Commit 02c6d0a3 authored by Justin Erenkrantz's avatar Justin Erenkrantz
Browse files

Change mod_ssl from using ssl_log() to ap_log_error().

The issue is that ssl_log doesn't handle apr_status_t result codes.  This
leads to a number of places (esp. with mutexes) where the error codes get
lost.  Rather than extending ssl_log further, since mod_ssl is part of
our core, migrate to ap_log_error.  This means that mod_ssl no longer
does its own logging.

Most uses of SSL_ADD_ERRNO are now mapped correctly to apr_status_t values
(mainly because the APIs that used to return errnos are now APRized and
have apr_status_t codes available).

SSL_LOG_TRACE and SSL_LOG_DEBUG were mapped to the APLOG_DEBUG values.
mod_ssl prints out a LOT of debugging information, so mod_ssl with LogLevel
Debug may not be a good idea - perhaps mod_ssl should be less chatty.

Numerous printf type collisions were also resolved.

(The ssl logging code itself will be removed in a subsequent commit.)

This has been discussed on dev@httpd, but the fact that there isn't
much to review besides the mindless changes, I'm going to commit now
and rely on CTR if I screwed up anything on the translation.


git-svn-id: https://svn.apache.org/repos/asf/httpd/httpd/trunk/modules/ssl@95127 13f79535-47bb-0310-9956-ffa450edef68
parent 8419b0df
Loading
Loading
Loading
Loading
+26 −20
Changes for mod_ssl.c: 26 added lines, 20 removed lines.
Original line number Diff line number Diff line
@@ -244,7 +244,7 @@ int ssl_proxy_enable(conn_rec *c)
    SSLConnRec *sslconn = ssl_init_connection_ctx(c);

    if (!sc->proxy_enabled) {
        ssl_log(c->base_server, SSL_LOG_ERROR,
        ap_log_error(APLOG_MARK, APLOG_ERR|APLOG_NOERRNO, 0, c->base_server,
                     "SSL Proxy requested for %s but not enabled "
                     "[Hint: SSLProxyEngine]", sc->vhost_id);

@@ -309,8 +309,8 @@ static int ssl_hook_pre_connection(conn_rec *c, void *csd)
     * later access inside callback functions
     */

    ssl_log(c->base_server, SSL_LOG_INFO,
            "Connection to child %d established "
    ap_log_error(APLOG_MARK, APLOG_INFO|APLOG_NOERRNO, 0, c->base_server,
                 "Connection to child %ld established "
                 "(server %s, client %s)", c->id, sc->vhost_id, 
                 c->remote_ip ? c->remote_ip : "unknown");

@@ -327,8 +327,9 @@ static int ssl_hook_pre_connection(conn_rec *c, void *csd)
     * so we can detach later.
     */
    if (!(ssl = SSL_new(mctx->ssl_ctx))) {
        ssl_log(c->base_server, SSL_LOG_ERROR,
                "Unable to create a new SSL connection from the SSL context");
        ap_log_error(APLOG_MARK, APLOG_ERR|APLOG_NOERRNO, 0, c->base_server,
                     "Unable to create a new SSL connection from the SSL "
                     "context");
        ssl_log_ssl_error(APLOG_MARK, APLOG_ERR, c->base_server);

        c->aborted = 1;
@@ -341,7 +342,7 @@ static int ssl_hook_pre_connection(conn_rec *c, void *csd)
    if (!SSL_set_session_id_context(ssl, (unsigned char *)vhost_md5,
                                    MD5_DIGESTSIZE*2))
    {
        ssl_log(c->base_server, SSL_LOG_ERROR,
        ap_log_error(APLOG_MARK, APLOG_ERR|APLOG_NOERRNO, 0, c->base_server,
                     "Unable to set session id context to `%s'", vhost_md5);
        ssl_log_ssl_error(APLOG_MARK, APLOG_ERR, c->base_server);

@@ -409,8 +410,8 @@ int ssl_hook_process_connection(SSLFilterRec *filter)
    if (!SSL_is_init_finished(filter->pssl)) {
        if (sslconn->is_proxy) {
            if ((n = SSL_connect(filter->pssl)) <= 0) {
                ssl_log(c->base_server,
                        SSL_LOG_ERROR|SSL_ADD_ERRNO,
                ap_log_error(APLOG_MARK, APLOG_ERR|APLOG_NOERRNO, 0,
                             c->base_server,
                             "SSL Proxy connect failed");
                ssl_log_ssl_error(APLOG_MARK, APLOG_ERR, c->base_server);
                return ssl_abort(filter, c);
@@ -428,7 +429,8 @@ int ssl_hook_process_connection(SSLFilterRec *filter)
                 * was transferred. That's not a real error and can occur
                 * sporadically with some clients.
                 */
                ssl_log(c->base_server, SSL_LOG_INFO,
                ap_log_error(APLOG_MARK, APLOG_INFO|APLOG_NOERRNO, 0,
                             c->base_server,
                             "SSL handshake stopped: connection was closed");
            }
            else if (err == SSL_ERROR_WANT_READ) {
@@ -452,17 +454,18 @@ int ssl_hook_process_connection(SSLFilterRec *filter)
                     (errno != EINTR))
            {
                if (errno > 0) {
                    ssl_log(c->base_server,
                            SSL_LOG_ERROR|SSL_ADD_ERRNO,
                    ap_log_error(APLOG_MARK, APLOG_ERR|APLOG_NOERRNO, 0,
                                 c->base_server,
                                 "SSL handshake interrupted by system "
                                 "[Hint: Stop button pressed in browser?!]");
                    ssl_log_ssl_error(APLOG_MARK, APLOG_ERR, c->base_server);
                }
                else {
                    ssl_log(c->base_server,
                            SSL_LOG_INFO|SSL_ADD_ERRNO,
                    ap_log_error(APLOG_MARK, APLOG_ERR|APLOG_NOERRNO, 0, 
                                 c->base_server,
                                 "Spurious SSL handshake interrupt [Hint: "
                            "Usually just one of those OpenSSL confusions!?]");
                                 "Usually just one of those OpenSSL "
                                 "confusions!?]");
                    ssl_log_ssl_error(APLOG_MARK, APLOG_INFO, c->base_server);
                }
            }
@@ -470,8 +473,8 @@ int ssl_hook_process_connection(SSLFilterRec *filter)
                /*
                 * Ok, anything else is a fatal error
                 */
                ssl_log(c->base_server,
                        SSL_LOG_ERROR|SSL_ADD_ERRNO,
                ap_log_error(APLOG_MARK, APLOG_ERR|APLOG_NOERRNO, 0, 
                             c->base_server,
                             "SSL handshake failed (server %s, client %s)",
                             ssl_util_vhostid(c->pool, c->base_server),
                             c->remote_ip ? c->remote_ip : "unknown");
@@ -500,10 +503,12 @@ int ssl_hook_process_connection(SSLFilterRec *filter)
                 * optional_no_ca doesn't appear to work as advertised
                 * in 1.x
                 */
                ssl_log(c->base_server, SSL_LOG_ERROR,
                ap_log_error(APLOG_MARK, APLOG_ERR|APLOG_NOERRNO, 0,
                             c->base_server,
                             "SSL client authentication failed, "
                             "accepting certificate based on "
                        "\"SSLVerifyClient optional_no_ca\" configuration");
                             "\"SSLVerifyClient optional_no_ca\" "
                             "configuration");
                ssl_log_ssl_error(APLOG_MARK, APLOG_ERR, c->base_server);
            }
            else {
@@ -511,7 +516,8 @@ int ssl_hook_process_connection(SSLFilterRec *filter)
                    sslconn->verify_error :
                    X509_verify_cert_error_string(verify_result);

                ssl_log(c->base_server, SSL_LOG_ERROR,
                ap_log_error(APLOG_MARK, APLOG_ERR|APLOG_NOERRNO, 0,
                             c->base_server,
                             "SSL client authentication failed: %s",
                             error ? error : "unknown");
                ssl_log_ssl_error(APLOG_MARK, APLOG_ERR, c->base_server);
@@ -535,7 +541,7 @@ int ssl_hook_process_connection(SSLFilterRec *filter)
        if ((sc->server->auth.verify_mode == SSL_CVERIFY_REQUIRE) &&
            !sslconn->client_cert)
        {
            ssl_log(c->base_server, SSL_LOG_ERROR,
            ap_log_error(APLOG_MARK, APLOG_ERR|APLOG_NOERRNO, 0, c->base_server,
                         "No acceptable peer certificate available");

            return ssl_abort(filter, c);
+54 −50
Changes for ssl_engine_init.c: 54 added lines, 50 removed lines.
Original line number Diff line number Diff line
@@ -98,7 +98,7 @@ static void ssl_add_version_components(apr_pool_t *p,
                                            version_components[i]);
    }

    ssl_log(s, SSL_LOG_INFO,
    ap_log_error(APLOG_MARK, APLOG_INFO|APLOG_NOERRNO, 0, s,
                 "Server: %s, Interface: %s, Library: %s",
                 AP_SERVER_BASEVERSION,
                 vals[1],  /* SSL_VERSION_INTERFACE */
@@ -111,7 +111,7 @@ static void ssl_add_version_components(apr_pool_t *p,
 */
static void ssl_init_SSLLibrary(server_rec *s)
{
    ssl_log(s, SSL_LOG_INFO,
    ap_log_error(APLOG_MARK, APLOG_INFO|APLOG_NOERRNO, 0, s,
                 "Init: Initializing %s library", SSL_LIBRARY_NAME);

    CRYPTO_malloc_init();
@@ -149,7 +149,7 @@ static void ssl_tmp_key_init_rsa(server_rec *s,
    if (!(mc->pTmpKeys[idx] =
          RSA_generate_key(bits, RSA_F4, NULL, NULL)))
    {
        ssl_log(s, SSL_LOG_ERROR,
        ap_log_error(APLOG_MARK, APLOG_ERR|APLOG_NOERRNO, 0, s,
                     "Init: Failed to generate temporary "
                     "%d bit RSA private key", bits);
        ssl_die();
@@ -165,7 +165,7 @@ static void ssl_tmp_key_init_dh(server_rec *s,
    if (!(mc->pTmpKeys[idx] =
          ssl_dh_GetTmpParam(bits)))
    {
        ssl_log(s, SSL_LOG_ERROR,
        ap_log_error(APLOG_MARK, APLOG_ERR|APLOG_NOERRNO, 0, s,
                     "Init: Failed to generate temporary "
                     "%d bit DH parameters", bits);
        ssl_die();
@@ -180,13 +180,13 @@ static void ssl_tmp_key_init_dh(server_rec *s,

static void ssl_tmp_keys_init(server_rec *s)
{
    ssl_log(s, SSL_LOG_INFO,
    ap_log_error(APLOG_MARK, APLOG_INFO|APLOG_NOERRNO, 0, s,
                 "Init: Generating temporary RSA private keys (512/1024 bits)");

    MODSSL_TMP_KEY_INIT_RSA(s, 512);
    MODSSL_TMP_KEY_INIT_RSA(s, 1024);

    ssl_log(s, SSL_LOG_INFO,
    ap_log_error(APLOG_MARK, APLOG_INFO|APLOG_NOERRNO, 0, s,
                 "Init: Generating temporary DH parameters (512/1024 bits)");

    MODSSL_TMP_KEY_INIT_DH(s, 512);
@@ -304,7 +304,7 @@ int ssl_init_Module(apr_pool_t *p, apr_pool_t *plog,
    /*
     *  initialize servers
     */
    ssl_log(base_server, SSL_LOG_INFO,
    ap_log_error(APLOG_MARK, APLOG_INFO|APLOG_NOERRNO, 0, base_server,
                 "Init: Initializing (virtual) servers for SSL");

    for (s = base_server; s; s = s->next) {
@@ -349,7 +349,7 @@ void ssl_init_Engine(server_rec *s, apr_pool_t *p)

    if (mc->szCryptoDevice) {
        if (!(e = ENGINE_by_id(mc->szCryptoDevice))) {
            ssl_log(s, SSL_LOG_ERROR,
            ap_log_error(APLOG_MARK, APLOG_ERR|APLOG_NOERRNO, 0, s,
                         "Init: Failed to load Crypto Device API `%s'",
                         mc->szCryptoDevice);
            ssl_die();
@@ -360,7 +360,7 @@ void ssl_init_Engine(server_rec *s, apr_pool_t *p)
        }

        if (!ENGINE_set_default(e, ENGINE_METHOD_ALL)) {
            ssl_log(s, SSL_LOG_ERROR,
            ap_log_error(APLOG_MARK, APLOG_ERR|APLOG_NOERRNO, 0, s,
                         "Init: Failed to enable Crypto Device API `%s'",
                         mc->szCryptoDevice);
            ssl_die();
@@ -381,7 +381,7 @@ static void ssl_init_server_check(server_rec *s,
     * possibility that the user forgot to set them.
     */
    if (!mctx->pks->cert_files[0]) {
        ssl_log(s, SSL_LOG_ERROR|SSL_INIT,
        ap_log_error(APLOG_MARK, APLOG_ERR|APLOG_NOERRNO, 0, s,
                "No SSL Certificate set [hint: SSLCertificateFile]");
        ssl_die();
    }
@@ -392,7 +392,7 @@ static void ssl_init_server_check(server_rec *s,
    if (mctx->pks->certs[SSL_AIDX_RSA] ||
        mctx->pks->certs[SSL_AIDX_DSA])
    {
        ssl_log(s, SSL_LOG_ERROR|SSL_INIT,
        ap_log_error(APLOG_MARK, APLOG_ERR|APLOG_NOERRNO, 0, s,
                "Illegal attempt to re-initialise SSL for server "
                "(theoretically shouldn't happen!)");
        ssl_die();
@@ -413,7 +413,7 @@ static void ssl_init_ctx_protocol(server_rec *s,
     *  Create the new per-server SSL context
     */
    if (protocol == SSL_PROTOCOL_NONE) {
        ssl_log(s, SSL_LOG_ERROR|SSL_INIT,
        ap_log_error(APLOG_MARK, APLOG_ERR|APLOG_NOERRNO, 0, s,
                "No SSL protocols available [hint: SSLProtocol]");
        ssl_die();
    }
@@ -425,7 +425,7 @@ static void ssl_init_ctx_protocol(server_rec *s,
                     NULL);
    cp[strlen(cp)-2] = NUL;

    ssl_log(s, SSL_LOG_TRACE|SSL_INIT,
    ap_log_error(APLOG_MARK, APLOG_DEBUG|APLOG_NOERRNO, 0, s,
                 "Creating new SSL context (protocols: %s)", cp);

    if (protocol == SSL_PROTOCOL_SSLV2) {
@@ -542,14 +542,14 @@ static void ssl_init_ctx_verify(server_rec *s,
     * Configure Client Authentication details
     */
    if (mctx->auth.ca_cert_file || mctx->auth.ca_cert_path) {
        ssl_log(s, SSL_LOG_TRACE|SSL_INIT,
        ap_log_error(APLOG_MARK, APLOG_DEBUG|APLOG_NOERRNO, 0, s,
                     "Configuring client authentication");

        if (!SSL_CTX_load_verify_locations(ctx,
                                           mctx->auth.ca_cert_file,
                                           mctx->auth.ca_cert_path))
        {
            ssl_log(s, SSL_LOG_ERROR|SSL_INIT,
            ap_log_error(APLOG_MARK, APLOG_ERR|APLOG_NOERRNO, 0, s,
                    "Unable to configure verify locations "
                    "for client authentication");
            ssl_log_ssl_error(APLOG_MARK, APLOG_ERR, s);
@@ -560,7 +560,7 @@ static void ssl_init_ctx_verify(server_rec *s,
                                      mctx->auth.ca_cert_file,
                                      mctx->auth.ca_cert_path);
        if (!ca_list) {
            ssl_log(s, SSL_LOG_ERROR|SSL_INIT,
            ap_log_error(APLOG_MARK, APLOG_ERR|APLOG_NOERRNO, 0, s,
                    "Unable to determine list of available "
                    "CA certificates for client authentication");
            ssl_die();
@@ -577,10 +577,10 @@ static void ssl_init_ctx_verify(server_rec *s,
        ca_list = (STACK_OF(X509_NAME) *)SSL_CTX_get_client_CA_list(ctx);

        if (sk_X509_NAME_num(ca_list) == 0) {
            ssl_log(s, SSL_LOG_WARN,
                    "Init: Oops, you want to request client authentication, "
                    "but no CAs are known for verification!? "
                    "[Hint: SSLCACertificate*]");
            ap_log_error(APLOG_MARK, APLOG_WARNING|APLOG_NOERRNO, 0, s,
                         "Init: Oops, you want to request client "
                         "authentication, but no CAs are known for "
                         "verification!?  [Hint: SSLCACertificate*]");
        }
    }
}
@@ -600,12 +600,12 @@ static void ssl_init_ctx_cipher_suite(server_rec *s,
        return;
    }

    ssl_log(s, SSL_LOG_TRACE|SSL_INIT,
    ap_log_error(APLOG_MARK, APLOG_DEBUG|APLOG_NOERRNO, 0, s,
                 "Configuring permitted SSL ciphers [%s]", 
                 suite);

    if (!SSL_CTX_set_cipher_list(ctx, suite)) {
        ssl_log(s, SSL_LOG_ERROR|SSL_INIT,
        ap_log_error(APLOG_MARK, APLOG_ERR|APLOG_NOERRNO, 0, s,
                "Unable to configure permitted SSL ciphers");
        ssl_log_ssl_error(APLOG_MARK, APLOG_ERR, s);
        ssl_die();
@@ -625,7 +625,7 @@ static void ssl_init_ctx_crl(server_rec *s,
        return;
    }

    ssl_log(s, SSL_LOG_TRACE|SSL_INIT,
    ap_log_error(APLOG_MARK, APLOG_DEBUG|APLOG_NOERRNO, 0, s,
                 "Configuring certificate revocation facility");

    mctx->crl =
@@ -633,7 +633,7 @@ static void ssl_init_ctx_crl(server_rec *s,
                              (char *)mctx->crl_path);

    if (!mctx->crl) {
        ssl_log(s, SSL_LOG_ERROR|SSL_INIT,
        ap_log_error(APLOG_MARK, APLOG_ERR|APLOG_NOERRNO, 0, s,
                "Unable to configure X.509 CRL storage "
                "for certificate revocation");
        ssl_log_ssl_error(APLOG_MARK, APLOG_ERR, s);
@@ -679,12 +679,12 @@ static void ssl_init_ctx_cert_chain(server_rec *s,
                                      (char *)chain, 
                                      skip_first, NULL);
    if (n < 0) {
        ssl_log(s, SSL_LOG_ERROR|SSL_INIT,
        ap_log_error(APLOG_MARK, APLOG_ERR|APLOG_NOERRNO, 0, s,
                "Failed to configure CA certificate chain!");
        ssl_die();
    }

    ssl_log(s, SSL_LOG_TRACE|SSL_INIT,
    ap_log_error(APLOG_MARK, APLOG_DEBUG|APLOG_NOERRNO, 0, s,
                 "Configuring server certificate chain "
                 "(%d CA certificate%s)",
                 n, n == 1 ? "" : "s");
@@ -728,19 +728,19 @@ static int ssl_server_import_cert(server_rec *s,
        return FALSE;
    }

    ssl_log(s, SSL_LOG_TRACE|SSL_INIT,
    ap_log_error(APLOG_MARK, APLOG_DEBUG|APLOG_NOERRNO, 0, s,
                 "Configuring %s server certificate", type);

    ptr = asn1->cpData;
    if (!(cert = d2i_X509(NULL, &ptr, asn1->nData))) {
        ssl_log(s, SSL_LOG_ERROR|SSL_INIT,
        ap_log_error(APLOG_MARK, APLOG_ERR|APLOG_NOERRNO, 0, s,
                "Unable to import %s server certificate", type);
        ssl_log_ssl_error(APLOG_MARK, APLOG_ERR, s);
        ssl_die();
    }

    if (SSL_CTX_use_certificate(mctx->ssl_ctx, cert) <= 0) {
        ssl_log(s, SSL_LOG_ERROR|SSL_INIT,
        ap_log_error(APLOG_MARK, APLOG_ERR|APLOG_NOERRNO, 0, s,
                "Unable to configure %s server certificate", type);
        ssl_log_ssl_error(APLOG_MARK, APLOG_ERR, s);
        ssl_die();
@@ -767,20 +767,20 @@ static int ssl_server_import_key(server_rec *s,
        return FALSE;
    }

    ssl_log(s, SSL_LOG_TRACE|SSL_INIT,
    ap_log_error(APLOG_MARK, APLOG_DEBUG|APLOG_NOERRNO, 0, s,
                 "Configuring %s server private key", type);

    ptr = asn1->cpData;
    if (!(pkey = d2i_PrivateKey(pkey_type, NULL, &ptr, asn1->nData)))
    {
        ssl_log(s, SSL_LOG_ERROR|SSL_INIT,
        ap_log_error(APLOG_MARK, APLOG_ERR|APLOG_NOERRNO, 0, s,
                "Unable to import %s server private key", type);
        ssl_log_ssl_error(APLOG_MARK, APLOG_ERR, s);
        ssl_die();
    }

    if (SSL_CTX_use_PrivateKey(mctx->ssl_ctx, pkey) <= 0) {
        ssl_log(s, SSL_LOG_ERROR|SSL_INIT,
        ap_log_error(APLOG_MARK, APLOG_ERR|APLOG_NOERRNO, 0, s,
                "Unable to configure %s server private key", type);
        ssl_log_ssl_error(APLOG_MARK, APLOG_ERR, s);
        ssl_die();
@@ -795,7 +795,7 @@ static int ssl_server_import_key(server_rec *s,

        if (pubkey && EVP_PKEY_missing_parameters(pubkey)) {
            EVP_PKEY_copy_parameters(pubkey, pkey);
            ssl_log(s, SSL_LOG_ERROR|SSL_INIT,
            ap_log_error(APLOG_MARK, APLOG_ERR|APLOG_NOERRNO, 0, s,
                    "Copying DSA parameters from private key to certificate");
            ssl_log_ssl_error(APLOG_MARK, APLOG_ERR, s);
        }
@@ -823,7 +823,7 @@ static void ssl_check_public_cert(server_rec *s,
     */

    if (SSL_X509_isSGC(cert)) {
        ssl_log(s, SSL_LOG_INFO|SSL_INIT,
        ap_log_error(APLOG_MARK, APLOG_INFO|APLOG_NOERRNO, 0, s,
                     "%s server certificate enables "
                     "Server Gated Cryptography (SGC)", 
                     ssl_asn1_keystr(type));
@@ -831,14 +831,14 @@ static void ssl_check_public_cert(server_rec *s,

    if (SSL_X509_getBC(cert, &is_ca, &pathlen)) {
        if (is_ca) {
            ssl_log(s, SSL_LOG_WARN|SSL_INIT,
            ap_log_error(APLOG_MARK, APLOG_WARNING|APLOG_NOERRNO, 0, s,
                         "%s server certificate is a CA certificate "
                         "(BasicConstraints: CA == TRUE !?)",
                         ssl_asn1_keystr(type));
        }

        if (pathlen > 0) {
            ssl_log(s, SSL_LOG_WARN|SSL_INIT,
            ap_log_error(APLOG_MARK, APLOG_WARNING|APLOG_NOERRNO, 0, s,
                         "%s server certificate is not a leaf certificate "
                         "(BasicConstraints: pathlen == %d > 0 !?)",
                         ssl_asn1_keystr(type), pathlen);
@@ -852,13 +852,13 @@ static void ssl_check_public_cert(server_rec *s,
            (apr_fnmatch(cn, s->server_hostname,
                         fnm_flags) == FNM_NOMATCH))
        {
            ssl_log(s, SSL_LOG_WARN|SSL_INIT,
            ap_log_error(APLOG_MARK, APLOG_WARNING|APLOG_NOERRNO, 0, s,
                         "%s server certificate wildcard CommonName (CN) `%s' "
                         "does NOT match server name!?",
                         ssl_asn1_keystr(type), cn);
        }
        else if (strNE(s->server_hostname, cn)) {
            ssl_log(s, SSL_LOG_WARN|SSL_INIT,
            ap_log_error(APLOG_MARK, APLOG_WARNING|APLOG_NOERRNO, 0, s,
                         "%s server certificate CommonName (CN) `%s' "
                         "does NOT match server name!?",
                         ssl_asn1_keystr(type), cn);
@@ -883,7 +883,7 @@ static void ssl_init_server_certs(server_rec *s,
    have_dsa = ssl_server_import_cert(s, mctx, dsa_id, SSL_AIDX_DSA);

    if (!(have_rsa || have_dsa)) {
        ssl_log(s, SSL_LOG_ERROR|SSL_INIT,
        ap_log_error(APLOG_MARK, APLOG_ERR|APLOG_NOERRNO, 0, s,
                "Oops, no RSA or DSA server certificate found?!");
        ssl_die();
    }
@@ -896,7 +896,7 @@ static void ssl_init_server_certs(server_rec *s,
    have_dsa = ssl_server_import_key(s, mctx, dsa_id, SSL_AIDX_DSA);

    if (!(have_rsa || have_dsa)) {
        ssl_log(s, SSL_LOG_ERROR|SSL_INIT,
        ap_log_error(APLOG_MARK, APLOG_ERR|APLOG_NOERRNO, 0, s,
                "Oops, no RSA or DSA server private key found?!");
        ssl_die();
    }
@@ -929,14 +929,14 @@ static void ssl_init_proxy_certs(server_rec *s,
    }

    if ((ncerts = sk_X509_INFO_num(sk)) > 0) {
        ssl_log(s, SSL_LOG_TRACE|SSL_INIT,
        ap_log_error(APLOG_MARK, APLOG_DEBUG|APLOG_NOERRNO, 0, s,
                     "loaded %d client certs for SSL proxy",
                     ncerts);

        pkp->certs = sk;
    }
    else {
        ssl_log(s, SSL_LOG_WARN|SSL_INIT,
        ap_log_error(APLOG_MARK, APLOG_WARNING|APLOG_NOERRNO, 0, s,
                     "no client certs found for SSL proxy");
        sk_X509_INFO_free(sk);
    }
@@ -973,7 +973,7 @@ void ssl_init_ConfigureServer(server_rec *s,
                              SSLSrvConfigRec *sc)
{
    if (sc->enabled) {
        ssl_log(s, SSL_LOG_INFO|SSL_INIT,
        ap_log_error(APLOG_MARK, APLOG_INFO|APLOG_NOERRNO, 0, s,
                     "Configuring server for SSL protocol");
        ssl_init_server_ctx(s, p, ptemp, sc);
    }
@@ -1001,7 +1001,8 @@ void ssl_init_CheckServers(server_rec *base_server, apr_pool_t *p)
        sc = mySrvConfig(s);

        if (sc->enabled && (s->port == DEFAULT_HTTP_PORT)) {
            ssl_log(base_server, SSL_LOG_WARN,
            ap_log_error(APLOG_MARK, APLOG_WARNING|APLOG_NOERRNO, 0,
                         base_server,
                         "Init: (%s) You configured HTTPS(%d) "
                         "on the standard HTTP(%d) port!",
                         ssl_util_vhostid(p, s),
@@ -1009,7 +1010,8 @@ void ssl_init_CheckServers(server_rec *base_server, apr_pool_t *p)
        }

        if (!sc->enabled && (s->port == DEFAULT_HTTPS_PORT)) {
            ssl_log(base_server, SSL_LOG_WARN,
            ap_log_error(APLOG_MARK, APLOG_WARNING|APLOG_NOERRNO, 0,
                         base_server,
                         "Init: (%s) You configured HTTP(%d) "
                         "on the standard HTTPS(%d) port!",
                         ssl_util_vhostid(p, s),
@@ -1037,7 +1039,8 @@ void ssl_init_CheckServers(server_rec *base_server, apr_pool_t *p)
        klen = strlen(key);

        if ((ps = (server_rec *)apr_hash_get(table, key, klen))) {
            ssl_log(base_server, SSL_LOG_WARN,
            ap_log_error(APLOG_MARK, APLOG_WARNING|APLOG_NOERRNO, 0,
                         base_server,
                         "Init: SSL server IP/port conflict: "
                         "%s (%s:%d) vs. %s (%s:%d)",
                         ssl_util_vhostid(p, s), 
@@ -1054,7 +1057,7 @@ void ssl_init_CheckServers(server_rec *base_server, apr_pool_t *p)
    }

    if (conflict) {
        ssl_log(base_server, SSL_LOG_WARN,
        ap_log_error(APLOG_MARK, APLOG_WARNING|APLOG_NOERRNO, 0, base_server,
                     "Init: You should not use name-based "
                     "virtual hosts in conjunction with SSL!!");
    }
@@ -1081,7 +1084,7 @@ static void ssl_init_PushCAList(STACK_OF(X509_NAME) *ca_list,
        char name_buf[256];
        X509_NAME *name = sk_X509_NAME_value(sk, n);

        ssl_log(s, SSL_LOG_TRACE,
        ap_log_error(APLOG_MARK, APLOG_DEBUG|APLOG_NOERRNO, 0, s,
                     "CA certificate: %s",
                     X509_NAME_oneline(name, name_buf, sizeof(name_buf)));

@@ -1131,9 +1134,10 @@ STACK_OF(X509_NAME) *ssl_init_FindCAList(server_rec *s,
        apr_dir_t *dir;
        apr_finfo_t direntry;
        apr_int32_t finfo_flags = APR_FINFO_MIN|APR_FINFO_NAME;
        apr_status_t rv;

        if (apr_dir_open(&dir, ca_path, ptemp) != APR_SUCCESS) {
            ssl_log(s, SSL_LOG_ERROR|SSL_ADD_ERRNO|SSL_INIT,
        if ((rv = apr_dir_open(&dir, ca_path, ptemp)) != APR_SUCCESS) {
            ap_log_error(APLOG_MARK, APLOG_ERR, rv, s,
                    "Failed to open SSLCACertificatePath `%s'",
                    ca_path);
            ssl_die();
+15 −13
Changes for ssl_engine_io.c: 15 added lines, 13 removed lines.
Original line number Diff line number Diff line
@@ -502,7 +502,7 @@ static int ssl_io_hook_read(SSL *ssl, char *buf, int len)
             * Log SSL errors
             */
            conn_rec *c = (conn_rec *)SSL_get_app_data(ssl);
            ssl_log(c->base_server, SSL_LOG_ERROR,
            ap_log_error(APLOG_MARK, APLOG_ERR|APLOG_NOERRNO, 0, c->base_server,
                    "SSL error on reading data");
            ssl_log_ssl_error(APLOG_MARK, APLOG_ERR, c->base_server);
        }
@@ -535,7 +535,7 @@ static int ssl_io_hook_write(SSL *ssl, unsigned char *buf, int len)
             * Log SSL errors
             */
            conn_rec *c = (conn_rec *)SSL_get_app_data(ssl);
            ssl_log(c->base_server, SSL_LOG_ERROR,
            ap_log_error(APLOG_MARK, APLOG_ERR|APLOG_NOERRNO, 0, c->base_server,
                    "SSL error on writing data");
            ssl_log_ssl_error(APLOG_MARK, APLOG_ERR, c->base_server);
        }
@@ -567,7 +567,7 @@ static apr_status_t ssl_filter_write(ap_filter_t *f,
            reason = "likely due to failed renegotiation";
        }

        ssl_log(c->base_server, SSL_LOG_ERROR,
        ap_log_error(APLOG_MARK, APLOG_ERR|APLOG_NOERRNO, 0, c->base_server,
                "failed to write %d of %d bytes (%s)",
                n > 0 ? len - n : len, len, reason);

@@ -765,7 +765,8 @@ static apr_status_t ssl_io_filter_error(ap_filter_t *f,
    switch (status) {
      case HTTP_BAD_REQUEST:
            /* log the situation */
            ssl_log(f->c->base_server, SSL_LOG_ERROR,
            ap_log_error(APLOG_MARK, APLOG_ERR|APLOG_NOERRNO, 0,
                         f->c->base_server,
                         "SSL handshake failed: HTTP spoken on HTTPS port; "
                         "trying to send HTML error page");
            ssl_log_ssl_error(APLOG_MARK, APLOG_ERR, f->c->base_server);
@@ -959,7 +960,7 @@ static void ssl_io_data_dump(server_rec *srvr,
    rows = (len / DUMP_WIDTH);
    if ((rows * DUMP_WIDTH) < len)
        rows++;
    ssl_log(srvr, SSL_LOG_DEBUG|SSL_NO_TIMESTAMP|SSL_NO_LEVELID,
    ap_log_error(APLOG_MARK, APLOG_DEBUG|APLOG_NOERRNO, 0, srvr,
            "+-------------------------------------------------------------------------+");
    for(i = 0 ; i< rows; i++) {
        apr_snprintf(tmp, sizeof(tmp), "| %04x: ", i * DUMP_WIDTH);
@@ -984,12 +985,13 @@ static void ssl_io_data_dump(server_rec *srvr,
            }
        }
        apr_cpystrn(buf+strlen(buf), " |", sizeof(buf)-strlen(buf));
        ssl_log(srvr, SSL_LOG_DEBUG|SSL_NO_TIMESTAMP|SSL_NO_LEVELID, "%s", buf);
        ap_log_error(APLOG_MARK, APLOG_DEBUG|APLOG_NOERRNO, 0, srvr,
                     "%s", buf);
    }
    if (trunc > 0)
        ssl_log(srvr, SSL_LOG_DEBUG|SSL_NO_TIMESTAMP|SSL_NO_LEVELID,
                "| %04x - <SPACES/NULS>", len + trunc);
    ssl_log(srvr, SSL_LOG_DEBUG|SSL_NO_TIMESTAMP|SSL_NO_LEVELID,
        ap_log_error(APLOG_MARK, APLOG_DEBUG|APLOG_NOERRNO, 0, srvr,
                "| %04ld - <SPACES/NULS>", len + trunc);
    ap_log_error(APLOG_MARK, APLOG_DEBUG|APLOG_NOERRNO, 0, srvr,
            "+-------------------------------------------------------------------------+");
    return;
}
@@ -1011,8 +1013,8 @@ long ssl_io_data_cb(BIO *bio, int cmd,
    if (   cmd == (BIO_CB_WRITE|BIO_CB_RETURN)
        || cmd == (BIO_CB_READ |BIO_CB_RETURN) ) {
        if (rc >= 0) {
            ssl_log(s, SSL_LOG_DEBUG,
                    "%s: %s %ld/%d bytes %s BIO#%08X [mem: %08lX] %s",
            ap_log_error(APLOG_MARK, APLOG_DEBUG|APLOG_NOERRNO, 0, s,
                    "%s: %s %ld/%d bytes %s BIO#%p [mem: %p] %s",
                    SSL_LIBRARY_NAME,
                    (cmd == (BIO_CB_WRITE|BIO_CB_RETURN) ? "write" : "read"),
                    rc, argi, (cmd == (BIO_CB_WRITE|BIO_CB_RETURN) ? "to" : "from"),
@@ -1022,8 +1024,8 @@ long ssl_io_data_cb(BIO *bio, int cmd,
                ssl_io_data_dump(s, argp, rc);
        }
        else {
            ssl_log(s, SSL_LOG_DEBUG,
                    "%s: I/O error, %d bytes expected to %s on BIO#%08X [mem: %08lX]",
            ap_log_error(APLOG_MARK, APLOG_DEBUG|APLOG_NOERRNO, 0, s,
                    "%s: I/O error, %d bytes expected to %s on BIO#%p [mem: %p]",
                    SSL_LIBRARY_NAME, argi,
                    (cmd == (BIO_CB_WRITE|BIO_CB_RETURN) ? "write" : "read"),
                    bio, argp);
+74 −61

File changed.

Preview size limit exceeded, changes collapsed.

+14 −11
Changes for ssl_engine_mutex.c: 14 added lines, 11 removed lines.
Original line number Diff line number Diff line
@@ -68,16 +68,14 @@
int ssl_mutex_init(server_rec *s, apr_pool_t *p)
{
    SSLModConfigRec *mc = myModConfig(s);
#if !defined(OS2) && !defined(WIN32) && !defined(BEOS) && !defined(NETWARE)
    apr_status_t rv;
#endif

    if (mc->nMutexMode == SSL_MUTEXMODE_NONE) 
        return TRUE;

    if (apr_global_mutex_create(&mc->pMutex, mc->szMutexFile,
                                APR_LOCK_DEFAULT, p) != APR_SUCCESS) {
        ssl_log(s, SSL_LOG_ERROR,
    if ((rv = apr_global_mutex_create(&mc->pMutex, mc->szMutexFile,
                                APR_LOCK_DEFAULT, p)) != APR_SUCCESS) {
        ap_log_error(APLOG_MARK, APLOG_ERR, rv, s,
                     "Cannot create SSLMutex file `%s'",
                     mc->szMutexFile);
        return FALSE;
@@ -86,8 +84,9 @@ int ssl_mutex_init(server_rec *s, apr_pool_t *p)
#if !defined(OS2) && !defined(WIN32) && !defined(BEOS) && !defined(NETWARE)
    rv = unixd_set_global_mutex_perms(mc->pMutex);
    if (rv != APR_SUCCESS) {
        ssl_log(s, SSL_LOG_ERROR, "Could not set permissions on "
                     "ssl_mutex; check User and Group directives");
        ap_log_error(APLOG_MARK, APLOG_ERR, rv, s,
                     "Could not set permissions on ssl_mutex; check User "
                     "and Group directives");
        return FALSE;
    }
#endif
@@ -110,11 +109,13 @@ int ssl_mutex_reinit(server_rec *s, apr_pool_t *p)
int ssl_mutex_on(server_rec *s)
{
    SSLModConfigRec *mc = myModConfig(s);
    apr_status_t rv;

    if (mc->nMutexMode == SSL_MUTEXMODE_NONE)
        return TRUE;
    if (apr_global_mutex_lock(mc->pMutex) != APR_SUCCESS) {
        ssl_log(s, SSL_LOG_WARN, "Failed to acquire global mutex lock");
    if ((rv = apr_global_mutex_lock(mc->pMutex)) != APR_SUCCESS) {
        ap_log_error(APLOG_MARK, APLOG_WARNING, rv, s,
                     "Failed to acquire global mutex lock");
        return FALSE;
    }
    return TRUE;
@@ -123,11 +124,13 @@ int ssl_mutex_on(server_rec *s)
int ssl_mutex_off(server_rec *s)
{
    SSLModConfigRec *mc = myModConfig(s);
    apr_status_t rv;

    if (mc->nMutexMode == SSL_MUTEXMODE_NONE)
        return TRUE;
    if (apr_global_mutex_unlock(mc->pMutex) != APR_SUCCESS) {
        ssl_log(s, SSL_LOG_WARN, "Failed to release global mutex lock");
    if ((rv = apr_global_mutex_unlock(mc->pMutex)) != APR_SUCCESS) {
        ap_log_error(APLOG_MARK, APLOG_WARNING, rv, s,
                     "Failed to release global mutex lock");
        return FALSE;
    }
    return TRUE;
Loading