Lighttpd 1.4.30 发布,比圣诞老人还快
openkk 13年前
<p><strong>编者注:</strong>此新闻的标题是官方新闻的直译,我估计其开发者也有点自嘲的意思,毕竟 lighttpd 好久都没有更新了。</p> <img title="Lighttpd logo" alt="Lighttpd 1.4.30 发布,比圣诞老人还快" src="https://simg.open-open.com/show/ece70b420756a11c5c4901dfa744c05b.gif" width="90" height="90" /> <div id="p_fullcontent" class="detail"> <p>Lighttpd 是一个德国人领导的开源Web服务器软件,其根本的目的是提供一个专门针对高性能网站,安全、快速、兼容性好并且灵活的web server环境。具有非常低的内存开销,cpu占用率低,效能好,以及丰富的模块等特点。</p> <p>Lighttpd是众多OpenSource轻量级的web server中较为优秀的一个。支持FastCGI, CGI, Auth, 输出压缩(output compress), URL重写, Alias等重要功能,而Apache之所以流行,很大程度也是因为功能丰富,在lighttpd上很多功能都有相应的实现了,这点对于apache的用 户是非常重要的,因为迁移到lighttpd就必须面对这些问题。</p> </div> <p></p> <p>Lighttpd 1.4 还活着,特别是对使用 SSL 的用户下面这个设置非常重要:</p> <pre>ssl.cipher-list = "ECDHE-RSA-AES256-SHA384:AES256-SHA256:RC4-SHA:RC4:HIGH:!MD5:!aNULL:!EDH:!AESGCM"</pre> <p><strong>Lighttpd 1.4.30 主要变化:</strong></p> <ul> <li>[mod_auth] Fix signedness error in http_auth (CVE-2011-4362)</li> <li>ssl: disable client initiated renegotiations</li> <li>ssl: support mitigating <span class="caps">BEAST</span> attack</li> <li>fix connection stalls</li> </ul> <p><strong>下载地址</strong></p> <ul> <li><a href="/misc/goto?guid=4958319120035396633">http://download.lighttpd.net/lighttpd/releases-1.4.x/lighttpd-1.4.30.tar.gz</a> <ul> <li><span class="caps">GPG</span> signature: <a href="/misc/goto?guid=4958319120824967967">http://download.lighttpd.net/lighttpd/releases-1.4.x/lighttpd-1.4.30.tar.gz.asc</a></li> <li><span class="caps">SHA256</span>: 59ae55b0ec427c328fa74d683e00eb1bc99bcc20cd184177875e9b6865de2b8b</li> </ul> </li> <li><a href="/misc/goto?guid=4958319121602165254">http://download.lighttpd.net/lighttpd/releases-1.4.x/lighttpd-1.4.30.tar.bz2</a> <ul> <li><span class="caps">GPG</span> signature: <a href="/misc/goto?guid=4958319122401583085">http://download.lighttpd.net/lighttpd/releases-1.4.x/lighttpd-1.4.30.tar.bz2.asc</a></li> <li><span class="caps">SHA256</span>: 0d795597e4666dbf6ffe44b4a42f388ddb44736ddfab0b1ac091e5bb35212c2d</li> </ul> </li> <li><a href="/misc/goto?guid=4958319123182088329">http://download.lighttpd.net/lighttpd/releases-1.4.x/lighttpd-1.4.30.tar.xz</a> <ul> <li><span class="caps">GPG</span> signature: <a href="/misc/goto?guid=4958319123969432952">http://download.lighttpd.net/lighttpd/releases-1.4.x/lighttpd-1.4.30.tar.xz.asc</a></li> <li><span class="caps">SHA256</span>: 0d795597e4666dbf6ffe44b4a42f388ddb44736ddfab0b1ac091e5bb35212c2d</li> </ul> </li> <li><span class="caps">SHA256</span> checksums: <a href="/misc/goto?guid=4958319124762081075">http://download.lighttpd.net/lighttpd/releases-1.4.x/lighttpd-1.4.30.sha256sum</a></li> </ul> <p><strong>与 1.4.29 版本的比较<br /> </strong></p> <ul> <li>Always use our ‘own’ md5 implementation, fixes linking issues on MacOS (fixes <a href="/misc/goto?guid=4958319125540287827">#2331</a>)</li> <li>Limit amount of bytes we send in one go; fixes stalling in one connection and timeouts on slow systems.</li> <li>[ssl] fix build errors when Elliptic-Curve Diffie-Hellman is disabled</li> <li>Add static-file.disable-pathinfo option to prevent handling of urls like …/secret.php/image.jpg as static file</li> <li>Don’t overwrite 401 (auth required) with 501 (unknown method) (fixes <a href="/misc/goto?guid=4958319126326864802">#2341</a>)</li> <li>Fix mod_status bug: always showed “0/0” in the “Read” column for uploads (fixes <a href="/misc/goto?guid=4958319127125436202">#2351</a>)</li> <li>[mod_auth] Fix signedness error in http_auth (fixes <a href="/misc/goto?guid=4958319127906918700">#2370</a>, <span class="caps">CVE</span>-2011-4362)</li> <li>[ssl] count renegotiations to prevent client renegotiations</li> <li>[ssl] add option to honor server cipher order (fixes <a href="/misc/goto?guid=4958319128695148029">#2364</a>, <span class="caps">BEAST</span> attack)</li> <li>[core] accept dots in ipv6 addresses in host header (fixes <a href="/misc/goto?guid=4958319129483160270">#2359</a>)</li> <li>[ssl] fix ssl connection aborts if files are larger than the <span class="caps">MAX</span>_WRITE_LIMIT (256kb)</li> <li>[libev/cgi] fix waitpid <span class="caps">ECHILD</span> errors in cgi with libev (fixes <a href="/misc/goto?guid=4958319130266676811">#2324</a>)</li> </ul> <p>官方发行说明:<br /> <a href="/misc/goto?guid=4958319131050739188" target="_blank">http://www.lighttpd.net/2011/12/18/1-4-30-faster-than-santa-your-first-present-this-year</a></p>