Re: [users@httpd] Unable to load Mod_security into Apache.

2020-05-21 Thread Andrei
100 :D On Fri, May 15, 2020 at 2:30 PM Eric Covener wrote: > On Fri, May 15, 2020 at 2:43 AM wrote: > > > > Thanks Eric for the reply, Can you please suggest us which version of > apache(HTTPD) and libaprutil has to be used to be compatible with > Mod_security version 3. As we have firewalls fo

Re: [users@httpd] Re: Custom Error Pages

2020-04-18 Thread Andrei
Horrible idea. Total overkill running all those echos and such for a mere 404... Bots will bend your server during spikes. Use shtml. Call it a day. On Sat, Apr 18, 2020, 18:27 Antony Stone wrote: > On Saturday 18 April 2020 at 17:05:22, Praveen Kumar K S wrote: > > > Hello, > > > > Any help wou

[users@httpd] more complex IfDefine directives

2019-09-11 Thread Florin Andrei
multiple conditions, using logical operators? Thanks, -- Florin Andrei http://florin.myip.org/ - To unsubscribe, e-mail: users-unsubscr...@httpd.apache.org For additional commands, e-mail: users-h...@httpd.apache.org

Re: [users@httpd] mod_lua and subprocess_env

2018-03-09 Thread Andrei Ivanov
Yann? Any chance to get this reviewed after the 2.4.32 release? On Tue, Jan 2, 2018 at 7:08 PM, Andrei Ivanov wrote: > Hello? Yann? > > On Thu, Dec 21, 2017 at 5:39 PM, Andrei Ivanov > wrote: > >> Yann? Are you there? ๐Ÿ˜ž >> >> On Mon, Dec 4, 2017 at 3:43 PM, A

Re: [users@httpd] mod_lua and subprocess_env

2018-01-02 Thread Andrei Ivanov
Hello? Yann? On Thu, Dec 21, 2017 at 5:39 PM, Andrei Ivanov wrote: > Yann? Are you there? ๐Ÿ˜ž > > On Mon, Dec 4, 2017 at 3:43 PM, Andrei Ivanov > wrote: > >> Hi Yann, >> Any news on the reviews? >> >> On Tue, Oct 3, 2017 at 9:58 AM, Andrei Ivanov >&

Re: [users@httpd] mod_lua and subprocess_env

2017-12-21 Thread Andrei Ivanov
Yann? Are you there? ๐Ÿ˜ž On Mon, Dec 4, 2017 at 3:43 PM, Andrei Ivanov wrote: > Hi Yann, > Any news on the reviews? > > On Tue, Oct 3, 2017 at 9:58 AM, Andrei Ivanov > wrote: > >> Woohoo! >> >> Thank you โ˜บ >> >> On Tue, Oct 3, 2017

Re: [users@httpd] mod_lua and subprocess_env

2017-12-04 Thread Andrei Ivanov
Hi Yann, Any news on the reviews? On Tue, Oct 3, 2017 at 9:58 AM, Andrei Ivanov wrote: > Woohoo! > > Thank you โ˜บ > > On Tue, Oct 3, 2017 at 1:44 AM, Yann Ylavic wrote: > >> Hi Andrei, >> >> Committed to trunk (http://svn.apache.org/r1810605), should have a &

Re: [users@httpd] mod_lua and subprocess_env

2017-10-02 Thread Andrei Ivanov
Woohoo! Thank you โ˜บ On Tue, Oct 3, 2017 at 1:44 AM, Yann Ylavic wrote: > Hi Andrei, > > Committed to trunk (http://svn.apache.org/r1810605), should have a better > visibility (and review) now. > > Regards, > Yann. > > > On Sun, Sep 17, 2017 at 8:18 PM, Andr

Re: [users@httpd] mod_lua and subprocess_env

2017-09-17 Thread Andrei Ivanov
Ok, I understand. Thank you very much ๐Ÿ™‚ On Sun, Sep 17, 2017 at 7:14 PM, Yann Ylavic wrote: > On Sun, Sep 10, 2017 at 12:46 PM, Andrei Ivanov > wrote: > > Yann? > > What's the next step? Your message didn't seem to draw attention from > others > > and

Re: [users@httpd] mod_lua and subprocess_env

2017-09-17 Thread Andrei Ivanov
Yann? Are you there? ๐Ÿ˜• On Sun, Sep 10, 2017 at 1:46 PM, Andrei Ivanov wrote: > Yann? > What's the next step? Your message didn't seem to draw attention from > others and it's been almost 2 months ๐Ÿ˜ž > > On Mon, Aug 7, 2017 at 3:30 PM, Andrei Ivanov > wrote

Re: [users@httpd] mod_lua and subprocess_env

2017-09-10 Thread Andrei Ivanov
Yann? What's the next step? Your message didn't seem to draw attention from others and it's been almost 2 months ๐Ÿ˜ž On Mon, Aug 7, 2017 at 3:30 PM, Andrei Ivanov wrote: > Hmm, if nobody comments on your proposal does it mean you get an implicit > commit acceptance after 1

Re: [users@httpd] mod_lua and subprocess_env

2017-08-07 Thread Andrei Ivanov
Hmm, if nobody comments on your proposal does it mean you get an implicit commit acceptance after 1 month? ๐Ÿ˜€ On Sat, Jul 15, 2017 at 7:35 PM, Andrei Ivanov wrote: > This is great news, thank you very much. > > So far I am monitoring the list archives through http://mail-archives. >

Re: [users@httpd] mod_lua and subprocess_env

2017-07-15 Thread Andrei Ivanov
This is great news, thank you very much. So far I am monitoring the list archives through http://mail-archives.apache.org/mod_mbox/httpd-dev/201707.mbox/browser :) On Sat, Jul 15, 2017 at 1:01 AM, Yann Ylavic wrote: > Hi Andrei, > > On Thu, Jul 13, 2017 at 3:21 PM, Andrei Ivanov

Re: [users@httpd] mod_lua and subprocess_env

2017-07-13 Thread Andrei Ivanov
Yann? Is it a good time now? ๐Ÿ™‚ On Tue, Jun 20, 2017 at 6:41 PM, Andrei Ivanov wrote: > Hi, > Seeing that 2.4.26 was released, is this a good time? ๐Ÿ˜€ > > Thanks again. > > On Sun, May 28, 2017 at 11:54 PM, Yann Ylavic > wrote: > >> Hi Andrei, >> >&g

Re: [users@httpd] 'require' directive result

2017-06-21 Thread Andrei Ivanov
On Wed, Jun 21, 2017 at 6:24 PM, Luca Toscano wrote: > Hi Andrei, > > 2017-06-16 15:23 GMT+02:00 Andrei Ivanov : > >> Hi, >> Now that I've managed to configure my 'require' directive, I have a >> requirement to log some details to sy

Re: [users@httpd] mod_lua and subprocess_env

2017-06-20 Thread Andrei Ivanov
;dr=on&is=1&token=48034&pp=13&rc=6> > ** > > On 20 June 2017 at 17:41:22, Andrei Ivanov (andrei.iva...@gmail.com) > wrote: > >> Hi, >> Seeing that 2.4.26 was released, is this a good time? ๐Ÿ˜€ >> >&

Re: [users@httpd] mod_lua and subprocess_env

2017-06-20 Thread Andrei Ivanov
Hi, Seeing that 2.4.26 was released, is this a good time? ๐Ÿ˜€ Thanks again. On Sun, May 28, 2017 at 11:54 PM, Yann Ylavic wrote: > Hi Andrei, > > On Wed, May 24, 2017 at 5:50 PM, Andrei Ivanov > wrote: > > > > Does anybody know anything about Yann? > > I do :) &g

[users@httpd] Re: 'require' directive result

2017-06-20 Thread Andrei Ivanov
Anybody? Can this be done in some way? On Fri, Jun 16, 2017 at 4:23 PM, Andrei Ivanov wrote: > Hi, > Now that I've managed to configure my 'require' directive, I have a > requirement to log some details to syslog in case the request is not > authorized

[users@httpd] 'require' directive result

2017-06-16 Thread Andrei Ivanov
Hi, Now that I've managed to configure my 'require' directive, I have a requirement to log some details to syslog in case the request is not authorized. Require expr "" // if expression is false, log details about the request and maybe the SSL certificate to syslog I've searched aro

Re: [users@httpd] mod_lua and subprocess_env

2017-05-28 Thread Andrei Ivanov
On Sun, May 28, 2017 at 11:54 PM, Yann Ylavic wrote: > Hi Andrei, > > On Wed, May 24, 2017 at 5:50 PM, Andrei Ivanov > wrote: > > > > Does anybody know anything about Yann? > > I do :) > > Sorry I didn't have the time to propose something to the dev te

Re: [users@httpd] mod_lua and subprocess_env

2017-05-24 Thread Andrei Ivanov
Does anybody know anything about Yann? ๐Ÿค” On Thu, Apr 27, 2017 at 3:47 PM, Andrei Ivanov wrote: > Yann? ๐Ÿ˜“ > > > On Wed, Apr 19, 2017 at 11:49 AM, Andrei Ivanov > wrote: > >> On Apr 10, 2017 12:10 PM, "Andrei Ivanov" >> wrote: >> >> On

Re: [users@httpd] mod_lua and subprocess_env

2017-04-27 Thread Andrei Ivanov
Yann? ๐Ÿ˜“ On Wed, Apr 19, 2017 at 11:49 AM, Andrei Ivanov wrote: > On Apr 10, 2017 12:10 PM, "Andrei Ivanov" wrote: > > On Tue, Apr 4, 2017 at 4:25 PM, Andrei Ivanov > wrote: > >> On Wed, Mar 29, 2017 at 12:16 PM, Andrei Ivanov >> wrote: >> >>

Re: [users@httpd] mod_lua and subprocess_env

2017-04-19 Thread Andrei Ivanov
On Apr 10, 2017 12:10 PM, "Andrei Ivanov" wrote: On Tue, Apr 4, 2017 at 4:25 PM, Andrei Ivanov wrote: > On Wed, Mar 29, 2017 at 12:16 PM, Andrei Ivanov > wrote: > >> On Thu, Mar 23, 2017 at 3:52 PM, Andrei Ivanov >> wrote: >> >>> On Wed, M

Re: [users@httpd] mod_lua and subprocess_env

2017-04-10 Thread Andrei Ivanov
On Tue, Apr 4, 2017 at 4:25 PM, Andrei Ivanov wrote: > On Wed, Mar 29, 2017 at 12:16 PM, Andrei Ivanov > wrote: > >> On Thu, Mar 23, 2017 at 3:52 PM, Andrei Ivanov >> wrote: >> >>> On Wed, Mar 22, 2017 at 5:08 PM, Yann Ylavic >>> wrote: >>&g

Re: [users@httpd] mod_lua and subprocess_env

2017-04-04 Thread Andrei Ivanov
On Wed, Mar 29, 2017 at 12:16 PM, Andrei Ivanov wrote: > On Thu, Mar 23, 2017 at 3:52 PM, Andrei Ivanov > wrote: > >> On Wed, Mar 22, 2017 at 5:08 PM, Yann Ylavic >> wrote: >> >>> On Wed, Mar 22, 2017 at 3:45 PM, Andrei Ivanov >>> wrote: >>

Re: [users@httpd] mod_lua and subprocess_env

2017-03-29 Thread Andrei Ivanov
On Thu, Mar 23, 2017 at 3:52 PM, Andrei Ivanov wrote: > On Wed, Mar 22, 2017 at 5:08 PM, Yann Ylavic wrote: > >> On Wed, Mar 22, 2017 at 3:45 PM, Andrei Ivanov >> wrote: >> > On Wed, Mar 22, 2017 at 3:53 PM, Andrei Ivanov > > >> > wrote: >>

Re: [users@httpd] Re: Spoofing SERVER_PORT/HTTPS env?

2017-03-23 Thread Andrei
So there's a restriction on $_SERVER[SERVER_PORT]? Is it compiled in? On Mar 23, 2017 14:37, "Rainer Canavan" wrote: [...] >> SetEnvIf X-HTTPS "on" SERVER_PORT=443 >> >> The above results in: [...] >> $_SERVER[SERVER_PORT]; => 80 We had the same problem a few years ago, and went with a worka

Re: [users@httpd] mod_lua and subprocess_env

2017-03-23 Thread Andrei Ivanov
On Wed, Mar 22, 2017 at 5:08 PM, Yann Ylavic wrote: > On Wed, Mar 22, 2017 at 3:45 PM, Andrei Ivanov > wrote: > > On Wed, Mar 22, 2017 at 3:53 PM, Andrei Ivanov > > wrote: > > > > Argh! You've sent more emails but Gmail received them out of order so I >

[users@httpd] Re: Spoofing SERVER_PORT/HTTPS env?

2017-03-22 Thread Andrei
bump On Thu, Mar 16, 2017 at 5:33 PM, Andrei wrote: > Hello everyone, > > I have a setup with Varnish/Hitch in front of Apache, where Hitch proxies > the SSL traffic to Varnish via HTTP, and Apache receives the request via > HTTP while the client request was done via https. This

Re: [users@httpd] mod_lua and subprocess_env

2017-03-22 Thread Andrei Ivanov
On Wed, Mar 22, 2017 at 3:53 PM, Andrei Ivanov wrote: > On Wed, Mar 22, 2017 at 3:27 PM, Yann Ylavic wrote: > >> On Wed, Mar 22, 2017 at 1:37 PM, Yann Ylavic >> wrote: >> > >> > There are two patches attached, one for the changes in httpd code, the >&

Re: [users@httpd] mod_lua and subprocess_env

2017-03-22 Thread Andrei Ivanov
On Wed, Mar 22, 2017 at 3:27 PM, Yann Ylavic wrote: > On Wed, Mar 22, 2017 at 1:37 PM, Yann Ylavic wrote: > > > > There are two patches attached, one for the changes in httpd code, the > > other for the files generated by the bison/flex parser. > > The second patch was missing the changes in ser

Re: [users@httpd] mod_lua and subprocess_env

2017-03-20 Thread Andrei Ivanov
On Mon, Mar 13, 2017 at 4:16 PM, Andrei Ivanov wrote: > On Fri, Mar 10, 2017 at 12:35 PM, Andrei Ivanov > wrote: > >> On Tue, Mar 7, 2017 at 7:08 PM, Andrei Ivanov >> wrote: >> >>> On Mon, Mar 6, 2017 at 12:57 PM, Yann Ylavic >>> wrote: >>&g

[users@httpd] Spoofing SERVER_PORT/HTTPS env?

2017-03-16 Thread Andrei
Hello everyone, I have a setup with Varnish/Hitch in front of Apache, where Hitch proxies the SSL traffic to Varnish via HTTP, and Apache receives the request via HTTP while the client request was done via https. This local downgrade is due to Varnish not supporting SSL. Since there are quite a fe

Re: [users@httpd] Re: ModSecurity and custom headers

2017-03-14 Thread Andrei
bump On Sat, Mar 11, 2017 at 4:14 PM, Andrei wrote: > I also tried for example: > > SecDefaultAction "phase:2,deny,log,status:406, > setenv:'env_modsecblk=%{rule.msg}'" > > Header always set X-ModSec-Block %{env_modsecblk}e env=env_modsecblk >

Re: [users@httpd] mod_lua and subprocess_env

2017-03-13 Thread Andrei Ivanov
On Fri, Mar 10, 2017 at 12:35 PM, Andrei Ivanov wrote: > On Tue, Mar 7, 2017 at 7:08 PM, Andrei Ivanov > wrote: > >> On Mon, Mar 6, 2017 at 12:57 PM, Yann Ylavic >> wrote: >> >>> Hi Andrei, >>> >>> On Mon, Mar 6, 2017 at 10:15 AM, Andrei Iv

Re: [users@httpd] Re: ModSecurity and custom headers

2017-03-11 Thread Andrei
2.conf: Cannot parse condition clause: Variable 'env_modsecblk' does not exist On Sat, Mar 11, 2017 at 8:06 AM, Andrei wrote: > Hello again :) > > So I went to the modsec lists, figured out how to get the environment > variable set with the rule message by default for all

Re: [users@httpd] Re: ModSecurity and custom headers

2017-03-11 Thread Andrei
X-ModSec-Block So I my question at this point is; how do I conditionally set the custom "X-ModSec-Block" header to the value of the "env_modsecblk" environment variable, if that variable exists, and isn't blank. Thanks again everyone :) 1 - http://httpd.apache.org/docs/

Re: [users@httpd] mod_lua and subprocess_env

2017-03-10 Thread Andrei Ivanov
On Tue, Mar 7, 2017 at 7:08 PM, Andrei Ivanov wrote: > On Mon, Mar 6, 2017 at 12:57 PM, Yann Ylavic wrote: > >> Hi Andrei, >> >> On Mon, Mar 6, 2017 at 10:15 AM, Andrei Ivanov >> wrote: >> >>> On Thu, Mar 2, 2017 at 12:40 PM, Andrei Ivanov >>

Re: [users@httpd] mod_lua and subprocess_env

2017-03-07 Thread Andrei Ivanov
On Mon, Mar 6, 2017 at 12:57 PM, Yann Ylavic wrote: > Hi Andrei, > > On Mon, Mar 6, 2017 at 10:15 AM, Andrei Ivanov > wrote: > >> On Thu, Mar 2, 2017 at 12:40 PM, Andrei Ivanov >> wrote: >> >>> On Tue, Feb 28, 2017 at 12:09 PM, Andrei Ivanov >>

Re: [users@httpd] mod_lua and subprocess_env

2017-03-06 Thread Andrei Ivanov
On Thu, Mar 2, 2017 at 12:40 PM, Andrei Ivanov wrote: > On Tue, Feb 28, 2017 at 12:09 PM, Andrei Ivanov > wrote: > >> On Mon, Feb 27, 2017 at 11:58 AM, Andrei Ivanov >> wrote: >> >>> On Fri, Feb 24, 2017 at 10:58 PM, Andrei Ivanov >> > wrote:

Re: [users@httpd] mod_lua and subprocess_env

2017-03-02 Thread Andrei Ivanov
On Tue, Feb 28, 2017 at 12:09 PM, Andrei Ivanov wrote: > On Mon, Feb 27, 2017 at 11:58 AM, Andrei Ivanov > wrote: > >> On Fri, Feb 24, 2017 at 10:58 PM, Andrei Ivanov >> wrote: >> >>> On Feb 24, 2017 22:54, "Yann Ylavic" wrote: >>> >&g

Re: [users@httpd] Re: ModSecurity and custom headers

2017-03-01 Thread Andrei
Thanks! On Wed, Mar 1, 2017 at 3:36 AM, Luca Toscano wrote: > Hi Andrei, > > 2017-03-01 6:54 GMT+01:00 Andrei : > >> Is there a different list I should be asking this on? >> > > I would start from https://modsecurity.org/help.html (Mod Security is not > part o

[users@httpd] Re: ModSecurity and custom headers

2017-02-28 Thread Andrei
Is there a different list I should be asking this on? On Mon, Feb 27, 2017 at 8:49 AM, Andrei wrote: > Hi all, > > How can I add a custom header using the 'msg' value from a ModSecurity > rule, for all rules triggered? I'm basically trying to track the ModSec >

Re: [users@httpd] mod_lua and subprocess_env

2017-02-28 Thread Andrei Ivanov
On Tue, Feb 28, 2017 at 2:02 PM, Eric Covener wrote: > On Mon, Feb 27, 2017 at 4:58 AM, Andrei Ivanov > wrote: > > But I think mod_headers has some different way of interpreting > expressions, > > because this doesn't work: > > The grammar has different star

Re: [users@httpd] mod_lua and subprocess_env

2017-02-28 Thread Andrei Ivanov
On Mon, Feb 27, 2017 at 11:58 AM, Andrei Ivanov wrote: > On Fri, Feb 24, 2017 at 10:58 PM, Andrei Ivanov > wrote: > >> On Feb 24, 2017 22:54, "Yann Ylavic" wrote: >> >> On Fri, Feb 24, 2017 at 6:50 PM, Andrei Ivanov >> wrote: >> > >>

[users@httpd] ModSecurity and custom headers

2017-02-27 Thread Andrei
g done at different phases, and found http://serverfault.com/questions/796088/modsecurity-creating-a-new-request-header-from-secrule which seems similar to this scenario, just that it's not quite working out for me. Any help is greatly appreciated! Andrei

Re: [users@httpd] mod_lua and subprocess_env

2017-02-27 Thread Andrei Ivanov
On Fri, Feb 24, 2017 at 10:58 PM, Andrei Ivanov wrote: > On Feb 24, 2017 22:54, "Yann Ylavic" wrote: > > On Fri, Feb 24, 2017 at 6:50 PM, Andrei Ivanov > wrote: > > > > I've managed to apply your patch and rebuild Apache and now I have: > > Header s

Re: [users@httpd] mod_lua and subprocess_env

2017-02-24 Thread Andrei Ivanov
On Feb 24, 2017 22:54, "Yann Ylavic" wrote: On Fri, Feb 24, 2017 at 6:50 PM, Andrei Ivanov wrote: > > I've managed to apply your patch and rebuild Apache and now I have: > Header set Client-IP "expr=%{REMOTE_ADDR}" > Header set Client-SAN "expr=%{Peer

Re: [users@httpd] mod_lua and subprocess_env

2017-02-24 Thread Andrei Ivanov
On Wed, Feb 22, 2017 at 5:10 PM, Yann Ylavic wrote: > On Wed, Feb 22, 2017 at 3:19 PM, Andrei Ivanov > wrote: > > On Wed, Feb 22, 2017 at 3:36 PM, Yann Ylavic > wrote: > >> > >> My bad, please try without the parentheses: > >> > >>

Re: [users@httpd] mod_lua and subprocess_env

2017-02-22 Thread Andrei Ivanov
On Wed, Feb 22, 2017 at 3:36 PM, Yann Ylavic wrote: > On Wed, Feb 22, 2017 at 11:19 AM, Andrei Ivanov > wrote: > > On Wed, Feb 22, 2017 at 12:02 PM, Yann Ylavic > wrote: > >> > >> On Wed, Feb 22, 2017 at 10:58 AM, Andrei Ivanov < > andrei.iva...@gmail.co

Re: [users@httpd] mod_lua and subprocess_env

2017-02-22 Thread Andrei Ivanov
On Wed, Feb 22, 2017 at 12:02 PM, Yann Ylavic wrote: > On Wed, Feb 22, 2017 at 10:58 AM, Andrei Ivanov > wrote: > > > > So... do I have a chance to get it running on RHEL 7.3 which ships with > > 2.4.6? > > That may work in 2.4.6, I just didn't try ;) > &q

Re: [users@httpd] mod_lua and subprocess_env

2017-02-22 Thread Andrei Ivanov
On Wed, Feb 22, 2017 at 2:13 AM, Yann Ylavic wrote: > On Wed, Feb 22, 2017 at 1:09 AM, Yann Ylavic wrote: > > On Tue, Feb 21, 2017 at 5:43 PM, Andrei Ivanov > wrote: > >> On Tue, Feb 21, 2017 at 6:32 PM, Yann Ylavic > wrote: > >>> > >>>

Re: [users@httpd] mod_lua and subprocess_env

2017-02-21 Thread Andrei Ivanov
On Tue, Feb 21, 2017 at 6:43 PM, Andrei Ivanov wrote: > On Tue, Feb 21, 2017 at 6:32 PM, Yann Ylavic wrote: > >> On Tue, Feb 21, 2017 at 4:50 PM, Andrei Ivanov >> wrote: >> >>> >> >>> Header set Client-SAN "%{PeerExtList('2.5.29.17&#x

Re: [users@httpd] mod_lua and subprocess_env

2017-02-21 Thread Andrei Ivanov
On Tue, Feb 21, 2017 at 6:32 PM, Yann Ylavic wrote: > On Tue, Feb 21, 2017 at 4:50 PM, Andrei Ivanov > wrote: > >>> > >>> Header set Client-SAN "%{PeerExtList('2.5.29.17')}s" > > The syntax may be rather: > > Header set Client-SAN

Re: [users@httpd] mod_lua and subprocess_env

2017-02-21 Thread Andrei Ivanov
On Mon, Feb 20, 2017 at 11:31 AM, Andrei Ivanov wrote: > On Fri, Feb 17, 2017 at 12:18 PM, Andrei Ivanov > wrote: > >> >> On Thu, Feb 16, 2017 at 9:26 PM, Eric Covener wrote: >> >>> On Thu, Feb 16, 2017 at 11:16 AM, Andrei Ivanov >>> wrote: >

Re: [users@httpd] mod_lua and subprocess_env

2017-02-20 Thread Andrei Ivanov
On Fri, Feb 17, 2017 at 12:18 PM, Andrei Ivanov wrote: > > On Thu, Feb 16, 2017 at 9:26 PM, Eric Covener wrote: > >> On Thu, Feb 16, 2017 at 11:16 AM, Andrei Ivanov >> wrote: >> > Is there a way to debug this? To print the values from the expression >> in t

Re: [users@httpd] filtering by IP SAN entries in the client certificate

2017-02-17 Thread Andrei Ivanov
On Thu, Feb 16, 2017 at 11:38 AM, Andrei Ivanov wrote: > On Wed, Feb 15, 2017 at 12:46 PM, Daniel Gruno > wrote: > >> On 02/15/2017 11:31 AM, Andrei Ivanov wrote: >> > Hi, >> > I have a requirement to check incoming requests, something that would be &

Re: [users@httpd] mod_lua and subprocess_env

2017-02-17 Thread Andrei Ivanov
On Thu, Feb 16, 2017 at 9:26 PM, Eric Covener wrote: > On Thu, Feb 16, 2017 at 11:16 AM, Andrei Ivanov > wrote: > > Is there a way to debug this? To print the values from the expression in > the > > logs maybe? > > One simple way to debug is to use the same [sub-]e

Re: [users@httpd] mod_lua and subprocess_env

2017-02-16 Thread Andrei Ivanov
On Thu, Feb 16, 2017 at 5:20 PM, Yann Ylavic wrote: > On Thu, Feb 16, 2017 at 2:46 PM, Andrei Ivanov > wrote: > > > > I gave it a try, but seems to reach the same limitation of the expression > > engine :-( > > NSSRequire %{REMOTE_ADDR} in PeerExtList('

Re: [users@httpd] mod_lua and subprocess_env

2017-02-16 Thread Andrei Ivanov
On Thu, Feb 16, 2017 at 2:49 PM, Yann Ylavic wrote: > On Tue, Feb 14, 2017 at 1:24 PM, Andrei Ivanov > wrote: > > > > I'm using mod_nss exactly because mod_ssl doesn't expose that variable > and > > my issue that requests that is sitting ignored for 2 mon

Re: [users@httpd] filtering by IP SAN entries in the client certificate

2017-02-16 Thread Andrei Ivanov
On Wed, Feb 15, 2017 at 12:46 PM, Daniel Gruno wrote: > On 02/15/2017 11:31 AM, Andrei Ivanov wrote: > > Hi, > > I have a requirement to check incoming requests, something that would be > > succinctly expressed this way: > > > > > > Require expr &qu

[users@httpd] filtering by IP SAN entries in the client certificate

2017-02-15 Thread Andrei Ivanov
Hi, I have a requirement to check incoming requests, something that would be succinctly expressed this way: Require expr "%{REMOTE_ADDR} in %{SSL_CLIENT_SAN_IPaddr}" This would check that the request IP address is among the IP addresses in the client certificate. Unfortunately, this doesn'

Re: [users@httpd] mod_lua and subprocess_env

2017-02-14 Thread Andrei Ivanov
On Tue, Feb 14, 2017 at 2:19 PM, Daniel Gruno wrote: > On 02/14/2017 01:16 PM, Andrei Ivanov wrote: > > On Tue, Feb 14, 2017 at 1:59 PM, Daniel Gruno > <mailto:humbed...@apache.org>> wrote: > > > > On 02/14/2017 12:38 PM, Andrei Ivanov wrote: > >

Re: [users@httpd] mod_lua and subprocess_env

2017-02-14 Thread Andrei Ivanov
On Tue, Feb 14, 2017 at 1:59 PM, Daniel Gruno wrote: > On 02/14/2017 12:38 PM, Andrei Ivanov wrote: > > Hi, > > I'm trying to create a lua authorization script but I can't seem to > > access the request environment: > > > > require 'apache2' &

[users@httpd] mod_lua and subprocess_env

2017-02-14 Thread Andrei Ivanov
Hi, I'm trying to create a lua authorization script but I can't seem to access the request environment: require 'apache2' function authz_check_remote_ip_in_client_san(r) r:err("remote_ip_in_client_san running..."); r:alert("uri: " .. r.uri); r:alert("useragent_ip: " .. r.u

Re: [users@httpd] SSL_CLIENT_SAN IP addr validation

2016-12-19 Thread Andrei Ivanov
I think the nicest way would be like mod_ssl does with PeerExtList: Example SSLRequire "foobar" in PeerExtList("1.2.3.4.5.6") So at least it's nice to know Apache Httpd already does this in some cases. I guess I'll update my ticket, or maybe create a new one for all the subjectAltName variables.

Re: [users@httpd] SSL_CLIENT_SAN IP addr validation

2016-12-19 Thread Andrei Ivanov
omething like this: > > Require expr "%{SSL_CLIENT_SAN_DNS_1} == %{REMOTE_ADDR}" > > > -- > > With Best Regards, > Marat Khalili > > On 19/12/16 18:48, Andrei Ivanov wrote: > > Hi, > Yes, I did notice the suggestion of using Require expr, the p

Re: [users@httpd] SSL_CLIENT_SAN IP addr validation

2016-12-19 Thread Andrei Ivanov
verify > SSL_CLIENT_S_DN_OU as well as SSL_CLIENT_S_DN_O. > -- > > With Best Regards, > Marat Khalili > > On 15/12/16 13:46, Andrei Ivanov wrote: > > Hi, > I'm trying to validate incoming requests by comparing the request IP to > the IP addresses provided in

[users@httpd] Re: SSL_CLIENT_SAN IP addr validation

2016-12-19 Thread Andrei Ivanov
Anybody? :-/ On Thu, Dec 15, 2016 at 12:46 PM, Andrei Ivanov wrote: > Hi, > I'm trying to validate incoming requests by comparing the request IP to > the IP addresses provided in the client certificate subjectAltName. > > Searching around, I found ht

[users@httpd] SSL_CLIENT_SAN IP addr validation

2016-12-15 Thread Andrei Ivanov
Hi, I'm trying to validate incoming requests by comparing the request IP to the IP addresses provided in the client certificate subjectAltName. Searching around, I found http://wiki.cacert.org/ApacheServerClientCertificateAuthentication, which gives an example using the email address: SSLRequire

Re: [us...@httpd] Client certificate authentication on tunneling proxy

2010-01-28 Thread Andrei T
Andrei T wrote: I tried configuring apache as a tunneling proxy through https, but in this scenario apache would not recognize the CONNECT request and would not establish a tunnel to the target server. I actually found that this is a known issue with apache: https://issues.apache.org

Re: [us...@httpd] Client certificate authentication on tunneling proxy

2010-01-28 Thread Andrei T
Matus UHLAR - fantomas wrote: On 21.01.10 18:33, Andrei T wrote: I am trying to connect to apache through SSL (port 443) and tell it to create a tunnel to some other server listening on port 80. why a tunnel? Who would create the tunnel? While It's possible, I don't know of any br

Re: [us...@httpd] Client certificate authentication on tunneling proxy

2010-01-20 Thread Andrei T
apache is not working even without them. My understanding that client certificate verification is possible only through an SSL connection. That's why I am trying to make apache run in HTTPS mode for proxying. On Thu, Jan 21, 2010 at 12:35 PM, Andrei T <mailto:magistra...@hot.ee>> w

[us...@httpd] Client certificate authentication on tunneling proxy

2010-01-20 Thread Andrei T
:+MEDIUM:+LOW:+SSLv2:+EXP:+eNULL SSLCertificateFile /etc/apache2/ssl.crt/server.crt SSLCertificateKeyFile /etc/apache2/ssl.key/server.key Any help would be appreciated. Thanks, -- Andrei T - The official User-To

Re: [us...@httpd] I need a technique for executing very fast code behind the httpd apache server.

2009-12-28 Thread Andrei Paul Nistor
also be a solution and I started to test that. Write to you all later and thanks alot for the fast answers. You are all great. On Sun, Dec 27, 2009 at 10:33 AM, Krist van Besien < krist.vanbes...@gmail.com> wrote: > On Sat, Dec 26, 2009 at 2:04 PM, Andrei Paul Nistor >

Re: [us...@httpd] I need a technique for executing very fast code behind the httpd apache server.

2009-12-26 Thread Andrei Paul Nistor
at, Dec 26, 2009 at 4:20 PM, Morten Kirkegaard Poulsen < m...@fabletech.com> wrote: > Hi Andrei, > > On Sat, 2009-12-26 at 16:01 +0200, Bogdan Cristea wrote: > > On Saturday 26 December 2009 15:56:43 Andrei > > Paul Nistor wrote: > > > I thought about using soap

Re: [us...@httpd] I need a technique for executing very fast code behind the httpd apache server.

2009-12-26 Thread Andrei Paul Nistor
I thought about using soap as an comunication protocol but in fact the remote procedures are php scripts or asp i need compiled code that can execute fast and share objects, the communication protocol isnt important it can be anything. With respect Andrei Paul Nistor On Sat, Dec 26, 2009 at 3:29

[us...@httpd] I need a technique for executing very fast code behind the httpd apache server.

2009-12-26 Thread Andrei Paul Nistor
Hello all. Question: Is it any way possible to access through the httpd server resources like objects or remote procedures that run on the server in binary form and dont get disposed after each call of the resources? I read lately alot about cgi and the apache server but i haven't found an answer

Re: [us...@httpd] mod_rewrite and setenv

2009-11-02 Thread Andrei Iarus
s info also in the mod_rewrite, RewriteCond's documentation page. Thanks a lot. Have a nice day! --- On Sun, 11/1/09, Andrรฉ Warnier wrote: From: Andrรฉ Warnier Subject: Re: [us...@httpd] mod_rewrite and setenv To: users@httpd.apache.org Date: Sunday, November 1, 2009, 10:36 PM Andrei Iaru

Re: [us...@httpd] mod_rewrite and setenv

2009-11-01 Thread Andrei Iarus
setenv To: users@httpd.apache.org Date: Sunday, November 1, 2009, 7:17 PM On Nov 1, 2009, at 10:50 , Andrei Iarus wrote: Hello, ย  I have looked a lot in Internet, and found many people complaining about the same problem, with no normal answer. ย  My problem: mod_rewrite with its

[us...@httpd] mod_rewrite and setenv

2009-11-01 Thread Andrei Iarus
Hello, ย  I have looked a lot in Internet, and found many people complaining about the same problem, with no normal answer. ย  My problem: mod_rewrite with its RewriteCond %{ENV:variable} form cannot read correctly the environment variables. ย  The variable is set directly in the .htaccess OR in the

[EMAIL PROTECTED] Apache 2.2 on Windows - problem with Params::Callback

2008-05-28 Thread Andrei Kozovski
this case, is _not_ to load anything into your parent process before the child processย is created ( opositeย from Unix case, when this is crutial for memory sharing ), i.e. without custom start.pl script into apache conf or custom loading of perl packages into httpd.conf. Regards, Andrei