From owner-freebsd-apache@FreeBSD.ORG Thu Dec 10 00:11:52 2009 Return-Path: Delivered-To: apache@FreeBSD.org Received: from mx1.freebsd.org (mx1.freebsd.org [IPv6:2001:4f8:fff6::34]) by hub.freebsd.org (Postfix) with ESMTP id 3F569106566B for ; Thu, 10 Dec 2009 00:11:52 +0000 (UTC) (envelope-from pgollucci@p6m7g8.com) Received: from exhub015-1.exch015.msoutlookonline.net (exhub015-1.exch015.msoutlookonline.net [207.5.72.93]) by mx1.freebsd.org (Postfix) with ESMTP id 299598FC12 for ; Thu, 10 Dec 2009 00:11:51 +0000 (UTC) Received: from philip.hq.rws (174.79.184.239) by smtpx15.msoutlookonline.net (207.5.72.103) with Microsoft SMTP Server (TLS) id 8.2.176.0; Wed, 9 Dec 2009 16:11:51 -0800 Message-ID: <4B203CC6.6060105@p6m7g8.com> Date: Thu, 10 Dec 2009 00:11:50 +0000 From: "Philip M. Gollucci" Organization: P6M7G8 Inc. User-Agent: Thunderbird 2.0.0.23 (X11/20091208) MIME-Version: 1.0 To: Jun Kuriyama References: <4AFCB886.9080708@p6m7g8.com> <48acff730912091547s549104fan1dc65da2dc2d56e9@mail.gmail.com> In-Reply-To: <48acff730912091547s549104fan1dc65da2dc2d56e9@mail.gmail.com> Content-Type: text/plain; charset="ISO-8859-1"; format=flowed Content-Transfer-Encoding: 7bit Cc: Chris , apache@FreeBSD.org Subject: Re: apache 2.2.14 missing in ports X-BeenThere: freebsd-apache@freebsd.org X-Mailman-Version: 2.1.5 Precedence: list List-Id: Support of apache-related ports List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Thu, 10 Dec 2009 00:11:52 -0000 Jun Kuriyama wrote: > 2009/11/13 Philip M. Gollucci : >> Chris wrote: >> At this point 2.2.15 is immiment and will include the recent ssl >> fix/work around. > > Is this related to "tslext" problem? I'm using 2.2.13 with -TSLv1 to > work around it. > > I'm not sure this is fixed in apache repository or not... > > 2.2.14 does not address anything related to the SSL issues. You'll need openssl updates first. Also you are only vulnerable if you do client side renegotiation. -- ------------------------------------------------------------------------ 1024D/DB9B8C1C B90B FBC3 A3A1 C71A 8E70 3F8C 75B8 8FFB DB9B 8C1C Philip M. Gollucci (pgollucci@p6m7g8.com) c: 703.336.9354 VP Apache Infrastructure; Member, Apache Software Foundation Committer, FreeBSD Foundation Consultant, P6M7G8 Inc. Sr. System Admin, Ridecharge Inc. Work like you don't need the money, love like you'll never get hurt, and dance like nobody's watching.