Commit 107f4274 authored by Doug MacEachern's avatar Doug MacEachern
Browse files

support reuse of encrypted DSA keys on restart


git-svn-id: https://svn.apache.org/repos/asf/httpd/httpd/trunk/modules/ssl@93799 13f79535-47bb-0310-9956-ffa450edef68
parent b8194772
Loading
Loading
Loading
Loading
+12 −4
Changes for ssl_engine_pphrase.c: 12 added lines, 4 removed lines.
Original line number Diff line number Diff line
@@ -319,16 +319,24 @@ void ssl_pphrase_Handle(server_rec *s, apr_pool_t *p)
                 * are used to give a better idea as to what failed.
                 */
                if (pkey_mtime) {
                    char *key_id = apr_psprintf(p, "%s:%s", cpVHostID, "RSA"); /* XXX: check for DSA key too? */
                    ssl_asn1_t *asn1 = ssl_asn1_table_get(mc->tPrivateKey, key_id);
                    const char *key_types[] = {"RSA", "DSA", NULL};
                    int i;

                    for (i=0; key_types[i]; i++) {
                        char *key_id =
                            apr_psprintf(p, "%s:%s", cpVHostID, key_types[i]);
                        ssl_asn1_t *asn1 = 
                            ssl_asn1_table_get(mc->tPrivateKey, key_id);
                    
                        if (asn1 && (asn1->source_mtime == pkey_mtime)) {
                            ssl_log(pServ, SSL_LOG_INFO,
                                "%s reusing existing private key on restart",
                                cpVHostID);
                                    "%s reusing existing "
                                    "%s private key on restart",
                                    cpVHostID, key_types[i]);
                            return;
                        }
                    }
                }

                cpPassPhraseCur = NULL;
                bReadable = ((pPrivateKey = SSL_read_PrivateKey(szPath, NULL,