[Bug 1358305] [NEW] harden default ssl settings

2014-08-18 Thread Christoph_vW
Public bug reported: Apache 2 default ssl configuration should be hardened to get better overall ssl security my proposal: /etc/apache2/mods-available/ssl.conf SSLHonorCipherOrder on SSLCipherSuite

[Bug 1358305] [NEW] harden default ssl settings

2014-08-18 Thread Christoph_vW
Public bug reported: Apache 2 default ssl configuration should be hardened to get better overall ssl security my proposal: /etc/apache2/mods-available/ssl.conf SSLHonorCipherOrder on SSLCipherSuite

[Bug 1206907] Re: drupal7 packaged version 7.12 on Ubuntu warns of security upgrade

2013-12-19 Thread Christoph_vW
Please sync with Debian 7: http://ftp-master.metadata.debian.org/changelogs//main/d/drupal7/drupal7_7.14-2+deb7u1_changelog -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/1206907 Title: drupal7

[Bug 1206907] Re: drupal7 packaged version 7.12 on Ubuntu warns of security upgrade

2013-12-13 Thread Christoph_vW
** Changed in: drupal7 (Ubuntu) Status: Expired = Confirmed -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/1206907 Title: drupal7 packaged version 7.12 on Ubuntu warns of security upgrade To

[Bug 1197884] Re: apache2.2 SSL has no forward-secrecy: need ECDHE keys

2013-09-10 Thread Christoph_vW
Don't you think it would be better to backport this for Apache 2.2? What about all the Ubuntu 12.04 LTS versions which will be running for some more years? -- You received this bug notification because you are a member of Ubuntu Server Team, which is subscribed to apache2 in Ubuntu.

[Bug 1197884] Re: apache2.2 SSL has no forward-secrecy: need ECDHE keys

2013-09-10 Thread Christoph_vW
Don't you think it would be better to backport this for Apache 2.2? What about all the Ubuntu 12.04 LTS versions which will be running for some more years? -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to the bug report.

[Bug 1219804] Re: Support custom DH parameter file in apache 2.4

2013-09-05 Thread Christoph_vW
http://blog.ivanristic.com/2013/08/increasing-dhe-strength-on- apache.html -- You received this bug notification because you are a member of Ubuntu Server Team, which is subscribed to apache2 in Ubuntu. https://bugs.launchpad.net/bugs/1219804 Title: Support custom DH parameter file in apache

[Bug 1219804] Re: Support custom DH parameter file in apache 2.4

2013-09-05 Thread Christoph_vW
http://blog.ivanristic.com/2013/08/increasing-dhe-strength-on- apache.html -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/1219804 Title: Support custom DH parameter file in apache 2.4 To manage

[Bug 1219804] [NEW] Support custom DH parameter file in apache 2.4

2013-09-02 Thread Christoph_vW
Public bug reported: Support custom DH parameter file in apache 2.4: https://issues.apache.org/bugzilla/show_bug.cgi?id=49559 This would allow for better Forward Secrecy Support without having a weak key Exchange (for DHE chiphers) . ** Affects: apache2 (Ubuntu) Importance: Undecided

[Bug 1219804] [NEW] Support custom DH parameter file in apache 2.4

2013-09-02 Thread Christoph_vW
Public bug reported: Support custom DH parameter file in apache 2.4: https://issues.apache.org/bugzilla/show_bug.cgi?id=49559 This would allow for better Forward Secrecy Support without having a weak key Exchange (for DHE chiphers) . ** Affects: apache2 (Ubuntu) Importance: Undecided

[Bug 939300] Re: Update Apache to 2.4

2013-08-27 Thread Christoph_vW
I would like to see this patch included as well: https://issues.apache.org/bugzilla/show_bug.cgi?id=49559 This would allow for better Forward Secrecy Support without having a weak key exchange. ** Bug watch added: Apache Software Foundation Bugzilla #49559

[Bug 939300] Re: Update Apache to 2.4

2013-08-27 Thread Christoph_vW
I would like to see this patch included as well: https://issues.apache.org/bugzilla/show_bug.cgi?id=49559 This would allow for better Forward Secrecy Support without having a weak key exchange. ** Bug watch added: Apache Software Foundation Bugzilla #49559

[Bug 965371] Re: HTTPS requests fail on sites which immediately close the connection if TLS 1.1 negotiation is attempted, on Ubuntu 12.04

2012-11-28 Thread Christoph_vW
this seems to be related: http://rt.openssl.org/Ticket/Display.html?id=2811 Changes between 1.0.1c and 1.0.1d [xx XXX ] *) Fix possible deadlock when decoding public keys. [Steve Henson] *) Don't use TLS 1.0 record version number in initial client hello if renegotiating.

[Bug 1011921] Re: package isc-dhcp-server 4.1.ESV-R4-0ubuntu5.1 failed to install/upgrade: subprocess installed post-installation script returned error exit status 1

2012-07-19 Thread Christoph_vW
*** This bug is a duplicate of bug 979720 *** https://bugs.launchpad.net/bugs/979720 I have the same issue: /var/log/upstart/isc-dhcp-server.log The error was: Internet Systems Consortium DHCP Server 4.1-ESV-R4 Copyright 2004-2011 Internet Systems Consortium. All rights reserved. For info,

[Bug 965371] Re: HTTPS requests fail on some sites on Ubuntu 12.04

2012-04-29 Thread Christoph_vW
the fixes from openssl 1.0.1b should go into 12.04 - it looks like otherwise TLS 1.1 will not work... -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/965371 Title: HTTPS requests fail on some sites

[Bug 988819] Re: wrong path to libxml2.so.2 in mod_security

2012-04-27 Thread Christoph_vW
** Tags added: precise -- You received this bug notification because you are a member of Ubuntu Server Team, which is subscribed to apache2 in Ubuntu. https://bugs.launchpad.net/bugs/988819 Title: wrong path to libxml2.so.2 in mod_security To manage notifications about this bug go to:

[Bug 989416] [NEW] Regression: libvirt kvm guest works only when graphics is set

2012-04-27 Thread Christoph_vW
Public bug reported: When graphics is enabled in the libvirt xml file the virtual machine boots up fine , when it is disabled it does not work anymore. On Ubuntu 10.04 LTS is worked even with graphics disabled. It works with this setting: graphics type='vnc' autoport='yes' listen='127.0.0.1'/

[Bug 988819] Re: wrong path to libxml2.so.2 in mod_security

2012-04-27 Thread Christoph_vW
** Tags added: precise -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/988819 Title: wrong path to libxml2.so.2 in mod_security To manage notifications about this bug go to:

[Bug 989416] Re: Regression: libvirt kvm guest works only when graphics is set

2012-04-27 Thread Christoph_vW
Yes, I did not have the graphics tag in the xml file before. And I inserted it to see why the machine would not boot - but then it did... Guest is Ubuntu 10.04 LTS -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu.

[Bug 988819] [NEW] wrong path to libxml2.so.2 in mod_security

2012-04-26 Thread Christoph_vW
Public bug reported: service apache2 restart apache2: Syntax error on line 210 of /etc/apache2/apache2.conf: Syntax error on line 1 of /etc/apache2/mods-enabled/mod-security.load: Cannot load /usr/lib/libxml2.so.2 into server: /usr/lib/libxml2.so.2: cannot open shared object file: No such file

[Bug 988819] Re: wrong path to libxml2.so.2 in mod_security

2012-04-26 Thread Christoph_vW
Ubuntu 12.04 LTS ** Bug watch added: Debian Bug tracker #670247 http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=670247 -- You received this bug notification because you are a member of Ubuntu Server Team, which is subscribed to apache2 in Ubuntu. https://bugs.launchpad.net/bugs/988819

[Bug 988819] Re: wrong path to libxml2.so.2 in mod_security

2012-04-26 Thread Christoph_vW
http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=670247 -- You received this bug notification because you are a member of Ubuntu Server Team, which is subscribed to apache2 in Ubuntu. https://bugs.launchpad.net/bugs/988819 Title: wrong path to libxml2.so.2 in mod_security To manage

[Bug 988819] [NEW] wrong path to libxml2.so.2 in mod_security

2012-04-26 Thread Christoph_vW
Public bug reported: service apache2 restart apache2: Syntax error on line 210 of /etc/apache2/apache2.conf: Syntax error on line 1 of /etc/apache2/mods-enabled/mod-security.load: Cannot load /usr/lib/libxml2.so.2 into server: /usr/lib/libxml2.so.2: cannot open shared object file: No such file

[Bug 988819] Re: wrong path to libxml2.so.2 in mod_security

2012-04-26 Thread Christoph_vW
http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=670247 -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/988819 Title: wrong path to libxml2.so.2 in mod_security To manage notifications about this

[Bug 988819] Re: wrong path to libxml2.so.2 in mod_security

2012-04-26 Thread Christoph_vW
Ubuntu 12.04 LTS ** Bug watch added: Debian Bug tracker #670247 http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=670247 -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/988819 Title: wrong path to

[Bug 965371] Re: HTTPS requests fail on some sites on Ubuntu 12.04

2012-04-02 Thread Christoph_vW
Isn't there a better solutution than disabling TLS 1.2 completely in openssl? I need TLS 1.1 and 1.2 to monitor my servers with icinga... Better force the admins of the broken servers to fix their stuff... -- You received this bug notification because you are a member of Ubuntu Bugs, which is

[Bug 958430] [NEW] TLS 1.1 support

2012-03-18 Thread Christoph_vW
Public bug reported: Please use openssl 1.0.1 in Ubuntu 12.04 LTS. I really need TLS 1.1 support and cannot wait another 2 years. ** Affects: openssl (Ubuntu) Importance: Undecided Status: New ** Tags: openssl -- You received this bug notification because you are a member of

[Bug 703812] [NEW] missing ldap support in squidguard

2011-01-16 Thread Christoph_vW
Public bug reported: Binary package hint: squidguard package: squidguard 1.2.0-8.4ubuntu1.0.10.04.1 release: Ubuntu 10.04.1 LTS Issue: syntax or parsing error when the ldapsearch line is read in. from http://www.squidguard.org/Doc/ldap.html: In order to use LDAP functionalities the system

[Bug 703812] Re: missing ldap support in squidguard

2011-01-16 Thread Christoph_vW
wrong line copied from squidguard page - should be this one: Before you compile squidGuard you must run configure with the ldap option activated -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/703812

[Bug 703812] Re: missing ldap support in squidguard

2011-01-16 Thread Christoph_vW
crap - http://www.squidguard.org/Doc/authentication.html states you need at least version 1.2.1 for ldap support. Looks like they should update their ldap page... Would it be possible to ship the minor upgrade to 1.2.1 in 10.04 LTS? -- You received this bug notification because you are a member

[Bug 459072] [NEW] missing options -le and -be in mksquashfs

2009-10-23 Thread Christoph_vW
Public bug reported: Binary package hint: squashfs-tools mksquashfs is missing the options -le and -be in 9.10 RC These options are working in 9.04 and are even displayed in the mksquashfs manpage on 9.10 squashfs-tools: 1:4.0-1 ** Affects: squashfs (Ubuntu) Importance: Undecided

[Bug 459072] Re: missing options -le and -be in mksquashfs

2009-10-23 Thread Christoph_vW
It looks like v4 removed big endian support. In this case the man page should be updated accordingly. -- missing options -le and -be in mksquashfs https://bugs.launchpad.net/bugs/459072 You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. --