Subject: Developers of Sympa
List archive
RE: [sympa-dev] session problems continued, and fixed
- From: Gavin Younger <address@concealed>
- To: "'David Verdin'" <address@concealed>, Adam Bernstein <address@concealed>
- Cc: "address@concealed" <address@concealed>
- Subject: RE: [sympa-dev] session problems continued, and fixed
- Date: Tue, 26 Oct 2010 15:05:52 +0100
Adam, David,
We were engaged in moving our sympa server from old to new hardware earlier this morning and ran into something that sounds very similar to what has been described here…
Source server : RedHat AS 4 (i386), sympa 5.3.4, perl 5.8.5, apache2.0.52 with mod_fastcgi 2.4.2
Target server : CentOS 5.5 (x86_64), sympa 5.3.4, perl 5.8.8, apache2.2.3 with mod_fastcgi 2.4.6
The ‘weirdness’ that was exhibited was cross-talk between different user sessions – very intermittently, a user visiting the wwsympa interface was being presented with the credentials of another logged-in user … note the sympa version hadn’t changed (only the supporting versions of perl/httpd/mod_fastcgi and the 64-bit ness of the new system)
Obviously users being given the login credentials of another is a serious security issue! ;->
On the target server, we replaced mod_fastcgi with mod_fcgid (and, like Adam, having not been able to test much), and now, we don’t appear to easily reproduce the problem…
Regards, Gavin Younger, University of Newcastle-upon-Tyne, UK
From: David Verdin [mailto:address@concealed]
Hi Adam, Hey all. We were still having weird problems with session management even after applying that recent fix, including cross-talk between different virtual robots and between SSL and non-SSL connections.
-- |
- RE: [sympa-dev] session problems continued, and fixed, Gavin Younger, 10/26/2010
Archive powered by MHonArc 2.6.19+.