SSL related DoS

2011-04-16 Thread Chris Hill
Dear Apache httpd dev list, There have been previous posts on this topic (I've initiated some in both OpenSSL and Apache mailing lists), but I'd like to now just narrow the topic down to what seems to be the most relevant points for which there are not yet answers. We need you (the smart folks ;)

Re: SSL related DoS

2011-04-17 Thread Chris Hill
011 11:52 AM, Chris Hill wrote: > >> > >> Dear Apache httpd dev list, > >> ... > >> The reason why I insist in this is that the world has come to depend on > >> HTTP/SOAP over SSL (and Apache/OpenSSL are probably the most popular > >> implementatio

Re: SSL related DoS

2011-04-17 Thread Chris Hill
ledge of the Internals of Apache/OpenSSL. On Saturday, April 16, 2011, William A. Rowe Jr. wrote: > On 4/16/2011 2:39 PM, Daniel Ruggeri wrote: >> On 4/16/2011 11:52 AM, Chris Hill wrote: >>> but how can I ensure this will never be turned back on in >>> future releases