Re: Apache reverse proxy timeout value

homesh joshi <[email protected]> Sat, 3 Feb 2024 10:15:59 +0530
Newsgroups gmane.comp.apache.mod-security.user
Message-ID <CAAjxK7vqEoVCDFTzPUqOU0QDv=_5ViKvc_TqMeMy_0xyHR89NQ@mail.gmail.com>
--===============0942815976356913832==
Content-Type: multipart/alternative; boundary="0000000000005dffc3061072e8f9"

--0000000000005dffc3061072e8f9
Content-Type: text/plain; charset="UTF-8"
Content-Transfer-Encoding: quoted-printable

Dear All,

This is resolved. found issue with the Backend web server not responding
intermittently.
No issues with apache or modsec.

Thanks for all the help.

Thanks,
Homesh

On Mon, Jan 29, 2024 at 1:18=E2=80=AFPM Christian Folini <
[email protected]> wrote:

> Hey Homesh,
>
> This is very much an Apache question. Please address it to the Apache
> user's mailinglist or some other Apache forum.
>
> With that being said, it's a very odd behavior, I have never see.
>
> Best,
>
> Christian
>
> On Mon, Jan 29, 2024 at 12:31:13PM +0530, homesh joshi wrote:
> > Hi All,
> >
> > I am not sure if this is a modsec issue as I have tested it by disablin=
g
> > the modsec still I face this issue.
> > I have apache setup in reverse proxy configuration with proxy timeout s=
et
> > as 20 sec.
> > for one website request for /favicon.ico takes 20 sec. if I reduce the
> > proxy timeout to 2 sec then request for favicon.ico takes 2 sec. I put
> the
> > proxy module log level to trace 8 and apache log level to debug. but
> still
> > i am not able to find why apache waits for timeout. Attached are the lo=
gs
> > for your reference.
> >
> > Thanks in advance.
> > Homesh
>
> > [Thu Jan 25 15:47:22.967833 2024] [socache_shmcb:debug] [pid 5731:tid
> 140199434626624] mod_socache_shmcb.c(508): AH00831: socache_shmcb_store
> (0x61 -> subcache 1)
> > [Thu Jan 25 15:47:22.967900 2024] [socache_shmcb:debug] [pid 5731:tid
> 140199434626624] mod_socache_shmcb.c(862): AH00847: insert happened at
> idx=3D29, data=3D(6525:6557)
> > [Thu Jan 25 15:47:22.967923 2024] [socache_shmcb:debug] [pid 5731:tid
> 140199434626624] mod_socache_shmcb.c(865): AH00848: finished insert,
> subcache: idx_pos/idx_used=3D25/5,
> > data_pos/data_used=3D5638/1084
> > [Thu Jan 25 15:47:22.967927 2024] [socache_shmcb:debug] [pid 5731:tid
> 140199434626624] mod_socache_shmcb.c(530): AH00834: leaving
> socache_shmcb_store successfully
> > [Thu Jan 25 15:47:22.968048 2024] [socache_shmcb:debug] [pid 5731:tid
> 140199434626624] mod_socache_shmcb.c(508): AH00831: socache_shmcb_store
> (0xab -> subcache 11)
> > [Thu Jan 25 15:47:22.968062 2024] [socache_shmcb:debug] [pid 5731:tid
> 140199434626624] mod_socache_shmcb.c(862): AH00847: insert happened at
> idx=3D26, data=3D(5857:5889)
> > [Thu Jan 25 15:47:22.968067 2024] [socache_shmcb:debug] [pid 5731:tid
> 140199434626624] mod_socache_shmcb.c(865): AH00848: finished insert,
> subcache: idx_pos/idx_used=3D22/5,
> > data_pos/data_used=3D4954/1099
> > [Thu Jan 25 15:47:22.968071 2024] [socache_shmcb:debug] [pid 5731:tid
> 140199434626624] mod_socache_shmcb.c(530): AH00834: leaving
> socache_shmcb_store successfully
> > [Thu Jan 25 15:47:22.969591 2024] [ssl:debug] [pid 5731:tid
> 140200633919040] ssl_engine_kernel.c(415): [remote 1.2.3.4:58139]
> AH02034: Subsequent (No.2) HTTPS request
> >  received for child 5394 (server play.lvu:443)
> > [Thu Jan 25 15:47:22.971124 2024] [proxy:trace2] [pid 5731:tid
> 140200633919040] mod_proxy.c(881): [remote 1.2.3.4:58139] AH03461:
> attempting to match URI path '/favic
> > on.ico' against prefix '/error/' for proxying
> > [Thu Jan 25 15:47:22.971161 2024] [proxy:trace2] [pid 5731:tid
> 140200633919040] mod_proxy.c(881): [remote 1.2.3.4:58139] AH03461:
> attempting to match URI path '/favic
> > on.ico' against prefix '/' for proxying
> > [Thu Jan 25 15:47:22.971167 2024] [proxy:trace1] [pid 5731:tid
> 140200633919040] mod_proxy.c(998): [remote 1.2.3.4:58139] AH03464: URI
> path '/favicon.ico' matches prox
> > y handler 'proxy:
> https://play-lvu-205133111.ap-south-1.elb.amazonaws.com:443/favicon.ico'
> > [Thu Jan 25 15:47:22.971190 2024] [authz_core:debug] [pid 5731:tid
> 140200633919040] mod_authz_core.c(843): [remote 1.2.3.4:58139] AH01628:
> authorization result: grant
> > ed (no directives)
> > [Thu Jan 25 15:47:22.975603 2024] [proxy:trace2] [pid 5731:tid
> 140200633919040] proxy_util.c(2335): [remote 1.2.3.4:58139] https: found
> worker https://play-lvu-20510
> > 2675.ap-south-1.elb.amazonaws.com/ for
> https://play-lvu-205133111.ap-south-1.elb.amazonaws.com/favicon.ico
> > [Thu Jan 25 15:47:22.975651 2024] [proxy:debug] [pid 5731:tid
> 140200633919040] mod_proxy.c(1503): [remote 1.2.3.4:58139] AH01143:
> Running scheme https handler (attemp
> > t 0)
> > [Thu Jan 25 15:47:22.975660 2024] [proxy_fcgi:debug] [pid 5731:tid
> 140200633919040] mod_proxy_fcgi.c(1054): [remote 1.2.3.4:58139] AH01076:
> url: https://play-lvu-205
> > 102675.ap-south-1.elb.amazonaws.com/favicon.ico proxyname: (null)
> proxyport: 0
> > [Thu Jan 25 15:47:22.975666 2024] [proxy_fcgi:debug] [pid 5731:tid
> 140200633919040] mod_proxy_fcgi.c(1059): [remote 1.2.3.4:58139] AH01077:
> declining URL https://play
> > -lvu-205133111.ap-south-1.elb.amazonaws.com/favicon.ico
> > [Thu Jan 25 15:47:22.975682 2024] [proxy:debug] [pid 5731:tid
> 140200633919040] proxy_util.c(2531): AH00942: https: has acquired
> connection for (play-lvu-205133111.ap-south
> > -1.elb.amazonaws.com)
> > [Thu Jan 25 15:47:22.975694 2024] [proxy:debug] [pid 5731:tid
> 140200633919040] proxy_util.c(2587): [remote 1.2.3.4:58139] AH00944:
> connecting https://play-lvu-205102
> > 675.ap-south-1.elb.amazonaws.com/favicon.ico to
> play-lvu-205133111.ap-south-1.elb.amazonaws.com:443
> > [Thu Jan 25 15:47:23.019184 2024] [proxy:debug] [pid 5731:tid
> 140200633919040] proxy_util.c(2810): [remote 1.2.3.4:58139] AH00947:
> connected /favicon.ico to play-lvu
> > -205133111.ap-south-1.elb.amazonaws.com:443
> > [Thu Jan 25 15:47:23.019277 2024] [proxy:trace2] [pid 5731:tid
> 140200633919040] proxy_util.c(3244): https: fam 2 socket created to conne=
ct
> to play-lvu-205133111.ap-south-1
> > .elb.amazonaws.com
> > [Thu Jan 25 15:47:43.039441 2024] [proxy:debug] [pid 5731:tid
> 140200633919040] proxy_util.c(3267): (70007)The timeout specified has
> expired: AH00957: https: attempt to conn
> > ect to 3.111.227.162:443 (
> play-lvu-205133111.ap-south-1.elb.amazonaws.com) failed
> > [Thu Jan 25 15:47:43.039558 2024] [proxy:trace2] [pid 5731:tid
> 140200633919040] proxy_util.c(3244): https: fam 2 socket created to conne=
ct
> to play-lvu-205133111.ap-south-1
> > .elb.amazonaws.com
> > [Thu Jan 25 15:47:43.057570 2024] [proxy:debug] [pid 5731:tid
> 140200633919040] proxy_util.c(3276): AH02824: https: connection establish=
ed
> with 3.109.6.57:443 (play-lvu-205
> > 102675.ap-south-1.elb.amazonaws.com)
> > [Thu Jan 25 15:47:43.057649 2024] [proxy:trace1] [pid 5731:tid
> 140200633919040] proxy_util.c(3450): [remote 3.109.6.57:443] https: set
> SNI to play.lvu for (play-lvu-20510
> > 2675.ap-south-1.elb.amazonaws.com)
> > [Thu Jan 25 15:47:43.057655 2024] [proxy:debug] [pid 5731:tid
> 140200633919040] proxy_util.c(3462): AH00962: https: connection complete =
to
> 3.111.227.162:443 (play-lvu-20510
> > 2675.ap-south-1.elb.amazonaws.com)
> > [Thu Jan 25 15:47:43.057663 2024] [qos:debug] [pid 5731:tid
> 140200633919040] apache2/mod_qos.c(8587): mod_qos(): skip processing of
> outgoing connection 3.109.6.57<->165.232
> > .187.180
> > [Thu Jan 25 15:47:43.057669 2024] [ssl:info] [pid 5731:tid
> 140200633919040] [remote 3.109.6.57:443] AH01964: Connection to child 0
> established (server play.lvu:443)
> > [Thu Jan 25 15:47:43.078549 2024] [ssl:debug] [pid 5731:tid
> 140200633919040] ssl_engine_kernel.c(1764): [remote 3.109.6.57:443]
> AH02275: Certificate Verification, depth 3,
> > CRL checking mode: none (0) [subject: CN=3DStarfield Services Root
> Certificate Authority - G2,O=3DStarfield Technologies\\,
> Inc.,L=3DScottsdale,ST=3DArizona,C=3DUS / issuer: OU=3DStarf
> > ield Class 2 Certification Authority,O=3DStarfield Technologies\\,
> Inc.,C=3DUS / serial: A70E4A4C3482B77F / notbefore: Sep  2 00:00:00 2009 =
GMT
> / notafter: Jun 28 17:39:16 2034
> >  GMT]
> > [Thu Jan 25 15:47:43.078695 2024] [ssl:debug] [pid 5731:tid
> 140200633919040] ssl_engine_kernel.c(1764): [remote 3.109.6.57:443]
> AH02275: Certificate Verification, depth 2,
> > CRL checking mode: none (0) [subject: CN=3DAmazon Root CA 1,O=3DAmazon,=
C=3DUS
> / issuer: CN=3DStarfield Services Root Certificate Authority - G2,O=3DSta=
rfield
> Technologies\\, Inc.,L=3DS
> > cottsdale,ST=3DArizona,C=3DUS / serial:
> 067F944A2A27CDF3FAC2AE2B01F908EEB9C4C6 / notbefore: May 25 12:00:00 2015
> GMT / notafter: Dec 31 01:00:00 2037 GMT]
> > [Thu Jan 25 15:47:43.078779 2024] [ssl:debug] [pid 5731:tid
> 140200633919040] ssl_engine_kernel.c(1764): [remote 3.109.6.57:443]
> AH02275: Certificate Verification, depth 1,
> > CRL checking mode: none (0) [subject: CN=3DAmazon RSA 2048
> M01,O=3DAmazon,C=3DUS / issuer: CN=3DAmazon Root CA 1,O=3DAmazon,C=3DUS /=
 serial:
> 077312380B9D6688A33B1ED9BF9CCDA68E0E0F / no
> > tbefore: Aug 23 22:21:28 2022 GMT / notafter: Aug 23 22:21:28 2030 GMT]
> > [Thu Jan 25 15:47:43.078863 2024] [ssl:debug] [pid 5731:tid
> 140200633919040] ssl_engine_kernel.c(1764): [remote 3.109.6.57:443]
> AH02275: Certificate Verification, depth 0,
> > CRL checking mode: none (0) [subject: CN=3Dplay.lvu / issuer: CN=3DAmaz=
on
> RSA 2048 M01,O=3DAmazon,C=3DUS / serial: 088DB8B2694138D3A4624BF0EEFF3856=
 /
> notbefore: Oct 11 00:00:00 20
> > 23 GMT / notafter: Nov  8 23:59:59 2024 GMT]
> > [Thu Jan 25 15:47:43.079137 2024] [ssl:debug] [pid 5731:tid
> 140200633919040] ssl_engine_kernel.c(2254): [remote 3.109.6.57:443]
> AH02041: Protocol: TLSv1.3, Cipher: TLS_AES_
> > 128_GCM_SHA256 (128/128 bits)
> > [Thu Jan 25 15:47:43.079199 2024] [ssl:debug] [pid 5731:tid
> 140200633919040] ssl_util_ssl.c(451): AH02412: [play.lvu:443] Cert matche=
s
> for name 'play.lvu' [subject: CN=3Dkl
> > ay.lvu / issuer: CN=3DAmazon RSA 2048 M01,O=3DAmazon,C=3DUS / serial:
> 088DB8B2694138D3A4624BF0EEFF3856 / notbefore: Oct 11 00:00:00 2023 GMT /
> notafter: Nov  8 23:59:59 2024 GMT
> > ]
> > [Thu Jan 25 15:47:43.100903 2024] [proxy:debug] [pid 5731:tid
> 140200633919040] proxy_util.c(2546): AH00943: https: has released
> connection for (play-lvu-205133111.ap-south
> > -1.elb.amazonaws.com)
> > [Thu Jan 25 15:47:43.100989 2024] [ssl:debug] [pid 5731:tid
> 140200633919040] ssl_engine_io.c(1147): [remote 3.109.6.57:443] AH02001:
> Connection closed to child 0 with stand
> > ard shutdown (server play.lvu:443)
> > [Thu Jan 25 15:47:43.101088 2024] [proxy:debug] [pid 5731:tid
> 140200633919040] proxy_util.c(3386): [remote 3.109.6.57:443] AH02642:
> proxy: connection shutdown
> > [Thu Jan 25 15:47:43.863505 2024] [ssl:debug] [pid 5731:tid
> 140200650737216] ssl_engine_kernel.c(415): [remote 1.2.3.4:58139]
> AH02034: Subsequent (No.2) HTTPS request
> >  received for child 1808 (server play.lvu:443), referer:
> https://play.lvu/favicon.ico
> > [Thu Jan 25 15:47:43.865077 2024] [proxy:trace2] [pid 5731:tid
> 140200650737216] mod_proxy.c(881): [remote 1.2.3.4:58139] AH03461:
> attempting to match URI path '/favic
> > on.ico' against prefix '/error/' for proxying, referer:
> https://play.lvu/favicon.ico
> > [Thu Jan 25 15:47:43.865165 2024] [proxy:trace2] [pid 5731:tid
> 140200650737216] mod_proxy.c(881): [remote 1.2.3.4:58139] AH03461:
> attempting to match URI path '/favic
> > on.ico' against prefix '/' for proxying, referer:
> https://play.lvu/favicon.ico
> > [Thu Jan 25 15:47:43.865192 2024] [proxy:trace1] [pid 5731:tid
> 140200650737216] mod_proxy.c(998): [remote 1.2.3.4:58139] AH03464: URI
> path '/favicon.ico' matches prox
> > y handler 'proxy:
> https://play-lvu-205133111.ap-south-1.elb.amazonaws.com:443/favicon.ico',
> referer: https://play.lvu/favicon.ico
> > [Thu Jan 25 15:47:43.865231 2024] [authz_core:debug] [pid 5731:tid
> 140200650737216] mod_authz_core.c(843): [remote 1.2.3.4:58139] AH01628:
> authorization result: grant
> > ed (no directives), referer: https://play.lvu/favicon.ico
> > [Thu Jan 25 15:47:43.868082 2024] [proxy:trace2] [pid 5731:tid
> 140200650737216] proxy_util.c(2335): [remote 1.2.3.4:58139] https: found
> worker https://play-lvu-20510
> > 2675.ap-south-1.elb.amazonaws.com/ for
> https://play-lvu-205133111.ap-south-1.elb.amazonaws.com/favicon.ico,
> referer: https://play.lvu/favicon.ico
> > [Thu Jan 25 15:47:43.868164 2024] [proxy:debug] [pid 5731:tid
> 140200650737216] mod_proxy.c(1503): [remote 1.2.3.4:58139] AH01143:
> Running scheme https handler (attemp
> > t 0), referer: https://play.lvu/favicon.ico
> > [Thu Jan 25 15:47:43.868198 2024] [proxy_fcgi:debug] [pid 5731:tid
> 140200650737216] mod_proxy_fcgi.c(1054): [remote 1.2.3.4:58139] AH01076:
> url: https://play-lvu-205
> > 102675.ap-south-1.elb.amazonaws.com/favicon.ico proxyname: (null)
> proxyport: 0, referer: https://play.lvu/favicon.ico
> > [Thu Jan 25 15:47:43.868223 2024] [proxy_fcgi:debug] [pid 5731:tid
> 140200650737216] mod_proxy_fcgi.c(1059): [remote 1.2.3.4:58139] AH01077:
> declining URL https://play
> > -lvu-205133111.ap-south-1.elb.amazonaws.com/favicon.ico, referer:
> https://play.lvu/favicon.ico
> > [Thu Jan 25 15:47:43.868248 2024] [proxy:debug] [pid 5731:tid
> 140200650737216] proxy_util.c(2531): AH00942: https: has acquired
> connection for (play-lvu-205133111.ap-south
> > -1.elb.amazonaws.com)
> > [Thu Jan 25 15:47:43.868273 2024] [proxy:debug] [pid 5731:tid
> 140200650737216] proxy_util.c(2587): [remote 1.2.3.4:58139] AH00944:
> connecting https://play-lvu-205102
> > 675.ap-south-1.elb.amazonaws.com/favicon.ico to
> play-lvu-205133111.ap-south-1.elb.amazonaws.com:443, referer:
> https://play.lvu/favicon.ico
> > [Thu Jan 25 15:47:43.868630 2024] [proxy:debug] [pid 5731:tid
> 140200650737216] proxy_util.c(2810): [remote 1.2.3.4:58139] AH00947:
> connected /favicon.ico to play-lvu
> > -205133111.ap-south-1.elb.amazonaws.com:443, referer:
> https://play.lvu/favicon.ico
> > [Thu Jan 25 15:47:43.868704 2024] [proxy:trace2] [pid 5731:tid
> 140200650737216] proxy_util.c(3244): https: fam 2 socket created to conne=
ct
> to play-lvu-205133111.ap-south-1
> > .elb.amazonaws.com
> > [Thu Jan 25 15:47:43.894557 2024] [proxy:debug] [pid 5731:tid
> 140200650737216] proxy_util.c(3276): AH02824: https: connection establish=
ed
> with 3.109.172.68:443 (play-lvu-2
> > 05102675.ap-south-1.elb.amazonaws.com)
> > [Thu Jan 25 15:47:43.894681 2024] [proxy:trace1] [pid 5731:tid
> 140200650737216] proxy_util.c(3450): [remote 3.109.172.68:443] https: set
> SNI to play.lvu for (play-lvu-205
> > 102675.ap-south-1.elb.amazonaws.com)
> > [Thu Jan 25 15:47:43.894708 2024] [proxy:debug] [pid 5731:tid
> 140200650737216] proxy_util.c(3462): AH00962: https: connection complete =
to
> 3.109.172.68:443 (play-lvu-205102
> > 675.ap-south-1.elb.amazonaws.com)
> > [Thu Jan 25 15:47:43.894748 2024] [qos:debug] [pid 5731:tid
> 140200650737216] apache2/mod_qos.c(8587): mod_qos(): skip processing of
> outgoing connection 3.109.172.68<->165.2
> > 32.187.180
> > [Thu Jan 25 15:47:43.894770 2024] [ssl:info] [pid 5731:tid
> 140200650737216] [remote 3.109.172.68:443] AH01964: Connection to child 0
> established (server play.lvu:443)
> > [Thu Jan 25 15:47:43.923819 2024] [ssl:debug] [pid 5731:tid
> 140200650737216] ssl_engine_kernel.c(1764): [remote 3.109.172.68:443]
> AH02275: Certificate Verification, depth 3
> > , CRL checking mode: none (0) [subject: CN=3DStarfield Services Root
> Certificate Authority - G2,O=3DStarfield Technologies\\,
> Inc.,L=3DScottsdale,ST=3DArizona,C=3DUS / issuer: OU=3DSta
> > rfield Class 2 Certification Authority,O=3DStarfield Technologies\\,
> Inc.,C=3DUS / serial: A70E4A4C3482B77F / notbefore: Sep  2 00:00:00 2009 =
GMT
> / notafter: Jun 28 17:39:16 20
> > 34 GMT]
> > [Thu Jan 25 15:47:43.924033 2024] [ssl:debug] [pid 5731:tid
> 140200650737216] ssl_engine_kernel.c(1764): [remote 3.109.172.68:443]
> AH02275: Certificate Verification, depth 2
> > , CRL checking mode: none (0) [subject: CN=3DAmazon Root CA
> 1,O=3DAmazon,C=3DUS / issuer: CN=3DStarfield Services Root Certificate Au=
thority
> - G2,O=3DStarfield Technologies\\, Inc.,L
> > =3DScottsdale,ST=3DArizona,C=3DUS / serial:
> 067F944A2A27CDF3FAC2AE2B01F908EEB9C4C6 / notbefore: May 25 12:00:00 2015
> GMT / notafter: Dec 31 01:00:00 2037 GMT]
> > [Thu Jan 25 15:47:43.924124 2024] [ssl:debug] [pid 5731:tid
> 140200650737216] ssl_engine_kernel.c(1764): [remote 3.109.172.68:443]
> AH02275: Certificate Verification, depth 1
> > , CRL checking mode: none (0) [subject: CN=3DAmazon RSA 2048
> M01,O=3DAmazon,C=3DUS / issuer: CN=3DAmazon Root CA 1,O=3DAmazon,C=3DUS /=
 serial:
> 077312380B9D6688A33B1ED9BF9CCDA68E0E0F /
> > notbefore: Aug 23 22:21:28 2022 GMT / notafter: Aug 23 22:21:28 2030 GM=
T]
> > [Thu Jan 25 15:47:43.924208 2024] [ssl:debug] [pid 5731:tid
> 140200650737216] ssl_engine_kernel.c(1764): [remote 3.109.172.68:443]
> AH02275: Certificate Verification, depth 0
> > , CRL checking mode: none (0) [subject: CN=3Dplay.lvu / issuer: CN=3DAm=
azon
> RSA 2048 M01,O=3DAmazon,C=3DUS / serial: 088DB8B2694138D3A4624BF0EEFF3856=
 /
> notbefore: Oct 11 00:00:00
> > 2023 GMT / notafter: Nov  8 23:59:59 2024 GMT]
> > [Thu Jan 25 15:47:43.924468 2024] [ssl:debug] [pid 5731:tid
> 140200650737216] ssl_engine_kernel.c(2254): [remote 3.109.172.68:443]
> AH02041: Protocol: TLSv1.3, Cipher: TLS_AE
> > S_128_GCM_SHA256 (128/128 bits)
> > [Thu Jan 25 15:47:43.924535 2024] [ssl:debug] [pid 5731:tid
> 140200650737216] ssl_util_ssl.c(451): AH02412: [play.lvu:443] Cert matche=
s
> for name 'play.lvu' [subject: CN=3Dkl
> > ay.lvu / issuer: CN=3DAmazon RSA 2048 M01,O=3DAmazon,C=3DUS / serial:
> 088DB8B2694138D3A4624BF0EEFF3856 / notbefore: Oct 11 00:00:00 2023 GMT /
> notafter: Nov  8 23:59:59 2024 GMT
> > ]
> > [Thu Jan 25 15:47:43.959108 2024] [proxy:debug] [pid 5731:tid
> 140200650737216] proxy_util.c(2546): AH00943: https: has released
> connection for (play-lvu-205133111.ap-south
> > -1.elb.amazonaws.com)
> > [Thu Jan 25 15:47:43.959261 2024] [ssl:debug] [pid 5731:tid
> 140200650737216] ssl_engine_io.c(1147): [remote 3.109.172.68:443]
> AH02001: Connection closed to child 0 with sta
> > ndard shutdown (server play.lvu:443)
> > [Thu Jan 25 15:47:43.959361 2024] [proxy:debug] [pid 5731:tid
> 140200650737216] proxy_util.c(3386): [remote 3.109.172.68:443] AH02642:
> proxy: connection shutdown
> > [Thu Jan 25 15:47:48.965114 2024] [ssl:debug] [pid 5731:tid
> 140199476590144] ssl_engine_io.c(1147): [client 1.2.3.4:58139] AH02001:
> Connection closed to child 16 with
> >  standard shutdown (server play.lvu:443)
> >
> >
> >
> > =E2=96=B8
>
>
> > _______________________________________________
> > mod-security-users mailing list
> > [email protected]
> > https://lists.sourceforge.net/lists/listinfo/mod-security-users
> > Commercial ModSecurity Rules and Support from Trustwave's SpiderLabs:
> > http://www.modsecurity.org/projects/commercial/rules/
> > http://www.modsecurity.org/projects/commercial/support/
>
>
>
> _______________________________________________
> mod-security-users mailing list
> [email protected]
> https://lists.sourceforge.net/lists/listinfo/mod-security-users
> Commercial ModSecurity Rules and Support from Trustwave's SpiderLabs:
> http://www.modsecurity.org/projects/commercial/rules/
> http://www.modsecurity.org/projects/commercial/support/
>

--0000000000005dffc3061072e8f9
Content-Type: text/html; charset="UTF-8"
Content-Transfer-Encoding: quoted-printable

<div dir=3D"ltr"><div>Dear All,</div><div><br></div><div>This is resolved. =
found issue with the Backend web server not responding intermittently.</div=
><div>No issues with apache or modsec.</div><div><br></div><div>Thanks for =
all the help.</div><div><br></div><div>Thanks,</div><div>Homesh<br></div></=
div><br><div class=3D"gmail_quote"><div dir=3D"ltr" class=3D"gmail_attr">On=
 Mon, Jan 29, 2024 at 1:18=E2=80=AFPM Christian Folini &lt;<a href=3D"mailt=
o:[email protected]">[email protected]</a>&gt; wrote:<b=
r></div><blockquote class=3D"gmail_quote" style=3D"margin:0px 0px 0px 0.8ex=
;border-left:1px solid rgb(204,204,204);padding-left:1ex">Hey Homesh,<br>
<br>
This is very much an Apache question. Please address it to the Apache<br>
user&#39;s mailinglist or some other Apache forum.<br>
<br>
With that being said, it&#39;s a very odd behavior, I have never see.<br>
<br>
Best,<br>
<br>
Christian<br>
<br>
On Mon, Jan 29, 2024 at 12:31:13PM +0530, homesh joshi wrote:<br>
&gt; Hi All,<br>
&gt; <br>
&gt; I am not sure if this is a modsec issue as I have tested it by disabli=
ng<br>
&gt; the modsec still I face this issue.<br>
&gt; I have apache setup in reverse proxy configuration with proxy timeout =
set<br>
&gt; as 20 sec.<br>
&gt; for one website request for /favicon.ico takes 20 sec. if I reduce the=
<br>
&gt; proxy timeout to 2 sec then request for favicon.ico takes 2 sec. I put=
 the<br>
&gt; proxy module log level to trace 8 and apache log level to debug. but s=
till<br>
&gt; i am not able to find why apache waits for timeout. Attached are the l=
ogs<br>
&gt; for your reference.<br>
&gt; <br>
&gt; Thanks in advance.<br>
&gt; Homesh<br>
<br>
&gt; [Thu Jan 25 15:47:22.967833 2024] [socache_shmcb:debug] [pid 5731:tid =
140199434626624] mod_socache_shmcb.c(508): AH00831: socache_shmcb_store (0x=
61 -&gt; subcache 1)<br>
&gt; [Thu Jan 25 15:47:22.967900 2024] [socache_shmcb:debug] [pid 5731:tid =
140199434626624] mod_socache_shmcb.c(862): AH00847: insert happened at idx=
=3D29, data=3D(6525:6557)<br>
&gt; [Thu Jan 25 15:47:22.967923 2024] [socache_shmcb:debug] [pid 5731:tid =
140199434626624] mod_socache_shmcb.c(865): AH00848: finished insert, subcac=
he: idx_pos/idx_used=3D25/5,<br>
&gt; data_pos/data_used=3D5638/1084<br>
&gt; [Thu Jan 25 15:47:22.967927 2024] [socache_shmcb:debug] [pid 5731:tid =
140199434626624] mod_socache_shmcb.c(530): AH00834: leaving socache_shmcb_s=
tore successfully<br>
&gt; [Thu Jan 25 15:47:22.968048 2024] [socache_shmcb:debug] [pid 5731:tid =
140199434626624] mod_socache_shmcb.c(508): AH00831: socache_shmcb_store (0x=
ab -&gt; subcache 11)<br>
&gt; [Thu Jan 25 15:47:22.968062 2024] [socache_shmcb:debug] [pid 5731:tid =
140199434626624] mod_socache_shmcb.c(862): AH00847: insert happened at idx=
=3D26, data=3D(5857:5889)<br>
&gt; [Thu Jan 25 15:47:22.968067 2024] [socache_shmcb:debug] [pid 5731:tid =
140199434626624] mod_socache_shmcb.c(865): AH00848: finished insert, subcac=
he: idx_pos/idx_used=3D22/5,<br>
&gt; data_pos/data_used=3D4954/1099<br>
&gt; [Thu Jan 25 15:47:22.968071 2024] [socache_shmcb:debug] [pid 5731:tid =
140199434626624] mod_socache_shmcb.c(530): AH00834: leaving socache_shmcb_s=
tore successfully<br>
&gt; [Thu Jan 25 15:47:22.969591 2024] [ssl:debug] [pid 5731:tid 1402006339=
19040] ssl_engine_kernel.c(415): [remote <a href=3D"http://1.2.3.4:58139" r=
el=3D"noreferrer" target=3D"_blank">1.2.3.4:58139</a>] AH02034: Subsequent =
(No.2) HTTPS request<br>
&gt;=C2=A0 received for child 5394 (server play.lvu:443)<br>
&gt; [Thu Jan 25 15:47:22.971124 2024] [proxy:trace2] [pid 5731:tid 1402006=
33919040] mod_proxy.c(881): [remote <a href=3D"http://1.2.3.4:58139" rel=3D=
"noreferrer" target=3D"_blank">1.2.3.4:58139</a>] AH03461: attempting to ma=
tch URI path &#39;/favic<br>
&gt; on.ico&#39; against prefix &#39;/error/&#39; for proxying<br>
&gt; [Thu Jan 25 15:47:22.971161 2024] [proxy:trace2] [pid 5731:tid 1402006=
33919040] mod_proxy.c(881): [remote <a href=3D"http://1.2.3.4:58139" rel=3D=
"noreferrer" target=3D"_blank">1.2.3.4:58139</a>] AH03461: attempting to ma=
tch URI path &#39;/favic<br>
&gt; on.ico&#39; against prefix &#39;/&#39; for proxying<br>
&gt; [Thu Jan 25 15:47:22.971167 2024] [proxy:trace1] [pid 5731:tid 1402006=
33919040] mod_proxy.c(998): [remote <a href=3D"http://1.2.3.4:58139" rel=3D=
"noreferrer" target=3D"_blank">1.2.3.4:58139</a>] AH03464: URI path &#39;/f=
avicon.ico&#39; matches prox<br>
&gt; y handler &#39;proxy:<a href=3D"https://play-lvu-205133111.ap-south-1.=
elb.amazonaws.com:443/favicon.ico" rel=3D"noreferrer" target=3D"_blank">htt=
ps://play-lvu-205133111.ap-south-1.elb.amazonaws.com:443/favicon.ico</a>&#3=
9;<br>
&gt; [Thu Jan 25 15:47:22.971190 2024] [authz_core:debug] [pid 5731:tid 140=
200633919040] mod_authz_core.c(843): [remote <a href=3D"http://1.2.3.4:5813=
9" rel=3D"noreferrer" target=3D"_blank">1.2.3.4:58139</a>] AH01628: authori=
zation result: grant<br>
&gt; ed (no directives)<br>
&gt; [Thu Jan 25 15:47:22.975603 2024] [proxy:trace2] [pid 5731:tid 1402006=
33919040] proxy_util.c(2335): [remote <a href=3D"http://1.2.3.4:58139" rel=
=3D"noreferrer" target=3D"_blank">1.2.3.4:58139</a>] https: found worker <a=
 href=3D"https://play-lvu-20510" rel=3D"noreferrer" target=3D"_blank">https=
://play-lvu-20510</a><br>
&gt; <a href=3D"http://2675.ap-south-1.elb.amazonaws.com/" rel=3D"noreferre=
r" target=3D"_blank">2675.ap-south-1.elb.amazonaws.com/</a> for <a href=3D"=
https://play-lvu-205133111.ap-south-1.elb.amazonaws.com/favicon.ico" rel=3D=
"noreferrer" target=3D"_blank">https://play-lvu-205133111.ap-south-1.elb.am=
azonaws.com/favicon.ico</a><br>
&gt; [Thu Jan 25 15:47:22.975651 2024] [proxy:debug] [pid 5731:tid 14020063=
3919040] mod_proxy.c(1503): [remote <a href=3D"http://1.2.3.4:58139" rel=3D=
"noreferrer" target=3D"_blank">1.2.3.4:58139</a>] AH01143: Running scheme h=
ttps handler (attemp<br>
&gt; t 0)<br>
&gt; [Thu Jan 25 15:47:22.975660 2024] [proxy_fcgi:debug] [pid 5731:tid 140=
200633919040] mod_proxy_fcgi.c(1054): [remote <a href=3D"http://1.2.3.4:581=
39" rel=3D"noreferrer" target=3D"_blank">1.2.3.4:58139</a>] AH01076: url: <=
a href=3D"https://play-lvu-205" rel=3D"noreferrer" target=3D"_blank">https:=
//play-lvu-205</a><br>
&gt; <a href=3D"http://102675.ap-south-1.elb.amazonaws.com/favicon.ico" rel=
=3D"noreferrer" target=3D"_blank">102675.ap-south-1.elb.amazonaws.com/favic=
on.ico</a> proxyname: (null) proxyport: 0<br>
&gt; [Thu Jan 25 15:47:22.975666 2024] [proxy_fcgi:debug] [pid 5731:tid 140=
200633919040] mod_proxy_fcgi.c(1059): [remote <a href=3D"http://1.2.3.4:581=
39" rel=3D"noreferrer" target=3D"_blank">1.2.3.4:58139</a>] AH01077: declin=
ing URL <a href=3D"https://play" rel=3D"noreferrer" target=3D"_blank">https=
://play</a><br>
&gt; -<a href=3D"http://lvu-205133111.ap-south-1.elb.amazonaws.com/favicon.=
ico" rel=3D"noreferrer" target=3D"_blank">lvu-205133111.ap-south-1.elb.amaz=
onaws.com/favicon.ico</a><br>
&gt; [Thu Jan 25 15:47:22.975682 2024] [proxy:debug] [pid 5731:tid 14020063=
3919040] proxy_util.c(2531): AH00942: https: has acquired connection for (p=
lay-lvu-205133111.ap-south<br>
&gt; -<a href=3D"http://1.elb.amazonaws.com" rel=3D"noreferrer" target=3D"_=
blank">1.elb.amazonaws.com</a>)<br>
&gt; [Thu Jan 25 15:47:22.975694 2024] [proxy:debug] [pid 5731:tid 14020063=
3919040] proxy_util.c(2587): [remote <a href=3D"http://1.2.3.4:58139" rel=
=3D"noreferrer" target=3D"_blank">1.2.3.4:58139</a>] AH00944: connecting <a=
 href=3D"https://play-lvu-205102" rel=3D"noreferrer" target=3D"_blank">http=
s://play-lvu-205102</a><br>
&gt; <a href=3D"http://675.ap-south-1.elb.amazonaws.com/favicon.ico" rel=3D=
"noreferrer" target=3D"_blank">675.ap-south-1.elb.amazonaws.com/favicon.ico=
</a> to <a href=3D"http://play-lvu-205133111.ap-south-1.elb.amazonaws.com:4=
43" rel=3D"noreferrer" target=3D"_blank">play-lvu-205133111.ap-south-1.elb.=
amazonaws.com:443</a><br>
&gt; [Thu Jan 25 15:47:23.019184 2024] [proxy:debug] [pid 5731:tid 14020063=
3919040] proxy_util.c(2810): [remote <a href=3D"http://1.2.3.4:58139" rel=
=3D"noreferrer" target=3D"_blank">1.2.3.4:58139</a>] AH00947: connected /fa=
vicon.ico to play-lvu<br>
&gt; -<a href=3D"http://205133111.ap-south-1.elb.amazonaws.com:443" rel=3D"=
noreferrer" target=3D"_blank">205133111.ap-south-1.elb.amazonaws.com:443</a=
><br>
&gt; [Thu Jan 25 15:47:23.019277 2024] [proxy:trace2] [pid 5731:tid 1402006=
33919040] proxy_util.c(3244): https: fam 2 socket created to connect to pla=
y-lvu-205133111.ap-south-1<br>
&gt; .<a href=3D"http://elb.amazonaws.com" rel=3D"noreferrer" target=3D"_bl=
ank">elb.amazonaws.com</a><br>
&gt; [Thu Jan 25 15:47:43.039441 2024] [proxy:debug] [pid 5731:tid 14020063=
3919040] proxy_util.c(3267): (70007)The timeout specified has expired: AH00=
957: https: attempt to conn<br>
&gt; ect to <a href=3D"http://3.111.227.162:443" rel=3D"noreferrer" target=
=3D"_blank">3.111.227.162:443</a> (<a href=3D"http://play-lvu-205133111.ap-=
south-1.elb.amazonaws.com" rel=3D"noreferrer" target=3D"_blank">play-lvu-20=
5133111.ap-south-1.elb.amazonaws.com</a>) failed<br>
&gt; [Thu Jan 25 15:47:43.039558 2024] [proxy:trace2] [pid 5731:tid 1402006=
33919040] proxy_util.c(3244): https: fam 2 socket created to connect to pla=
y-lvu-205133111.ap-south-1<br>
&gt; .<a href=3D"http://elb.amazonaws.com" rel=3D"noreferrer" target=3D"_bl=
ank">elb.amazonaws.com</a><br>
&gt; [Thu Jan 25 15:47:43.057570 2024] [proxy:debug] [pid 5731:tid 14020063=
3919040] proxy_util.c(3276): AH02824: https: connection established with <a=
 href=3D"http://3.109.6.57:443" rel=3D"noreferrer" target=3D"_blank">3.109.=
6.57:443</a> (play-lvu-205<br>
&gt; <a href=3D"http://102675.ap-south-1.elb.amazonaws.com" rel=3D"noreferr=
er" target=3D"_blank">102675.ap-south-1.elb.amazonaws.com</a>)<br>
&gt; [Thu Jan 25 15:47:43.057649 2024] [proxy:trace1] [pid 5731:tid 1402006=
33919040] proxy_util.c(3450): [remote <a href=3D"http://3.109.6.57:443" rel=
=3D"noreferrer" target=3D"_blank">3.109.6.57:443</a>] https: set SNI to pla=
y.lvu for (play-lvu-20510<br>
&gt; <a href=3D"http://2675.ap-south-1.elb.amazonaws.com" rel=3D"noreferrer=
" target=3D"_blank">2675.ap-south-1.elb.amazonaws.com</a>)<br>
&gt; [Thu Jan 25 15:47:43.057655 2024] [proxy:debug] [pid 5731:tid 14020063=
3919040] proxy_util.c(3462): AH00962: https: connection complete to <a href=
=3D"http://3.111.227.162:443" rel=3D"noreferrer" target=3D"_blank">3.111.22=
7.162:443</a> (play-lvu-20510<br>
&gt; <a href=3D"http://2675.ap-south-1.elb.amazonaws.com" rel=3D"noreferrer=
" target=3D"_blank">2675.ap-south-1.elb.amazonaws.com</a>)<br>
&gt; [Thu Jan 25 15:47:43.057663 2024] [qos:debug] [pid 5731:tid 1402006339=
19040] apache2/mod_qos.c(8587): mod_qos(): skip processing of outgoing conn=
ection 3.109.6.57&lt;-&gt;165.232<br>
&gt; .187.180<br>
&gt; [Thu Jan 25 15:47:43.057669 2024] [ssl:info] [pid 5731:tid 14020063391=
9040] [remote <a href=3D"http://3.109.6.57:443" rel=3D"noreferrer" target=
=3D"_blank">3.109.6.57:443</a>] AH01964: Connection to child 0 established =
(server play.lvu:443)<br>
&gt; [Thu Jan 25 15:47:43.078549 2024] [ssl:debug] [pid 5731:tid 1402006339=
19040] ssl_engine_kernel.c(1764): [remote <a href=3D"http://3.109.6.57:443"=
 rel=3D"noreferrer" target=3D"_blank">3.109.6.57:443</a>] AH02275: Certific=
ate Verification, depth 3,<br>
&gt; CRL checking mode: none (0) [subject: CN=3DStarfield Services Root Cer=
tificate Authority - G2,O=3DStarfield Technologies\\, Inc.,L=3DScottsdale,S=
T=3DArizona,C=3DUS / issuer: OU=3DStarf<br>
&gt; ield Class 2 Certification Authority,O=3DStarfield Technologies\\, Inc=
.,C=3DUS / serial: A70E4A4C3482B77F / notbefore: Sep=C2=A0 2 00:00:00 2009 =
GMT / notafter: Jun 28 17:39:16 2034<br>
&gt;=C2=A0 GMT]<br>
&gt; [Thu Jan 25 15:47:43.078695 2024] [ssl:debug] [pid 5731:tid 1402006339=
19040] ssl_engine_kernel.c(1764): [remote <a href=3D"http://3.109.6.57:443"=
 rel=3D"noreferrer" target=3D"_blank">3.109.6.57:443</a>] AH02275: Certific=
ate Verification, depth 2,<br>
&gt; CRL checking mode: none (0) [subject: CN=3DAmazon Root CA 1,O=3DAmazon=
,C=3DUS / issuer: CN=3DStarfield Services Root Certificate Authority - G2,O=
=3DStarfield Technologies\\, Inc.,L=3DS<br>
&gt; cottsdale,ST=3DArizona,C=3DUS / serial: 067F944A2A27CDF3FAC2AE2B01F908=
EEB9C4C6 / notbefore: May 25 12:00:00 2015 GMT / notafter: Dec 31 01:00:00 =
2037 GMT]<br>
&gt; [Thu Jan 25 15:47:43.078779 2024] [ssl:debug] [pid 5731:tid 1402006339=
19040] ssl_engine_kernel.c(1764): [remote <a href=3D"http://3.109.6.57:443"=
 rel=3D"noreferrer" target=3D"_blank">3.109.6.57:443</a>] AH02275: Certific=
ate Verification, depth 1,<br>
&gt; CRL checking mode: none (0) [subject: CN=3DAmazon RSA 2048 M01,O=3DAma=
zon,C=3DUS / issuer: CN=3DAmazon Root CA 1,O=3DAmazon,C=3DUS / serial: 0773=
12380B9D6688A33B1ED9BF9CCDA68E0E0F / no<br>
&gt; tbefore: Aug 23 22:21:28 2022 GMT / notafter: Aug 23 22:21:28 2030 GMT=
]<br>
&gt; [Thu Jan 25 15:47:43.078863 2024] [ssl:debug] [pid 5731:tid 1402006339=
19040] ssl_engine_kernel.c(1764): [remote <a href=3D"http://3.109.6.57:443"=
 rel=3D"noreferrer" target=3D"_blank">3.109.6.57:443</a>] AH02275: Certific=
ate Verification, depth 0,<br>
&gt; CRL checking mode: none (0) [subject: CN=3Dplay.lvu / issuer: CN=3DAma=
zon RSA 2048 M01,O=3DAmazon,C=3DUS / serial: 088DB8B2694138D3A4624BF0EEFF38=
56 / notbefore: Oct 11 00:00:00 20<br>
&gt; 23 GMT / notafter: Nov=C2=A0 8 23:59:59 2024 GMT]<br>
&gt; [Thu Jan 25 15:47:43.079137 2024] [ssl:debug] [pid 5731:tid 1402006339=
19040] ssl_engine_kernel.c(2254): [remote <a href=3D"http://3.109.6.57:443"=
 rel=3D"noreferrer" target=3D"_blank">3.109.6.57:443</a>] AH02041: Protocol=
: TLSv1.3, Cipher: TLS_AES_<br>
&gt; 128_GCM_SHA256 (128/128 bits)<br>
&gt; [Thu Jan 25 15:47:43.079199 2024] [ssl:debug] [pid 5731:tid 1402006339=
19040] ssl_util_ssl.c(451): AH02412: [play.lvu:443] Cert matches for name &=
#39;play.lvu&#39; [subject: CN=3Dkl<br>
&gt; ay.lvu / issuer: CN=3DAmazon RSA 2048 M01,O=3DAmazon,C=3DUS / serial: =
088DB8B2694138D3A4624BF0EEFF3856 / notbefore: Oct 11 00:00:00 2023 GMT / no=
tafter: Nov=C2=A0 8 23:59:59 2024 GMT<br>
&gt; ]<br>
&gt; [Thu Jan 25 15:47:43.100903 2024] [proxy:debug] [pid 5731:tid 14020063=
3919040] proxy_util.c(2546): AH00943: https: has released connection for (p=
lay-lvu-205133111.ap-south<br>
&gt; -<a href=3D"http://1.elb.amazonaws.com" rel=3D"noreferrer" target=3D"_=
blank">1.elb.amazonaws.com</a>)<br>
&gt; [Thu Jan 25 15:47:43.100989 2024] [ssl:debug] [pid 5731:tid 1402006339=
19040] ssl_engine_io.c(1147): [remote <a href=3D"http://3.109.6.57:443" rel=
=3D"noreferrer" target=3D"_blank">3.109.6.57:443</a>] AH02001: Connection c=
losed to child 0 with stand<br>
&gt; ard shutdown (server play.lvu:443)<br>
&gt; [Thu Jan 25 15:47:43.101088 2024] [proxy:debug] [pid 5731:tid 14020063=
3919040] proxy_util.c(3386): [remote <a href=3D"http://3.109.6.57:443" rel=
=3D"noreferrer" target=3D"_blank">3.109.6.57:443</a>] AH02642: proxy: conne=
ction shutdown<br>
&gt; [Thu Jan 25 15:47:43.863505 2024] [ssl:debug] [pid 5731:tid 1402006507=
37216] ssl_engine_kernel.c(415): [remote <a href=3D"http://1.2.3.4:58139" r=
el=3D"noreferrer" target=3D"_blank">1.2.3.4:58139</a>] AH02034: Subsequent =
(No.2) HTTPS request<br>
&gt;=C2=A0 received for child 1808 (server play.lvu:443), referer: <a href=
=3D"https://play.lvu/favicon.ico" rel=3D"noreferrer" target=3D"_blank">http=
s://play.lvu/favicon.ico</a><br>
&gt; [Thu Jan 25 15:47:43.865077 2024] [proxy:trace2] [pid 5731:tid 1402006=
50737216] mod_proxy.c(881): [remote <a href=3D"http://1.2.3.4:58139" rel=3D=
"noreferrer" target=3D"_blank">1.2.3.4:58139</a>] AH03461: attempting to ma=
tch URI path &#39;/favic<br>
&gt; on.ico&#39; against prefix &#39;/error/&#39; for proxying, referer: <a=
 href=3D"https://play.lvu/favicon.ico" rel=3D"noreferrer" target=3D"_blank"=
>https://play.lvu/favicon.ico</a><br>
&gt; [Thu Jan 25 15:47:43.865165 2024] [proxy:trace2] [pid 5731:tid 1402006=
50737216] mod_proxy.c(881): [remote <a href=3D"http://1.2.3.4:58139" rel=3D=
"noreferrer" target=3D"_blank">1.2.3.4:58139</a>] AH03461: attempting to ma=
tch URI path &#39;/favic<br>
&gt; on.ico&#39; against prefix &#39;/&#39; for proxying, referer: <a href=
=3D"https://play.lvu/favicon.ico" rel=3D"noreferrer" target=3D"_blank">http=
s://play.lvu/favicon.ico</a><br>
&gt; [Thu Jan 25 15:47:43.865192 2024] [proxy:trace1] [pid 5731:tid 1402006=
50737216] mod_proxy.c(998): [remote <a href=3D"http://1.2.3.4:58139" rel=3D=
"noreferrer" target=3D"_blank">1.2.3.4:58139</a>] AH03464: URI path &#39;/f=
avicon.ico&#39; matches prox<br>
&gt; y handler &#39;proxy:<a href=3D"https://play-lvu-205133111.ap-south-1.=
elb.amazonaws.com:443/favicon.ico" rel=3D"noreferrer" target=3D"_blank">htt=
ps://play-lvu-205133111.ap-south-1.elb.amazonaws.com:443/favicon.ico</a>&#3=
9;, referer: <a href=3D"https://play.lvu/favicon.ico" rel=3D"noreferrer" ta=
rget=3D"_blank">https://play.lvu/favicon.ico</a><br>
&gt; [Thu Jan 25 15:47:43.865231 2024] [authz_core:debug] [pid 5731:tid 140=
200650737216] mod_authz_core.c(843): [remote <a href=3D"http://1.2.3.4:5813=
9" rel=3D"noreferrer" target=3D"_blank">1.2.3.4:58139</a>] AH01628: authori=
zation result: grant<br>
&gt; ed (no directives), referer: <a href=3D"https://play.lvu/favicon.ico" =
rel=3D"noreferrer" target=3D"_blank">https://play.lvu/favicon.ico</a><br>
&gt; [Thu Jan 25 15:47:43.868082 2024] [proxy:trace2] [pid 5731:tid 1402006=
50737216] proxy_util.c(2335): [remote <a href=3D"http://1.2.3.4:58139" rel=
=3D"noreferrer" target=3D"_blank">1.2.3.4:58139</a>] https: found worker <a=
 href=3D"https://play-lvu-20510" rel=3D"noreferrer" target=3D"_blank">https=
://play-lvu-20510</a><br>
&gt; <a href=3D"http://2675.ap-south-1.elb.amazonaws.com/" rel=3D"noreferre=
r" target=3D"_blank">2675.ap-south-1.elb.amazonaws.com/</a> for <a href=3D"=
https://play-lvu-205133111.ap-south-1.elb.amazonaws.com/favicon.ico" rel=3D=
"noreferrer" target=3D"_blank">https://play-lvu-205133111.ap-south-1.elb.am=
azonaws.com/favicon.ico</a>, referer: <a href=3D"https://play.lvu/favicon.i=
co" rel=3D"noreferrer" target=3D"_blank">https://play.lvu/favicon.ico</a><b=
r>
&gt; [Thu Jan 25 15:47:43.868164 2024] [proxy:debug] [pid 5731:tid 14020065=
0737216] mod_proxy.c(1503): [remote <a href=3D"http://1.2.3.4:58139" rel=3D=
"noreferrer" target=3D"_blank">1.2.3.4:58139</a>] AH01143: Running scheme h=
ttps handler (attemp<br>
&gt; t 0), referer: <a href=3D"https://play.lvu/favicon.ico" rel=3D"norefer=
rer" target=3D"_blank">https://play.lvu/favicon.ico</a><br>
&gt; [Thu Jan 25 15:47:43.868198 2024] [proxy_fcgi:debug] [pid 5731:tid 140=
200650737216] mod_proxy_fcgi.c(1054): [remote <a href=3D"http://1.2.3.4:581=
39" rel=3D"noreferrer" target=3D"_blank">1.2.3.4:58139</a>] AH01076: url: <=
a href=3D"https://play-lvu-205" rel=3D"noreferrer" target=3D"_blank">https:=
//play-lvu-205</a><br>
&gt; <a href=3D"http://102675.ap-south-1.elb.amazonaws.com/favicon.ico" rel=
=3D"noreferrer" target=3D"_blank">102675.ap-south-1.elb.amazonaws.com/favic=
on.ico</a> proxyname: (null) proxyport: 0, referer: <a href=3D"https://play=
.lvu/favicon.ico" rel=3D"noreferrer" target=3D"_blank">https://play.lvu/fav=
icon.ico</a><br>
&gt; [Thu Jan 25 15:47:43.868223 2024] [proxy_fcgi:debug] [pid 5731:tid 140=
200650737216] mod_proxy_fcgi.c(1059): [remote <a href=3D"http://1.2.3.4:581=
39" rel=3D"noreferrer" target=3D"_blank">1.2.3.4:58139</a>] AH01077: declin=
ing URL <a href=3D"https://play" rel=3D"noreferrer" target=3D"_blank">https=
://play</a><br>
&gt; -<a href=3D"http://lvu-205133111.ap-south-1.elb.amazonaws.com/favicon.=
ico" rel=3D"noreferrer" target=3D"_blank">lvu-205133111.ap-south-1.elb.amaz=
onaws.com/favicon.ico</a>, referer: <a href=3D"https://play.lvu/favicon.ico=
" rel=3D"noreferrer" target=3D"_blank">https://play.lvu/favicon.ico</a><br>
&gt; [Thu Jan 25 15:47:43.868248 2024] [proxy:debug] [pid 5731:tid 14020065=
0737216] proxy_util.c(2531): AH00942: https: has acquired connection for (p=
lay-lvu-205133111.ap-south<br>
&gt; -<a href=3D"http://1.elb.amazonaws.com" rel=3D"noreferrer" target=3D"_=
blank">1.elb.amazonaws.com</a>)<br>
&gt; [Thu Jan 25 15:47:43.868273 2024] [proxy:debug] [pid 5731:tid 14020065=
0737216] proxy_util.c(2587): [remote <a href=3D"http://1.2.3.4:58139" rel=
=3D"noreferrer" target=3D"_blank">1.2.3.4:58139</a>] AH00944: connecting <a=
 href=3D"https://play-lvu-205102" rel=3D"noreferrer" target=3D"_blank">http=
s://play-lvu-205102</a><br>
&gt; <a href=3D"http://675.ap-south-1.elb.amazonaws.com/favicon.ico" rel=3D=
"noreferrer" target=3D"_blank">675.ap-south-1.elb.amazonaws.com/favicon.ico=
</a> to <a href=3D"http://play-lvu-205133111.ap-south-1.elb.amazonaws.com:4=
43" rel=3D"noreferrer" target=3D"_blank">play-lvu-205133111.ap-south-1.elb.=
amazonaws.com:443</a>, referer: <a href=3D"https://play.lvu/favicon.ico" re=
l=3D"noreferrer" target=3D"_blank">https://play.lvu/favicon.ico</a><br>
&gt; [Thu Jan 25 15:47:43.868630 2024] [proxy:debug] [pid 5731:tid 14020065=
0737216] proxy_util.c(2810): [remote <a href=3D"http://1.2.3.4:58139" rel=
=3D"noreferrer" target=3D"_blank">1.2.3.4:58139</a>] AH00947: connected /fa=
vicon.ico to play-lvu<br>
&gt; -<a href=3D"http://205133111.ap-south-1.elb.amazonaws.com:443" rel=3D"=
noreferrer" target=3D"_blank">205133111.ap-south-1.elb.amazonaws.com:443</a=
>, referer: <a href=3D"https://play.lvu/favicon.ico" rel=3D"noreferrer" tar=
get=3D"_blank">https://play.lvu/favicon.ico</a><br>
&gt; [Thu Jan 25 15:47:43.868704 2024] [proxy:trace2] [pid 5731:tid 1402006=
50737216] proxy_util.c(3244): https: fam 2 socket created to connect to pla=
y-lvu-205133111.ap-south-1<br>
&gt; .<a href=3D"http://elb.amazonaws.com" rel=3D"noreferrer" target=3D"_bl=
ank">elb.amazonaws.com</a><br>
&gt; [Thu Jan 25 15:47:43.894557 2024] [proxy:debug] [pid 5731:tid 14020065=
0737216] proxy_util.c(3276): AH02824: https: connection established with <a=
 href=3D"http://3.109.172.68:443" rel=3D"noreferrer" target=3D"_blank">3.10=
9.172.68:443</a> (play-lvu-2<br>
&gt; <a href=3D"http://05102675.ap-south-1.elb.amazonaws.com" rel=3D"norefe=
rrer" target=3D"_blank">05102675.ap-south-1.elb.amazonaws.com</a>)<br>
&gt; [Thu Jan 25 15:47:43.894681 2024] [proxy:trace1] [pid 5731:tid 1402006=
50737216] proxy_util.c(3450): [remote <a href=3D"http://3.109.172.68:443" r=
el=3D"noreferrer" target=3D"_blank">3.109.172.68:443</a>] https: set SNI to=
 play.lvu for (play-lvu-205<br>
&gt; <a href=3D"http://102675.ap-south-1.elb.amazonaws.com" rel=3D"noreferr=
er" target=3D"_blank">102675.ap-south-1.elb.amazonaws.com</a>)<br>
&gt; [Thu Jan 25 15:47:43.894708 2024] [proxy:debug] [pid 5731:tid 14020065=
0737216] proxy_util.c(3462): AH00962: https: connection complete to <a href=
=3D"http://3.109.172.68:443" rel=3D"noreferrer" target=3D"_blank">3.109.172=
.68:443</a> (play-lvu-205102<br>
&gt; <a href=3D"http://675.ap-south-1.elb.amazonaws.com" rel=3D"noreferrer"=
 target=3D"_blank">675.ap-south-1.elb.amazonaws.com</a>)<br>
&gt; [Thu Jan 25 15:47:43.894748 2024] [qos:debug] [pid 5731:tid 1402006507=
37216] apache2/mod_qos.c(8587): mod_qos(): skip processing of outgoing conn=
ection 3.109.172.68&lt;-&gt;165.2<br>
&gt; 32.187.180<br>
&gt; [Thu Jan 25 15:47:43.894770 2024] [ssl:info] [pid 5731:tid 14020065073=
7216] [remote <a href=3D"http://3.109.172.68:443" rel=3D"noreferrer" target=
=3D"_blank">3.109.172.68:443</a>] AH01964: Connection to child 0 establishe=
d (server play.lvu:443)<br>
&gt; [Thu Jan 25 15:47:43.923819 2024] [ssl:debug] [pid 5731:tid 1402006507=
37216] ssl_engine_kernel.c(1764): [remote <a href=3D"http://3.109.172.68:44=
3" rel=3D"noreferrer" target=3D"_blank">3.109.172.68:443</a>] AH02275: Cert=
ificate Verification, depth 3<br>
&gt; , CRL checking mode: none (0) [subject: CN=3DStarfield Services Root C=
ertificate Authority - G2,O=3DStarfield Technologies\\, Inc.,L=3DScottsdale=
,ST=3DArizona,C=3DUS / issuer: OU=3DSta<br>
&gt; rfield Class 2 Certification Authority,O=3DStarfield Technologies\\, I=
nc.,C=3DUS / serial: A70E4A4C3482B77F / notbefore: Sep=C2=A0 2 00:00:00 200=
9 GMT / notafter: Jun 28 17:39:16 20<br>
&gt; 34 GMT]<br>
&gt; [Thu Jan 25 15:47:43.924033 2024] [ssl:debug] [pid 5731:tid 1402006507=
37216] ssl_engine_kernel.c(1764): [remote <a href=3D"http://3.109.172.68:44=
3" rel=3D"noreferrer" target=3D"_blank">3.109.172.68:443</a>] AH02275: Cert=
ificate Verification, depth 2<br>
&gt; , CRL checking mode: none (0) [subject: CN=3DAmazon Root CA 1,O=3DAmaz=
on,C=3DUS / issuer: CN=3DStarfield Services Root Certificate Authority - G2=
,O=3DStarfield Technologies\\, Inc.,L<br>
&gt; =3DScottsdale,ST=3DArizona,C=3DUS / serial: 067F944A2A27CDF3FAC2AE2B01=
F908EEB9C4C6 / notbefore: May 25 12:00:00 2015 GMT / notafter: Dec 31 01:00=
:00 2037 GMT]<br>
&gt; [Thu Jan 25 15:47:43.924124 2024] [ssl:debug] [pid 5731:tid 1402006507=
37216] ssl_engine_kernel.c(1764): [remote <a href=3D"http://3.109.172.68:44=
3" rel=3D"noreferrer" target=3D"_blank">3.109.172.68:443</a>] AH02275: Cert=
ificate Verification, depth 1<br>
&gt; , CRL checking mode: none (0) [subject: CN=3DAmazon RSA 2048 M01,O=3DA=
mazon,C=3DUS / issuer: CN=3DAmazon Root CA 1,O=3DAmazon,C=3DUS / serial: 07=
7312380B9D6688A33B1ED9BF9CCDA68E0E0F /<br>
&gt; notbefore: Aug 23 22:21:28 2022 GMT / notafter: Aug 23 22:21:28 2030 G=
MT]<br>
&gt; [Thu Jan 25 15:47:43.924208 2024] [ssl:debug] [pid 5731:tid 1402006507=
37216] ssl_engine_kernel.c(1764): [remote <a href=3D"http://3.109.172.68:44=
3" rel=3D"noreferrer" target=3D"_blank">3.109.172.68:443</a>] AH02275: Cert=
ificate Verification, depth 0<br>
&gt; , CRL checking mode: none (0) [subject: CN=3Dplay.lvu / issuer: CN=3DA=
mazon RSA 2048 M01,O=3DAmazon,C=3DUS / serial: 088DB8B2694138D3A4624BF0EEFF=
3856 / notbefore: Oct 11 00:00:00<br>
&gt; 2023 GMT / notafter: Nov=C2=A0 8 23:59:59 2024 GMT]<br>
&gt; [Thu Jan 25 15:47:43.924468 2024] [ssl:debug] [pid 5731:tid 1402006507=
37216] ssl_engine_kernel.c(2254): [remote <a href=3D"http://3.109.172.68:44=
3" rel=3D"noreferrer" target=3D"_blank">3.109.172.68:443</a>] AH02041: Prot=
ocol: TLSv1.3, Cipher: TLS_AE<br>
&gt; S_128_GCM_SHA256 (128/128 bits)<br>
&gt; [Thu Jan 25 15:47:43.924535 2024] [ssl:debug] [pid 5731:tid 1402006507=
37216] ssl_util_ssl.c(451): AH02412: [play.lvu:443] Cert matches for name &=
#39;play.lvu&#39; [subject: CN=3Dkl<br>
&gt; ay.lvu / issuer: CN=3DAmazon RSA 2048 M01,O=3DAmazon,C=3DUS / serial: =
088DB8B2694138D3A4624BF0EEFF3856 / notbefore: Oct 11 00:00:00 2023 GMT / no=
tafter: Nov=C2=A0 8 23:59:59 2024 GMT<br>
&gt; ]<br>
&gt; [Thu Jan 25 15:47:43.959108 2024] [proxy:debug] [pid 5731:tid 14020065=
0737216] proxy_util.c(2546): AH00943: https: has released connection for (p=
lay-lvu-205133111.ap-south<br>
&gt; -<a href=3D"http://1.elb.amazonaws.com" rel=3D"noreferrer" target=3D"_=
blank">1.elb.amazonaws.com</a>)<br>
&gt; [Thu Jan 25 15:47:43.959261 2024] [ssl:debug] [pid 5731:tid 1402006507=
37216] ssl_engine_io.c(1147): [remote <a href=3D"http://3.109.172.68:443" r=
el=3D"noreferrer" target=3D"_blank">3.109.172.68:443</a>] AH02001: Connecti=
on closed to child 0 with sta<br>
&gt; ndard shutdown (server play.lvu:443)<br>
&gt; [Thu Jan 25 15:47:43.959361 2024] [proxy:debug] [pid 5731:tid 14020065=
0737216] proxy_util.c(3386): [remote <a href=3D"http://3.109.172.68:443" re=
l=3D"noreferrer" target=3D"_blank">3.109.172.68:443</a>] AH02642: proxy: co=
nnection shutdown<br>
&gt; [Thu Jan 25 15:47:48.965114 2024] [ssl:debug] [pid 5731:tid 1401994765=
90144] ssl_engine_io.c(1147): [client <a href=3D"http://1.2.3.4:58139" rel=
=3D"noreferrer" target=3D"_blank">1.2.3.4:58139</a>] AH02001: Connection cl=
osed to child 16 with<br>
&gt;=C2=A0 standard shutdown (server play.lvu:443)<br>
&gt;=C2=A0 <br>
&gt;=C2=A0 <br>
&gt; <br>
&gt; =E2=96=B8<br>
<br>
<br>
&gt; _______________________________________________<br>
&gt; mod-security-users mailing list<br>
&gt; <a href=3D"mailto:[email protected]" target=3D"=
_blank">[email protected]</a><br>
&gt; <a href=3D"https://lists.sourceforge.net/lists/listinfo/mod-security-u=
sers" rel=3D"noreferrer" target=3D"_blank">https://lists.sourceforge.net/li=
sts/listinfo/mod-security-users</a><br>
&gt; Commercial ModSecurity Rules and Support from Trustwave&#39;s SpiderLa=
bs:<br>
&gt; <a href=3D"http://www.modsecurity.org/projects/commercial/rules/" rel=
=3D"noreferrer" target=3D"_blank">http://www.modsecurity.org/projects/comme=
rcial/rules/</a><br>
&gt; <a href=3D"http://www.modsecurity.org/projects/commercial/support/" re=
l=3D"noreferrer" target=3D"_blank">http://www.modsecurity.org/projects/comm=
ercial/support/</a><br>
<br>
<br>
<br>
_______________________________________________<br>
mod-security-users mailing list<br>
<a href=3D"mailto:[email protected]" target=3D"_blan=
k">[email protected]</a><br>
<a href=3D"https://lists.sourceforge.net/lists/listinfo/mod-security-users"=
 rel=3D"noreferrer" target=3D"_blank">https://lists.sourceforge.net/lists/l=
istinfo/mod-security-users</a><br>
Commercial ModSecurity Rules and Support from Trustwave&#39;s SpiderLabs:<b=
r>
<a href=3D"http://www.modsecurity.org/projects/commercial/rules/" rel=3D"no=
referrer" target=3D"_blank">http://www.modsecurity.org/projects/commercial/=
rules/</a><br>
<a href=3D"http://www.modsecurity.org/projects/commercial/support/" rel=3D"=
noreferrer" target=3D"_blank">http://www.modsecurity.org/projects/commercia=
l/support/</a><br>
</blockquote></div>

--0000000000005dffc3061072e8f9--


--===============0942815976356913832==
Content-Type: text/plain; charset="us-ascii"
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
Content-Disposition: inline


--===============0942815976356913832==
Content-Type: text/plain; charset="us-ascii"
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
Content-Disposition: inline

_______________________________________________
mod-security-users mailing list
[email protected]
https://lists.sourceforge.net/lists/listinfo/mod-security-users
Commercial ModSecurity Rules and Support from Trustwave's SpiderLabs:
http://www.modsecurity.org/projects/commercial/rules/
http://www.modsecurity.org/projects/commercial/support/

--===============0942815976356913832==--