 3rd-party modules as well. Until 2.2 PCRE was such a library *plus

Re: Fwd: [users@httpd] 2.3.15-beta: module proxy_balancer requires the not automatically loaded module slotmem_shm

2011-11-09 Thread Rainer Jung
On 09.11.2011 13:53, Stefan Fritsch wrote: Hi, On Wed, 9 Nov 2011, William A. Rowe Jr. wrote: This one in from the users@ list. It sounds vaguely familiar to the issue previously mentioned about win32 defaults and some strange dependency failure between proxy_balancer and slotmem providers. On

Re: [VOTE] Release 2.3.15-beta as beta

2011-11-09 Thread Rainer Jung
On 09.11.2011 11:12, Jim Jagielski wrote: 2010-11-04 is the day I created the new key… it's unexpired (at least from what I can see ;) ) Sorry for the noise, false alarm :( Regards, Rainer On Nov 9, 2011, at 7:52 AM, Rainer Jung wrote: On 09.11.2011 07:43, Rainer Jung wrote: Hi Jim

Re: [VOTE] Release 2.3.15-beta as beta

2011-11-09 Thread Rainer Jung
On 09.11.2011 07:43, Rainer Jung wrote: Hi Jim, it looks like your key expired last Friday? Oups, was so convinced it is new, that I didn't see it already expired a year ago. Maybe you should sign 2.4.0 with a new one? Rainer % gpg --verify ../incoming/httpd/trunk/2.3.15/httpd-2

Re: Current LoadModule enabling status

2011-11-09 Thread Rainer Jung
On 08.11.2011 13:57, Stefan Fritsch wrote: On Tue, 8 Nov 2011, Rainer Jung wrote: After Stefan's change r1199027 we no longer load all built modules by default. The new behaviour is (citing Stefan): "By default, only load those modules that are either required or explicitly sel

Re: [VOTE] Release 2.3.15-beta as beta

2011-11-09 Thread Rainer Jung
Hi Jim, it looks like your key expired last Friday? % gpg --verify ../incoming/httpd/trunk/2.3.15/httpd-2.3.15-beta.tar.gz.asc gpg: WARNING: using insecure memory! gpg: please see http://www.gnupg.org/faq.html for more information gpg: Signature made November 9, 2011 3:20:26 PM CET using RSA k

Re: 2.3.15-dev

2011-11-08 Thread Rainer Jung
+1 On 08.11.2011 14:47, Jim Jagielski wrote: > So far 3 +1s and counting… > > On Nov 8, 2011, at 12:49 PM, Jim Jagielski wrote: > >> OK… let's polish this… "gem". >> >> I'd really like to T&R 2.3.15-dev, get some feedback quickly and >> let's push on for a quick 2.4.0 release!

Re: Current LoadModule enabling status

2011-11-08 Thread Rainer Jung
On 08.11.2011 10:03, William A. Rowe Jr. wrote: > On 11/8/2011 11:53 AM, Rainer Jung wrote: >> After Stefan's change r1199027 we no longer load all built modules by >> default. The new behaviour is (citing Stefan): >> >> "By default, only load those m

Current LoadModule enabling status

2011-11-08 Thread Rainer Jung
After Stefan's change r1199027 we no longer load all built modules by default. The new behaviour is (citing Stefan): "By default, only load those modules that are either required or explicitly selected by a configure --enable-foo argument. The LoadModule statements for modules enabled by --enable-

Re: mod_proxy_html

2011-10-13 Thread Rainer Jung
On 12.10.2011 23:56, Nick Kew wrote: > > On 10 Oct 2011, at 23:02, Nick Kew wrote: > >> Any interest? > > Looks like a lazy consensus in favour! If you ant it a bit less lazy: +1 from me also. > Regarding IP, it's mine to sign over, so that's straightforward. > So I guess it's just a matter of

Re: Improving SSL config

2011-10-06 Thread Rainer Jung
On 06.10.2011 10:58, Rainer Jung wrote: > Hi Bill, > > On 02.10.2011 09:07, William A. Rowe Jr. wrote: >> On 9/29/2011 9:31 AM, Rainer Jung wrote: >>> In light of the TLS 1.0 CBC attack (aka BEAST, CVE-2011-3389) I suggest >>> we update our SSL configura

Re: Improving SSL config

2011-10-06 Thread Rainer Jung
Hi Bill, On 02.10.2011 09:07, William A. Rowe Jr. wrote: > On 9/29/2011 9:31 AM, Rainer Jung wrote: >> In light of the TLS 1.0 CBC attack (aka BEAST, CVE-2011-3389) I suggest >> we update our SSL configuration analogous to what's in trunk. >> >> - Choose a better

Re: Change loglevel of "File does not exist" messages

2011-10-05 Thread Rainer Jung
On 06.10.2011 01:07, Daniel Ruggeri wrote: > On 10/5/2011 4:18 PM, Stefan Fritsch wrote: >> True. But a generic apparatus for even more fine-grained log >> configuration won't happen in time for 2.4. > > I have toyed with the idea of this... do you have suggestions on how > this might be implement

Re: Make loglevel of "File does not exist" configurable

2011-10-05 Thread Rainer Jung
On 05.10.2011 02:38, William A. Rowe Jr. wrote: > On 10/4/2011 1:00 PM, Stefan Fritsch wrote: >> >> I think this one has been controversial in the past, therefore I thought I'd >> ask for >> comments before making this change: > > I believe you are right, but I don't see a reason for the extra di

Re: [PATCH] Support for TLS Session Tickets

2011-09-30 Thread Rainer Jung
On 30.09.2011 14:33, Paul Querna wrote: > On Fri, Sep 30, 2011 at 12:38 AM, Rainer Jung wrote: >> On 30.09.2011 08:08, Paul Querna wrote: >>> Hiya, >> So do we actually need to worry about the keys? > > If you don't set anything, OpenSSL randomly generates a

Re: [PATCH] Support for TLS Session Tickets

2011-09-30 Thread Rainer Jung
Hi Paul, On 30.09.2011 08:08, Paul Querna wrote: > Hiya, > > Attached is a patch > > to add support for setting SSL_CTX_set_tlsext_ticket_keys. Unfortunately I don't have answers to your questions, but I'm a bit curious about

Improving SSL config

2011-09-29 Thread Rainer Jung
In light of the TLS 1.0 CBC attack (aka BEAST, CVE-2011-3389) I suggest we update our SSL configuration analogous to what's in trunk. - Choose a better default SSLCipherSuite - Add SSLHonorCipherOrder - restrict MSIE exceptions to MSIE 2-5 The patch looks like this: svn diff docs/conf/extra/http

Re: svn commit: r1176019 - in /httpd/httpd/trunk: CHANGES modules/filters/mod_substitute.c

2011-09-29 Thread Rainer Jung
On 29.09.2011 13:09, "Plüm, Rüdiger, VF-Group" wrote: > Anyone time for remote eyes if my findings are correct or wrong? I did only locally check the scratch and fbytes stuff, but I agree, it must be Index: modules/filters/mod_substitute.c =

Re: svn commit: r1177080 - in /httpd/httpd/branches/2.2.x: CHANGES STATUS modules/http/byterange_filter.c

2011-09-29 Thread Rainer Jung
On 29.09.2011 00:38, William A. Rowe Jr. wrote: > On 9/28/2011 4:48 PM, s...@apache.org wrote: >>  -*- coding: utf-8 >> -*- >> Changes with Apache 2.2.22 >> >> - >> + *) Fix a regression introduced by the CVE-2011-3192 byterange fix in

Re: How to treat "Range: bytes=0-"

2011-09-26 Thread Rainer Jung
On 26.09.2011 19:07, Jim Jagielski wrote: > > On Sep 26, 2011, at 12:58 PM, Stefan Fritsch wrote: > >> >> But we are breaking quite a few popular clients here: VLC, everything >> based on lavf, firefox (the ogg media support). >> >> And httpd violates a SHOULD with the current form of RFC 2616 1

Re: httpd 2.0.65 - when?

2011-09-26 Thread Rainer Jung
On 26.09.2011 17:35, Jim Jagielski wrote: > All looks good… testing passes w/ no regressions so I'll > likely tag and roll tomorrow AM. Is there consensus how to handle the range "0-" returns 200 problem? It looks like the discussion for 2.2 is still open, but I haven't checked whether that influe

Re: Pushing for httpd 2.4.0 GA

2011-09-18 Thread Rainer Jung
On 19.09.2011 01:37, Rich Bowen wrote: > > On Sep 18, 2011, at 7:16 PM, Nick Kew wrote: > - mod_socache_dbm - mod_socache_memcache - mod_socache_shmcb >>> >>> Not sure about socache, but docs are definitely needed, because you need >>> socache for mod_ssl

Re: Pushing for httpd 2.4.0 GA

2011-09-18 Thread Rainer Jung
On 19.09.2011 00:17, Rich Bowen wrote: > My current list is: > > - mod_serf mod_serf likely to get dropped for 2.4, see our main STATUS file > - mod_watchdog Mainly written by Mladen, so maybe he can provide a few pointers > - mod_heartbeat > - mod_heartmonitor

Re: EOL for 2.0

2011-09-17 Thread Rainer Jung
On 16.09.2011 17:59, William A. Rowe Jr. wrote: > On 9/16/2011 12:51 AM, Issac Goldstand wrote: >> IIRC, we talked about making 2.0 EOL when we make the next release, but >> I don't think we ever formalized the decision. >> >> Does anyone have comments for or against announcing 2.0 End-Of-Life at

Re: [Vote] httpd 2.2.21 release

2011-09-11 Thread Rainer Jung
On 09.09.2011 18:10, William A. Rowe Jr. wrote: > Candidate binaries are available from http://httpd.apache.org/dev/dist/ > which do not yet constitute ASF releases. win32-x86 binary distribution > will follow shortly. > > This will be a 72 hour vote, which ends no later than Noon ET Monday > >

Re: [Vote] httpd 2.2.21 release

2011-09-10 Thread Rainer Jung
On 10.09.2011 13:46, William A. Rowe Jr. wrote: > On 9/10/2011 5:10 AM, Rainer Jung wrote: >> Hi Bill, >> >> can you please add your key "60C5442D" to the KEYS file at >> //www.apache.org/dist/httpd/KEYS? > > You mean > > pub 4096R/B55D

Re: [Vote] httpd 2.2.21 release

2011-09-10 Thread Rainer Jung
Hi Bill, can you please add your key "60C5442D" to the KEYS file at //www.apache.org/dist/httpd/KEYS? Do you plan to provide the two symbols files for Windows? Regards, Rainer

Re: Appropriate patches for 2.2.19 and 2.0.64?

2011-09-03 Thread Rainer Jung
On 03.09.2011 21:49, Jeff Trawick wrote: > On Wed, Aug 31, 2011 at 9:51 PM, William A. Rowe Jr. > wrote: >> On 8/31/2011 4:16 PM, William A. Rowe Jr. wrote: >>> I've attempted to simply substitute the 2.2.19 filter code into the >>> 2.0.64 http_protocol.c sources, and am unsure how far off these p

Re: Detecting which MPM a module is running in

2011-09-01 Thread Rainer Jung
On 01.09.2011 23:39, Joshua Marantz wrote: > Hello from mod_pagespeed again. > > We are adding support for running in the Worker MPM, having spent most of > our time since we launched the product sheltered in the prefork MPM where > our multi-threading challenges are all of our own making. > > Ha

Re: Appropriate patches for 2.2.19 and 2.0.64?

2011-09-01 Thread Rainer Jung
On 01.09.2011 19:18, William A. Rowe Jr. wrote: > On 9/1/2011 2:41 AM, "Plüm, Rüdiger, VF-Group" wrote: > Ideally can you provide me the -verbose output (offlist or to your > people.a.o/ space if it's lengthy)? Sorry for kicking in late. I was on holidays until Sunday and was a bit overwhelmed by

Re: [Notice] chair change

2011-08-17 Thread Rainer Jung
On 17.08.2011 23:34, William A. Rowe Jr. wrote: > I'd like to thank and welcome Eric Covener as our new HTTP Server > project chair, as confirmed today by the ASF Board of Directors! > > It's been a pleasure serving as your chair these past two years, > and I know that Eric will do a great job as

Re: websocket support for mod_proxy

2011-08-09 Thread Rainer Jung
On 09.08.2011 08:49, Greg Wilkins wrote: > Is there any plans to implement websocket support in mod_proxy. I > would think that it could be done pretty simply as a variation of > mod_proxy_connect, as once the HTTP upgrade is done mod_proxy can > treat the connection as a simple byte tunnel. > >

Re: [VOTE] Release httpd-2.3.14 as beta

2011-08-08 Thread Rainer Jung
On 08.08.2011 10:55, Stefan Fritsch wrote: > On Monday 08 August 2011, Rainer Jung wrote: >> - I can't run test test suite for Solaris on the statically linked >> reallyall, since then also mod_privileges in included and I have >> problems running the test suite wit

Re: [VOTE] Release httpd-2.3.14 as beta

2011-08-08 Thread Rainer Jung
On 01.08.2011 18:58, Jim Jagielski wrote: > The tarballs for httpd-2.3.14 are available at: > > http://httpd.apache.org/dev/dist/ > > Please VOTE on whether to release these as Apache httpd-2.3.14, > beta. +1 to 2.3.14-beta. - Sigs and hashes OK - contents of tarballs identical - content

Re: help from autoconf savvy folks -- mod_deflate zlib detection?

2011-08-02 Thread Rainer Jung
On 02.08.2011 13:00, Eric Covener wrote: >> Line 48 is surrounded by >> >> if test "x$ap_zlib_base" = "x"; then >> >> and ap_zlib_base ist set when using --with-z. So in this case the >> automatic detection part should be skipped. >> >> What problem do you actually observe? > > Can't get it to mis

Re: svn commit: r1153004 - /httpd/test/framework/trunk/t/conf/extra.conf.in

2011-08-02 Thread Rainer Jung
Hi Eric, On 02.08.2011 04:51, cove...@apache.org wrote: > Author: covener > Date: Tue Aug 2 02:51:19 2011 > New Revision: 1153004 > > URL: http://svn.apache.org/viewvc?rev=1153004&view=rev > Log: > whitespace change only to indent the block wrapped in a new ifModule in > r1153003 > > Modified:

Re: help from autoconf savvy folks -- mod_deflate zlib detection?

2011-08-02 Thread Rainer Jung
Hi Eric, On 02.08.2011 04:40, Eric Covener wrote: > I'm setting up a new system to test httpd releases, with a crufty OS > that doesn't have good packaged prereqs and doesn't have years of my > own kludges giving me anything for free. > > I've built and installed zlib into a random directory. I

Re: mod_ssl in trunk with OpenSSL 0.9.7 as a minimum requirement?

2011-07-31 Thread Rainer Jung
On 31.07.2011 11:17, Kaspar Brand wrote: > Hi Rainer, > >> There was a similar discussion "RFC: drop support for OpenSSL < 1.0 in >> trunk/2.3?" on this list in May/June 2010. > > Thanks for the pointer! (Too long ago for me to remember, but should > have searched the archives, that's true.) No

Re: mod_ssl in trunk with OpenSSL 0.9.7 as a minimum requirement?

2011-07-31 Thread Rainer Jung
Hi Kaspar, On 31.07.2011 09:38, Kaspar Brand wrote: > I'm considering cleaning up some of the cert revocation checking code in > mod_ssl, in particular ssl_callback_SSLVerify_CRL(), which currently has > the following comment: > > * OpenSSL provides the general mechanism to deal with CRLs but do

Re: [NOTICE] Intent to T&R httpd 2.3.14

2011-07-30 Thread Rainer Jung
I did some test builds for r1151214 on Solaris 10 Sparc: - Building against APR trunk with "reallyall" failed because of missing ldap support in apr trunk. Building against with "all" and disabled ldap works - For static builds it seems mod_watchdog and mod_proxy_fdpass are still build as dynamic

Re: [vote] mod_ldap

2011-07-11 Thread Rainer Jung
On 12.07.2011 00:35, Stefan Fritsch wrote: > On Monday 11 July 2011, William A. Rowe Jr. wrote: >> On 7/10/2011 5:34 PM, Roy T. Fielding wrote: > Especially r1142938 needs checking, I think I may have accidentally > reverted some bits from that when resolving some conflicts. I can check and reap

Re: [vote] mod_ldap

2011-07-08 Thread Rainer Jung
On 07.07.2011 18:55, William A. Rowe Jr. wrote: > Only presently available options are available as choices to end this > now unproductive discussion [any heretofore unseen complete abstration > of ldap cannot be considered with no patches offered]. This vote is > limited to the scope of the httpd

Re: reallyall vs. all vs. most

2011-07-06 Thread Rainer Jung
On 05.07.2011 23:21, Stefan Fritsch wrote: > On Tuesday 05 July 2011, Igor Galić wrote: >> even though it means that "reallyall" will yield different >> results on different systems > > That was the point of "reallyall". Build everything that is possible > with the installed dependencies. It woul

Re: RUNPATH for module dependencies on Unix/Linux

2011-07-05 Thread Rainer Jung
> I will think about a good way, how users can pass additional LDADD > flags. Putting the "-R ..." into the LDFLAGS seems to be too heavy, > because then the RPATH of every module etc. will contain the given > directory. The real problematic cases are only mod_lua and in rare > circumstances (you w

Re: RUNPATH for module dependencies on Unix/Linux

2011-07-05 Thread Rainer Jung
Hi Joe, On 05.07.2011 09:46, Joe Orton wrote: > On Mon, Jul 04, 2011 at 09:07:49PM +0200, Rainer Jung wrote: >> Hi everyone, >> >> a couple of modules have additional external dependencies: >> >> mod_deflate: zlib >> mod_lua: lua >> mod_serf: serf >

Re: svn commit: r1142739 - in /httpd/httpd/trunk: CHANGES configure.in

2011-07-04 Thread Rainer Jung
Hi Igor, On 05.07.2011 03:00, Igor Galić wrote: > I'm not sure if it's this change that breaks the build > or if it was always broken but: It broke it, but ... > /opt/bw/share/apr/build/libtool --silent --mode=link gcc -std=gnu99 -pthread > -mtune=native -march=native -O3 -g -Wl,--as-neede

Re: distcache

2011-07-04 Thread Rainer Jung
Good morning Igor :) On 05.07.2011 03:09, Igor Galić wrote: > > When trying to compile httpd with --enable-mods-shared=reallyall > configure will currently abort on my system because it doesn't > find distcache. Yup, sorry, used AC_MSG_ERROR instead of AC_MSG_WARN for failure message during dist

Question about mod_privileges

2011-07-04 Thread Rainer Jung
When testing 2.3.13 I built mod_privileges. I notices that I couldn't load it if the process was run by a non root user. Platform was Solaris 10, and the problem was, that the module wants to add proc_setid to PRIV_PERMITTED. Of course the module needs this privilege to work and a normal user does

Re: Windows 2.3.13 :: SSLSessionCache: 'shm' session cache not supported

2011-07-04 Thread Rainer Jung
On 04.07.2011 16:55, Steffen wrote: > Can some tell me how now to configure SSLSessionCache: 'shm' > > In the shipped ssl.conf the following line is there: > SSLSessionCache"shmcb:c:/Apache23/logs/ssl_scache(512000)" > > But that does not work, get the error: > SSLSessionCache: 'shm' sess

RUNPATH for module dependencies on Unix/Linux

2011-07-04 Thread Rainer Jung
Hi everyone, a couple of modules have additional external dependencies: mod_deflate: zlib mod_lua: lua mod_serf: serf mod_socache_dc: distcache At the moment, the compiled modules do not contain any RPATH/RUNPATH info except when the libraries themselves are installed as libtool libraries, i.e.

Re: [VOTE] Release Apache httpd-2.3.13 as beta

2011-07-04 Thread Rainer Jung
On 28.06.2011 19:27, Jim Jagielski wrote: > The candidate tarballs for 2.3.13 are now available at: > > http://httpd.apache.org/dev/dist/ > > I'm opening up a vote to release these as 2.3.13-beta, with > a hope to push on for a quick GA after maybe another beta > release in the near future.

Re: mod_lua Filter Hook?

2011-06-23 Thread Rainer Jung
On 22.06.2011 22:39, Stefan Fritsch wrote: > On Thursday 16 June 2011, Brian McCallister wrote: >> My personal use cases for mod_lua are not content generation >> oriented, but you should be able to do content generation with it. >> I suspect that if you are doing "serious apps" then you will get >

Re: Time for httpd 2.3.13...? And 2.4.0??

2011-06-18 Thread Rainer Jung
On 18.06.2011 14:44, Stefan Fritsch wrote: > On Friday 17 June 2011, William A. Rowe Jr. wrote: >> On 6/17/2011 6:39 AM, Jim Jagielski wrote: >>> Are we ready for the next beta release??? >>> >>> And Maybe Even The Next Release being GA?? >> >> 2.3.13 soon, I'll fix the mod_ldap load ordering quirk

Re: 2.2.19 (and probably earlier) won't let you make non-ssl vhosts on 443?

2011-05-26 Thread Rainer Jung
On 26.05.2011 11:10, Issac Goldstand wrote: > I just upgraded a machine from 2.2.8 to 2.2.19 and suddenly Apache > wouldn't let me run non-SSL vhosts on port 443. A snippet like below: > > > DocumentRoot /home/foo/httpdocs > ServerName foo > > allow from all > Options +Indexes > > > > Sudden

<    4   5   6   7   8   9   10   11   12   13   >