Re: [users@httpd] Howto run Apache web server on Linux read-only root file system

2011-08-31 Thread Monika Kistler
Hi Tom, > I believe this is your distribution's init script which is trying to > do something clever. You are right, it is the openSUSE init script, that does all this stuff. So I know, where to hit now. Thanks for your help, Cheers, Moni http://www.telemotive.de

[users@httpd] Using Apache HTTP to load balance with windows single sign on

2011-08-31 Thread RAMM, David
Hi Users, I have an application that runs in a single tomcat 6 instance. It is using waffle for windows single sign on. That seems to work no problems. I'm now trying to load balance the application, i.e. I have a few tomcat servers running the application in the back end and use Apache HTTP at

[users@httpd] replacing html form?

2011-08-31 Thread Rajeev Prasad
Hello,   This is not exactly related to Apache, but i could not find where to post this question: (if you know any good HTML mailing list kindly let me know)   is 'html form'  the only way to get data from user?     can't we use something else?   thank you. Rajeev

[users@httpd] PDF app.launchURL and browser cache

2011-08-31 Thread Geert Mak
Hello list, We have a web applications which opens a PDF and the PDF does app.launchURL back to the web application. The strange thing is that in between 50 and 80% of the cases and sometimes in all cases, after this redirect the browser, instead of showing the page, outputs HTML code -

[users@httpd] RES: apache + AD auth

2011-08-31 Thread Diego Maciel Gomes
Hey Tony, Well, I was testing with a lot of possibilites... When it was working, is was without quotes, like this: Require ldap-group CN=group_access, OU=Group, DC=domain, DC=com I did a lot of tests, put the quotes, remove the quotes It doesn't work anyway... Im still looking for a solut

[users@httpd] RE: apache + AD auth

2011-08-31 Thread Bennett, Tony
Diego, Not sure about 2.2.3, but the current version of the documentation for the " Require ldap-group" directive (http://httpd.apache.org/docs/2.2/mod/mod_authnz_ldap.html#reqgroup) Says: Require ldap-group This directive specifies an LDAP group whose members are allowed access

Re: [users@httpd] Apache Security Page and CVE-2011-3192

2011-08-31 Thread William A. Rowe Jr.
On 8/31/2011 8:17 AM, Jeff Trawick wrote: > On Wed, Aug 31, 2011 at 6:22 AM, Paul Reilly wrote: >> Why is there no information about the recent header Rang DoS vulnerability >> in Apache on the Apache security page? >> >> http://httpd.apache.org/security/ >> >> I would have expected at least to

[users@httpd] RES: apache + AD auth

2011-08-31 Thread Diego Maciel Gomes
Anynone? De: Diego Maciel Gomes [diego.go...@cecred.coop.br] Enviado: terça-feira, 30 de agosto de 2011 15:08 Para: users@httpd.apache.org Assunto: [users@httpd] apache + AD auth Hello All... I have auth against AD... It was working fine, in a good day,

Re: [users@httpd] Which module is affected by the Range header issue?

2011-08-31 Thread Steve Foster
i've also had a thought, I also implemented the following: LimitRequestLine 4000 Which is about half of the default size i beleive, could this be limiting the impact on my servers and thus not making them vulnerable. Does anyone know what length of request the killapache script sends? cheers S

Re: [users@httpd] Howto run Apache web server on Linux read-only root file system

2011-08-31 Thread Tom Evans
On Wed, Aug 31, 2011 at 2:56 PM, Monika Kistler wrote: > Hi all, > > I'm running the Apache web server 2.2.17 on an openSUSE 11.4 system. > > Out of security reasons I need to have the root file system mounted read-only. > /var is mounted read/write on a separate partition, thus the log files do n

[users@httpd] Howto run Apache web server on Linux read-only root file system

2011-08-31 Thread Monika Kistler
Hi all, I'm running the Apache web server 2.2.17 on an openSUSE 11.4 system. Out of security reasons I need to have the root file system mounted read-only. /var is mounted read/write on a separate partition, thus the log files do not cause any problem. When booting my system I get the followin

Re: [users@httpd] Apache Security Page and CVE-2011-3192

2011-08-31 Thread Jeff Trawick
On Wed, Aug 31, 2011 at 6:22 AM, Paul Reilly wrote: > Why is there no information about the recent header Rang DoS  vulnerability > in Apache on the Apache security page? > >  http://httpd.apache.org/security/ > > I would have expected at least to see some mention of it, and possible > work-around

[users@httpd] [ANNOUNCEMENT] Apache HTTP Server 2.2.20 Released

2011-08-31 Thread Jim Jagielski
Apache HTTP Server 2.2.20 Released The Apache Software Foundation and the Apache HTTP Server Project are pleased to announce the release of version 2.2.20 of the Apache HTTP Server ("Apache"). This version of Apache is principally a security and bug fix release: * SECURITY: C

[users@httpd] Apache Security Page and CVE-2011-3192

2011-08-31 Thread Paul Reilly
Why is there no information about the recent header Rang DoS vulnerability in Apache on the Apache security page? http://httpd.apache.org/security/ I would have expected at least to see some mention of it, and possible work-arounds. Paul

Re: [users@httpd] Recent Apache DOS advisory - problem applying the SetEnvIf/ RequestHeader workaround.

2011-08-31 Thread Roel Wagenaar
Op 31 aug 2011 schreef Roel Wagenaar: > Op 25 aug 2011 schreef William A. Rowe Jr.: > > > On 8/24/2011 8:28 PM, William A. Rowe Jr. wrote: > > > On 8/24/2011 8:02 PM, Tom Sztur wrote: > > >> > > > > I get this error when restarting Apache: > > > > > > "'RequestHeader', perhaps misspelled or _/de