<?xml version="1.0" encoding="utf-8" ?>

<rss version="2.0" 
   xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#"
   xmlns:admin="http://webns.net/mvcb/"
   xmlns:dc="http://purl.org/dc/elements/1.1/"
   xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
   xmlns:wfw="http://wellformedweb.org/CommentAPI/"
   xmlns:content="http://purl.org/rss/1.0/modules/content/"
   >
<channel>
    <title>Daniel Lange's blog - Comments</title>
    <link>http://daniel-lange.com/</link>
    <description>Daniel Lange's blog - Life, IT, Managers, Cars...</description>
    <dc:language>en</dc:language>
    <generator>Serendipity 1.3.1 - http://www.s9y.org/</generator>
    <pubDate>Fri, 21 Nov 2008 17:13:31 GMT</pubDate>

    <image>
        <url>http://daniel-lange.com/templates/bulletproof/img/s9y_banner_small.png</url>
        <title>RSS: Daniel Lange's blog - Comments - Daniel Lange's blog - Life, IT, Managers, Cars...</title>
        <link>http://daniel-lange.com/</link>
        <width>100</width>
        <height>21</height>
    </image>

<item>
    <title>Adult Ühler: Seredipity default event_s9ymarkup plugin breaking URLs that contain underscores</title>
    <link>http://daniel-lange.com/archives/28-Seredipity-default-event_s9ymarkup-plugin-breaking-URLs-that-contain-underscores.html#c26</link>
            <category></category>
    
    <comments>http://daniel-lange.com/archives/28-Seredipity-default-event_s9ymarkup-plugin-breaking-URLs-that-contain-underscores.html#comments</comments>
    <wfw:comment>http://daniel-lange.com/wfwcomment.php?cid=28</wfw:comment>

    

    <author>nospam@example.com (Adult Ühler)</author>
    <content:encoded>
    Nasty. A while back I spent some days writing what I think is a near-bulletprtoof string to URL function that can even turn Chinese characters to the roman equivilent. 
    </content:encoded>

    <pubDate>Mon, 30 Jun 2008 14:10:27 +0200</pubDate>
    <guid isPermaLink="false">http://daniel-lange.com/archives/28-guid.html#c26</guid>
    
</item>
<item>
    <title>Daniel Lange: kloeri announces Exherbo, another source based Linux distribution</title>
    <link>http://daniel-lange.com/archives/30-kloeri-announces-Exherbo,-another-source-based-Linux-distribution.html#c25</link>
            <category></category>
    
    <comments>http://daniel-lange.com/archives/30-kloeri-announces-Exherbo,-another-source-based-Linux-distribution.html#comments</comments>
    <wfw:comment>http://daniel-lange.com/wfwcomment.php?cid=30</wfw:comment>

    

    <author>nospam@example.com (Daniel Lange)</author>
    <content:encoded>
    Works here with eroyf-exherbo-x86-2008-05-21.tar.bz2 and my (up-to-date) Gentoo install. But you&#039;re right, base systems need to be able to both fulfill the same dependencies (i.e. libs etc). 
    </content:encoded>

    <pubDate>Fri, 23 May 2008 08:25:49 +0200</pubDate>
    <guid isPermaLink="false">http://daniel-lange.com/archives/30-guid.html#c25</guid>
    
</item>
<item>
    <title>Ciaran McCreesh: kloeri announces Exherbo, another source based Linux distribution</title>
    <link>http://daniel-lange.com/archives/30-kloeri-announces-Exherbo,-another-source-based-Linux-distribution.html#c24</link>
            <category></category>
    
    <comments>http://daniel-lange.com/archives/30-kloeri-announces-Exherbo,-another-source-based-Linux-distribution.html#comments</comments>
    <wfw:comment>http://daniel-lange.com/wfwcomment.php?cid=30</wfw:comment>

    

    <author>nospam@example.com (Ciaran McCreesh)</author>
    <content:encoded>
    I&#039;m not even sure that that would work... Gentoo and Exherbo have a different base system, so generated binaries aren&#039;t in general transferable. 
    </content:encoded>

    <pubDate>Fri, 23 May 2008 08:13:57 +0200</pubDate>
    <guid isPermaLink="false">http://daniel-lange.com/archives/30-guid.html#c24</guid>
    
</item>
<item>
    <title>Daniel Lange: kloeri announces Exherbo, another source based Linux distribution</title>
    <link>http://daniel-lange.com/archives/30-kloeri-announces-Exherbo,-another-source-based-Linux-distribution.html#c23</link>
            <category></category>
    
    <comments>http://daniel-lange.com/archives/30-kloeri-announces-Exherbo,-another-source-based-Linux-distribution.html#comments</comments>
    <wfw:comment>http://daniel-lange.com/wfwcomment.php?cid=30</wfw:comment>

    

    <author>nospam@example.com (Daniel Lange)</author>
    <content:encoded>
    Thats why I said &quot;Ebuild-builds ... i.e. take a Gentoo build result and package it for importing into the Exherbo system&quot;. Build-result = directory tree after src_install. 
    </content:encoded>

    <pubDate>Fri, 23 May 2008 07:32:07 +0200</pubDate>
    <guid isPermaLink="false">http://daniel-lange.com/archives/30-guid.html#c23</guid>
    
</item>
<item>
    <title>Ciaran McCreesh: kloeri announces Exherbo, another source based Linux distribution</title>
    <link>http://daniel-lange.com/archives/30-kloeri-announces-Exherbo,-another-source-based-Linux-distribution.html#c22</link>
            <category></category>
    
    <comments>http://daniel-lange.com/archives/30-kloeri-announces-Exherbo,-another-source-based-Linux-distribution.html#comments</comments>
    <wfw:comment>http://daniel-lange.com/wfwcomment.php?cid=30</wfw:comment>

    

    <author>nospam@example.com (Ciaran McCreesh)</author>
    <content:encoded>
    Your importare comment doesn&#039;t really make sense -- importare is for installing hand-built things and things that need no build. There&#039;s no special migration path from Gentoo any more than there is one from Ubuntu or Fedora. 
    </content:encoded>

    <pubDate>Thu, 22 May 2008 23:03:05 +0200</pubDate>
    <guid isPermaLink="false">http://daniel-lange.com/archives/30-guid.html#c22</guid>
    
</item>
<item>
    <title>Daniel Lange: Multiple Apache VHosts on the same IP and port</title>
    <link>http://daniel-lange.com/archives/2-Multiple-Apache-VHosts-on-the-same-IP-and-port.html#c19</link>
            <category></category>
    
    <comments>http://daniel-lange.com/archives/2-Multiple-Apache-VHosts-on-the-same-IP-and-port.html#comments</comments>
    <wfw:comment>http://daniel-lange.com/wfwcomment.php?cid=2</wfw:comment>

    

    <author>nospam@example.com (Daniel Lange)</author>
    <content:encoded>
    You need to have a VHOST section that encapsulates your proxy settings. Each VHOST can have different SSLCert* settings, thus a different certificate offered to the client. 
    </content:encoded>

    <pubDate>Wed, 13 Feb 2008 11:23:12 +0100</pubDate>
    <guid isPermaLink="false">http://daniel-lange.com/archives/2-guid.html#c19</guid>
    
</item>
<item>
    <title>Oliver: Multiple Apache VHosts on the same IP and port</title>
    <link>http://daniel-lange.com/archives/2-Multiple-Apache-VHosts-on-the-same-IP-and-port.html#c18</link>
            <category></category>
    
    <comments>http://daniel-lange.com/archives/2-Multiple-Apache-VHosts-on-the-same-IP-and-port.html#comments</comments>
    <wfw:comment>http://daniel-lange.com/wfwcomment.php?cid=2</wfw:comment>

    

    <author>nospam@example.com (Oliver)</author>
    <content:encoded>
    hmmmmm... i have just activated the sni use flag on a reverse proxy where the certificate issue has always bugged me. does not seem to do anything.....&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
ServerName internal.myserver.org&lt;br /&gt;
ServerAdmin root@myserver.org&lt;br /&gt;
&lt;br /&gt;
ProxyRequests Off&lt;br /&gt;
ProxyPreserveHost On&lt;br /&gt;
&lt;br /&gt;
SSLProxyEngine on&lt;br /&gt;
&lt;br /&gt;
SSLCipherSuite ALL:!ADH:!EXPORT56:RC4+RSA:+HIGH:+MEDIUM:+LOW:+SSLv2:+EXP:+eNULL&lt;br /&gt;
SSLCertificateFile /etc/apache2/ssl/internal.myserver.org.crt&lt;br /&gt;
SSLCertificateKeyFile /etc/apache2/ssl/internal.myserver.org.key&lt;br /&gt;
&lt;br /&gt;
ErrorLog /var/log/apache2/ssl_error_log&lt;br /&gt;
TransferLog /var/log/apache2/ssl_access_log&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
Order deny,allow&lt;br /&gt;
Allow from all&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
ProxyPass /sharedfiles/ https://internal.myserver.org/sharedfiles/&lt;br /&gt;
ProxyPassReverse /sharedfiles/ https://myserver.org/sharedfiles/&lt;br /&gt;
&lt;br /&gt;
ProxyPass /myapp/ https://internal.myserver.org/myapp/&lt;br /&gt;
ProxyPassReverse /myapp/ https://myserver.org/myapp/&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
am i doing something really wrong here? 
    </content:encoded>

    <pubDate>Wed, 13 Feb 2008 11:06:43 +0100</pubDate>
    <guid isPermaLink="false">http://daniel-lange.com/archives/2-guid.html#c18</guid>
    
</item>
<item>
    <title>hans: Google Pagerank fuss</title>
    <link>http://daniel-lange.com/archives/4-Google-Pagerank-fuss.html#c16</link>
            <category></category>
    
    <comments>http://daniel-lange.com/archives/4-Google-Pagerank-fuss.html#comments</comments>
    <wfw:comment>http://daniel-lange.com/wfwcomment.php?cid=4</wfw:comment>

    

    <author>nospam@example.com (hans)</author>
    <content:encoded>
    Excellent essay. It is very useful for me. Thank you very much 
    </content:encoded>

    <pubDate>Sun, 10 Feb 2008 20:02:18 +0100</pubDate>
    <guid isPermaLink="false">http://daniel-lange.com/archives/4-guid.html#c16</guid>
    
</item>
<item>
    <title>Gregory Kohs: Wikimedia Fundraiser Analysis III</title>
    <link>http://daniel-lange.com/archives/19-Wikimedia-Fundraiser-Analysis-III.html#c15</link>
            <category></category>
    
    <comments>http://daniel-lange.com/archives/19-Wikimedia-Fundraiser-Analysis-III.html#comments</comments>
    <wfw:comment>http://daniel-lange.com/wfwcomment.php?cid=19</wfw:comment>

    

    <author>nospam@example.com (Gregory Kohs)</author>
    <content:encoded>
    Thank you for this critique, Daniel.  I am increasingly convinced that the fish rots from the head down, and for the past 18 months, Jimmy Wales has not demonstrated to me that he has very much legitimacy to lead this project any more.&lt;br /&gt;
&lt;br /&gt;
The fact that tens of thousands of accounts are blocked and banned from editing Wikipedia, the fact that the Board has commingled personnel with Wikia, Inc. without declaring it fully on the Form 990, the utter disparagement of critics... all tell me that the Wikipedia &quot;mission&quot; is not thriving. 
    </content:encoded>

    <pubDate>Mon, 07 Jan 2008 20:42:08 +0100</pubDate>
    <guid isPermaLink="false">http://daniel-lange.com/archives/19-guid.html#c15</guid>
    
</item>
<item>
    <title>YellowLed: Serendipity plugin livesearch does not work with bulletproof template</title>
    <link>http://daniel-lange.com/archives/3-Serendipity-plugin-livesearch-does-not-work-with-bulletproof-template.html#c11</link>
            <category></category>
    
    <comments>http://daniel-lange.com/archives/3-Serendipity-plugin-livesearch-does-not-work-with-bulletproof-template.html#comments</comments>
    <wfw:comment>http://daniel-lange.com/wfwcomment.php?cid=3</wfw:comment>

    

    <author>nospam@example.com (YellowLed)</author>
    <content:encoded>
    Just for the record: It is (as far as I know, Don was more involved in that particular issue) working in BP v1.2, the latest version at the time of writing this comment. 
    </content:encoded>

    <pubDate>Tue, 11 Dec 2007 23:02:36 +0100</pubDate>
    <guid isPermaLink="false">http://daniel-lange.com/archives/3-guid.html#c11</guid>
    
</item>
<item>
    <title>Daniel Lange: Multiple Apache VHosts on the same IP and port</title>
    <link>http://daniel-lange.com/archives/2-Multiple-Apache-VHosts-on-the-same-IP-and-port.html#c10</link>
            <category></category>
    
    <comments>http://daniel-lange.com/archives/2-Multiple-Apache-VHosts-on-the-same-IP-and-port.html#comments</comments>
    <wfw:comment>http://daniel-lange.com/wfwcomment.php?cid=2</wfw:comment>

    

    <author>nospam@example.com (Daniel Lange)</author>
    <content:encoded>
    Your assuming a safe set-up. That&#039;s quite often not the case. Apache servers are used to serve many applications in parallel. That makes SNI so attractive in a corporate environment. Not another IP to allocate to the Apache host(s) once a new project needs SSL. But: There are usually no access rules to shield VHosts from the internet IPs or the gateway proxy IPs. I&#039;ve not seen a single company use them &quot;by default&quot;. The intranet is assumed &quot;safe&quot;.&lt;br /&gt;
&lt;br /&gt;
Luckily a lot of reverse proxies terminate SSL connections on the proxy and open a new connection to the destination host. This will break all SNI functionality (as the proxies don&#039;t even know about this functionality yet) but will also only allow access to the default SSL VHost as the SNI tag does not get through to the destination host.&lt;br /&gt;
Those who have saved on computing power and forward SSL connections without interim termination or use port forwarding, are at risk though.&lt;br /&gt;
&lt;br /&gt;
The &quot;servername&quot; is determined from a callback out of the TLS library to Apache (&quot;ssl_servername_cb&quot;), then a patched Apache sets the context (&quot;ssl_set_vhost_ctx&quot;) and finally checks the hostname that came from the client against the available vhosts (&quot;set_ssl_vhost&quot;).&lt;br /&gt;
Thus separate (name based) VHosts won&#039;t help you, separate certificates won&#039;t either (the attacker will see the other certificate as his/her first indication of success). Access rules will help, but as stated above, I&#039;ve not seen them being used as a default anywhere. That has to change, if one deploys SNI in a DMZ scenario. 
    </content:encoded>

    <pubDate>Thu, 22 Nov 2007 11:29:33 +0100</pubDate>
    <guid isPermaLink="false">http://daniel-lange.com/archives/2-guid.html#c10</guid>
    
</item>
<item>
    <title>Strahler: Multiple Apache VHosts on the same IP and port</title>
    <link>http://daniel-lange.com/archives/2-Multiple-Apache-VHosts-on-the-same-IP-and-port.html#c9</link>
            <category></category>
    
    <comments>http://daniel-lange.com/archives/2-Multiple-Apache-VHosts-on-the-same-IP-and-port.html#comments</comments>
    <wfw:comment>http://daniel-lange.com/wfwcomment.php?cid=2</wfw:comment>

    

    <author>nospam@example.com (Strahler)</author>
    <content:encoded>
    &quot;Let&#039;s assume a system serves both Intranet and Internet traffic. A client contacts the Internet IP with SSL but specifies the Intranet Hostname in it&#039;s TLS SNI entry. Guess what will happen?&quot;&lt;br /&gt;
&lt;br /&gt;
I don&#039;t see the problem. That host has one Virtual Host for each hostname, each has its own certificate and its own access rules.&lt;br /&gt;
The Intranet Virtual Host should already be filtering out incoming traffic from the internet.&lt;br /&gt;
&lt;br /&gt;
If it isn&#039;t, there was a security issue previous to the use of SNI, just as serious and exploitable as before. 
    </content:encoded>

    <pubDate>Wed, 21 Nov 2007 20:58:47 +0100</pubDate>
    <guid isPermaLink="false">http://daniel-lange.com/archives/2-guid.html#c9</guid>
    
</item>
<item>
    <title>Casey Abell: Wikimedia Fundraiser Webpage now cuts off at the last 10.000 donations</title>
    <link>http://daniel-lange.com/archives/9-Wikimedia-Fundraiser-Webpage-now-cuts-off-at-the-last-10.000-donations.html#c8</link>
            <category></category>
    
    <comments>http://daniel-lange.com/archives/9-Wikimedia-Fundraiser-Webpage-now-cuts-off-at-the-last-10.000-donations.html#comments</comments>
    <wfw:comment>http://daniel-lange.com/wfwcomment.php?cid=9</wfw:comment>

    

    <author>nospam@example.com (Casey Abell)</author>
    <content:encoded>
    By the way, while I&#039;d like to take credit for unearthing the donate.wikimedia.org/en/node/22 website, the link was published in the Wikipedia Signpost. The foundation hasn&#039;t publicized the site, which has spawned a few conspiracy theories. I&#039;m keeping an updated graph of the daily contributions at http://en.wikipedia.org/wiki/Image:2007_Fundraiser_By_Day.JPG. 
    </content:encoded>

    <pubDate>Sat, 10 Nov 2007 03:29:34 +0100</pubDate>
    <guid isPermaLink="false">http://daniel-lange.com/archives/9-guid.html#c8</guid>
    
</item>
<item>
    <title>Casey Abell: Wikimedia Fundraiser Webpage now cuts off at the last 10.000 donations</title>
    <link>http://daniel-lange.com/archives/9-Wikimedia-Fundraiser-Webpage-now-cuts-off-at-the-last-10.000-donations.html#c6</link>
            <category></category>
    
    <comments>http://daniel-lange.com/archives/9-Wikimedia-Fundraiser-Webpage-now-cuts-off-at-the-last-10.000-donations.html#comments</comments>
    <wfw:comment>http://daniel-lange.com/wfwcomment.php?cid=9</wfw:comment>

    

    <author>nospam@example.com (Casey Abell)</author>
    <content:encoded>
    There&#039;s a daily tracker at donate.wikimedia.org/en/node/22. Contributions ticked up after the new, even uglier begging ad was introduced. But the effect looks to be wearing off. Maybe we&#039;ll get an even bigger, more obnoxious ad pretty soon.&lt;br /&gt;
&lt;br /&gt;
I wish the site would sell a few ads and stop begging. The ads on Veropedia are far less annoying. If Wikipedia keeps jacking up its budget to ridiculous levels, paid advertising is the least irritating way to go. It beats constant begging, anyway. 
    </content:encoded>

    <pubDate>Fri, 09 Nov 2007 15:14:56 +0100</pubDate>
    <guid isPermaLink="false">http://daniel-lange.com/archives/9-guid.html#c6</guid>
    
</item>
<item>
    <title>Pete Prodoehl: Google Pagerank fuss</title>
    <link>http://daniel-lange.com/archives/4-Google-Pagerank-fuss.html#c1</link>
            <category></category>
    
    <comments>http://daniel-lange.com/archives/4-Google-Pagerank-fuss.html#comments</comments>
    <wfw:comment>http://daniel-lange.com/wfwcomment.php?cid=4</wfw:comment>

    

    <author>nospam@example.com (Pete Prodoehl)</author>
    <content:encoded>
    I&#039;ve been creating unique content on a site for 10 years, and for the last 4 years or so it&#039;s been a PR7 but just dropped to a PR4. Yes, it does have sponsored text links on it. Another site I almost never update, and gets nowhere near as much traffic is still a PR5, and it has no ads. Seems weird. 
    </content:encoded>

    <pubDate>Fri, 26 Oct 2007 00:09:43 +0200</pubDate>
    <guid isPermaLink="false">http://daniel-lange.com/archives/4-guid.html#c1</guid>
    
</item>

</channel>
</rss>