Google Groups no longer supports new Usenet posts or subscriptions. Historical content remains viewable.
Dismiss

Bug#577141: libapache2-mod-gnutls: incompatible with mod_proxy_http

137 views
Skip to first unread message

als...@indymedia.org

unread,
Apr 9, 2010, 8:50:02 PM4/9/10
to
Package: libapache2-mod-gnutls
Version: 0.5.1-1
Severity: important
Tags: patch

Description:
As discussed on the upstream bug tracker at
http://issues.outoforder.cc/view.php?id=87 mod_gnutls 0.5.1 is
incompatible with mod_proxy_http.

Symptom:
The web browser will keep loading for a long time. When a timeout is
reached, it will return an error message:
> Bad Gateway
> The proxy server received an invalid response from an upstream server.

The servers' / VirtualHosts' error log will contain entries such as:
> [error] [client 127.0.0.1] GnuTLS: Handshake Failed. Hit Maximum Attempts
> [error] (103)Software caused connection abort: proxy: pass request
body failed to 127.0.0.1:8180 (127.0.0.1)
> [error] proxy: pass request body failed to 127.0.0.1:8180 (127.0.0.1) from 127.0.0.1 ()

Workaround:
* Use mod-(open)ssl instead of mod-gnutls
* Use mod_jk instead of mod_proxy if you're using mod_proxy to connect
to tomcat
* Rebuild package with patch at
http://issues.outoforder.cc/file_download.php?file_id=33&type=bug
* Backport version from squeeze which should contain this patch

Fix:
* Rebuild package with patch at
http://issues.outoforder.cc/file_download.php?file_id=33&type=bug

Note that this is just a partial fix since, as discussed at
http://issues.outoforder.cc/view.php?id=97 , the patch only fixes
non-encrypted ProxyPass connections (http but not https).


Thanks.

-- System Information:
Debian Release: 5.0.4
APT prefers stable
APT policy: (500, 'stable')
Architecture: amd64 (x86_64)

Kernel: Linux 2.6.26-2-xen-amd64 (SMP w/1 CPU core)
Locale: LANG=en_US.UTF-8, LC_CTYPE=en_US.UTF-8 (charmap=UTF-8)
Shell: /bin/sh linked to /bin/bash

Versions of packages libapache2-mod-gnutls depends on:
ii libc6 2.7-18lenny2 GNU C Library: Shared libraries
ii libgnutls26 2.4.2-6+lenny2 the GNU TLS library - runtime libr

libapache2-mod-gnutls recommends no packages.

libapache2-mod-gnutls suggests no packages.

-- no debconf information

--
To UNSUBSCRIBE, email to debian-bugs-...@lists.debian.org
with a subject of "unsubscribe". Trouble? Contact listm...@lists.debian.org

als...@indymedia.org

unread,
Jul 19, 2010, 11:40:02 PM7/19/10
to
Hi Jack,

and thanks for your reply.

So there is an upstream fix and there is a fixed package in testing and
unstable. But I don't see how this satisfies closing this bug, since
Lenny is still affected?

I'm not that much into Debian policy, but it would seem wrong to me.

Alster
--
GPG USERS PLEASE NOTE: My old key 0x05059C17 expired Apr 05, 2010.
My new key is 0x3B4044FD. To proove this, I have used my old key to
sign my new key. Please verify, sign it, too, and upload this signed
key to hkp://zimmermann.mayfirst.org - thank you!

GPG key http://zimmermann.mayfirst.org/pks/lookup?search=0x3B4044FD
GPG FP 55A9 A530 06D4 8C7C 7CBC 7C98 4F39 0F83 3B40 44FD
Info https://docs.indymedia.org/view/Main/AlsteR

signature.asc
0 new messages