@hirose31ããã¨ãApache HTTPDããHTTPSã§ãã¡ã¤ã«ãã¦ã³ãã¼ãä¸ã«ãµã¼ãããã»ã¹ãSIGBUSã§æ»ã¬ã£ã¦ä»¶ã«ã¶ã¡ãããã ãOpenSSLã®ä¸ã§memcpyãSIGBUSãã¦ã¾ããããªããªãã ã£ã¦ã¼ï¼ã ã£ã¦èª¿ã¹ãã®ã§ãããçç±ã¯ä»¥ä¸ã®ã¨ããã ã£ãã HTTPSã®å ´åãããã©ã«ãè¨å®ã ã¨ãã¡ã¤ã«èªè¾¼ã«mmap(2)ã使ããã mmapããããã¡ã¤ã«ã®ãµã¤ãºãå¤æ´ããã¦ãApacheã¯ãããæ¤ç¥ãããããªã ããã¦ããã¡ã¤ã«æ«å°¾ä»¥éã®ãã¼ã¿ãèªããã¨ããã¨ã»ã°ã¡ã³ãã¼ã·ã§ã³ã¨ã©ã¼(SIGBUS)ãçºçããApacheã®ãµã¼ãããã»ã¹ã¯ç°å¸¸çµäºãã HTTPã®å ´åã¯ããã¼ã«ã«ãã¡ã¤ã«ã·ã¹ãã ã®å ´åsendfile(2)ã使ãããã®ã§ããã¡ã¤ã«ãµã¤ãºãå¤æ´ã«ãªã£ã¦ãApacheã¯ç°å¸¸çµäºããªã ãã ããmod_deflateã®ãããªåºåãã£ã«ã¿ã使ã£ã¦ããå ´åã¯ãHTTP
At Velocity, I saw Adam Langley give a great presentation entitled Overclocking SSL. Last week Adam posted a distilled version of the Overclocking SSL presentation on his blog. He covers many topics for improving SSL performance. Unfortunately, his recommendations are decidedly focused on how Google runs their servers, and not a practical guide to how to improve your performance with a more standa
Summary This module is used to treat the useragent which initiated the request as the originating useragent as identified by httpd for the purposes of authorization and logging, even where that useragent is behind a load balancer, front end server, or proxy server. The module overrides the client IP address for the connection with the useragent IP address reported in the request header configured
Apacheã§reverse proxyããã¨ãã«ãããã¯ã¨ã³ãã¯åããªãã ãã©åãããã¹ã«å¿ãã¦å¥ãªã¿ã¤ã ã¢ã¦ãå¤ãè¨å®ãããã¨ãã¦ããã£ãã®ã§ãã®ã¡ã¢ã§ãã 以ä¸ãApache 2.2.22 ã§ã®ã話ã§ãã2.4ã§ã©ããªã£ã¦ãããã©ãªãããåç¥ã§ãããæãã¦ãã ããï¼ï¼ ã¾ãæãã¤ãã®ã¯ãããªè¨å®ã ã¨æãã¾ãã ProxyTimeout 7 ProxyPass /3sec/ http://127.0.0.1:9999/ timeout=3 ProxyPass /5sec/ http://127.0.0.1:9999/ timeout=5ããã¯ã¨ã³ã (127.0.0.1:9999) ã¯ããããªã®ãåããã¦ããã°ååã§ãã $ while true; do echo listen...; nc -l 9999; doneããã§ã¯ã©ã¤ã¢ã³ãã§ã¢ã¯ã»ã¹ãã¦ã¿ãã¨â¦ $ time curl h
人éã¨ã¦ã§ãã®æªæ¥ï¼æ§ï¼ ãã¦ã§ãã®æ´å²ã¯äººé¡ã®æ´å²ã®ç¹°ãè¿ããã¨ãã観ç¹ããè²ã åå¼·ãã¦ãã¾ãã2014å¹´ã¾ã§ã®äººéã¨ã¦ã§ãã®æªæ¥ã®æ§ããã°ã§ãã ããã¾ã§ã®Apache2.2系以åã§ã®ã¢ã¯ã»ã¹å¶å¾¡ã®æ¸ãæ¹ã¯è³å¦ä¸¡è«ã§ãããåã¯ãã¾ã好ãããããã¾ããã§ããã éå»ã®ã¢ã¯ã»ã¹å¶å¾¡ã«é¢ãã¦ã¯ã以ä¸ã®è¨äºãã¨ã¦ãããããããã¾ã¨ãããã¦ããã¨æãã¾ãã ãããã®æè¡æ¥è¨Â â Apacheã®ã¢ã¯ã»ã¹å¶å¾¡ãã¡ããã¨ç解ããã ããã§ã以ä¸ã®ããã«è¨åããã¦ãã¾ãã ãããªããããã¦ãã¦ãæ¬å½ã¯ã©ãã§ãããã¨æããApache 3.0ã§ã¯ããã£ãããDSL(VCL)ã§æ¸ããããã«ããæ§æ³ããããããã®ã§ããã°ã£ã¦ã»ããã ã¨ãããã¨ã§ã2.4ç³»ã§ã¯DSLã¨ã¯ãããªãã¾ã§ããRequire*ã¨ãããã£ã¬ã¯ãã£ãã使ã£ãã¢ãã³ãªæ¸ãæ¹ãã§ããããã«ãªã£ãã®ã§ãããã2.2系以åã®ã¢ã¯ã»ã¹å¶å¾¡ã®è¨è¿°ã¨æ¯
Apache HTTP Server 2.4.4 ããªãªã¼ã¹ããã¾ãããã»ãã¥ãªãã£ä¸ã®ä¿®æ£ãæ©è½ã®è¿½å ããã°ä¿®æ£ãªã©ã§ãã mod_info ãªã©ã§ã®ãã¹ãååºå㧠XSS ãçºçããå¯è½æ§ããã£ãã®ãä¿®æ£ mod_proxy_manager ã®ç®¡çç»é¢ã§ã® XSS ã®2件ã«ã¤ãã¦ã¯ CVE ãå²ãå½ã¦ããã¦ãã¾ããã»ãã«æ°ã«ãªãã¨ããã¨ãã¦ã¯ã SSLCompression ãã£ã¬ã¯ãã£ãã追å ãããSSL ã§å§ç¸®ããªãã®ãããã©ã«ãã¨ãªã£ãã ã¨ããã®ãããã¾ãããã®ãã£ã¬ã¯ãã£ã㯠SSL ã§ã®å§ç¸®ã on/off ãããã®ã§ãå°å ¥ã®ãã£ããã¯è² è·å¯¾çã ã£ãããã§ããããããSPDY ã¸ã®æ»ææ¹æ³ãããã«ã¯ SSL ã¸ã®æ»ææ¹æ³ (çè´) ã¨ãã¦ç¥ãããããã«ãªã£ã CRIME æ»æã¸ã®å¯¾å¦ã«ããªãã¾ãããã®åé¡ã¯ 2.2 ç³»ã«ãããã®ã§ãã¾ããªããªãªã¼ã¹ãããã§ããã 2.2.2
Apacheãèµ·åããã¨ãã«ä½¿ãäºããã apachectl ã® -k restart 㯠stop && start ã§ã¯ãªãã®ã§æ³¨æãã¾ãããã ServerLimitãThreadLimitãªã©ã®ä¸é¨ã®è¨å®ã¯ãrestart ã§ã¯é©ç¨ããããstop && start ãå¿ è¦ã«ãªãã¾ãã apachectl ã¯å®ã¯shellscriptã§åºæ¥ã¦ãã¾ããä¸ãã®ãã㨠#!/bin/sh .. HTTPD='../httpd' .. start|stop|restart|graceful|graceful-stop) $HTTPD -k $ARGV ERROR=$? ;; ã¨æ¸ããã¦ãã¾ããrestartã¯httpdã³ãã³ãã«ãã®ã¾ã¾æ¸¡ãããããã§ãã ããã§httpdã³ãã³ãã®ããã¥ã¡ã³ããèªãã¨è©³ãã㯠Stopping Apache httpd http://httpd.apach
ããã«ã¡ã¯ãcombinedãã°æ²æ» å§å¡ä¼ã®ã²ããã§ãã Apacheã®combinedãNginxã®ããã©ã«ãã®log_formatã¯ãæ©æ¢°å¦ç(æ¥ä»ã§ã®ã½ã¼ãããã¼ã¹)ããã¥ããä¸ã«ã人ã®ç®ã«ããã¾ãè¦ããããã©ã¼ãããã¨ã¯ãããªãã¨æã£ã¦ãã¾ãã ãªã®ã§èªå® ã®ãµã¼ãã¼ã§ã¯ã æ¥ä»ã¯ ISO8601 ã«ãã sortã³ãã³ãã¨ãã§ç°¡åã«ããã¼ã£ã¨ã½ã¼ãã§ããããã«ãªã æ¥ä»ãã¬ã¹ãã³ã¹ã³ã¼ããæè¦æéã¨ãåºå®é·çãªãã£ã¼ã«ãã¯å·¦ã«å¯ãã URLã¨ãUAã¨ãå¯å¤é·ã§é·ãã®ã¯å³ã«å¯ãã ãªã¯ã¨ã¹ã(%r)ãå³ã«å¯ããæ¹ãããããããªæ°ããã¦ããããã æ°å¤ã ãã ã¨ãããã¥ããã®ã§ãªãã¨ãªããããããã«ãã£ã¼ã«ãåãæ·»ãã ãã£ã¼ã«ãåãé·ãããã¨ãããããããªãåé¢ããã°ãµã¤ãºã大ãããªãã®ã§æ³¨æ ã¨ãã観ç¹ã§æ¬¡ã®ãããªãã°ãã©ã¼ãããã«ãã¦ãã¾ãã # Apache LogFormat
SSL ã¢ã¯ã»ã©ã¬ã¼ã¿ã®ä¾¡æ ¼ã«èãçãã¦ããè²´å ããããè²·ãã SSL ã®ããã ãã«ãµã¼ãã®å°æ°ããã§ããã§ãå¢ããã¦ããè²´å ãããã§ãªãã¨ã SSL ã®ããã©ã¼ãã³ã¹ã§ãåãã®è²´å ã®ããã«ãããããã¾ã¨ãã¦ã¿ã¾ãããã SSLã»ãã·ã§ã³ãã£ãã·ã¥ã®ã¿ã¤ã ã¢ã¦ãè¨å®ãé·ãããã SSL ã®è² è·ã®ã»ã¨ãã©ã¯ã»ãã·ã§ã³ã®çæã«ãããã®ãªã®ã§ãå½ç¶ã®ããã«ãµã¼ãå´ã® SSL ã»ãã·ã§ã³ãã£ãã·ã¥ãæå¹ã«ãã¦ããããã¨æãã¾ããããã®ã¿ã¤ã ã¢ã¦ãã®è¨å®ãããã©ã«ãã®ã¾ã¾ã¨ããæ¹ãå¤ãã®ã§ã¯ãªãã§ããããã ãã¨ãã°Apacheã§ããããè¨å®ãµã³ãã«ã®ã¾ã¾ SSLSessionCache shm:/usr/local/apache/logs/ssl_gcache_data(512000) SSLSessionCacheTimeout 300 ã¨ãã¦ããæ¹ãå¤ãã®ã§ã¯ãªãã§ããããã åãµã¼ãã®ããã©
人éã¨ã¦ã§ãã®æªæ¥ï¼æ§ï¼ ãã¦ã§ãã®æ´å²ã¯äººé¡ã®æ´å²ã®ç¹°ãè¿ããã¨ãã観ç¹ããè²ã åå¼·ãã¦ãã¾ãã2014å¹´ã¾ã§ã®äººéã¨ã¦ã§ãã®æªæ¥ã®æ§ããã°ã§ãã æè¿ã¯è«æãæ¸ãã¦ã°ã£ãããªã®ã§ãã³ã¼ãã£ã³ã°ãå¿ããªãããã«ã¡ãã£ã¨ããApacheã¢ã¸ã¥ã¼ã«ãä½ã£ã¦ã¾ããã ã¾ãã¯æ©è½ãã ãã®ã¢ã¸ã¥ã¼ã«ã®ååã¯ãmod_request_dumperã¨ãã¾ããã mod_request_dumperæ©è½ã¯ãApacheå é¨ããªã¯ã¨ã¹ãããã¬ã¹ãã³ã¹ãè¿ãã¾ã§ã«æã¤request_recæ§é ä½ï¼ä¸ã«å«ã¾ããserver_recãconn_recãå«ãï¼ã®ä¸èº«ããå種ããã¯ã®ã¿ã¤ãã³ã°ã§Dumpããã¢ã¸ã¥ã¼ã«ã§ããDumpã®ä»æ¹ã¯ãJSONå½¢å¼ã«æ§é ä½ã®ä¸»è¦ãªãã¼ã¿ãã·ãªã¢ã©ã¤ãºãã¦ä»»æã®ãã¡ã¤ã«ã«åºåãã¾ãã ï¼è¿½è¨ï¼2012/05/22ï¼ ã¾ããCustomLogã®ãããªãã¤ããã°å½¢å¼ã®è¨è¿°ãè¡ããã¨
Apacheã®confã«ã³ã¡ã³ããæ¸ãéã«ãè¨å®ã®å¾ãã«æ¸ãäºã¯ã§ããªãã®ã¯ç¥ããã¦ããã®ãã©ãããããããã¾ãããããã®éãã§ããä¾ãã° MaxRequestsPerChild 200 #å°ãªãã« ãã㯠syntax error ã«ãªãã¾ã % ./local/httpd/bin/apachectl -t Syntax error on line 12 of /Users/.../local/httpd/conf/httpd.conf: MaxRequestsPerChild takes one argument, Maximum number of requests a particular child serves before dying. ãããããã¡ãªãã§ãããããã¥ã¡ã³ãã«ã Directives in the configuration files are case-in
人éã¨ã¦ã§ãã®æªæ¥ï¼æ§ï¼ ãã¦ã§ãã®æ´å²ã¯äººé¡ã®æ´å²ã®ç¹°ãè¿ããã¨ãã観ç¹ããè²ã åå¼·ãã¦ãã¾ãã2014å¹´ã¾ã§ã®äººéã¨ã¦ã§ãã®æªæ¥ã®æ§ããã°ã§ãã ã¨ããã¤ã¤ããããã¾ã§å¤§ãããã¨ã¯ãã¦ããªãã luaã¨ããé«éã«åä½ããçµã¿è¾¼ã¿ç³»ã®ã¹ã¯ãªããè¨èªã§éãã§ã¿ããã£ãã®ã¨ãããã ã£ãmod_luaã§éãã§ã¿ãã°ãããªã¨æã£ãã ãã§ãããã§ãå®éã«mod_luaãã³ã³ãã¤ã«ãã¦éãã§ã¿ããã³ã³ãã¤ã«ãªãã·ã§ã³ã¯ä»¥ä¸ã ./configure --prefix=/usr/local/apache2.4 --with-apr=/usr/local/apr --with-apr-util=/usr/local/apr --enable-modules=all --enable-mods-shared=all --enable-mpms-shared='prefork worker event' -
å°ããã¤ã¢ãããã®ä¸ã®è©±ããã¦ããã¾ãã ä»åã¯ãããã¯ã¼ã¯ãµã¼ãã®åºæ¬ã¨ãªãã½ã±ããå®è£ ã®è©±ã§ãã ã¢ãããã®ã½ã±ãããµã¼ãå®è£ ã¯çµæ§æåãªæ¹æ³ã ã¨æã£ã¦ããã®ã§ãã 人ã¨ã®ä¼è©±ä¸ã«ãæå¤ã¨ç¥ããã¦ããªãã®ãããããªãã¨æããäºããã£ãã®ã§ æ¸ãã¦ã¿ããã¨æã£ã次第ã§ãã å ¥éæ¸ãªã©ã§åºã¦ããä¸è¬çãªã½ã±ãããµã¼ãã®å®è£ æ¹æ³ // ã½ã±ããä½æ listen_sock = socket(...); // ã¢ãã¬ã¹:ãã¼ããç´ä»ã bind(listen_sock,...); // ã¯ã©ã¤ã¢ã³ãåä»éå§ listen(listen_sock,...); // ã¯ã©ã¤ã¢ã³ãåä»ã«ã¼ã for (;;){ // ã¯ã©ã¤ã¢ã³ãã®æ¥ç¶ã¾ã§å¾ æ© client_sock = accept(listen_sock,...); // åããã»ã¹ä½æ if ( fork() == 0 ) { // åããã»
Overview mod_xsendfile is a small Apache2 module that processes X-SENDFILE headers registered by the original output handler. If it encounters the presence of such header it will discard all output and send the file specified by that header instead using Apache internals including all optimizations like caching-headers and sendfile or mmap if configured. It is useful for processing script-output o
Overview of new features in Apache HTTP Server 2.4 - Apache HTTP Server Expressions http://httpd.apache.org/docs/2.4/en/expr.html ãSetEnvIfExpr, RewriteCond, Headerã§ä½¿ããè©ä¾¡å¼ ã®è¿½å http://httpd.apache.org/docs/2.4/en/mod/core.html#if ããããç°å¢å¤æ°ãåç §ãã¦ç´°ããå¶å¾¡ãã§ããããã«ãªã£ããã¨ã«å ããelseçãªãããã¯ãæ¸ãã®ã«è¦å´ãããã¨ããããã§æå ±ã§ã ErrorLogFormat http://httpd.apache.org/docs/2.4/en/mod/core.html#errorlogformat ErrorLogãæ¸å¼è¨å®ã§ããããã«ã %L (L
wildpointer*referencing whatever comes to mind, by chet nichols Pagesmyself Categories code theory tech apache apple netscaler perl scalability RSS To be honest, I had never thought twice about it. At my past employer, we had implemented tracking request rate for the Apache hosts by parsing out Total Accesses (ie: Total Requests) from server-status (thanks to our friendly module mod_status), publi
ãªããæ¯åå¿ããã®ã§ã¡ã¢ã ã½ã¼ã«ããå ¥ããapacheã®configureãªãã·ã§ã³ã調ã¹ãã«ã¯ä»¥ä¸ã®ãã¡ã¤ã«ã調ã¹ãã $ cat /usr/local/apache2/build/config.nice #! /bin/sh # # Created by configure "./configure" \ "--prefix=/usr/local/apache2" \ "--with-mpm=worker" \ "--enable-ssl" \ "--enable-rewrite" \ "--enable-proxy" \ "$@"ãããªãã§ãããã§ãã
ãªãªã¼ã¹ãé害æ å ±ãªã©ã®ãµã¼ãã¹ã®ãç¥ãã
ææ°ã®äººæ°ã¨ã³ããªã¼ã®é ä¿¡
å¦çãå®è¡ä¸ã§ã
j次ã®ããã¯ãã¼ã¯
kåã®ããã¯ãã¼ã¯
lãã¨ã§èªã
eã³ã¡ã³ãä¸è¦§ãéã
oãã¼ã¸ãéã
{{#tags}}- {{label}}
{{/tags}}