<?xml version="1.0" encoding="iso-8859-1" ?>
<?xml-stylesheet title="XSL_formatting" type="text/xsl" href="/images/lists/rssstyle2.xsl"?>
<rss version="2.0">
<channel>
<title>Apache | Dev</title>
<description>Mailing List Archive by Gossamer Threads</description>
<link>http://www.gossamer-threads.com/lists/apache/dev/</link>
<language>en-us</language>
<copyright>(c) Gossamer Threads Inc. All rights reserved.</copyright>
<lastBuildDate>08 Nov  2009 19:38:34 -0800</lastBuildDate>
<ttl>120</ttl>
<image>
<title>Gossamer Threads | Apache | Dev</title>
<width>75</width>
<height>23</height>
<link>http://www.gossamer-threads.com/lists/apache/dev/</link>
<url>http://www.gossamer-threads.com/images/lists/rss_logo.jpg</url>
</image>
<item>
<title>Re: [UPDATED] Re: [PATCH] new default SSLCipherSuite and SSL BrowserMatch configuration</title>
<description>Stefan Fritsch wrote on 2009-11-07 11:24:03: &amp;gt; Shouldn&amp;#039;t you use something like this? &amp;gt; &amp;gt; BrowserMatch &amp;quot;MSIE [2-5]&amp;quot; nokeepalive ssl-unclean-shutdown</description>
<pubDate>08 Nov  2009 16:53:01 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/apache/dev/376443</link>
</item><item>
<title>Bug report for Apache httpd-2 [2009/11/08]</title>
<description>+---------------------------------------------------------------------------+ | Bugzilla Bug ID</description>
<pubDate>08 Nov  2009 15:08:17 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/apache/dev/376442</link>
</item><item>
<title>Bug report for Apache httpd-1.3 [2009/11/08]</title>
<description>+---------------------------------------------------------------------------+ | Bugzilla Bug ID</description>
<pubDate>08 Nov  2009 15:08:16 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/apache/dev/376441</link>
</item><item>
<title>Re: Server Gated Certs (Was: TLS renegotiation attack, mod_ssl and OpenSSL)</title>
<description>Dirk-Willem van Gulik wrote: &amp;gt; Dirk-Willem van Gulik wrote: &amp;gt; &amp;gt;&amp;gt; Actually Steve - you may know - what besides the obvious &amp;gt;&amp;gt; &amp;gt;&amp;gt; extendedKeyUsage=nsSG</description>
<pubDate>08 Nov  2009 04:47:06 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/apache/dev/376436</link>
</item><item>
<title>Re: Httpd 3.0 or something else</title>
<description>On 06/11/09 20:07, Jim Jagielski wrote: &amp;gt; &amp;gt;&amp;gt; &amp;gt;&amp;gt; I&amp;#039;d like we remove the entire forwarding proxy stuff &amp;gt;&amp;gt; for example. &amp;gt; So we have mod_forward_proxy an</description>
<pubDate>08 Nov  2009 00:56:03 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/apache/dev/376433</link>
</item><item>
<title>Re: svn commit: r833738 - in /httpd/httpd/trunk: CHANGES docs/manual/mod/mod_log_config.xml modules/loggers/mod_log_config.c</title>
<description>On 11/07/2009 08:19 PM, sf@apache.org wrote: &amp;gt; Author: sf &amp;gt; Date: Sat Nov 7 19:19:10 2009 &amp;gt; New Revision: 833738 &amp;gt; &amp;gt; URL: http://svn.apache.org/view</description>
<pubDate>07 Nov  2009 17:45:22 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/apache/dev/376432</link>
</item><item>
<title>Re: [PATCH] mod_ssl: improving session caching for SNI configurations</title>
<description>Kaspar Brand wrote: &amp;gt; Dr Stephen Henson wrote: &amp;gt;&amp;gt; A few comments about that: &amp;gt; &amp;gt; Thanks for the review! &amp;gt; &amp;gt;&amp;gt; These are cryptographic keys (or at lea</description>
<pubDate>07 Nov  2009 09:35:39 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/apache/dev/376421</link>
</item><item>
<title>Re: [PATCH] mod_ssl: improving session caching for SNI configurations</title>
<description>Dr Stephen Henson wrote: &amp;gt; A few comments about that: Thanks for the review! &amp;gt; These are cryptographic keys (or at least the HMAC and AES keys are)</description>
<pubDate>07 Nov  2009 06:56:00 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/apache/dev/376417</link>
</item><item>
<title>Re: [PATCH] mod_ssl: improving session caching for SNI configurations</title>
<description>Kaspar Brand wrote:  +#if !defined(OPENSSL_NO_TLSEXT) &amp;amp;&amp;amp; OPENSSL_VERSION_NUMBER &amp;lt; 0x009080d0 +#define TICK_KEYS_LEN  sizeof(((SSL_CTX *)0)-&amp;gt;tlsext_t</description>
<pubDate>07 Nov  2009 04:21:56 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/apache/dev/376416</link>
</item><item>
<title>Re: [PATCH] mod_ssl: improving session caching for SNI configurations</title>
<description>Kaspar Brand wrote: &amp;gt; Does that sound reasonable? If so, I would prepare a new patch with &amp;gt; SSL_CTX_set_tlsext_ticket_keys and the new config directiv</description>
<pubDate>07 Nov  2009 03:06:28 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/apache/dev/376415</link>
</item><item>
<title>Re: [UPDATED] Re: [PATCH] new default SSLCipherSuite and SSL BrowserMatch configuration</title>
<description>On Saturday 07 November 2009, Lars Eilebrecht wrote: &amp;gt; Ruediger Pluem wrote on 2009-11-07 00:29:41: &amp;gt; &amp;gt; &amp;gt; -BrowserMatch &amp;quot;.*MSIE.*&amp;quot; \ &amp;gt; &amp;gt; &amp;gt; -     n</description>
<pubDate>07 Nov  2009 02:24:03 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/apache/dev/376414</link>
</item><item>
<title>Re: Pull mod_unique_id out of default build?</title>
<description>On 7 Nov 2009, at 06:25, Brian Rectanus wrote: &amp;gt; Yes, mod_security requires it. Many who use mod_security may not even &amp;gt; realize it. It would be a</description>
<pubDate>07 Nov  2009 01:28:10 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/apache/dev/376429</link>
</item><item>
<title>Re: [UPDATED] Re: [PATCH] new default SSLCipherSuite and SSL BrowserMatch configuration</title>
<description>On 11/07/2009 02:21 AM, Lars Eilebrecht wrote: &amp;gt; Ruediger Pluem wrote on 2009-11-07 00:29:41: &amp;gt; &amp;gt;&amp;gt;&amp;gt; -BrowserMatch &amp;quot;.*MSIE.*&amp;quot; \ &amp;gt;&amp;gt;&amp;gt; -     nokeepal</description>
<pubDate>07 Nov  2009 01:09:26 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/apache/dev/376413</link>
</item><item>
<title>Re: Pull mod_unique_id out of default build?</title>
<description>On Thu, Nov 5, 2009 at 11:02 PM, Ruediger Pluem &amp;lt;rpluem@apache.org&amp;gt; wrote: &amp;gt; &amp;gt; &amp;gt; On 11/06/2009 06:45 AM, Nick Kew wrote: &amp;gt;&amp;gt; On 6 Nov 2009, at 05:30, S</description>
<pubDate>06 Nov  2009 22:25:31 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/apache/dev/376412</link>
</item><item>
<title>Re: [UPDATED] Re: [PATCH] new default SSLCipherSuite and SSL BrowserMatch configuration</title>
<description>Ruediger Pluem wrote on 2009-11-07 00:29:41: &amp;gt; &amp;gt; -BrowserMatch &amp;quot;.*MSIE.*&amp;quot; \ &amp;gt; &amp;gt; -     nokeepalive ssl-unclean-shutdown \ &amp;gt; &amp;gt; -     downgrade-</description>
<pubDate>06 Nov  2009 17:21:45 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/apache/dev/376410</link>
</item><item>
<title>CVE-2009-3555 - apache/mod_ssl vulnerability and mitigation (final draft)</title>
<description>-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 Subject: CVE-2009-3555 - apache/mod_ssl vulnerability and mitigation Apache httpd is affected by CVE-2</description>
<pubDate>06 Nov  2009 17:21:08 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/apache/dev/376409</link>
</item><item>
<title>[PATCH] Enable Elliptic Curve Keys and ciphers</title>
<description>Folks, This is Vipul Gupta&amp;#039;s patch (Bugzilla 40132) against today&amp;#039;s trunk.  This compiles and works under some manual testing. Looks like OpenSSL</description>
<pubDate>06 Nov  2009 16:41:02 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/apache/dev/376408</link>
</item><item>
<title>Re: svn commit: r833582 - in /httpd/httpd/trunk/modules/ssl:	ssl_engine_init.c ssl_engine_io.c ssl_engine_kernel.c ssl_private.h</title>
<description>Joe Orton wrote: &amp;gt; Awesome, thanks a lot! &amp;gt; &amp;gt; +1 for backport to 2.2.x here too. +1 here from me as well. So the trunk patch is     svn diff -r8</description>
<pubDate>06 Nov  2009 16:23:44 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/apache/dev/376407</link>
</item><item>
<title>Re: svn commit: r833582 - in /httpd/httpd/trunk/modules/ssl: ssl_engine_init.c ssl_engine_io.c ssl_engine_kernel.c ssl_private.h</title>
<description>On Sat, Nov 07, 2009 at 12:37:56AM +0100, Ruediger Pluem wrote: &amp;gt; On 11/06/2009 11:33 PM, jorton@apache.org wrote: &amp;gt; &amp;gt; Author: jorton &amp;gt; &amp;gt; Date: Fri No</description>
<pubDate>06 Nov  2009 16:08:18 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/apache/dev/376401</link>
</item><item>
<title>Re: [UPDATED] Re: [PATCH] new default SSLCipherSuite and SSL BrowserMatch configuration</title>
<description>On Fri, Nov 06, 2009 at 03:19:12PM -0800, Lars Eilebrecht wrote: &amp;gt; attached is a slightly different patch, it includes &amp;quot;!EXP&amp;quot; and I&amp;#039;ve &amp;gt; moved the dir</description>
<pubDate>06 Nov  2009 15:57:30 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/apache/dev/376400</link>
</item><item>
<title>Re: svn commit: r833582 - in /httpd/httpd/trunk/modules/ssl: ssl_engine_init.c ssl_engine_io.c ssl_engine_kernel.c ssl_private.h</title>
<description>On 11/06/2009 11:33 PM, jorton@apache.org wrote: &amp;gt; Author: jorton &amp;gt; Date: Fri Nov 6 22:33:19 2009 &amp;gt; New Revision: 833582 &amp;gt; &amp;gt; URL: http://svn.apache.</description>
<pubDate>06 Nov  2009 15:37:56 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/apache/dev/376399</link>
</item><item>
<title>Re: [UPDATED] Re: [PATCH] new default SSLCipherSuite and SSL BrowserMatch configuration</title>
<description>On 11/07/2009 12:19 AM, Lars Eilebrecht wrote: &amp;gt; Hi, &amp;gt; &amp;gt; attached is a slightly different patch, it includes &amp;quot;!EXP&amp;quot; and I&amp;#039;ve &amp;gt; moved the directive ou</description>
<pubDate>06 Nov  2009 15:29:41 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/apache/dev/376398</link>
</item><item>
<title>Re: TLS renegotiation attack, mod_ssl and OpenSSL</title>
<description>Joe Orton wrote: &amp;gt; On Fri, Nov 06, 2009 at 03:09:22AM +0000, Joe Orton wrote: &amp;gt;&amp;gt; A second hack, slightly less rough hack: &amp;gt; &amp;gt; I committed this in r833</description>
<pubDate>06 Nov  2009 15:28:03 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/apache/dev/376397</link>
</item><item>
<title>[UPDATED] Re: [PATCH] new default SSLCipherSuite and SSL BrowserMatch configuration</title>
<description>Hi, attached is a slightly different patch, it includes &amp;quot;!EXP&amp;quot; and I&amp;#039;ve moved the directive out of the vhost into the main server config (there&amp;#039;s not</description>
<pubDate>06 Nov  2009 15:19:12 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/apache/dev/376396</link>
</item><item>
<title>Re: TLS renegotiation attack, mod_ssl and OpenSSL</title>
<description>On Fri, Nov 06, 2009 at 03:09:22AM +0000, Joe Orton wrote: &amp;gt; A second hack, slightly less rough hack: I committed this in r833582 with some minor cha</description>
<pubDate>06 Nov  2009 14:49:14 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/apache/dev/376395</link>
</item>
</channel>
</rss>
