Re: [users@httpd] mod_md questions

2022-03-03 Thread Dan Mahoney (Gushi)
On Mon, 28 Feb 2022, Gillis J. de Nijs wrote: It does mention it, but I agree it's not too straightforward. https://httpd.apache.org/docs/current/mod/mod_md.html says (emphasis mine): "If Let's Encrypt can verify the ownership of the domain, the module will retrieve the certificate and its

[users@httpd] mod_md questions

2022-02-27 Thread Dan Mahoney (Gushi)
Hey there, Does mod_md require periodic "apachectl graceful" to be added to cron? The github site mentions this requirement, but the apache.org docs do not. -Dan -- Dan Mahoney Techie, Sysadmin, WebGeek Gushi on efnet/undernet IRC FB: fb.com/DanielMahoneyIV LI:

[users@httpd] mod_md and "fallback" certificates

2021-05-09 Thread Dan Mahoney (Gushi)
Hey all, I had an interesting dilemma come up. I want to start using mod_md, but needed an answer as to what to do if lets encrypt can't auth. Now, unlike any other certificate solution, mod_md will not block a vhost from starting if no cert is defined. This is good. But it places the

[users@httpd] Impact of CVE-2017-9789?

2017-09-21 Thread Dan Mahoney (Gushi)
Hey all, Under FreeBSD, mod_http2 is not compiled by the ports tree by default. Are we still vulnerable to this? Is there any mitigation strategy besides upgrading? (Disabling htaccess parsing, for example?) -Dan -- -