Ivan Ristic wrote:
>
> Thanks for pointing out the content of the "Location" header. You are right
> in that the content is truncated but it's not ModSecurity or Apache that's
> doing it. It is received that way so it's probably the client that is sending
> it. There appears to be a limit of 432 bytes (imposed by the client).
FYI, we've come to a conclusion that Siteminder, which works as an Apache
module, does something to change the URI so that it is different from the URI
received in the request. We've left it at that.
--
Ivan Ristic, Technical Director
Thinking Stone, http://www.thinkingstone.com
ModSecurity: Open source Web Application Firewall
Apache Security (O'Reilly): http://www.apachesecurity.net
|