Re: apache 1.3.12 with newer mod_ssl

2002-04-11 Thread Jeff

http://www.modssl.org/docs/2.8/ssl_faq.html#ToC5

quote: "And this also means you only can apply this mod_ssl version to
exactly this Apache version "

Regards
Jeff
- Original Message -
From: <[EMAIL PROTECTED]>
To: <[EMAIL PROTECTED]>
Sent: Thursday, April 11, 2002 1:21 AM
Subject: apache 1.3.12 with newer mod_ssl


>
> What are the issues with using a newer mod_ssl with an older apache?
>
> I need to use Apache 1.3.12 for a project and am wondering if I can use
> the newer mod_ssl releases?  Are there bugs or vulnerabilities with the
> mod_ssl for Apache 1.3.12 or is it safe to use the older mod_ssl?
>
> __
> Apache Interface to OpenSSL (mod_ssl)   www.modssl.org
> User Support Mailing List  [EMAIL PROTECTED]
> Automated List Manager[EMAIL PROTECTED]
>

__
Apache Interface to OpenSSL (mod_ssl)   www.modssl.org
User Support Mailing List  [EMAIL PROTECTED]
Automated List Manager[EMAIL PROTECTED]



Re: apache 1.3.12 with newer mod_ssl

2002-04-11 Thread Owen Boyle

[EMAIL PROTECTED] wrote:
> 
> What are the issues with using a newer mod_ssl with an older apache?
> 
> I need to use Apache 1.3.12 for a project and am wondering if I can use
> the newer mod_ssl releases?  Are there bugs or vulnerabilities with the
> mod_ssl for Apache 1.3.12 or is it safe to use the older mod_ssl?

AFAIK, mod_ssl is tweaked with every new apache version. If you look on
the mod_ssl site you will see that each distro is tagged with the apache
version to which it applies. I would not expect mod_ssl-2.8.8-1.3.24 to
work with apache 1.3.12.

Why do you need to use 1.3.12? If your binary was not compiled with EAPI
(needed for mod_ssl) you will need to recompile anyway.

Rgds,

Owen Boyle.
__
Apache Interface to OpenSSL (mod_ssl)   www.modssl.org
User Support Mailing List  [EMAIL PROTECTED]
Automated List Manager[EMAIL PROTECTED]



Re: apache 1.3.12 with newer mod_ssl

2002-04-11 Thread Cliff Woolley

On Wed, 10 Apr 2002 [EMAIL PROTECTED] wrote:

> What are the issues with using a newer mod_ssl with an older apache?

First of all, it would be difficult to get the patches to apply without
heavy manual assistance.

> I need to use Apache 1.3.12 for a project and am wondering if I can use
> the newer mod_ssl releases?  Are there bugs or vulnerabilities with the
> mod_ssl for Apache 1.3.12 or is it safe to use the older mod_ssl?

Secondly, there are both bugs and (relatively minor) vulnerabilities in
older versions of both mod_ssl and Apache.

--Cliff

__
Apache Interface to OpenSSL (mod_ssl)   www.modssl.org
User Support Mailing List  [EMAIL PROTECTED]
Automated List Manager[EMAIL PROTECTED]