httpd-cvs mailing list archives

Site index · List index
Message view « Date » · « Thread »
Top « Date » · « Thread »
From i...@apache.org
Subject cvs commit: httpd-2.0 STATUS
Date Mon, 27 May 2002 14:00:46 GMT
ianh        02/05/27 07:00:46

  Modified:    .        STATUS
  Log:
  remove a vote which was resolved
  
  Revision  Changes    Path
  1.630     +1 -19     httpd-2.0/STATUS
  
  Index: STATUS
  ===================================================================
  RCS file: /home/cvs/httpd-2.0/STATUS,v
  retrieving revision 1.629
  retrieving revision 1.630
  diff -u -r1.629 -r1.630
  --- STATUS	26 May 2002 22:28:06 -0000	1.629
  +++ STATUS	27 May 2002 14:00:46 -0000	1.630
  @@ -1,5 +1,5 @@
   APACHE 2.0 STATUS:                                              -*-text-*-
  -Last modified at [$Date: 2002/05/26 22:28:06 $]
  +Last modified at [$Date: 2002/05/27 14:00:46 $]
   
   Release:
   
  @@ -132,24 +132,6 @@
         +0:   BrianP, Aaron (mutex contention is looking better with the
               latest code, let's continue tuning and testing)
         -0:   Lars
  -
  -    * Change the default config so that we add a ServerToken Minimal
  -      to the config. Possibly go one step further and add a option
  -      to just report '2.0' instead of '2.0.x'
  -      +1:   IanH, BrianP
  -      -1: Greg, Cliff, Justin
  -         I use the default response all the time to verify that a
  -	 module is present and at the proper version. This information
  -	 is also very handy for the module surveys, to determine what
  -	 modules are out there and in prevalent use (see
  -	 securityspace.com; frickin' JServ is still increasing in
  -	 numbers!). Security conscious people can change this on their
  -	 own, when required. Removing the information doesn't remove
  -	 any future vulnerabilities. Assuming that a vulnerability
  -	 occurred, I highly doubt that somebody would actually bother
  -	 to *test* the version reported in the response before
  -	 attempting to use the vulnerability, so trying to hide the
  -	 information isn't all that useful.
   
   RELEASE NON-SHOWSTOPPERS BUT WOULD BE REAL NICE TO WRAP THESE UP:
   
  
  
  

Mime
View raw message