<?xml version="1.0" encoding="iso-8859-1" ?>
<?xml-stylesheet title="XSL_formatting" type="text/xsl" href="/images/lists/rssstyle2.xsl"?>
<rss version="2.0">
<channel>
<title>Apache | Dev</title>
<description>Mailing List Archive by Gossamer Threads</description>
<link>http://www.gossamer-threads.com/lists/apache/dev/</link>
<language>en-us</language>
<copyright>(c) Gossamer Threads Inc. All rights reserved.</copyright>
<lastBuildDate>07 Nov  2009 20:33:08 -0800</lastBuildDate>
<ttl>120</ttl>
<image>
<title>Gossamer Threads | Apache | Dev</title>
<width>75</width>
<height>23</height>
<link>http://www.gossamer-threads.com/lists/apache/dev/</link>
<url>http://www.gossamer-threads.com/images/lists/rss_logo.jpg</url>
</image>
<item>
<title>Re: svn commit: r833738 - in /httpd/httpd/trunk: CHANGES docs/manual/mod/mod_log_config.xml modules/loggers/mod_log_config.c</title>
<description>On 11/07/2009 08:19 PM, sf@apache.org wrote: &amp;gt; Author: sf &amp;gt; Date: Sat Nov 7 19:19:10 2009 &amp;gt; New Revision: 833738 &amp;gt; &amp;gt; URL: http://svn.apache.org/view</description>
<pubDate>07 Nov  2009 17:45:22 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/apache/dev/376432</link>
</item><item>
<title>CVE-2009-3555 - apache/mod_ssl vulnerability and mitigation (final draft)</title>
<description>-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 Subject: CVE-2009-3555 - apache/mod_ssl vulnerability and mitigation Apache httpd is affected by CVE-2</description>
<pubDate>06 Nov  2009 17:21:08 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/apache/dev/376409</link>
</item><item>
<title>[PATCH] Enable Elliptic Curve Keys and ciphers</title>
<description>Folks, This is Vipul Gupta&amp;#039;s patch (Bugzilla 40132) against today&amp;#039;s trunk.  This compiles and works under some manual testing. Looks like OpenSSL</description>
<pubDate>06 Nov  2009 16:41:02 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/apache/dev/376408</link>
</item><item>
<title>Re: svn commit: r833582 - in /httpd/httpd/trunk/modules/ssl: ssl_engine_init.c ssl_engine_io.c ssl_engine_kernel.c ssl_private.h</title>
<description>On 11/06/2009 11:33 PM, jorton@apache.org wrote: &amp;gt; Author: jorton &amp;gt; Date: Fri Nov 6 22:33:19 2009 &amp;gt; New Revision: 833582 &amp;gt; &amp;gt; URL: http://svn.apache.</description>
<pubDate>06 Nov  2009 15:37:56 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/apache/dev/376399</link>
</item><item>
<title>[UPDATED] Re: [PATCH] new default SSLCipherSuite and SSL BrowserMatch configuration</title>
<description>Hi, attached is a slightly different patch, it includes &amp;quot;!EXP&amp;quot; and I&amp;#039;ve moved the directive out of the vhost into the main server config (there&amp;#039;s not</description>
<pubDate>06 Nov  2009 15:19:12 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/apache/dev/376396</link>
</item><item>
<title>Updated draft announcement apache.</title>
<description>With some feedback from various folks. Thanks, Dw. Apache httpd is affected by CVE-2009-3555[1] (The SSL Injectin or MiM attack[2]). We strongly</description>
<pubDate>06 Nov  2009 14:13:14 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/apache/dev/376385</link>
</item><item>
<title>[PATCH] new default SSLCipherSuite and SSL BrowserMatch configuration</title>
<description>Hi, I would like to propose the attached patch for inclusion in 2.2 (I&amp;#039;ll commit to trunk soon unless I&amp;#039;m getting any -1s in response to this email).</description>
<pubDate>06 Nov  2009 13:04:01 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/apache/dev/376378</link>
</item><item>
<title>Pull mod_unique_id out of default build?</title>
<description>Folks, Maybe my understanding is limited and my fu is weak, but I have  personally never had a use for mod_unique_id. The only thing it does  for</description>
<pubDate>05 Nov  2009 21:30:00 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/apache/dev/376339</link>
</item><item>
<title>Server Gated Certs (Was: TLS renegotiation attack, mod_ssl and OpenSSL)</title>
<description>So with Joe his patch doing the right thing it seems (would be nice if we could get Ben or the OpenSSL guys to confirm that) - that we propably only</description>
<pubDate>05 Nov  2009 17:38:28 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/apache/dev/376328</link>
</item><item>
<title>TLS renegotiation attack, mod_ssl and OpenSSL</title>
<description>With reference to the issue described here: http://www.ietf.org/mail-archive/web/tls/current/msg03948.html Considering the impact on mod_ssl, I&amp;#039;m ma</description>
<pubDate>05 Nov  2009 06:01:26 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/apache/dev/376279</link>
</item>
</channel>
</rss>
