Re: Bug#733564: pu: apache2 with ECDHE support

2014-06-15 Thread Adam D. Barratt
Control: tags -1 + pending On Sun, 2014-05-25 at 17:55 +0200, Stefan Fritsch wrote: I have just uploaded apache2_2.2.22-13+deb7u2: Flagged for acceptance; sorry for the delay. apache2 (2.2.22-13+deb7u2) wheezy; urgency=medium * Backport support for SSL ECC keys and ECDH ciphers. For

Re: Bug#733564: pu: apache2 with ECDHE support

2014-06-15 Thread Paul Wise
On Mon, Jun 16, 2014 at 6:06 AM, Adam D. Barratt wrote: Control: tags -1 + pending On Sun, 2014-05-25 at 17:55 +0200, Stefan Fritsch wrote: I have just uploaded apache2_2.2.22-13+deb7u2: Flagged for acceptance; sorry for the delay. Awesome, thanks! apache2 (2.2.22-13+deb7u2) wheezy;

Re: Bug#733564: pu: apache2 with ECDHE support

2014-05-12 Thread Kurt Roeckx
On Wed, May 07, 2014 at 10:34:43PM +0100, Adam D. Barratt wrote: On Thu, 2014-05-01 at 15:59 +0200, Kurt Roeckx wrote: On Mon, Apr 14, 2014 at 09:57:21PM +0200, Stefan Fritsch wrote: Am Montag, 14. April 2014, 21:18:46 schrieb Philipp Kern: So I'd say that we should go and add ECDHE

Re: Bug#733564: pu: apache2 with ECDHE support

2014-05-12 Thread Adam D. Barratt
On Mon, 2014-05-12 at 23:29 +0200, Kurt Roeckx wrote: On Wed, May 07, 2014 at 10:34:43PM +0100, Adam D. Barratt wrote: + * Actually restart the services when restart-without-asking is set. +(Closes: #745801) That change wasn't previously mentioned and is not fixed in the unstable

Re: Bug#733564: pu: apache2 with ECDHE support

2014-05-07 Thread Adam D. Barratt
On Thu, 2014-05-01 at 15:59 +0200, Kurt Roeckx wrote: On Mon, Apr 14, 2014 at 09:57:21PM +0200, Stefan Fritsch wrote: Am Montag, 14. April 2014, 21:18:46 schrieb Philipp Kern: So I'd say that we should go and add ECDHE support to Apache as suggested and also patch OpenSSL for the OS X bug

Re: Bug#733564: pu: apache2 with ECDHE support

2014-05-01 Thread Kurt Roeckx
On Mon, Apr 14, 2014 at 09:57:21PM +0200, Stefan Fritsch wrote: Am Montag, 14. April 2014, 21:18:46 schrieb Philipp Kern: So I'd say that we should go and add ECDHE support to Apache as suggested and also patch OpenSSL for the OS X bug as the fingerprinting landed upstream and we would

Re: Bug#733564: pu: apache2 with ECDHE support

2014-04-27 Thread Philipp Kern
Hi, On Thu, Apr 17, 2014 at 06:46:00PM +0200, Kurt Roeckx wrote: I would like to also add support for the padding extention in stable. It's part of the 1.0.1g release. NACK, at least for now. Kind regards Philipp Kern signature.asc Description: Digital signature

Re: Bug#733564: pu: apache2 with ECDHE support

2014-04-27 Thread Kurt Roeckx
On Sun, Apr 27, 2014 at 03:39:13PM +0200, Philipp Kern wrote: Hi, On Thu, Apr 17, 2014 at 06:46:00PM +0200, Kurt Roeckx wrote: I would like to also add support for the padding extention in stable. It's part of the 1.0.1g release. NACK, at least for now. I might have not mailed this

Re: Bug#733564: pu: apache2 with ECDHE support

2014-04-17 Thread Kurt Roeckx
On Mon, Apr 14, 2014 at 10:07:30PM +0200, Kurt Roeckx wrote: On Mon, Apr 14, 2014 at 09:57:21PM +0200, Stefan Fritsch wrote: Am Montag, 14. April 2014, 21:18:46 schrieb Philipp Kern: So I'd say that we should go and add ECDHE support to Apache as suggested and also patch OpenSSL for the

Re: Bug#733564: pu: apache2 with ECDHE support

2014-04-14 Thread Philipp Kern
Hi, On Thu, Apr 10, 2014 at 08:02:46AM +0200, Stefan Fritsch wrote: Browser support in itself is not the interesting factor here. We are not disabling other ciphers, so clients not supporting ECDHE will just continue to work. The question is how many browsers have broken implemetations AND

Re: Bug#733564: pu: apache2 with ECDHE support

2014-04-14 Thread Stefan Fritsch
Am Montag, 14. April 2014, 21:18:46 schrieb Philipp Kern: So I'd say that we should go and add ECDHE support to Apache as suggested and also patch OpenSSL for the OS X bug as the fingerprinting landed upstream and we would merely replicate current upstream behavior. OK, sounds good. Kurt, if

Re: Bug#733564: pu: apache2 with ECDHE support

2014-04-14 Thread Kurt Roeckx
On Mon, Apr 14, 2014 at 09:57:21PM +0200, Stefan Fritsch wrote: Am Montag, 14. April 2014, 21:18:46 schrieb Philipp Kern: So I'd say that we should go and add ECDHE support to Apache as suggested and also patch OpenSSL for the OS X bug as the fingerprinting landed upstream and we would

Re: Bug#733564: pu: apache2 with ECDHE support

2014-04-10 Thread Stefan Fritsch
Am Montag, 30. Dezember 2013, 15:23:17 schrieb Kurt Roeckx: On Mon, Dec 30, 2013 at 01:41:31PM +0100, Cyril Brulebois wrote: Stefan Fritsch s...@sfritsch.de (2013-12-30): Am Sonntag, 29. Dezember 2013, 23:58:54 schrieb Kurt Roeckx: Adding ECDHE support in apache will probably require

Re: Re: Bug#733564: pu: apache2 with ECDHE support

2014-03-31 Thread Ralf Jung
Hi, This was added somewhere in a 2.3 version and so only part of a stable release in 2.4. This has been backported to 2.2.26 in the meantime: http://svn.apache.org/viewvc?view=revisionrevision=r1540727 more readable diff:

Re: Bug#733564: pu: apache2 with ECDHE support

2013-12-30 Thread Kurt Roeckx
On Mon, Dec 30, 2013 at 01:41:31PM +0100, Cyril Brulebois wrote: Stefan Fritsch s...@sfritsch.de (2013-12-30): Am Sonntag, 29. Dezember 2013, 23:58:54 schrieb Kurt Roeckx: Adding ECDHE support in apache will probably require backporting the patches for that. I'm not sure how much work

Bug#733564: pu: apache2 with ECDHE support

2013-12-29 Thread Kurt Roeckx
Package: release.debian.org User: release.debian@packages.debian.org Usertags: pu Severity: normal Hi, I would like to see apache in stable support ECDHE. This was added somewhere in a 2.3 version and so only part of a stable release in 2.4. The reason I want to see is ECDHE is that we