Re: Securing apache

Jochen Spieker <ml@well-adjusted.de> wrote:
> Tanstaafl:
>> I'm curious how many here enable the testing repo so they can run
>> apache 2.4, which apparently is a bit more secure? If so, any gotchas
>> or things to be aware of?

> I didn't check, but I would be surprised if it was possible to only
> install Apache 2.4 from testing without upgrading half of your system.
> What you need is a backport -- Apache 2.4 compiled against the library
> versions available in wheezy. Currently, there is no official
> backport.

Since to backport apache2.4 you need to backport (or at lease recompile)
_everything_ touching apache, including _any_ package providing
config-snippets (since some of the syntax of the apache-configuration
changed), I doubt there will ever be a backport of apache2.4 to Wheezy.

This already has been asked on the backports-users list and was denied
because of the points mentioned above.


