Compare commits

4 Commits

Author SHA1 Message Date
9bf4ffad38 fix badges 2026-07-27 08:19:21 -06:00
e6befea75e fixup 2026-07-20 21:42:12 -06:00
3a781a129a unoobify 2026-07-19 21:38:00 -06:00
2769994edd new banners 2026-07-19 21:19:51 -06:00
3 changed files with 124 additions and 84 deletions

Binary file not shown.

After

Width:  |  Height:  |  Size: 4.9 KiB

View File

@@ -4,10 +4,11 @@
<title>rawley.xyz</title> <title>rawley.xyz</title>
<meta charset="UTF-8"> <meta charset="UTF-8">
<meta name="description" value="Rawley Fowler's personal website, about Perl, Emacs and Software in General."> <meta name="description" value="Rawley Fowler's personal website, about Perl, Emacs and Software in General.">
<meta name="keywords" value="Rawley Fowler rawley.xyz emacs netbsd functional clojure perl software architecture bugs fixing maker">
<link rel="stylesheet" href="index.css"> <link rel="stylesheet" href="index.css">
</head> </head>
<body> <body>
<div> <div class="blerb">
<p> <p>
Hi, I'm Rawley. I'm a full-time Husband, Dad, Emacs evangelist and Perl aficionado. Hi, I'm Rawley. I'm a full-time Husband, Dad, Emacs evangelist and Perl aficionado.
</p> </p>
@@ -60,6 +61,7 @@
</li> </li>
</ul> </ul>
<h2>Noteworthy Projects</h2> <h2>Noteworthy Projects</h2>
<div class="projects">
<ul> <ul>
<li> <li>
<a href="https://github.com/mollusc-labs/slapbird">SlapbirdAPM</a> <a href="https://github.com/mollusc-labs/slapbird">SlapbirdAPM</a>
@@ -71,13 +73,19 @@
<a href="https://github.com/rawleyfowler/mojolicious-Plugin-IsBot">Mojolicious::Plugin::IsBot</a> <a href="https://github.com/rawleyfowler/mojolicious-Plugin-IsBot">Mojolicious::Plugin::IsBot</a>
</li> </li>
</ul> </ul>
<br /> </div>
<div> <div class="cards">
<a href="http://www.gnu.org/software/emacs"> <a href="http://www.gnu.org/software/emacs">
<img src="/assets/gnu_emacs.png"/> <img src="/assets/gnu_emacs.png" width="88" height="31"/>
</a> </a>
<a href="https://openbsd.org"> <a href="http://www.gnu.org/software/emacs">
<img src="/assets/openbsd.gif" style="width: 120px; height 80px" /> <img src="/assets/made_with_emacs.png" width="88" height="31"/>
</a>
<a href="https://netbsd.org">
<img src="/assets/powered_by_netbsd.png" width="88" height="31"/>
</a>
<a href="#">
<img src="/assets/no_bad_hair_days.png" width="88" height="31"/>
</a> </a>
</div> </div>
<h2>Disclaimer</h2> <h2>Disclaimer</h2>

View File

@@ -0,0 +1,32 @@
<!DOCTYPE html>
<html>
<head>
<title>Fix Apache 421 SNI Errors Behind AWS ALB</title>
<meta content="Description of post" name="description">
<meta name="robots">
<meta content="keywords" name="Apache SNI Fix 421">
<meta content="description" name="How to fix the Apache SNI issues (421 misdirected) behind AWS ALB">
<meta charset="utf-8" content="utf-8" name="charset">
<link href="/index.css" rel="stylesheet">
</head>
<body>
<a href="/">&lt;&lt; back</a>
<h1>Fixing Apache SNI 421 Errors Behind AWS ALB</h1>
<h2>Understanding the Problem</h2>
<p>
SNI (Server Name Indicator) is a flag set in the "Client Hello" of a TLS request. It tells the server what domain you want,
without having to decrypt the request later to get the <code>Host</code> header, or whatever else you might be using to route traffic with.
Apache uses SNI to figure out what cert to use to decrypt the request. When SNI is missing, or Apache can't find a VHost associated
with the domain in the SNI, it will route to the default VHost for decryption and request handling. This is now the default behaviour in 2.4.64 and up,
it was applied to fix CVE-2025-23048. Note this is a good change, and means that Apache will reject potentially dangerous requests where SNI isn't the same as the Host header.
</p>
<h2>Solution</h2>
<p>
If you're using HTTPS on your Apache, behind an AWS ALB, you're going to run into this issue, because AWS ALB's seemingly don't set SNI at all.
The solution is to tell Apache to relax its policy, and allow the default VHost to decrypt the message,
and then route on the Host header to the next VHost (I think this is how it works, I could be wrong).
You can do this with the <code>SSLVHostSNIPolicy</code> directive, setting it to <code>authonly</code> will
return the pre 2.4.64 functionality, however it supposedly only works on 2.4.65, so you may have to skip 2.4.64.
</p>
</body>
</html>