You are viewing a plain text version of this content. The canonical link for it is here.
Posted to dev@httpd.apache.org by Aaron Bannert <aa...@clove.org> on 2002/05/07 20:27:39 UTC
Re: cvs commit: httpd-2.0 STATUS
> + * Change the default config so that we add a ServerToken Minimal
> + to the config. Possibly go one step further and add a option
> + to just report '2.0' instead of '2.0.x'
> + +1: IanH
I don't think we should change what we are doing now by default, since
there don't seem to be any problems with that format. I'm not even sure
that making this configurable is such a good idea, since there is IMVHO
no valid security reason for doing so.
-aaron
Re: cvs commit: httpd-2.0 STATUS
Posted by Greg Stein <gs...@lyra.org>.
On Tue, May 07, 2002 at 11:27:39AM -0700, Aaron Bannert wrote:
> > + * Change the default config so that we add a ServerToken Minimal
> > + to the config. Possibly go one step further and add a option
> > + to just report '2.0' instead of '2.0.x'
> > + +1: IanH
>
> I don't think we should change what we are doing now by default, since
> there don't seem to be any problems with that format. I'm not even sure
> that making this configurable is such a good idea, since there is IMVHO
> no valid security reason for doing so.
Right. I said pretty much the same in my commit just now. There are
definitely reasons to keep it, but (none?) to remove it.
Cheers,
-g
--
Greg Stein, http://www.lyra.org/