Re: Tagging 2.2.15 to play openssl catchup?

2010-03-01 Thread Niklas Edmundsson
On Sun, 28 Feb 2010, William A. Rowe Jr. wrote: by Monday morning, guess we will have to slide this once again. I wouldn't defer for feature additions, nor will I vote for them. Carefully reviewed bug fixes? The more the merrier :) I'm not voting against them, they are probably very nice to

Re: Tagging 2.2.15 to play openssl catchup?

2010-02-28 Thread Stefan Fritsch
On Thu, 25 Feb 2010, William A. Rowe Jr. wrote: Let's start a three day clock to the tag, and I'll tag Sunday about noon CST. There is still one proposal missing just one vote, and two proposals cannot be reviewed because people.apache.org is down (at least I cannot reach it). Maybe delay

Re: Tagging 2.2.15 to play openssl catchup?

2010-02-28 Thread Rainer Jung
Stefan: can you mail me your mod_reqtimeout 2.2.x backport patch? Since p.a.o is still offline; i can not download your patch. I tested a backport I made this morning and it looks fine. If it is identical to yours, I'll vote immediately for it. On 28.02.2010 15:04, Stefan Fritsch wrote: On

Re: Tagging 2.2.15 to play openssl catchup?

2010-02-28 Thread Stefan Fritsch
On Sunday 28 February 2010, Rainer Jung wrote: Stefan: can you mail me your mod_reqtimeout 2.2.x backport patch? Since p.a.o is still offline; i can not download your patch. I tested a backport I made this morning and it looks fine. If it is identical to yours, I'll vote immediately for it.

Re: Tagging 2.2.15 to play openssl catchup?

2010-02-28 Thread William A. Rowe Jr.
On 2/25/2010 3:36 PM, William A. Rowe Jr. wrote: I'd like to move ahead and catch up to OpenSSL 0.9.8m which was released today, and that requires a 2.2 release. Let's start a three day clock to the tag, and I'll tag Sunday about noon CST. That gives folks friday, and weekend warriors time

Re: Tagging 2.2.15 to play openssl catchup?

2010-02-28 Thread William A. Rowe Jr.
On 2/25/2010 3:36 PM, William A. Rowe Jr. wrote: I'd like to move ahead and catch up to OpenSSL 0.9.8m which was released today, and that requires a 2.2 release. Let's start a three day clock to the tag, and I'll tag Sunday about noon CST. That gives folks friday, and weekend warriors time

Re: Tagging 2.2.15 to play openssl catchup?

2010-02-28 Thread William A. Rowe Jr.
On 2/28/2010 8:04 AM, Stefan Fritsch wrote: There is still one proposal missing just one vote, and two proposals cannot be reviewed because people.apache.org is down (at least I cannot reach it). Maybe delay the tag a bit, like 2-3 days? Done; pushed this one day. This is a security fix

RE: Tagging 2.2.15 to play openssl catchup?

2010-02-26 Thread Plüm, Rüdiger, VF-Group
-Original Message- From: Rainer Jung Sent: Freitag, 26. Februar 2010 12:17 To: dev@httpd.apache.org Subject: Re: Tagging 2.2.15 to play openssl catchup? On 25.02.2010 22:36, William A. Rowe Jr. wrote: I'd like to move ahead and catch up to OpenSSL 0.9.8m which was released

Re: Tagging 2.2.15 to play openssl catchup?

2010-02-26 Thread Joe Orton
On Fri, Feb 26, 2010 at 12:17:14PM +0100, Rainer Jung wrote: Isn't 0.9.8m by default still allowing unsafe renegs? So updated clients will be safe, but the server doesn't enforce the safetyness (and reject unsafe client). No, OpenSSL now only allows secure reneg by default, so this is

Re: Tagging 2.2.15 to play openssl catchup?

2010-02-26 Thread William A. Rowe Jr.
On 2/26/2010 5:38 AM, Joe Orton wrote: On Fri, Feb 26, 2010 at 12:17:14PM +0100, Rainer Jung wrote: I guess backporting is pretty straightforward. Wouldn't it be nice to already support this with 2.2.15? That was always implicit in the proposal to tag 2.2.15 - catch up with the API. As Joe

Re: Tagging 2.2.15 to play openssl catchup?

2010-02-26 Thread Joe Orton
On Fri, Feb 26, 2010 at 12:17:14PM +0100, Rainer Jung wrote: Joe, do you already have a candidate, or should I suggest a backport patch myself? Here's the patch: http://people.apache.org/~jorton/ms_reneg22_v1.diff I've excluded the docs from that since they don't require RTC, but obviously

Re: Tagging 2.2.15 to play openssl catchup?

2010-02-26 Thread William A. Rowe Jr.
On 2/26/2010 10:50 AM, Joe Orton wrote: On Fri, Feb 26, 2010 at 12:17:14PM +0100, Rainer Jung wrote: Joe, do you already have a candidate, or should I suggest a backport patch myself? Here's the patch: http://people.apache.org/~jorton/ms_reneg22_v1.diff In the midst of everything, had

Tagging 2.2.15 to play openssl catchup?

2010-02-25 Thread William A. Rowe Jr.
I'd like to move ahead and catch up to OpenSSL 0.9.8m which was released today, and that requires a 2.2 release. Let's start a three day clock to the tag, and I'll tag Sunday about noon CST. That gives folks friday, and weekend warriors time Saturday to catch up with final important bugfix

Re: Tagging 2.2.15 to play openssl catchup?

2010-02-25 Thread Jeff Trawick
On Thu, Feb 25, 2010 at 4:36 PM, William A. Rowe Jr. wr...@rowe-clan.net wrote: I'd like to move ahead and catch up to OpenSSL 0.9.8m which was released today, and that requires a 2.2 release. Let's start a three day clock to the tag, and I'll tag Sunday about noon CST. That gives folks

Re: Tagging 2.2.15 to play openssl catchup?

2010-02-25 Thread Graham Leggett
On 25 Feb 2010, at 11:36 PM, William A. Rowe Jr. wrote: I'd like to move ahead and catch up to OpenSSL 0.9.8m which was released today, and that requires a 2.2 release. Let's start a three day clock to the tag, and I'll tag Sunday about noon CST. That gives folks friday, and weekend