Apache 2.4 Security Features for new version
The ISC and Apache highlight security features in the latest release
Apache 2.4 Security Features for new version
http://isc.sans.edu/diary.html?storyid=12643
http://httpd.apache.org/docs/2.4/new_features_2_4.html
QUOTE: The Apache Foundation released version 2.4.1 of its popular web server, including a number of interesting changes. Among the features, I would like to highlight some of the security relevant changes:
- More granular logging
- Various changes to timeouts
- Changes to the proxy configuration
- Apache now includes a "mod_session" that will have Apache take care of sessions
- Mod_ssl has been improved to allow it to check for invalid client certificates via OCSP.