Skip to content

apache and modsecurity #2603

New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Closed
ghost opened this issue Aug 11, 2021 · 3 comments
Closed

apache and modsecurity #2603

ghost opened this issue Aug 11, 2021 · 3 comments

Comments

@ghost
Copy link

ghost commented Aug 11, 2021

I have been trying to build modsecurity 3.0.5 and modsecurity-apache 0.0.9-beta1 and am really struggling.

I have seen a comment from zimmerle saying that "currently modsecurity-apache supports modsecurity 3.0.4" - but I don't know what version of modsecurity-apache "currently" refers to. Is it still the case as at today? or have things changed.

Subsequently I have tried to build 3.0.4 and am seeing issue 2519 - which is really not an ideal start.

Further, I am seeing people commenting on modsecurity-apache issues saying it's "unstable" and asking "what is planned for future?" for the connector - and there is absolutely no response from the developers

...all of which is really worrying.

Against this backdrop, my questions are really as follows:
Has apache been abandoned from a modsecurity 3.0.x connector perspective?
Is modsecurity-apache 0.0.9-beta1 stable for an apache production environment, or should I be installing modsecurity v2.9.4 ? And if so, what is the future of the modsecurity 2.9 series?

@martinhsv
Copy link
Contributor

Hi @rickyrocker ,

It is not recommended to use ModSecurity v3 with Apache. There are still enough portions of functionality that do not work correctly that it is not considered production-ready.

With Apache, ModSecurity v2.9.x is still the recommended version to use.

Re:

Further, I am seeing people commenting on modsecurity-apache issues saying it's "unstable" and asking "what is planned for future?" for the connector - and there is absolutely no response from the developers

There is a response here at least:
owasp-modsecurity/ModSecurity-apache#77

The Apache connector has not been abandoned. The lack of progress there is simply a matter of prioritization.

ModSecurity v2.9.x continues to be a solid implementation. There are no plans to discontinue the v2.9.x line while a fully functioning v3 implementation for Apache is still unavailable.

@willyamcts
Copy link

Hi @rickyrocker ,

It is not recommended to use ModSecurity v3 with Apache. There are still enough portions of functionality that do not work correctly that it is not considered production-ready.

With Apache, ModSecurity v2.9.x is still the recommended version to use.

Re:

Further, I am seeing people commenting on modsecurity-apache issues saying it's "unstable" and asking "what is planned for future?" for the connector - and there is absolutely no response from the developers

There is a response here at least: SpiderLabs/ModSecurity-apache#77

The Apache connector has not been abandoned. The lack of progress there is simply a matter of prioritization.

ModSecurity v2.9.x continues to be a solid implementation. There are no plans to discontinue the v2.9.x line while a fully functioning v3 implementation for Apache is still unavailable.

Currently,

Some restriction from usage Modescurity v3 in production with Apache?

@martinhsv
Copy link
Contributor

@willyamcts ,

There is no change in status. For use with Apache, ModSecurity v2.9.x is the recommended version.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

2 participants