Re: [users@httpd] SSL Client Certificates and CGI

2012-09-30 Thread Mark Montague
On September 30, 2012 19:45 , Tom Browder wrote: Does anyone have a pointer to help on restricting a directory to access only with valid SSL Client Certificates and how to work CGI scripts to respect that restriction? I have been successful restricting direct access, but it seems that certain c

[users@httpd] SSL Client Certificates and CGI

2012-09-30 Thread Tom Browder
Does anyone have a pointer to help on restricting a directory to access only with valid SSL Client Certificates and how to work CGI scripts to respect that restriction? I have been successful restricting direct access, but it seems that certain cgi programs can access the directory with impunity.

RE: [users@httpd] availability of httpd 2.0.65

2012-09-30 Thread Regev Ayelet
In this link: http://wiki.apache.org/httpd/CVE-2011-3192 FIX This vulnerability has been fixed in release 2.2.20 and further corrected in 2.2.21. You are advised to upgrade to version 2.2.21 (or newer) or the legacy 2.0.65 release, once this is published (anticipated in September). If you

Re: [users@httpd] availability of httpd 2.0.65

2012-09-30 Thread Eric Covener
On Sun, Sep 30, 2012 at 9:56 AM, Regev Ayelet wrote: > Hi All, > > According to apache.org , httpd 2.0.65 suppose to be released during > September. > Does anyone have updates on this issue? > I tried to install the patch, but my security system still claim there is a > security bug… > Where do y

[users@httpd] availability of httpd 2.0.65

2012-09-30 Thread Regev Ayelet
Hi All, According to apache.org , httpd 2.0.65 suppose to be released during September. Does anyone have updates on this issue? I tried to install the patch, but my security system still claim there is a security bug... Ayelet Regev-Dabah System Software Platform TL Comverse Office: +972 3 64593