Re: Interests in mod_security support ?
Hi Gwenn,
Thanks for your interest in this work. We're targeting apache support first. If there is interest in nginx support, then we can share efforts for such support. In the long term, a route services integration will probably make sense, especially when direct routing to containers will lower the latency impact. Regarding rules updates, we're leveraging the default OWASP rules <https://www.owasp.org/index.php/Category:OWASP_ModSecurity_Core_Rule_Set_Project> (from https://github.com/SpiderLabs/owasp-modsecurity-crs/tree/master/base_rules) it's likely that we'll cascade upstream changes into our fork, and automate this in our ci work. Regards, Guillaume. Guillaume. On Fri, Jun 3, 2016 at 3:04 AM, Gwenn Etourneau <getourneau(a)pivotal.io> wrote: Guillaume,
|
|