question about 2.4 availability

2010-12-13 Thread fredk2
Hello httpd developers, Is there already a feel for when the 2.3.x will become the stable 2.4? Based on your experience(s) shall we assume that the duration of the beta will be the same as an alpha? Kind regards - Fred -- View this message in context:

Re: TLS renegotiation attack, mod_ssl and OpenSSL

2010-01-26 Thread fredk2
Hi, Joe Orton wrote: On Tue, Nov 10, 2009 at 03:19:39PM +0100, Jean-Marc Desperrier wrote: Joe Orton wrote: On Fri, Nov 06, 2009 at 12:00:06AM +, Joe Orton wrote: On Thu, Nov 05, 2009 at 09:31:00PM +, Joe Orton wrote: * we can detect in mod_ssl when the client is

Re: mod_noloris: mitigating against slowloris-style attack

2009-06-30 Thread fredk2
Hi Nick, I looked at the code (I am not a coder) and wondered what made you say it's geared clearly to the very small server. Rgds - Fred Nick Kew wrote: Stefan Fritsch wrote: Nick Kew wrote: Is this worth hacking up, or more trouble than it saves? It seems it already exists (I

mod_proxy_ajp and ssl

2006-10-18 Thread fredk2
Hi: I have a rhetorical question for the developers of mod_proxy_ajp (and mod_jk). Assuming the tomcat ajp connector was able to accept ssl connections - if the apache httpd server and tomcat are on separate machines and you needed to secure the connection with ssl, would you get better