<?xml version="1.0" encoding="UTF-8"?>
<feed xml:lang="en-US" xmlns="http://www.w3.org/2005/Atom">
  <title>lighttpd - Home</title>
  <id>tag:www.lighttpd.net,2012:mephisto/</id>
  <generator version="0.8.0" uri="http://mephistoblog.com">Mephisto Drax</generator>
  <link href="http://www.lighttpd.net/feed/atom.xml" rel="self" type="application/atom+xml"/>
  <link href="http://www.lighttpd.net/" rel="alternate" type="text/html"/>
  <updated>2011-12-20T00:28:37Z</updated>
  <entry xml:base="http://www.lighttpd.net/">
    <author>
      <name>stbuehler</name>
    </author>
    <id>tag:www.lighttpd.net,2011-12-18:1352</id>
    <published>2011-12-18T15:59:00Z</published>
    <updated>2011-12-20T00:28:37Z</updated>
    <category term="download"/>
    <category term="1.4.30"/>
    <category term="lighttpd"/>
    <category term="releases"/>
    <link href="http://www.lighttpd.net/2011/12/18/1-4-30-faster-than-santa-your-first-present-this-year" rel="alternate" type="text/html"/>
    <title>1.4.30 - Faster than santa, your first present this year!</title>
<summary type="html">&lt;p&gt;And lighttpd 1.4 is still alive :)&lt;/p&gt;


Especially for ssl users this release should be important: by setting
&lt;pre&gt;ssl.cipher-list = &quot;ECDHE-RSA-AES256-SHA384:AES256-SHA256:RC4-SHA:RC4:HIGH:!MD5:!aNULL:!EDH:!AESGCM&quot;&lt;/pre&gt;
you can mitigate &lt;a href=&quot;http://blog.ivanristic.com/2011/10/mitigating-the-beast-attack-on-tls.html&quot;&gt;&lt;span class=&quot;caps&quot;&gt;BEAST&lt;/span&gt;&lt;/a&gt; attacks.&lt;br&gt;
Also check your site with &lt;a href=&quot;https://www.ssllabs.com/ssldb/analyze.html&quot;&gt;Qualys &lt;span class=&quot;caps&quot;&gt;SSL&lt;/span&gt; Labs Server Test&lt;/a&gt;&lt;br&gt;&lt;br&gt;

	&lt;h2&gt;Important changes&lt;/h2&gt;


	&lt;ul&gt;
	&lt;li&gt;[mod_auth] Fix signedness error in http_auth (CVE-2011-4362)&lt;/li&gt;
		&lt;li&gt;ssl: disable client initiated renegotiations&lt;/li&gt;
		&lt;li&gt;ssl: support mitigating &lt;span class=&quot;caps&quot;&gt;BEAST&lt;/span&gt; attack&lt;/li&gt;
		&lt;li&gt;fix connection stalls&lt;/li&gt;
	&lt;/ul&gt;


	&lt;h1&gt;Downloads&lt;/h1&gt;


	&lt;ul&gt;
	&lt;li&gt;&lt;a href=&quot;http://download.lighttpd.net/lighttpd/releases-1.4.x/lighttpd-1.4.30.tar.gz&quot;&gt;http://download.lighttpd.net/lighttpd/releases-1.4.x/lighttpd-1.4.30.tar.gz&lt;/a&gt;
	&lt;ul&gt;
	&lt;li&gt;&lt;span class=&quot;caps&quot;&gt;GPG&lt;/span&gt; signature: &lt;a href=&quot;http://download.lighttpd.net/lighttpd/releases-1.4.x/lighttpd-1.4.30.tar.gz.asc&quot;&gt;http://download.lighttpd.net/lighttpd/releases-1.4.x/lighttpd-1.4.30.tar.gz.asc&lt;/a&gt;&lt;/li&gt;
		&lt;li&gt;&lt;span class=&quot;caps&quot;&gt;SHA256&lt;/span&gt;: 59ae55b0ec427c328fa74d683e00eb1bc99bcc20cd184177875e9b6865de2b8b&lt;/li&gt;
	&lt;/ul&gt;
	&lt;/li&gt;
		&lt;li&gt;&lt;a href=&quot;http://download.lighttpd.net/lighttpd/releases-1.4.x/lighttpd-1.4.30.tar.bz2&quot;&gt;http://download.lighttpd.net/lighttpd/releases-1.4.x/lighttpd-1.4.30.tar.bz2&lt;/a&gt;
	&lt;ul&gt;
	&lt;li&gt;&lt;span class=&quot;caps&quot;&gt;GPG&lt;/span&gt; signature: &lt;a href=&quot;http://download.lighttpd.net/lighttpd/releases-1.4.x/lighttpd-1.4.30.tar.bz2.asc&quot;&gt;http://download.lighttpd.net/lighttpd/releases-1.4.x/lighttpd-1.4.30.tar.bz2.asc&lt;/a&gt;&lt;/li&gt;
		&lt;li&gt;&lt;span class=&quot;caps&quot;&gt;SHA256&lt;/span&gt;: 0d795597e4666dbf6ffe44b4a42f388ddb44736ddfab0b1ac091e5bb35212c2d&lt;/li&gt;
	&lt;/ul&gt;
	&lt;/li&gt;
		&lt;li&gt;&lt;a href=&quot;http://download.lighttpd.net/lighttpd/releases-1.4.x/lighttpd-1.4.30.tar.xz&quot;&gt;http://download.lighttpd.net/lighttpd/releases-1.4.x/lighttpd-1.4.30.tar.xz&lt;/a&gt;
	&lt;ul&gt;
	&lt;li&gt;&lt;span class=&quot;caps&quot;&gt;GPG&lt;/span&gt; signature: &lt;a href=&quot;http://download.lighttpd.net/lighttpd/releases-1.4.x/lighttpd-1.4.30.tar.xz.asc&quot;&gt;http://download.lighttpd.net/lighttpd/releases-1.4.x/lighttpd-1.4.30.tar.xz.asc&lt;/a&gt;&lt;/li&gt;
		&lt;li&gt;&lt;span class=&quot;caps&quot;&gt;SHA256&lt;/span&gt;: c237692366935b19ef8a6a600b2f3c9b259a9c3107271594c081a45902bd9c9b&lt;/li&gt;
	&lt;/ul&gt;
	&lt;/li&gt;
		&lt;li&gt;&lt;span class=&quot;caps&quot;&gt;SHA256&lt;/span&gt; checksums: &lt;a href=&quot;http://download.lighttpd.net/lighttpd/releases-1.4.x/lighttpd-1.4.30.sha256sum&quot;&gt;http://download.lighttpd.net/lighttpd/releases-1.4.x/lighttpd-1.4.30.sha256sum&lt;/a&gt;&lt;/li&gt;
	&lt;/ul&gt;


	&lt;p&gt;In the comments for 1.4.29 we were asked for a launchpad repository for ubuntu. This is not going to happen (launchpad sucks), but we have repositories for some dists on &lt;a href=&quot;https://build.opensuse.org/&quot;&gt;build.opensuse.org&lt;/a&gt;.
Checkout &lt;a href=&quot;http://redmine.lighttpd.net/projects/lighttpd/wiki/GetLighttpd&quot;&gt;GetLighttpd&lt;/a&gt;, or &lt;a href=&quot;https://build.opensuse.org/package/show?package=lighttpd&amp;amp;project=server%3Ahttp&quot;&gt;server:http/lighttpd&lt;/a&gt; or &lt;a href=&quot;https://build.opensuse.org/package/show?package=lighttpd&amp;amp;project=home%3Astbuehler&quot;&gt;home:stbuehler/lighttpd&lt;/a&gt; on &lt;a href=&quot;https://build.opensuse.org/&quot;&gt;build.opensuse.org&lt;/a&gt;.&lt;/p&gt;</summary><content type="html">
            &lt;p&gt;And lighttpd 1.4 is still alive :)&lt;/p&gt;


Especially for ssl users this release should be important: by setting
&lt;pre&gt;ssl.cipher-list = &quot;ECDHE-RSA-AES256-SHA384:AES256-SHA256:RC4-SHA:RC4:HIGH:!MD5:!aNULL:!EDH:!AESGCM&quot;&lt;/pre&gt;
you can mitigate &lt;a href=&quot;http://blog.ivanristic.com/2011/10/mitigating-the-beast-attack-on-tls.html&quot;&gt;&lt;span class=&quot;caps&quot;&gt;BEAST&lt;/span&gt;&lt;/a&gt; attacks.&lt;br&gt;
Also check your site with &lt;a href=&quot;https://www.ssllabs.com/ssldb/analyze.html&quot;&gt;Qualys &lt;span class=&quot;caps&quot;&gt;SSL&lt;/span&gt; Labs Server Test&lt;/a&gt;&lt;br&gt;&lt;br&gt;

	&lt;h2&gt;Important changes&lt;/h2&gt;


	&lt;ul&gt;
	&lt;li&gt;[mod_auth] Fix signedness error in http_auth (CVE-2011-4362)&lt;/li&gt;
		&lt;li&gt;ssl: disable client initiated renegotiations&lt;/li&gt;
		&lt;li&gt;ssl: support mitigating &lt;span class=&quot;caps&quot;&gt;BEAST&lt;/span&gt; attack&lt;/li&gt;
		&lt;li&gt;fix connection stalls&lt;/li&gt;
	&lt;/ul&gt;


	&lt;h1&gt;Downloads&lt;/h1&gt;


	&lt;ul&gt;
	&lt;li&gt;&lt;a href=&quot;http://download.lighttpd.net/lighttpd/releases-1.4.x/lighttpd-1.4.30.tar.gz&quot;&gt;http://download.lighttpd.net/lighttpd/releases-1.4.x/lighttpd-1.4.30.tar.gz&lt;/a&gt;
	&lt;ul&gt;
	&lt;li&gt;&lt;span class=&quot;caps&quot;&gt;GPG&lt;/span&gt; signature: &lt;a href=&quot;http://download.lighttpd.net/lighttpd/releases-1.4.x/lighttpd-1.4.30.tar.gz.asc&quot;&gt;http://download.lighttpd.net/lighttpd/releases-1.4.x/lighttpd-1.4.30.tar.gz.asc&lt;/a&gt;&lt;/li&gt;
		&lt;li&gt;&lt;span class=&quot;caps&quot;&gt;SHA256&lt;/span&gt;: 59ae55b0ec427c328fa74d683e00eb1bc99bcc20cd184177875e9b6865de2b8b&lt;/li&gt;
	&lt;/ul&gt;
	&lt;/li&gt;
		&lt;li&gt;&lt;a href=&quot;http://download.lighttpd.net/lighttpd/releases-1.4.x/lighttpd-1.4.30.tar.bz2&quot;&gt;http://download.lighttpd.net/lighttpd/releases-1.4.x/lighttpd-1.4.30.tar.bz2&lt;/a&gt;
	&lt;ul&gt;
	&lt;li&gt;&lt;span class=&quot;caps&quot;&gt;GPG&lt;/span&gt; signature: &lt;a href=&quot;http://download.lighttpd.net/lighttpd/releases-1.4.x/lighttpd-1.4.30.tar.bz2.asc&quot;&gt;http://download.lighttpd.net/lighttpd/releases-1.4.x/lighttpd-1.4.30.tar.bz2.asc&lt;/a&gt;&lt;/li&gt;
		&lt;li&gt;&lt;span class=&quot;caps&quot;&gt;SHA256&lt;/span&gt;: 0d795597e4666dbf6ffe44b4a42f388ddb44736ddfab0b1ac091e5bb35212c2d&lt;/li&gt;
	&lt;/ul&gt;
	&lt;/li&gt;
		&lt;li&gt;&lt;a href=&quot;http://download.lighttpd.net/lighttpd/releases-1.4.x/lighttpd-1.4.30.tar.xz&quot;&gt;http://download.lighttpd.net/lighttpd/releases-1.4.x/lighttpd-1.4.30.tar.xz&lt;/a&gt;
	&lt;ul&gt;
	&lt;li&gt;&lt;span class=&quot;caps&quot;&gt;GPG&lt;/span&gt; signature: &lt;a href=&quot;http://download.lighttpd.net/lighttpd/releases-1.4.x/lighttpd-1.4.30.tar.xz.asc&quot;&gt;http://download.lighttpd.net/lighttpd/releases-1.4.x/lighttpd-1.4.30.tar.xz.asc&lt;/a&gt;&lt;/li&gt;
		&lt;li&gt;&lt;span class=&quot;caps&quot;&gt;SHA256&lt;/span&gt;: c237692366935b19ef8a6a600b2f3c9b259a9c3107271594c081a45902bd9c9b&lt;/li&gt;
	&lt;/ul&gt;
	&lt;/li&gt;
		&lt;li&gt;&lt;span class=&quot;caps&quot;&gt;SHA256&lt;/span&gt; checksums: &lt;a href=&quot;http://download.lighttpd.net/lighttpd/releases-1.4.x/lighttpd-1.4.30.sha256sum&quot;&gt;http://download.lighttpd.net/lighttpd/releases-1.4.x/lighttpd-1.4.30.sha256sum&lt;/a&gt;&lt;/li&gt;
	&lt;/ul&gt;


	&lt;p&gt;In the comments for 1.4.29 we were asked for a launchpad repository for ubuntu. This is not going to happen (launchpad sucks), but we have repositories for some dists on &lt;a href=&quot;https://build.opensuse.org/&quot;&gt;build.opensuse.org&lt;/a&gt;.
Checkout &lt;a href=&quot;http://redmine.lighttpd.net/projects/lighttpd/wiki/GetLighttpd&quot;&gt;GetLighttpd&lt;/a&gt;, or &lt;a href=&quot;https://build.opensuse.org/package/show?package=lighttpd&amp;amp;project=server%3Ahttp&quot;&gt;server:http/lighttpd&lt;/a&gt; or &lt;a href=&quot;https://build.opensuse.org/package/show?package=lighttpd&amp;amp;project=home%3Astbuehler&quot;&gt;home:stbuehler/lighttpd&lt;/a&gt; on &lt;a href=&quot;https://build.opensuse.org/&quot;&gt;build.opensuse.org&lt;/a&gt;.&lt;/p&gt;
&lt;h1&gt;Changes from 1.4.29&lt;/h1&gt;


	&lt;ul&gt;
	&lt;li&gt;Always use our &#8216;own&#8217; md5 implementation, fixes linking issues on MacOS (fixes &lt;a href=&quot;http://redmine.lighttpd.net/issues/show/2331&quot;&gt;#2331&lt;/a&gt;)&lt;/li&gt;
		&lt;li&gt;Limit amount of bytes we send in one go; fixes stalling in one connection and timeouts on slow systems.&lt;/li&gt;
		&lt;li&gt;[ssl] fix build errors when Elliptic-Curve Diffie-Hellman is disabled&lt;/li&gt;
		&lt;li&gt;Add static-file.disable-pathinfo option to prevent handling of urls like &#8230;/secret.php/image.jpg as static file&lt;/li&gt;
		&lt;li&gt;Don&#8217;t overwrite 401 (auth required) with 501 (unknown method) (fixes &lt;a href=&quot;http://redmine.lighttpd.net/issues/show/2341&quot;&gt;#2341&lt;/a&gt;)&lt;/li&gt;
		&lt;li&gt;Fix mod_status bug: always showed &#8220;0/0&#8221; in the &#8220;Read&#8221; column for uploads (fixes &lt;a href=&quot;http://redmine.lighttpd.net/issues/show/2351&quot;&gt;#2351&lt;/a&gt;)&lt;/li&gt;
		&lt;li&gt;[mod_auth] Fix signedness error in http_auth (fixes &lt;a href=&quot;http://redmine.lighttpd.net/issues/show/2370&quot;&gt;#2370&lt;/a&gt;, &lt;span class=&quot;caps&quot;&gt;CVE&lt;/span&gt;-2011-4362)&lt;/li&gt;
		&lt;li&gt;[ssl] count renegotiations to prevent client renegotiations&lt;/li&gt;
		&lt;li&gt;[ssl] add option to honor server cipher order (fixes &lt;a href=&quot;http://redmine.lighttpd.net/issues/show/2364&quot;&gt;#2364&lt;/a&gt;, &lt;span class=&quot;caps&quot;&gt;BEAST&lt;/span&gt; attack)&lt;/li&gt;
		&lt;li&gt;[core] accept dots in ipv6 addresses in host header (fixes &lt;a href=&quot;http://redmine.lighttpd.net/issues/show/2359&quot;&gt;#2359&lt;/a&gt;)&lt;/li&gt;
		&lt;li&gt;[ssl] fix ssl connection aborts if files are larger than the &lt;span class=&quot;caps&quot;&gt;MAX&lt;/span&gt;_WRITE_LIMIT (256kb)&lt;/li&gt;
		&lt;li&gt;[libev/cgi] fix waitpid &lt;span class=&quot;caps&quot;&gt;ECHILD&lt;/span&gt; errors in cgi with libev (fixes &lt;a href=&quot;http://redmine.lighttpd.net/issues/show/2324&quot;&gt;#2324&lt;/a&gt;)&lt;/li&gt;
	&lt;/ul&gt;
          </content>  </entry>
</feed>

