- Fri May 8 2009 Joe Orton <jorton@redhat.com> 2.2.3-22.el5_3.1
- add security fixes for CVE-2008-1678, CVE-2009-1195 (#499284)
- Thu Nov 13 2008 Joe Orton <jorton@redhat.com> 2.2.3-22.el5
- add security fixes for CVE-2008-2939 (#468841)
- note that the mod_proxy 2.2.9 rebase fixed CVE-2008-2634 - Wed Oct 22 2008 Joe Orton <jorton@redhat.com> 2.2.3-21.el5
- avoid strict-aliasing warnings (#462877)
- Wed Oct 22 2008 Joe Orton <jorton@redhat.com> 2.2.3-20.el5
- mod_proxy: scoreboard access fix (#252024)
- Fri Sep 19 2008 Joe Orton <jorton@redhat.com> 2.2.3-19.el5
- mod_proxy: various backport fixes (#252024)
- Fri Sep 19 2008 Joe Orton <jorton@redhat.com> 2.2.3-17.el5
- fix mod_proxy symbol use
- Tue Sep 16 2008 Joe Orton <jorton@redhat.com> 2.2.3-16.el5
- mod_proxy*, mod_cache*: rebase to 2.2.9 (#252024, #249534,
- backport changes to make chunk filter non-blocking (#454098) - Sat Sep 13 2008 Joe Orton <jorton@redhat.com> 2.2.3-15.el5
- mod_ldap: fix memory lifetime issues (#440259)
- mod_ssl: configure OpenSSL dynamic lock callbacks (#462044)
- escape the Request-Method in canned error responses (#445888)
- build the event MPM and fix a deadlock therein (#444643)
- mod_headers: support "RequestHeader edit" (#428253)
- use "OPTIONS *" rather than "GET /" in dummy connection (#367981) - Fri Aug 15 2008 Joe Orton <jorton@redhat.com> 2.2.3-14.el5
- mod_proxy: add ProxyPassMatch support (#449159)
- Tue Jul 22 2008 Joe Orton <jorton@redhat.com> 2.2.3-13.el5
- mod_proxy_balancer: allow alternative string to match for
stickysession parameter (#439218)
- fix dist tag in Release (#440615) - Sat Jan 12 2008 Joe Orton <jorton@redhat.com> 2.2.3-12.el5_1.3
- further update to backport for CVE-2007-6421 (#427240)
- Sat Jan 12 2008 Joe Orton <jorton@redhat.com> 2.2.3-12.el5_1.2
- updated backport for CVE-2007-6421 (#427240)
- Tue Jan 8 2008 Joe Orton <jorton@redhat.com> 2.2.3-11.el5_1.1
- add security fixes for CVE-2007-6388, CVE-2007-6421
and CVE-2007-6422 (#427240)
- add security fix for CVE-2007-4465, CVE-2007-5000 (#421631)
- add security fix for mod_proxy_ftp UTF-7 XSS (#427745) - Tue Aug 7 2007 Joe Orton <jorton@redhat.com> 2.2.3-11.el5
- mark httpd.conf config(noreplace) (#247881)
- Sat Aug 4 2007 Joe Orton <jorton@redhat.com> 2.2.3-10.el5
- add security fix for CVE-2007-3847 (#250761)
- Thu Aug 2 2007 Joe Orton <jorton@redhat.com> 2.2.3-9.el5
- load mod_version by default (#247881)
- Wed Jun 27 2007 Joe Orton <jorton@redhat.com> 2.2.3-8.el5
- add 'ServerTokens Full-Release' config option (#240857)
- use init script in logrotate postrotate (#241680)
- fix mod_proxy option inheritance (#245719)
- fix ProxyErrorOverride to only affect 4xx, 5xx responses (#240024)
- bump logresolve line buffer length to 10K (#245763)
- add security fixes for CVE-2007-1863, CVE-2007-3304,
and CVE-2006-5752 (#244666) - Thu Nov 30 2006 Joe Orton <jorton@redhat.com> 2.2.3-6.el5
- fix path to instdso.sh in special.mk (#217677)
- fix detection of links in "apachectl fullstatus" - Wed Sep 20 2006 Joe Orton <jorton@redhat.com> 2.2.3-5.el5
- rebuild
- Sat Aug 12 2006 Joe Orton <jorton@redhat.com> 2.2.3-3.el5
- use RHEL branding
- Fri Aug 4 2006 Joe Orton <jorton@redhat.com> 2.2.3-3
- init: use killproc() delay to avoid race killing parent
- Sat Jul 29 2006 Joe Orton <jorton@redhat.com> 2.2.3-2
- update to 2.2.3
- trim %changelog to >=2.0.52 - Fri Jul 21 2006 Joe Orton <jorton@redhat.com> 2.2.2-8
- fix segfault on dummy connection failure at graceful restart (#199429)
- Thu Jul 20 2006 Joe Orton <jorton@redhat.com> 2.2.2-7
- fix "apxs -g"-generated Makefile
- fix buildconf with autoconf 2.60 - Thu Jul 13 2006 Jesse Keating <jkeating@redhat.com> - 2.2.2-5.1
- rebuild
- Thu Jun 8 2006 Joe Orton <jorton@redhat.com> 2.2.2-5
- require pkgconfig for -devel (#194152)
- fixes for installed support makefiles (special.mk et al)
- BR autoconf - Sat Jun 3 2006 Joe Orton <jorton@redhat.com> 2.2.2-4
- make -devel package multilib-safe (#192686)
- Fri May 12 2006 Joe Orton <jorton@redhat.com> 2.2.2-3
- build DSOs using -z relro linker flag
- Thu May 4 2006 Joe Orton <jorton@redhat.com> 2.2.2-2
- update to 2.2.2
- Fri Apr 7 2006 Joe Orton <jorton@redhat.com> 2.2.0-6
- rebuild to pick up apr-util LDAP interface fix (#188073)
- Sat Feb 11 2006 Jesse Keating <jkeating@redhat.com> - (none):2.2.0-5.1.2
- bump again for double-long bug on ppc(64)
- Wed Feb 8 2006 Jesse Keating <jkeating@redhat.com> - (none):2.2.0-5.1.1
- rebuilt for new gcc4.1 snapshot and glibc changes
- Tue Feb 7 2006 Joe Orton <jorton@redhat.com> 2.2.0-5.1
- mod_auth_basic/mod_authn_file: if no provider is configured,
and AuthUserFile is not configured, decline to handle authn
silently rather than failing noisily. - Sat Feb 4 2006 Joe Orton <jorton@redhat.com> 2.2.0-5
- mod_ssl: add security fix for CVE-2005-3357 (#177914)
- mod_imagemap: add security fix for CVE-2005-3352 (#177913)
- add fix for AP_INIT_* designated initializers with C++ compilers
- httpd.conf: enable HTMLTable in default IndexOptions
- httpd.conf: add more "redirect-carefully" matches for DAV clients - Fri Jan 6 2006 Joe Orton <jorton@redhat.com> 2.2.0-4
- mod_proxy_ajp: fix Cookie handling (Mladen Turk, r358769)
- Sat Dec 10 2005 Jesse Keating <jkeating@redhat.com>
- rebuilt
- Thu Dec 8 2005 Joe Orton <jorton@redhat.com> 2.2.0-3
- strip manual to just English content
- Tue Dec 6 2005 Joe Orton <jorton@redhat.com> 2.2.0-2
- don't strip C-L from HEAD responses (Greg Ames, #110552)
- load mod_proxy_balancer by default
- add proxy_ajp.conf to load/configure mod_proxy_ajp
- Obsolete mod_jk
- update docs URLs in httpd.conf/ssl.conf - Sat Dec 3 2005 Joe Orton <jorton@redhat.com> 2.2.0-1
- update to 2.2.0
- Thu Dec 1 2005 Joe Orton <jorton@redhat.com> 2.1.10-2
- enable mod_authn_alias, mod_authn_anon
- update default httpd.conf - Sat Nov 26 2005 Joe Orton <jorton@redhat.com> 2.1.10-1
- update to 2.1.10
- require apr >= 1.2.0, apr-util >= 1.2.0 - Thu Nov 10 2005 Tomas Mraz <tmraz@redhat.com> 2.0.54-16
- rebuilt against new openssl
- Fri Nov 4 2005 Joe Orton <jorton@redhat.com> 2.0.54-15
- log notice giving SELinux context at startup if enabled
- drop SSLv2 and restrict default cipher suite in default
SSL configuration - Fri Oct 21 2005 Joe Orton <jorton@redhat.com> 2.0.54-14
- mod_ssl: add security fix for SSLVerifyClient (CVE-2005-2700)
- add security fix for byterange filter DoS (CVE-2005-2728)
- add security fix for C-L vs T-E handling (CVE-2005-2088)
- mod_ssl: add security fix for CRL overflow (CVE-2005-1268)
- mod_ldap/mod_auth_ldap: add fixes from 2.0.x branch (upstream #34209 etc)
- add fix for dummy connection handling (#167425)
- mod_auth_digest: fix hostinfo comparison in CONNECT requests
- mod_include: fix variable corruption in nested includes (upstream #12655)
- mod_ssl: add fix for handling non-blocking reads
- mod_ssl: fix to enable output buffering (upstream #35279)
- mod_ssl: buffer request bodies for per-location renegotiation (upstream #12355) - Sun Aug 14 2005 Joe Orton <jorton@redhat.com> 2.0.54-13
- don't load by default: mod_cern_meta, mod_asis
- do load by default: mod_ext_filter (#165893) - Fri Jul 29 2005 Joe Orton <jorton@redhat.com> 2.0.54-12
- drop broken epoch deps
- Fri Jul 1 2005 Joe Orton <jorton@redhat.com> 2.0.54-11
- mod_dav_fs: fix uninitialized variable (#162144)
- add epoch to dependencies as appropriate
- mod_ssl: drop dependencies on dev, make
- mod_ssl: mark post script dependencies as such - Tue May 24 2005 Joe Orton <jorton@redhat.com> 2.0.54-10
- remove broken symlink (Robert Scheck, #158404)
- Thu May 19 2005 Joe Orton <jorton@redhat.com> 2.0.54-9
- add piped logger fixes (w/Jeff Trawick)
- Tue May 10 2005 Joe Orton <jorton@redhat.com> 2.0.54-8
- drop old "powered by Red Hat" logos
- Thu May 5 2005 Joe Orton <jorton@redhat.com> 2.0.54-7
- mod_userdir: fix memory allocation issue (upstream #34588)
- mod_ldap: fix memory corruption issue (Brad Nicholes, upstream #34618) - Wed Apr 27 2005 Joe Orton <jorton@redhat.com> 2.0.54-6
- fix key/cert locations in post script
- Tue Apr 26 2005 Joe Orton <jorton@redhat.com> 2.0.54-5
- create default dummy cert in /etc/pki/tls
- use a pseudo-random serial number on the dummy cert
- change default ssl.conf to point at /etc/pki/tls
- merge back -suexec subpackage; SELinux policy can now be
used to persistently disable suexec (#155716)
- drop /etc/httpd/conf/ssl.* directories and Makefiles
- unconditionally enable PIE support
- mod_ssl: fix for picking up -shutdown options (upstream #34452) - Tue Apr 19 2005 Joe Orton <jorton@redhat.com> 2.0.54-4
- replace PreReq with Requires(pre)
- Tue Apr 19 2005 Joe Orton <jorton@redhat.com> 2.0.54-3
- update to 2.0.54
- Wed Mar 30 2005 Joe Orton <jorton@redhat.com> 2.0.53-6
- update default httpd.conf:
* clarify the comments on AddDefaultCharset usage (#135821)
* remove all the AddCharset default extensions
* don't load mod_imap by default
* synch with upstream 2.0.53 httpd-std.conf
- mod_ssl: set user from SSLUserName in access hook (upstream #31418)
- htdigest: fix permissions of created files (upstream #33765)
- remove htsslpass - Thu Mar 3 2005 Joe Orton <jorton@redhat.com> 2.0.53-5
- apachectl: restore use of $OPTIONS again
- Thu Feb 10 2005 Joe Orton <jorton@redhat.com> 2.0.53-4
- update to 2.0.53
- move prefork/worker modules comparison to %check - Tue Feb 8 2005 Joe Orton <jorton@redhat.com> 2.0.52-7
- fix cosmetic issues in "service httpd reload"
- move User/Group higher in httpd.conf (#146793)
- load mod_logio by default in httpd.conf
- apachectl: update for correct libselinux tools locations - Wed Nov 17 2004 Joe Orton <jorton@redhat.com> 2.0.52-6
- add security fix for CVE CAN-2004-0942 (memory consumption DoS)
- SELinux: run httpd -t under runcon in configtest (Steven Smalley)
- fix SSLSessionCache comment for distcache in ssl.conf
- restart using SIGHUP not SIGUSR1 after logrotate
- add ap_save_brigade fix (upstream #31247)
- mod_ssl: fix possible segfault in auth hook (upstream #31848)
- add htsslpass(1) and configure as default SSLPassPhraseDialog (#128677)
- apachectl: restore use of $OPTIONS
- apachectl, httpd.init: refuse to restart if $HTTPD -t fails
- apachectl: run $HTTPD -t in user SELinux context for configtest
- update for pcre-5.0 header locations - Sun Nov 14 2004 Jeff Johnson <jbj@redhat.com> 2.0.52-5
- rebuild against db-4.3.21 aware apr-util.
- Fri Nov 12 2004 Jeff Johnson <jbj@jbj.org> 2.0.52-4
- rebuild against db-4.3-21.
- Wed Sep 29 2004 Joe Orton <jorton@redhat.com> 2.0.52-3
- add dummy connection address fixes from HEAD
- mod_ssl: add security fix for CAN-2004-0885 - Wed Sep 29 2004 Joe Orton <jorton@redhat.com> 2.0.52-2
- update to 2.0.52