[users@httpd] Re: users Digest 30 Jan 2019 15:52:55 -0000 Issue 5789

2019-02-28 Thread Luca Toscano
ch module is my > problem? > > Thanks > Jan > > > > > > > - Message from Luca Toscano on Wed, 30 Jan 2019 > 07:52:37 -0800 - > To: > users@httpd.apache.org > Subject: > Re: [users@httpd] Segmentation fault when builded with openssl 1.1.1 &g

Re: [users@httpd] Apache upgrade 2.2 -> 2.4 and "PerlAuthenHandler Authen::Simple::IMAP"

2019-02-19 Thread Luca Toscano
Hi again, Can you use something like LogLevel warn perl:trace8 and see if you get more info in the error log? Luca Il giorno mer 20 feb 2019 alle ore 02:23 Jobst Schmalenbach ha scritto: > > On Mon, Feb 18, 2019 at 07:47:20AM +0100, Luca Toscano > (toscano.l...@gmail.com) wrote: >

Re: [users@httpd] Port 80 error still there even though listening on different port

2019-02-17 Thread Luca Toscano
Hi Mike, Il giorno lun 18 feb 2019 alle ore 04:08 Mike Starr ha scritto: > > Hi, I am still getting the ubiquitous Port 80 blocked error when starting > Apache even though I am listening on port 8080 in httpd.conf. > > What am I doing wrong? I assume your OS is Linux, so what I'd do is run a com

Re: [users@httpd] Apache upgrade 2.2 -> 2.4 and "PerlAuthenHandler Authen::Simple::IMAP"

2019-02-17 Thread Luca Toscano
Hi Jobst, Il giorno lun 18 feb 2019 alle ore 04:05 Jobst Schmalenbach ha scritto: > > Hi > > I have just started upgrading all of my CentOS servers from 6.X to 7.X. > With that Apache gets upgraded from 2.2 to 2.4. > > While I have fixed most of the issues one that I cannot solve is the > "PerlAu

Re: [users@httpd] Stupid question time - VirtualHost

2019-02-02 Thread Luca Toscano
Hi Jeff! Il giorno ven 1 feb 2019 alle ore 16:02 Jeff Cauhape ha scritto: > > My usage of Apache has been pretty plain vanilla, and now I am required to > > add a virtual host to a system, and I’m wondering what doing wrong. My hunch > > is that it’s obvious to others. > > > > I am using Apache 2

Re: [users@httpd] Segmentation fault when builded with openssl 1.1.1

2019-01-30 Thread Luca Toscano
Hi! Il giorno lun 28 gen 2019 alle ore 06:36 ha scritto: > > Hi, > > I have an issue with version httpd 2.4.38 when it is builded with openssl > 1.1.1 and mod_cluster > There are repeated error messages in error.log: > > AH00052: child pid exit signal Segmentation fault (11) > > These error

Re: [users@httpd] Developing Private Cache Module

2018-09-16 Thread Luca Toscano
Il giorno ven 14 set 2018 alle ore 06:39 Yann Ylavic ha scritto: > > Hi Thomas, > > On Fri, Sep 14, 2018 at 4:18 AM Thomas Salemy wrote: > > > > I want to redevelop the shared object cache that is used to filter > > HTTP requests. Specifically, I want to serve requests even faster by > > replacin

Re: [users@httpd] Apache 2.4 mod_ratelimit breaks mod_autoindex

2018-08-30 Thread Luca Toscano
More info: https://bz.apache.org/bugzilla/show_bug.cgi?id=62568 Luca 2018-08-29 23:02 GMT+02:00 Eric Covener : > mod_ratelimit is broken in the current release and due to be fixed in > the next update. > On Wed, Aug 29, 2018 at 4:07 PM Aram Akhavan wrote: >> >> I'm trying to use mod_ratelimit to

Re: [users@httpd] mod_wsgi in Apache 2.4

2018-06-01 Thread Luca Toscano
Hi! 2018-06-01 15:38 GMT+02:00 Stormy : > To support Python code, it appears that mod_wsgi is necessary? | > desirable. It appears to function correctly within Apache 2.4, but I cannot > find it in the *Apache* documentation /2.4/mod/> (the developer's documentati

Re: [users@httpd] Re: mod_suexec with mod_userdir and fcgid (webapps in subdirs with separated user context)

2018-05-23 Thread Luca Toscano
Hi Jonas, 2018-05-10 0:59 GMT+02:00 Jonas Meurer : > > > Thanks a ton. I'm still not 100% sure whether I do it the right way, but > it occurs to me as if I just discovered two bugs in Apache2 suExec that > make crazy workarounds necessary. > > What do you think? > Sorry for the lag in answering.

Re: [users@httpd] Running Lua Script using mod_lua

2018-05-16 Thread Luca Toscano
Hi, 2018-05-16 12:22 GMT+02:00 Hemant Chaudhary : > Hi, > > While running lua_script using mod_lua, I am getting this error in > error_log. What does it mean > "PANIC: unprotected error in call to Lua API (core and library have > incompatible numeric types)" > > What version of Lua are you using

Re: [users@httpd] Missing headers on 403 pages

2018-05-09 Thread Luca Toscano
Hi Gradus, 2018-05-09 9:18 GMT+02:00 Gradus Kooistra : > Dear Sir/Madam, > > We setup apache to set headers, like the X-Frame-Options. > But this doesn’t work for the 403 pages, only the > Strict-Transport-Security works. On non-error pages, the headers are > showing correctly in the browser/secu

Re: [users@httpd] mod_ratelimit working by steps ?

2018-05-08 Thread Luca Toscano
2018-04-22 21:15 GMT+02:00 : > Hi, > > I created a 4MB file and rate limited its directory container in the >> httpd's conf, and tested 8/20/30/etc.. settings as you suggested with >> curl: >> >> curl http://localhost/test.txt > /dev/null (in this way I drop the >> returned response but keep the c

Re: [users@httpd] Re: mod_suexec with mod_userdir and fcgid (webapps in subdirs with separated user context)

2018-04-24 Thread Luca Toscano
Hi Jonas, 2018-04-23 15:40 GMT+02:00 Jonas Meurer : > Hello again, > > maybe my previous mail was to verbose, or maybe simply nobody has an > idea. Still I'd like to give it a second try: > > Do you have a good idea why php-cgi7.0 throws the following error when > used with mod_fcgid, mod_usermod

Re: [users@httpd] mod_ratelimit working by steps ?

2018-04-21 Thread Luca Toscano
Hi, 2018-04-19 13:47 GMT+02:00 : > Hello all, > > I'm using Apache 2.4.24 on Debian 9 Stable, behind a DSL connection, with > an estimated upload capacity of ~130kB/s. > I'm trying to limit the bandwidth available to my users (per-connection > limit is fine). > However, it seems to me that the ra

Re: [users@httpd] Require directives

2018-04-17 Thread Luca Toscano
Hi Robert, 2018-04-17 16:27 GMT+02:00 Robert Schweikert : > Hi, > > Configuration question. > > Apache version 2.4.23 > > What I am trying to do is have users authenticate but only allow access > to that authentication method from known IP ranges. To this effect I > have a config file that sets:

Re: [users@httpd] ProxyErrorOverride on with PHP-FPM

2018-04-14 Thread Luca Toscano
Hi Matthias, 2018-04-11 11:34 GMT+02:00 Matthias Leopold : > Hi, > > I'm trying to get rid of the message > > [proxy_fcgi:error] ... AH01071: Got error 'Primary script unknown\n' > > in error logs (LogLevel notice) when proxying to an php-fpm daemon and the > requested php file doesn't exist. > >

Re: [users@httpd] proxy_fcgi - force flush to client

2018-03-03 Thread Luca Toscano
2018-02-19 12:07 GMT+01:00 Hajo Locke : > Hello, > > > Am 19.02.2018 um 10:11 schrieb Hajo Locke: > > Hello, > > Am 08.02.2018 um 19:33 schrieb Luca Toscano: > > > > 2018-02-02 12:20 GMT+01:00 Hajo Locke : > >> >> >> Am 02.02.2018 um 07:05

Re: [users@httpd] proxy_fcgi - force flush to client

2018-02-08 Thread Luca Toscano
2018-02-02 12:20 GMT+01:00 Hajo Locke : > > > Am 02.02.2018 um 07:05 schrieb Luca Toscano: > > Hello Hajo, > > 2018-02-01 13:20 GMT+01:00 Hajo Locke : > >> Hello Luca, >> >> Am 01.02.2018 um 09:10 schrieb Hajo Locke: >> >> Hello Luca, >&

Re: [users@httpd] problems benchmarking php-fpm/proxy_fcgi with h2load

2018-02-04 Thread Luca Toscano
2018-02-05 2:41 GMT+01:00 Eric Covener : > On Sun, Feb 4, 2018 at 8:27 PM, Luca Toscano > wrote: > > Hi Hajo, > > > > > > 2018-02-01 3:58 GMT+01:00 Luca Toscano : > >> > >> Hi Hajo, > >> > >> 2018-01-31 2:37 GMT-08:00 Hajo L

Re: [users@httpd] problems benchmarking php-fpm/proxy_fcgi with h2load

2018-02-04 Thread Luca Toscano
Hi Hajo, 2018-02-01 3:58 GMT+01:00 Luca Toscano : > Hi Hajo, > > 2018-01-31 2:37 GMT-08:00 Hajo Locke : > >> Hello, >> >> >> Am 22.01.2018 um 11:54 schrieb Hajo Locke: >> >> Hello, >> >> Am 19.01.2018 um 15:48 schrieb Luca Toscano

Re: [users@httpd] stable version of 2.4 running in production?

2018-02-02 Thread Luca Toscano
Hi, 2018-02-02 16:50 GMT+01:00 renee ko : > I am planing to upgrade Apache from 2.2 to 2.4 on RHEL 6.6. > > I am looking for best practice, should i perform an upgrade from 2.2 or > install 2.4? > https://httpd.apache.org/docs/current/upgrading.html is a good starting point :) Luca

Re: [users@httpd] proxy_fcgi - force flush to client

2018-02-01 Thread Luca Toscano
Hello Hajo, 2018-02-01 13:20 GMT+01:00 Hajo Locke : > Hello Luca, > > Am 01.02.2018 um 09:10 schrieb Hajo Locke: > > Hello Luca, > > Am 01.02.2018 um 04:46 schrieb Luca Toscano: > > Hi Hajo, > > 2018-01-31 1:27 GMT-08:00 Hajo Locke : > >> Hello Li

Re: [users@httpd] virtual host gives unexpected network read error

2018-01-31 Thread Luca Toscano
Hi David, 2018-01-29 19:45 GMT-08:00 David Mehler : > Hello, > > Can someone take a look at the below virtual host configuration? > Whenever I put it in my apache 2.4 the server returns an alert > unexpected network read error connection aborted message. If I take it > out the server behaves norm

Re: [users@httpd] proxy_fcgi - force flush to client

2018-01-31 Thread Luca Toscano
Hi Hajo, 2018-01-31 1:27 GMT-08:00 Hajo Locke : > Hello List, > > currently i compare features and behaviour of proxy_fcgi to classical > methods like mod_fastcgi/mod_php. > > mod_php/fastcgi have options to send every output from backend immediately > to client. So it is possible to see progress

Re: [users@httpd] problems benchmarking php-fpm/proxy_fcgi with h2load

2018-01-31 Thread Luca Toscano
Hi Hajo, 2018-01-31 2:37 GMT-08:00 Hajo Locke : > Hello, > > > Am 22.01.2018 um 11:54 schrieb Hajo Locke: > > Hello, > > Am 19.01.2018 um 15:48 schrieb Luca Toscano: > > Hi Hajo, > > 2018-01-19 13:23 GMT+01:00 Hajo Locke : > >> Hello, >> >

Re: [users@httpd] problems benchmarking php-fpm/proxy_fcgi with h2load

2018-01-20 Thread Luca Toscano
2018-01-20 20:23 GMT+01:00 Luca Toscano : > Hi Yann, > > 2018-01-19 17:40 GMT+01:00 Yann Ylavic : > >> On Fri, Jan 19, 2018 at 5:14 PM, Yann Ylavic >> wrote: >> > On Fri, Jan 19, 2018 at 1:46 PM, Daniel wrote: >> >> I vaguely recall some issue with r

Re: [users@httpd] problems benchmarking php-fpm/proxy_fcgi with h2load

2018-01-20 Thread Luca Toscano
Hi Yann, 2018-01-19 17:40 GMT+01:00 Yann Ylavic : > On Fri, Jan 19, 2018 at 5:14 PM, Yann Ylavic wrote: > > On Fri, Jan 19, 2018 at 1:46 PM, Daniel wrote: > >> I vaguely recall some issue with reuse when using unix socket files so > >> it was deliberately set to off by default, but yes, perhaps

Re: [users@httpd] problems benchmarking php-fpm/proxy_fcgi with h2load

2018-01-19 Thread Luca Toscano
Hi Hajo, 2018-01-19 13:23 GMT+01:00 Hajo Locke : > Hello, > > thanks Daniel and Stefan. This is a good point. > I did the test with a static file and this test was successfully done > within only a few seconds. > > finished in 20.06s, 4984.80 req/s, 1.27GB/s > requests: 10 total, 10 start

Re: [users@httpd] Redirect only a specific index.php page to new location

2018-01-19 Thread Luca Toscano
Hi Kory, 2018-01-18 5:53 GMT+01:00 Kory Wheatley : > When someone types to go to http://sftpinterface/deptblogs/ or a link I > need it to redirect to http://intranet/template_departments.cfm. Which I > was able to accomplish in the index.php header content with > > /* Redirect browser */ > he

Re: [users@httpd] SFTP JAIL

2018-01-16 Thread Luca Toscano
Hi Rodrigo, 2018-01-16 14:51 GMT+01:00 Rodrigo Cunha : > Hi everyone, > I have a problem with setup sftp access.My sftp user can't jaule. > I configure setup with this procedures: > https://wiki.archlinux.org/index.php/SFTP_chroot > But when i setup my user webmaster in group sftponly my client

Re: [users@httpd] SSL checker reports server vulnerable to BEAST attack

2018-01-16 Thread Luca Toscano
Hi Robert, 2018-01-16 10:21 GMT+01:00 Robert S : > Hi. > > I have run a server test on > https://cryptoreport.rapidssl.com/checker/views/certCheck.jsp. It > reports that my certificate is installed correctly but the server is > vulnerable to a BEAST attack. It says "Make sure you have the TLSv1

Re: [users@httpd] Reverse proxy not working

2018-01-02 Thread Luca Toscano
Hi, 2017-12-31 10:25 GMT+01:00 Noor Mohammad : > I have an application correctly working on locahost:8080 and I am setting > up a reverse proxy as follows but on a remote browser, when using the > proxy, i am getting local links as if apache is ignoring the reverse proxy. > The definition of the

Re: [users@httpd] How to connect Apache and Tomcat using http2 protocol

2017-12-12 Thread Luca Toscano
Hi! 2017-12-12 6:48 GMT+01:00 Ananya Dey : > Hi > > I am trying to connect Apache and Tomcat using HTTP2 protocol. > 1. These are the changes that I have made in my server.xml. > maxThreads="150" SSLEnabled="false" >sslImplementationName="org.apache.tomcat.util.net. > openssl

Re: [users@httpd] ProxyPassReverse rewrites Location header where it should not

2017-11-30 Thread Luca Toscano
Hi Vlad, 2017-11-29 20:54 GMT+01:00 Vlad Liapko : > I have below config, non essential stuff removed > > ProxyPassReverse http://backendhost.com > ProxyPassReverse / > > > It happens that backend sends Location header already correctly pointing > to the front end, no need to rewrite, like this

Re: [users@httpd] Using variables with mod_substitute to rewrite dynamically

2017-11-24 Thread Luca Toscano
Hi Vlad, 2017-11-23 16:29 GMT+01:00 Vlad Liapko : > Hi, > > I’m trying to substitute a server name dynamically in xml responses > Substitute s|http://blah.com|${SERVER_NAME}|n > to now success. Apache complains conf variable is not defined, but it is > there in VirtualHost. > > So far I was able

Re: [users@httpd] Apache creates Semaphore

2017-11-02 Thread Luca Toscano
Hi Hemant, as indicated in https://httpd.apache.org/docs/2.4/mod/core.html#mutex you can use different kind of mutex implementations and experiment with them. >From your description though it seems to me that your approach of killing httpd leads to semaphore leaking, something that would be avoide

Re: [users@httpd] rpmbuild of httpd-2.4.29

2017-10-24 Thread Luca Toscano
2017-10-24 4:06 GMT+02:00 kohmoto : > Hi, > > I have finished rpmbuild of httpd-2.4.29 perfectly and installed it > successfully using the rpm. > Thank you all relative to this release. > > CentOS 7.4 > kernel: 3.10.0-693.5.2 > > Yours truly, > Kazuhiko Kohmoto Thanks for the feedback! Luca

Re: [users@httpd] SSL hooks

2017-10-19 Thread Luca Toscano
Hi, 2017-10-19 1:06 GMT+02:00 Adi Mallikarjuna Reddy V < adimallikarjunare...@gmail.com>: > Hi > > I am looking at this file https://github.com/apache/httpd/blob/trunk/ > modules/ssl/mod_ssl_openssl.h and see that there are 3 hooks defined for > handling SSL connections. Are these available for m

Re: [users@httpd] Apache load module path

2017-10-19 Thread Luca Toscano
Hi, 2017-10-18 21:14 GMT+02:00 renee ko : > Team, > > I have LoadModules configured under the default RedHat httpd directory. > > Example: > LoadModule proxy_module /usr/lib64/httpd/modules/mod_proxy. > > I would like the modules to be changed to another > directory(/usr/local/apache2/modules). >

Re: [users@httpd] how to exit a C Apache module

2017-10-12 Thread Luca Toscano
Hi! 2017-10-12 12:42 GMT+02:00 eeadev dev : > I tried with the C exit() but it returns a page with this content: > > > > > > > > *The connection was resetThe connection to the server was reset while the > page was loading.The site could be temporarily unavailable or too busy. > Try again in a

Re: [users@httpd] mod_authz_core and http response 451

2017-09-06 Thread Luca Toscano
Hi Galen, 2017-09-05 22:02 GMT+02:00 Galen Johnson : > Hello, > > I've googled a bit and I can't find a way to handle this without using a > rewrite rule. > > I'm setting up a rule using mod_geoip to block embargoed countries. I set > up the config as follows: > > > # Blocking a clien

Re: [users@httpd] MPM Modules Rule of Thumb

2017-09-05 Thread Luca Toscano
<= some % > of free memory. That way it can never halt my system. > > Hope this helps. > > On Tue, Sep 5, 2017 at 1:16 PM Luca Toscano > wrote: > >> Hi Tony, >> >> 2017-08-31 23:43 GMT+02:00 Tony DiLoreto : >> >>> Hi All, >>> &

Re: [users@httpd] MPM Modules Rule of Thumb

2017-09-05 Thread Luca Toscano
Hi Tony, 2017-08-31 23:43 GMT+02:00 Tony DiLoreto : > Hi All, > > I've been scouring the internet for best practices or heuristics for > specifying parameter values of the MPM directives. My server seems to lock > up regardless of the values I enter. Are there "rules of thumb" for each > MPM type

Re: [users@httpd] mod_rewrite + proxy + unix socket results in 400 bad request

2017-08-31 Thread Luca Toscano
Hi David, 2017-08-29 17:41 GMT+02:00 David Mugnai : > Hi, > > I'm trying to configure a virtual host that, based on the host name, > forwards the request on a backend server listening on an unix socket. > > My apache version is 2.4.18 as shipped by Ubuntu 16.04 > > The configuration I've tried so

Re: [users@httpd] Problems with Http11NioProtocol and proxy server

2017-08-31 Thread Luca Toscano
Hi Marco, 2017-08-29 11:07 GMT+02:00 : > Hi, > > we've build a web application with JSF 2.1 and RichFaces 4.5.13.Final > running on JBoss EAP 6.4.12. We're also using a Apache HTTP server 2.4.7 as > a HTTPS/WSS proxy to access the application for customers. > > After we've changed the EAP http co

Re: [users@httpd] MPM_Worker main process

2017-08-30 Thread Luca Toscano
Hi Hemant, 2017-08-30 13:05 GMT+02:00 Hemant Chaudhary : > Hi Luca, > > Thanks for reply. > Actually I want to use apache web server for some transaction where I > can't afford any type of failure. That's why I was trying If by mistake > someone killed or something happen to my parent process th

Re: [users@httpd] Build apache without mpm

2017-08-30 Thread Luca Toscano
Hi Hemant, 2017-08-31 7:32 GMT+02:00 Hemant Chaudhary : > Hi > > By which configuration I can build apache without threaded> I dont want to > sue mpm. > The mpm is mandatory and you can choose between prefork (not threaded) and worker/event. If you need more info about the httpd's internal you c

Re: [users@httpd] MPM_Worker main process

2017-08-30 Thread Luca Toscano
Hi Hemant, 2017-08-30 8:26 GMT+02:00 Hemant Chaudhary : > Hi folks, > > I have my apache-2.4.25 with worker mpm. For testing, I have killed the > master/main process and send simultaneous requests from apache j-meter and > my apache serves all the requests. What I have observed is that even with

Re: [users@httpd] RewriteRule: Pattern matching and grouping part of the URL expands to its local filesystem path

2017-08-29 Thread Luca Toscano
Hi Gustau, 2017-08-22 9:01 GMT+02:00 Gustau Perez : > >Hello everybody, > >I’ve checking all kinds of sources of information so far without > success, I hope I didn’t miss anything. > >I have a very simple RewriteRule which should take the requested > resource part. What I want to ach

Re: [users@httpd] ''AH00288: scoreboard is full, not at MaxRequestWorkers'

2017-08-29 Thread Luca Toscano
Hi, 2017-08-29 2:07 GMT+02:00 : > > Some malicious persons are flooding our server ( Server > Version: Apache/2.4.27 (cPanel) OpenSSL/1.0.2k mod_bwlimited/1.4 > Server MPM: worker Server Built: Aug 17 2017 00:51:40 ) with bogus > traffic. It's been going down every few hours, often posti

Re: [users@httpd] Honouring the DNS ttl in proxy-pass

2017-08-28 Thread Luca Toscano
Hi Gustau, 2017-08-23 12:47 GMT+02:00 Gustau Perez : >Hi, > >We’re trying to set a bunch of Apaches 2.4.18 to proxy pass the > requests it receives to our partner's upstream server. Our partner uses > Amazon’s Elastic Load Balancing and thus the only we know about their > servers is its D

Re: [users@httpd] Two questions on httpd tuning

2017-08-18 Thread Luca Toscano
Hi Martin, 2017-08-18 10:09 GMT+02:00 Martin Knoblauch : > > > Lets say I wanted to increase MaxRequestWorkers to e.g. 800. One of the > several solutions would be to up ServerLimit to 32 and leave > ThreadsPerChild at 25. But I could also leave ServerLimit at 16 and up > ThreadsPerChild to 50. O

Re: [users@httpd] Two questions on httpd tuning

2017-08-18 Thread Luca Toscano
Hi Martin, 2017-08-17 17:40 GMT+02:00 Martin Knoblauch : > Hi, > > this is for httpd-2.4.26 with the mpm_worker_module. I have one practical > and one more theoretical question. > > First, is there a way to determine the maximum number of concurrent > requests that have been processed at any tim

Re: [users@httpd] How to different SSLProtocol for each of the conf files

2017-07-25 Thread Luca Toscano
: > Hi Luca, > > I have uploaded the content : > > https://apaste.info/t5ez > > Please review. > > --Chetan > > On Tue, Jul 25, 2017 at 4:17 AM, Luca Toscano > wrote: > >> Hi, >> >> we'd need to get your vhost configuration before help

Re: [users@httpd] How to different SSLProtocol for each of the conf files

2017-07-25 Thread Luca Toscano
Hi, we'd need to get your vhost configuration before helping further on, as Eric mentioned you have probably some overlapping but it is very difficult to debug only from your description. If you can put your configuration in https://apaste.info/ it would be great, otherwise I'd suggest to reach ou

Re: [users@httpd] configure apache2 on ubuntu 16.04 vps to use php-fpm is not leading to the desired outcome

2017-07-25 Thread Luca Toscano
Hi Dino, 2017-07-23 1:32 GMT+02:00 Dino Vliet : > > Modified this file: > > /etc/apache2/sites-available/000-default.conf to now have this inside: > > > > > Require all granted > > > > > > AddHandler php7-fcgi .php > > Action php7-fcgi /php7-fcgi virtual > > Alias /php7-fcgi /usr/

Re: [users@httpd] Apache Struts Vulnerability - CVE-2017-9791

2017-07-21 Thread Luca Toscano
Hi, 2017-07-21 18:35 GMT+02:00 Chunduru, Krishnachaithanya < krishnachaithanya.chund...@broadridge.com>: > Hi All, > > > Can someone please confirm if Apache 2.4.10 is vulnerable to the > CVE-2017-9791. > We came to know that Apache which is having Apache Struts version 2.3.x > with Struts 1 plu

Re: [users@httpd] How does Apache detects a stopped Tomcat JVM?

2017-07-20 Thread Luca Toscano
Hello, 2017-07-18 15:48 GMT+02:00 Suvendu Sekhar Mondal : > Hello Folks, > > I am new to Apache httpd world and wanted to know more about it. :) > > Reason I got interested in this is that, in our case, we are running > multiple Tomcat JVMs under a single Apache cluster. If we shut down > all the

Re: [users@httpd] Apache server response very very slow from chrome/ firefox and works fine from Safari - User-Agent issue

2017-07-20 Thread Luca Toscano
Hi Kumar, 2017-07-18 9:14 GMT+02:00 Kumar Devarakonda : > Hi, > > We have a strange issue recently with Apache. When we request some > webpages (running on apache web server) from our server, if we make the > request from Safari, they are loaded instantly. If we load the web page > from Chrome or

Re: [users@httpd] Crashes in CentOS 7

2017-07-20 Thread Luca Toscano
Hi Bruno, 2017-07-20 16:33 GMT+02:00 Bruno Dorchain : > We got the following crash when under load: > *** Error in `/usr/sbin/httpd': double free or corruption (!prev): > 0x7f19a010cf80 *** > === Backtrace: = > /lib64/libc.so.6(+0x7c503)[0x7f19ce15c503] > /lib64/libapr-1.so.0(apr_

Re: [users@httpd] 2.4.27 installed, no con fig change, but web site down!

2017-07-19 Thread Luca Toscano
Hi Tom, 2017-07-19 3:33 GMT+02:00 Tom Browder : > I installed 2.4.27, along with the latest openssl. no config was changed, > but my server isn't serving. > > I show no errors in the error log. > > I will try to go back to previous versions to see if I can recover, but > wonder if anyone can gues

Re: [users@httpd] virtual host double slash effect, need solution

2017-07-16 Thread Luca Toscano
Hi David, 2017-07-15 3:11 GMT+02:00 David Mehler : > Hello, > > I'm running Apache 2.4 on a FreeBSD 10.3 system, with several virtual > hosts. My goal is to have all of them completely ssl, except for the > .well-known area needed for letsencrypt. > > > ServerName example.com > RewriteEn

Re: [users@httpd] rpmbuild of httpd-2.4.27 is successful

2017-07-12 Thread Luca Toscano
Hello David, we don't have much control in the Centos release schedule, I would suggest to follow up in their support mailing lists :) Thanks! Luca 2017-07-12 11:03 GMT+02:00 David Goudet : > Hello, > > This is great news, thank you for the job. > > Currently in Centos7 (release 7.3.1611) repo

Re: [users@httpd] [ANNOUNCEMENT] Apache HTTP Server 2.4.27 Released

2017-07-11 Thread Luca Toscano
Also a more in depth explanation from the dev@ mailing list: https://lists.apache.org/thread.html/bae472cadaeeb761b88bb4569cc0b7d87bc2dcb2fbcbf472d895f32e@%3Cdev.httpd.apache.org%3E Luca 2017-07-11 15:56 GMT+02:00 Luca Toscano : > Hi David, > > https://bz.apache.org/bugzilla/show_b

Re: [users@httpd] [ANNOUNCEMENT] Apache HTTP Server 2.4.27 Released

2017-07-11 Thread Luca Toscano
Hi David, https://bz.apache.org/bugzilla/show_bug.cgi?id=61237 contains the background that brought to this decision :) Luca 2017-07-11 15:41 GMT+02:00 David Copeland : > I'm wondering what the reason for this is? > > Thanks. > > On 11/07/17 09:04 AM, Jim Jagielski wrote: > >Apache

Re: [users@httpd] Graphical representation of serer status

2017-06-23 Thread Luca Toscano
2017-06-23 15:56 GMT+02:00 Hemant Chaudhary : > Hi > > I want to have graphical representation of my apache server. Any module > available to acheive this. I am working on httpd -2.4.25 > > There is the awesome https://github.com/Humbedooh/server-status that was recently donated to the httpd proj

Re: [users@httpd] server-statut ACC value and MaxConnectionsPerChild

2017-06-22 Thread Luca Toscano
Hi Bertrand, 2017-06-20 15:54 GMT+02:00 Bertrand Lods : > Hi > > [root@fusion ~]# httpd -V > Server version: Apache/2.4.6 (CentOS) > Server built: Apr 12 2017 21:03:28 > Server's Module Magic Number: 20120211:24 > Server loaded: APR 1.4.8, APR-UTIL 1.5.2 > Compiled using: APR 1.4.8, APR-UTIL 1

Re: [users@httpd] 'require' directive result

2017-06-21 Thread Luca Toscano
Hi Andrei, 2017-06-16 15:23 GMT+02:00 Andrei Ivanov : > Hi, > Now that I've managed to configure my 'require' directive, I have a > requirement to log some details to syslog in case the request is not > authorized. > > > Require expr "" > // if expression is false, log details about

Re: [users@httpd] if directive not being respected in Apache 2.4.6

2017-06-21 Thread Luca Toscano
Hi Chuck, 2017-06-09 18:36 GMT+02:00 Day, Chuck : > While trying to set a conditional parameter for the OpenIDC apache module, > it seems the directive is not being respected at run-time. For example: > > > > > >Define locale1 fr-FR > > > > > >Define locale1 en-UK > > > > OIDC

Re: [users@httpd] How does apache2.4 maintains php7.0 opcache in prefork model

2017-06-09 Thread Luca Toscano
Hi, 2017-06-09 17:42 GMT+02:00 Kalyana sundaram : > Does each apache2.4 child processes maintain their own opcache or is there > a global opcache shared by all children? > if you are talking about a prefork model with mod_php then I'd say that the opcache is one per children and not shared. Luc

Re: [users@httpd] Vendor Connection via Proxy to SNI Server response 403 Forbidden

2017-06-08 Thread Luca Toscano
Hi Reid, while re-reading the logs I noticed one thing: 2017-06-07 2:42 GMT+02:00 Reid Watson : > > [Wed Jun 07 11:54:28.887001 2017] [ssl:trace3] [pid 9177:tid > 140532624602880] ssl_engine_io.c(1086): [remote 54.230.144.17:443] SNI > extension for SSL Proxy request set to 'Internal-site.test.

Re: [users@httpd] Vendor Connection via Proxy to SNI Server response 403 Forbidden

2017-06-07 Thread Luca Toscano
2017-06-07 2:42 GMT+02:00 Reid Watson : > Hi Luca, > > I think the vendor is might be putting me down the wrong path because I > receive > > "[Wed Jun 07 11:54:29.302145 2017] [ssl:trace3] [pid 9177:tid > 140532624602880] ssl_engine_kernel.c(1807): [remote 54.230.144.17:443] > OpenSSL: Write: SSL

Re: [users@httpd] Vendor Connection via Proxy to SNI Server response 403 Forbidden

2017-06-05 Thread Luca Toscano
Hi Reid, 2017-06-03 3:11 GMT+02:00 Reid Watson : > Hi Everyone, > > There are few posts going around and I was wondering if any one had some > advice or experienced a similar issues > > Current Apache Version: httpd-2.4.12 > > Issue > > - External Vendor WebServer enables SNI check > - I currentl

Re: [users@httpd] Apache 2.4.25 with openssl 1.1.0e

2017-06-05 Thread Luca Toscano
Hi, 2017-06-05 8:52 GMT+02:00 Hemant Chaudhary : > Hi > > I am trying to build httpd-2.4.25 with openssl-1.1.0e. But getting error > in SSLv2_Client_Method, CRYPTO_malloc_init functions . > > Whether anyone encountered the same problem? > Does apache-2.4.25 support openssl 1.1.0e? > The support

Re: Re[2]: [users@httpd] apache in proxy mode introduces extra delay for sockjs in xhr poll mode

2017-06-01 Thread Luca Toscano
Hi Stepan, Have you tried to explicitly set ProxyTimeout? If your environment is a testing one, would it be possible for you to raise the LogLevel to trace8 and send us the logs ( https://httpd.apache.org/docs/2.4/mod/core.html#loglevel) ? I am assuming that you have httpd 2.4, but which version?

Re: [users@httpd] http/2 vs. Headername

2017-05-23 Thread Luca Toscano
Hi Hajo, any chance that you could download/build/test the latest release of https://github.com/icing/mod_h2/releases ? Luca 2017-05-23 11:30 GMT+02:00 Hajo Locke : > Hello, > > no one has an idea? Currently i believe this is a kind of apache bug. > I compiled curl with http2 Support to view mo

Re: [users@httpd] Apache HTTP Server - 2.4.15-mod_prefork module

2017-05-23 Thread Luca Toscano
Hi! Probably you have another LoadModule some-mpm in one of the included files (look for Include in your httpd config), can you double check? Luca 2017-05-23 10:07 GMT+02:00 Velmurugan Dhakshnamoorthy : > But, I am loading only one, others are commented out. > > Thanks. > > On May 23, 2017 14

Re: [users@httpd] apache 2.4 includes vi .swp files

2017-05-11 Thread Luca Toscano
2017-05-09 11:40 GMT+02:00 Nick Kew : > > > But i wonder if apache should basically tries to include a file > > "beginning with dot"/"ending with swp" which generelly indicates a > > temporary/hidden file. > > Once you start excluding files by convention (which may be > entirely different and inap

Re: [users@httpd] cgi script error output logging

2017-05-11 Thread Luca Toscano
Hi Sandro, have you checked https://httpd.apache.org/docs/2.4/mod/core.html#errorlogformat ? What is the current format that you are using? Also, what version of httpd? Luca 2017-05-11 10:07 GMT+02:00 KASPAR Sandro : > Hi suomi, > > > Thank you for your answer. Unfortunately I am not using php-

Re: [users@httpd] I need help figuring out a 500 response code

2017-05-05 Thread Luca Toscano
Hi John, can you share with us your error log (redacting IPs and personal info) so we can check as well? Otherwise I'd suggest to reach out to the #httpd Freenode IRC channel more a quicker response, there are a lot of people in there that might help you. Luca 2017-05-04 19:33 GMT+02:00 John Co

Re: [users@httpd] Apache + Squid Proxy: AH01991: SSL input filter read failed

2017-05-03 Thread Luca Toscano
Hi, 2017-05-02 19:18 GMT+02:00 chiasa.men : > Hi, > my apache is behind a squid proxy which is configured like that: > https_port 3128 accel cert=/cert.pem key=/cert.key defaultsite= > ww1.example.com > vhost > acl server20_domains dstdomain ww1.example.com ww2.example.com > http_access allow ser

Re: [users@httpd] Apache 2.4 with Mysql authentication

2017-05-02 Thread Luca Toscano
Hi David, 2017-05-01 23:39 GMT+02:00 David Mehler : > > Can someone take a look at my mysql setup and tell me if I have any > mistakes in it? > Can you tell us what is the issue that you are seeing? Anything relevant in the error_log? What version of httpd? Thanks, Luca

Re: [users@httpd] how to enable TLS v1.1 and TLS v1.2 alone in Apache 2.4.10 ?

2017-05-02 Thread Luca Toscano
Hi, I'd suggest to reach out to the IRC #httpd channel on Freenode, a lot of people in there can help you quickly than a users@ email thread, especially due to the fact that your issue will require a lot of details not yet provided. Luca 2017-05-01 15:20 GMT+02:00 Chunduru, Krishnachaithanya < k

Re: [users@httpd] Apache as HTTP Proxy: GZIP compression handling configuration question

2017-05-01 Thread Luca Toscano
> | > | |<-| > | | | > | 200 OK | | > | (Body uncompressed) | | > |<-|

Re: [users@httpd] Apache as HTTP Proxy: GZIP compression handling configuration question

2017-04-28 Thread Luca Toscano
Hi Markus, 2017-04-26 12:21 GMT+02:00 Markus Gausling : > Hello, > > I am using Apache (2.4.10) as an HTTP Proxy with two virtual hosts > listening > on different ports: > - Forward Proxy > - Reverse Proxy > > Depending on the use case applications either use the Forward Proxy or the > Reverse Pr

Re: [users@httpd] Re: Error trying to use 'mod_auth_form' and 'mod_dbd' with sqlite3

2017-04-28 Thread Luca Toscano
Hi Tom, 2017-04-28 1:16 GMT+02:00 Tom Donovan : > On 04/26/2017 06:49 AM, Tom Browder wrote: > >> On Wed, Apr 26, 2017 at 05:06 Tom Browder > tom.brow...@gmail.com>> wrote: >> >> On Wed, Apr 26, 2017 at 04:04 Luca Toscano > <mailto:toscano.l...@g

Re: [users@httpd] Re: Reg : Limiting http connections at Apache 2.4.25

2017-04-27 Thread Luca Toscano
hrow an > error. > > Regards, > Vel > > On Apr 21, 2017 18:52, "Luca Toscano" wrote: > >> Hi, >> >> I think that you'd just need to install httpd without any reference to >> mod_qos (that is a third party module, so configure is not aware

Re: [users@httpd] Looking for direction: porting server from Apache 2.2.2 to 2.4.6 - ProxyHTMLURLMap ?

2017-04-27 Thread Luca Toscano
Hi Jeff, 2017-04-26 19:35 GMT+02:00 Jeff Cauhape : > Hi, > > > > I’ve been given the task of moving a website from Apache 2.2.2 on Solaris > to Apache 2.4.6 on Linux. > > > > So far, so good, but I’m running into a ‘syntax’ error when a config file > uses the ProxyHTMLURLMap > > function. Apache

Re: [users@httpd] Re: Error trying to use 'mod_auth_form' and 'mod_dbd' with sqlite3

2017-04-26 Thread Luca Toscano
Hi Tom, 2017-04-26 3:23 GMT+02:00 Tom Browder : > On Tue, Apr 25, 2017 at 14:47 Tom Browder wrote: > > > > On Tue, Apr 25, 2017 at 12:03 PM, Tom Browder > wrote: > > > Host: httpd version 2.4.25, Debian 8, 64-bit > > > > > > I am so close but getting the following error: > > ... > > > > I think

Re: [users@httpd] Re: Reg : Limiting http connections at Apache 2.4.25

2017-04-21 Thread Luca Toscano
e-ssl > --enable-unique-id > make > > > Regards, > Velmurugan Dhakshnamoorthy (Vel) > Singapore. > > On Tue, Apr 18, 2017 at 2:51 PM, Luca Toscano > wrote: > >> Not sure what is the status of mod_qos (third party module), but you >> might want to give it a try and

Re: [users@httpd] Virtual hosts, include php.conf, DirectoryIndex failure

2017-04-20 Thread Luca Toscano
Hi Marc, +1 to what Rick is saying, if you could avoid mod_php it would be really better (more info https://wiki.apache.org/httpd/php). > But when I included the php7.file in the global http.conf or in the global default-server.conf files then it works! Sorry for the extra question but are you s

Re: Re: [users@httpd] Reg: Custom error message at Apache 2.4.25

2017-04-20 Thread Luca Toscano
wrote: >> >>> Thanks again for your valuable inputs, I am actually restricting number >>> of HTTP sessions at weblogic layer, beyond the specified limit, weblogic >>> throws 500 error message, which is not very useful to users, I want only >>> the 50

Re: [users@httpd] Help: Apache Crashing Everyday

2017-04-20 Thread Luca Toscano
Hi! 2017-04-19 8:41 GMT+02:00 Jayaram Ponnusamy : > Hi Luca, > > Thanks for the details. > 1. our server's ulimit values are: > ]$ ulimit -a > max user processes (-u) 1024 > > Please let me know whether the values are sufficient to allow at least 500 > concurrent connections. > To b

Re: [users@httpd] Problem with Apache2 after upgrade from Ubuntu14.04 to 16.04

2017-04-18 Thread Luca Toscano
Hi! 2017-04-18 13:35 GMT+02:00 Purvez : > Hi > > Newbie to the forum here so I hope I'm doing this right. If not please > would someone guide me. Thx in advance. > > As the subject line says Apache2 is not working at all / satisfactorily > since the Ubuntu upgrade. The details follow: > >

Re: [users@httpd] Help: Apache Crashing Everyday

2017-04-18 Thread Luca Toscano
Hi, Some suggestions: 1) check your RHEL ulimits applied to httpd, the error message "Resource temporarily unavailable: setuid: unable to change to uid" could be related to maximum number of processes (allowed by the OS) reached. This should allow you to spawn more httpd processes. 2) Have you c

Re: [users@httpd] Re: Reg : Limiting http connections at Apache 2.4.25

2017-04-17 Thread Luca Toscano
Not sure what is the status of mod_qos (third party module), but you might want to give it a try and see if it fits your needs! http://mod-qos.sourceforge.net/#requestlevelcontrol Luca 2017-04-17 3:08 GMT+02:00 Velmurugan Dhakshnamoorthy : > Dear All, > Any specific setup to cut and disallow th

Re: [users@httpd] Reg: Custom error message at Apache 2.4.25

2017-04-17 Thread Luca Toscano
Hi! As Nick mentioned there are a couple of options: 1) https://httpd.apache.org/docs/2.4/mod/mod_substitute.html or https://httpd.apache.org/docs/current/mod/mod_proxy_html.html in case you want to replace some parts of the response coming from the backend with your content. 2) Write your own c

Re: [users@httpd] Help with conditional ProxyPassMatch

2017-04-13 Thread Luca Toscano
Hi! 2017-04-12 20:42 GMT+02:00 Gryzli Bugbear : > Hi to all, > > I want to make conditional forward proxy within Apache ,based on request > header if a given request header exists, I want to proxy the request, if > not, not proxy > and also I need to do this NOT with RewriteRule and [P] flags. >

Re: [users@httpd] Apache substitute issue

2017-04-10 Thread Luca Toscano
Hi! 2017-04-10 8:24 GMT+02:00 Hemalatha A : > Hi, > > I am facing 2 issues with Apache mod_proxy and substitute. > > 1. I have a substitute like say: > Substitute "s/http/https/ni" > It works perfectly fine when I do curl. But on browser, it somehow > doesn't seem to apply the substitute, it st

  1   2   >