Fwd: [users@httpd] mod_authz_dbd regression in apache 2.4.12?

2015-05-12 Thread Yann Ylavic
This as been raised on users@. -- Forwarded message -- From: Yann Ylavic ylavic@gmail.com Date: Tue, May 12, 2015 at 10:09 AM On Mon, May 11, 2015 at 10:54 PM, Michel Stam mic...@reverze.net wrote: I was tinkering over the weekend with mod_authz_dbd and mysql, and i could

Re: Solving mutex concerns with OCSP stapling

2015-05-12 Thread Jeff Trawick
On 05/06/2015 08:19 PM, Jeff Trawick wrote: On 05/03/2015 09:58 PM, Jeff Trawick wrote: Your thoughts on the following? Current OCSP behavior that I think needs to be fixed: mod_ssl holds the single stapling global mutex when looking up a cached entry, deserializing it, checking validity,

Re: svn commit: r1679032 - in /httpd/httpd/trunk: CHANGES docs/manual/mod/mod_ssl.xml modules/ssl/mod_ssl.c modules/ssl/ssl_engine_config.c modules/ssl/ssl_private.h modules/ssl/ssl_util_stapling.c

2015-05-12 Thread Yann Ylavic
On Tue, May 12, 2015 at 8:59 PM, traw...@apache.org wrote: Author: trawick Date: Tue May 12 18:59:29 2015 New Revision: 1679032 URL: http://svn.apache.org/r1679032 Log: mod_ssl OCSP Stapling: Don't block initial handshakes while refreshing the OCSP response for a different certificate.

Re: silly ab patch for SNI and OCSP stapling

2015-05-12 Thread Yann Ylavic
+1, to both! Thanks. On Tue, May 12, 2015 at 9:31 PM, Jeff Trawick traw...@gmail.com wrote: ... where OCSP stapling means get the server to do the related work but don't care what you get back. Perhaps this doesn't save any time for anybody that would want to test such a thing, but who

silly ab patch for SNI and OCSP stapling

2015-05-12 Thread Jeff Trawick
... where OCSP stapling means get the server to do the related work but don't care what you get back. Perhaps this doesn't save any time for anybody that would want to test such a thing, but who knows? Index: support/ab.c ===

Re: svn commit: r1679032 - in /httpd/httpd/trunk: CHANGES docs/manual/mod/mod_ssl.xml modules/ssl/mod_ssl.c modules/ssl/ssl_engine_config.c modules/ssl/ssl_private.h modules/ssl/ssl_util_stapling.c

2015-05-12 Thread Jeff Trawick
On 05/12/2015 03:32 PM, Yann Ylavic wrote: On Tue, May 12, 2015 at 8:59 PM, traw...@apache.org wrote: Author: trawick Date: Tue May 12 18:59:29 2015 New Revision: 1679032 URL: http://svn.apache.org/r1679032 Log: mod_ssl OCSP Stapling: Don't block initial handshakes while refreshing the OCSP

Re: [users@httpd] mod_authz_dbd regression in apache 2.4.12?

2015-05-12 Thread Yann Ylavic
(CC'ing Michel, sorry for the resend, my initial omission) On Tue, May 12, 2015 at 10:41 AM, Yann Ylavic ylavic@gmail.com wrote: This as been raised on users@. -- Forwarded message -- From: Yann Ylavic ylavic@gmail.com Date: Tue, May 12, 2015 at 10:09 AM On Mon, May