OCSP validation of client leaf certificates only

2015-06-16 Thread Meelis Roos
Hello. We (Cybernetica AS) would like to add a feature to the Apache httpd mod_ssl module. This mail is about asking for advice and feasibility. We have a client who has a probem with CA chains. They have a local CA, local CA issues client certificates. Local CA has working OCSP responder

Re: TWS ; LWS permitted by RFC 7230 4.1.1? Apparently, no.

2015-06-16 Thread William A Rowe Jr
On Jun 15, 2015 6:11 PM, Roy T. Fielding field...@gbiv.com wrote: On Jun 15, 2015, at 9:33 AM, William A Rowe Jr wr...@rowe-clan.net wrote: Reviewing the spec, I cannot find where Sambar server is permitted to insert whitespace. I further reviewed the ABNF appendix, and it does not appear

Re: TWS ; LWS permitted by RFC 7230 4.1.1? Apparently, no.

2015-06-16 Thread Jim Jagielski
Sooo in order to get 2.4.15 out, it would be nice to have a patch :)

Re: TWS ; LWS permitted by RFC 7230 4.1.1? Apparently, no.

2015-06-16 Thread Yann Ylavic
On Tue, Jun 16, 2015 at 7:22 PM, Jim Jagielski j...@jagunet.com wrote: Sooo in order to get 2.4.15 out, it would be nice to have a patch :) Isn't the one proposed in STATUS suitable (section SHOWSTOPPERS)? It has been positively tested by Steffen in [1] and also passes the new framework

Re: TWS ; LWS permitted by RFC 7230 4.1.1? Apparently, no.

2015-06-16 Thread William A Rowe Jr
Note in STATUS I've requested that you split the approved patch from security@ that seemed to be lost in long and winding patch versioning from the spaces accepted. A patch should correct one thing, not several, it makes these too difficult to review when folks have a small window of free time.

Re: TWS ; LWS permitted by RFC 7230 4.1.1? Apparently, no.

2015-06-16 Thread Yann Ylavic
On Tue, Jun 16, 2015 at 10:50 PM, Yann Ylavic ylavic@gmail.com wrote: On Tue, Jun 16, 2015 at 8:09 PM, William A Rowe Jr wr...@rowe-clan.net wrote: Note in STATUS I've requested that you split the approved patch from security@ that seemed to be lost in long and winding patch versioning

Re: SSLCertificateChainFile deprecation, still (was: svn commit: r1685371 - /httpd/httpd/branches/2.4.x/STATUS)

2015-06-16 Thread olli hauer
On 2015-06-16 13:39, Yann Ylavic wrote: On Mon, Jun 15, 2015 at 7:24 PM, olli hauer oha...@gmx.de wrote: As a side note, even I've read the Release Notes I was thankful to see my console was trashed with the deprecation warning ;) What I miss is a section on httpd.apache.org/docs/2.4/ with

Re: TWS ; LWS permitted by RFC 7230 4.1.1? Apparently, no.

2015-06-16 Thread Yann Ylavic
On Tue, Jun 16, 2015 at 8:09 PM, William A Rowe Jr wr...@rowe-clan.net wrote: Note in STATUS I've requested that you split the approved patch from security@ that seemed to be lost in long and winding patch versioning from the spaces accepted. A patch should correct one thing, not several, it

Re: ********* Re: [VOTE] Release Apache httpd 2.4.14 as GA

2015-06-16 Thread Steffen
Works with 2.4.x patch: http://people.apache.org/~ylavic/httpd-2.4.x-ap_http_filter_chunked.patch -Original Message- From: Yann Ylavic Sent: Sunday, June 14, 2015 3:27 AM Newsgroups: gmane.comp.apache.devel To: dev@httpd.apache.org Subject: Re: * Re: [VOTE] Release Apache

Re: SSLCertificateChainFile deprecation, still (was: svn commit: r1685371 - /httpd/httpd/branches/2.4.x/STATUS)

2015-06-16 Thread Yann Ylavic
On Mon, Jun 15, 2015 at 7:24 PM, olli hauer oha...@gmx.de wrote: As a side note, even I've read the Release Notes I was thankful to see my console was trashed with the deprecation warning ;) What I miss is a section on httpd.apache.org/docs/2.4/ with a link list what has changed since