Re: Upgrading to v3.0.4

Christian Folini <[email protected]>
Newsgroups gmane.comp.apache.mod-security.user
Message-ID <20200115113632.GA27689@leander>
Hey Monah,

The developers of ModSecurity consider libModSecurity 3.0.x as stable and
production ready for use with NGINX. The connector module that links the
engine with Apache is not deemed stable though. And I can confirm that.

The OWASP ModSecurity Core Rule Set project considers ModSecurity 2.9.x on
Apache as the reference platform and continues to do so until several
problems with ModSec3 have been sorted out. One of them is that ModSec3
is not passing the CRS test suite. It's fairly close with ModSec3 + NGINX, but
there are quite a few open issues with ModSec3 + Apache.

So for the time being, it's best to stay with ModSecurity 2.9 in your
situation.

I would also advise against a platform change for an existing Apache/ModSec
setup.

Hope this helps.

Cheers,

Christian


On Wed, Jan 15, 2020 at 06:28:11AM -0500, Monah Baki wrote:
> Hi Christian,
> 
> Apache :)
> 
> On Wed, Jan 15, 2020 at 12:06 AM Christian Folini <
> [email protected]> wrote:
> 
> > Hey Monah,
> >
> > What platform are you working on?
> >
> > ModSec3 on Apache is not production ready.
> >
> > Cheers,
> >
> > Christian
> >
> > On Tue, Jan 14, 2020 at 08:31:07PM -0500, Monah Baki wrote:
> > > Hi all,
> > >
> > > Any good documents as to how to upgrade from 2.9.3 on Centos7
> > >
> > > Thanks
> > > Monah
> >
> >
> > > _______________________________________________
> > > mod-security-users mailing list
> > > [email protected]
> > > https://lists.sourceforge.net/lists/listinfo/mod-security-users
> > > Commercial ModSecurity Rules and Support from Trustwave's SpiderLabs:
> > > http://www.modsecurity.org/projects/commercial/rules/
> > > http://www.modsecurity.org/projects/commercial/support/
> >
> >
> >
> > _______________________________________________
> > mod-security-users mailing list
> > [email protected]
> > https://lists.sourceforge.net/lists/listinfo/mod-security-users
> > Commercial ModSecurity Rules and Support from Trustwave's SpiderLabs:
> > http://www.modsecurity.org/projects/commercial/rules/
> > http://www.modsecurity.org/projects/commercial/support/
> >


> _______________________________________________
> mod-security-users mailing list
> [email protected]
> https://lists.sourceforge.net/lists/listinfo/mod-security-users
> Commercial ModSecurity Rules and Support from Trustwave's SpiderLabs:
> http://www.modsecurity.org/projects/commercial/rules/
> http://www.modsecurity.org/projects/commercial/support/



_______________________________________________
mod-security-users mailing list
[email protected]
https://lists.sourceforge.net/lists/listinfo/mod-security-users
Commercial ModSecurity Rules and Support from Trustwave's SpiderLabs:
http://www.modsecurity.org/projects/commercial/rules/
http://www.modsecurity.org/projects/commercial/support/
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.