Profile cover photo
Profile photo
Chris Wadge
56 followers -
Open source enthusiast, security and performance guy
Open source enthusiast, security and performance guy

56 followers
About
Posts

Hiawatha 10.8.3 Now Available!

Changes since 10.8.2:

• Several fixes in build system
• mbed TLS updated to 2.13.0
• Added build system for nghttp2

Debian packages are available directly: https://files.tuxhelp.org/hiawatha/ or via apt: https://mirror.tuxhelp.org/debian/
Add a comment...

Hiawatha Webserver packages for Debian have been updated to include Mbed TLS 2.11.0.

Direct download: https://files.tuxhelp.org/hiawatha/
Apt repository: https://mirror.tuxhelp.org/debian/

Note that this will be the final release to support Wheezy, as its LTS support has expired.
Add a comment...

Updated Hiawatha 10.8.1-1 Debian packages with Mbed TLS 2.9.0 (https://tls.mbed.org/tech-updates/releases/mbedtls-2.9.0-2.7.3-and-2.1.12-released) are built, tested and available in the usual places:

https://files.tuxhelp.org/hiawatha/ (direct download)
https://mirror.tuxhelp.org/debian/ (apt repository)
Add a comment...

Post has attachment
Hiawatha 10.8.1 is live

Changelog:

• mbed TLS updated to 2.8.0.
• Removed support for secp192r1 and secp192k1 curves, to make it PCI DSS compliant out of the box.
• Small improvements to Let's Encrypt ACMEv2 script.
Add a comment...

Post has attachment

Post has attachment
Hiawatha 10.8 is live

Changelog:

• New Let's Encrypt script that supports ACME v2.
• Added Syslog option.
• Added GZipExtensions option.
• AllowDotFiles now used to show hidden files in directory listings.
• mbed TLS updated to 2.7.0.
• Removed support for static RSA ciphers.
• Hiawatha log format changed.
• Small improvements.
• Bugfix: certain characters in filenames disrupted directory index output.
• Bugfix: requesting non-regular files now results in a 403 instead of blocking that thread.
Add a comment...

Post has attachment
Hiawatha 10.8-rc1 is now available for testing

• New Let's Encrypt script that supports ACME v2.
• Added Syslog option, makes Hiawatha log to Syslog.
• Added GZipExtensions option.
• Hiawatha uses AllowDotFiles to show hidden files in directory listings.
• mbed TLS updated to 2.7.0.
• Hiawatha log format changed.
• Small improvements.
• Bugfix: certain characters in filenames disrupted directory index output.
• Bugfix: requesting non-regular files now results in a 403 instead of
blocking that thread.

It's also worth noting that TLS_RSA_<etc.> suites without Diffie-Hellman or elliptic curve DH exchanges are considered obsolete, and therefore disabled at build time in this and all future versions.
Add a comment...

Post has attachment
Add a comment...

Post has attachment
Add a comment...

Post has attachment
I should probably take my home fileserver down for a good dusting more often.
Photo
Add a comment...
Wait while more posts are being loaded