Live data from Hacker News

Apache HTTP Server 2.4.58 (CVE fixes)

downloads.apache.org

31–40 of 47 posts

Re: Apache HTTP Server 2.4.58 (CVE fixes)

#31

Earlier quoted context omitted.

I love apache as much as anyone, cut my teeth with it and still work with it plenty. It doesn’t strike me as odd to question its fit for people who have more experience with containers. If there’s a reverse proxy in the front, one may just need business logic in the back.

>If there’s a reverse proxy in the front, one may just need business logic in the back. I'm trying to imagine what that haircut would look like

Walk into your nearest Hot Topic.

Re: Apache HTTP Server 2.4.58 (CVE fixes)

#32

I'm surprised people still actively use it and it seems on par with nginx, at least according to https://www.netcraft.com/blog/january-2023-web-server-survey...

I wonder what "other" is and how it suddenly shot up while Apache was suddenly going down.

Re: Apache HTTP Server 2.4.58 (CVE fixes)

#33
post #13

Earlier quoted context omitted.

Why surprised? It's rock solid, stable, fast, and does pretty much everything you need, and nothing is hidden behind premium tiers, unlike nginx where they leave bugs and awful behaviour in the open source version that aren't in the premium ones (e.g. nginx used to only resolve hostname entries on start-up, https://forum.nginx.org/read.php?2,215830,215832#msg-215832 , so if you used a hostname in proxy_pass, and the…

I love apache as much as anyone, cut my teeth with it and still work with it plenty. It doesn’t strike me as odd to question its fit for people who have more experience with containers. If there’s a reverse proxy in the front, one may just need business logic in the back.

I run all my microservices and web sites in containers behind Apache. It's not required to use any specific reverse proxy, nginx is Russian made, like Jetbrains' products so Google pushes them and that's why under-educated milenials assume nginx is the only reverse proxy on Earth.

Re: Apache HTTP Server 2.4.58 (CVE fixes)

#34

Earlier quoted context omitted.

I love apache as much as anyone, cut my teeth with it and still work with it plenty. It doesn’t strike me as odd to question its fit for people who have more experience with containers. If there’s a reverse proxy in the front, one may just need business logic in the back.

>If there’s a reverse proxy in the front, one may just need business logic in the back. I'm trying to imagine what that haircut would look like

Full disclosure: I haven't cut my hair in awhile. It may be influencing my architecture decisions at this point.

Re: Apache HTTP Server 2.4.58 (CVE fixes)

#35
"The early Apache server was a big hit, but we all knew that the codebase needed a general overhaul and redesign."

From the README of the apache_1.3.0 distribution (April 1998) https://archive.apache.org/dist/httpd/

Love this project. It changed the world and it still goes strong. The closest to "forever software"?

Re: Apache HTTP Server 2.4.58 (CVE fixes)

#36

Earlier quoted context omitted.

I love apache as much as anyone, cut my teeth with it and still work with it plenty. It doesn’t strike me as odd to question its fit for people who have more experience with containers. If there’s a reverse proxy in the front, one may just need business logic in the back.

I run all my microservices and web sites in containers behind Apache. It's not required to use any specific reverse proxy, nginx is Russian made, like Jetbrains' products so Google pushes them and that's why under-educated milenials assume nginx is the only reverse proxy on Earth.

Why do you believe Google "pushes" Russian software? That seems odd.

Re: Apache HTTP Server 2.4.58 (CVE fixes)

#37

Earlier quoted context omitted.

I love apache as much as anyone, cut my teeth with it and still work with it plenty. It doesn’t strike me as odd to question its fit for people who have more experience with containers. If there’s a reverse proxy in the front, one may just need business logic in the back.

I run all my microservices and web sites in containers behind Apache. It's not required to use any specific reverse proxy, nginx is Russian made, like Jetbrains' products so Google pushes them and that's why under-educated milenials assume nginx is the only reverse proxy on Earth.

I guess referring to conspiracy theories is one way of evaluating software.

Re: Apache HTTP Server 2.4.58 (CVE fixes)

#38

Earlier quoted context omitted.

I'm surprised you're surprised. It's a good web server.

I'm surprised HN hasn't added a feature where if you start a comment with "I'm surprised" it asks you to tick a box to confirm that you're really sure you're contributing to the discussion.

I've found the experience when people are explicitly requested to never do this (feign surprise) to be excellent; for example, Recurse Center: https://www.recurse.com/manual#sub-sec-social-rules

Re: Apache HTTP Server 2.4.58 (CVE fixes)

#39

Earlier quoted context omitted.

I love apache as much as anyone, cut my teeth with it and still work with it plenty. It doesn’t strike me as odd to question its fit for people who have more experience with containers. If there’s a reverse proxy in the front, one may just need business logic in the back.

I am actively trying to remove apache from a large chunk of projects mainly because at this point it is being used as a poor reverse proxy and not a web server which is its core competency.

Actually, its reverse proxy implementation is quite capable and performant.

Re: Apache HTTP Server 2.4.58 (CVE fixes)

#40

I'm surprised people still actively use it and it seems on par with nginx, at least according to https://www.netcraft.com/blog/january-2023-web-server-survey...

It's still in most distros default repos, unlike things like caddy, and also supports features like mod_ldap out of the box without enterprise, like nginx. If you just need a simple web server, potentially with some auth even for static files its a no brainier default for internal projects.
Post reply on HN