<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Cloud Testing Blog &#187; Apache</title>
	<atom:link href="http://www.cloudtesting.com/blog/tag/apache/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.cloudtesting.com/blog</link>
	<description>Automated Functional, Cross Browser and Load Testing for Websites</description>
	<lastBuildDate>Fri, 23 Jul 2010 21:48:09 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.0</generator>
		<item>
		<title>Apache/mod_ssl vulnerability and mitigation</title>
		<link>http://www.cloudtesting.com/blog/2009/11/07/apachemod_ssl-vulnerability-and-mitigation/</link>
		<comments>http://www.cloudtesting.com/blog/2009/11/07/apachemod_ssl-vulnerability-and-mitigation/#comments</comments>
		<pubDate>Sat, 07 Nov 2009 09:51:13 +0000</pubDate>
		<dc:creator>Phil Smith - Cloud Testing</dc:creator>
				<category><![CDATA[Apache]]></category>
		<category><![CDATA[mod_ssl]]></category>

		<guid isPermaLink="false">http://blog.cloudtesting.com/?p=947</guid>
		<description><![CDATA[The following announcement has just been made to the announce mailing list: Apache httpd is affected by CVE-2009-3555[1] (The SSL Injection or MiM attack[2]). The Apache httpd webserver relies on OpenSSL for the implementation of the SSL/TLS protocol. We strongly urge you to upgrade to OpenSSL 0.9.8l; and to be prepared to deploy OpenSSL 0.9.8m [...]]]></description>
			<content:encoded><![CDATA[<p><img class="aligncenter size-full wp-image-592" title="Apache HTTP feather logo" src="http://cloudtesting.files.wordpress.com/2009/08/feather.gif" alt="Apache HTTP feather logo" width="248" height="70" /></p>
<p>The following announcement has just been made to the announce mailing list:</p>
<blockquote><p>Apache httpd is affected by CVE-2009-3555[1] (The SSL Injection or MiM attack[2]).</p>
<p>The Apache httpd webserver relies on OpenSSL for the implementation of the SSL/TLS protocol.</p>
<p>We strongly urge you to upgrade to OpenSSL 0.9.8l; and to be prepared to deploy OpenSSL 0.9.8m as it becomes available[3].</p>
<p>Note that these are for short term and mid-term mitigation only; the long term solution may well require a modification of the SSL and/or</p>
<p>TLS protocols[4].</p>
<p>For those who are not able to upgrade OpenSSL swiftly and/or for those who need detailed logging &#8211; we recommend that you roll out</p>
<p>this patch[5]:</p>
<p><a href="http://www.apache.org/dist/httpd/patches/">http://www.apache.org/dist/httpd/patches/</a></p>
<p>apply_to_2.2.14 CVE-2009-3555-2.2.patch</p>
<p>sha1: 28cd58f3758f1add39417333825b9d854f4f5f43</p>
<p>as soon as possible. This is a partial fix in lieu of the protocol issues being addressed and further changes to OpenSSL. Like the</p>
<p>OpenSSL 0.9.8l stopgap measure this patch rejects in-session renegotiation.</p>
<p>If you are unable to patch and unable to roll our a newer version of OpenSSL, and you rely on Client Side Authentication with Certificates</p>
<p>then we recommend that you 1) ensure that you limit your configuration to a single &#8216;SSLClient require&#8217; on VirtualHost/Sever level and 2)</p>
<p>remove all other (re)negotiation/require directives. However this does NOT fully protect you &#8211; it just curtails authentication in this</p>
<p>specific setting.</p></blockquote>
]]></content:encoded>
			<wfw:commentRss>http://www.cloudtesting.com/blog/2009/11/07/apachemod_ssl-vulnerability-and-mitigation/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Apache HTTP Server 2.2.13</title>
		<link>http://www.cloudtesting.com/blog/2009/08/10/apache-http-server-2-2-13-released/</link>
		<comments>http://www.cloudtesting.com/blog/2009/08/10/apache-http-server-2-2-13-released/#comments</comments>
		<pubDate>Mon, 10 Aug 2009 15:36:43 +0000</pubDate>
		<dc:creator>Phil Smith - Cloud Testing</dc:creator>
				<category><![CDATA[Apache]]></category>
		<category><![CDATA[HTTP Server]]></category>

		<guid isPermaLink="false">http://blog.cloudtesting.com/2009/08/10/apache-http-server-2-2-13-released/</guid>
		<description><![CDATA[An updated version of the Apache 2.2 web server has been released. It is primarily a security and bug fix release. It also bundles version 1.3.8 of the APR Library version 1.3.9 of the APR Utility Library, which addresses a security concern that may be triggered by some 3rd party modules. All users are encouraged [...]]]></description>
			<content:encoded><![CDATA[<p><img class="alignleft size-full wp-image-592" title="Apache HTTP feather logo" src="http://cloudtesting.files.wordpress.com/2009/08/feather.gif" alt="Apache HTTP feather logo" width="248" height="70" /></p>
<p>An updated version of the Apache 2.2 web server has been released. It is primarily a security and bug fix release. It also bundles version 1.3.8 of the APR Library version 1.3.9 of the APR Utility Library, which addresses a security concern that may be triggered by some 3rd party modules.</p>
<p>All users are encouraged to upgrade to this version.</p>
<p>For full details see the Apache HTTP Server website at <a href="http://httpd.apache.org/">http://httpd.apache.org/</a></p>
<p>If you need to check your websites, why not give Cloud Testing a try &#8211; <a title="Cloud Testing Website" href="http://www.cloudtesting.com/">http://www.cloudtesting.com/</a>, we offer a Functional Testing Service, Cross Browser Testing Service and a Website Archiving Service.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.cloudtesting.com/blog/2009/08/10/apache-http-server-2-2-13-released/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>
