Commit 3a645f19 authored by Joe Orton's avatar Joe Orton
Browse files

* modules/ssl/ssl_engine_pphrase.c (modssl_load_engine_keypair): Load

  the engine associated with the private key (&cert) explicitly
  rather than requiring the engine to be set as the default method
  for all operations (with "SSLCryptoDevice <engine>").

(Thanks to Anderson Sasaki <ansasaki redhat.com> for suggested
improvement and guidance)


git-svn-id: https://svn.apache.org/repos/asf/httpd/httpd/trunk@1835614 13f79535-47bb-0310-9956-ffa450edef68
parent 50a5690a
Loading
Loading
Loading
Loading
+1 −1
Changes for docs/log-message-tags/next-number: 1 added line, 1 removed line.
Original line number Diff line number Diff line
10149
10150
+3 −9
Changes for docs/manual/mod/mod_ssl.xml: 3 added lines, 9 removed lines.
Original line number Diff line number Diff line
@@ -920,8 +920,7 @@ files, a certificate identifier can be used to identify a certificate
stored in a token.  Currently, only <a
href="https://tools.ietf.org/html/rfc7512">PKCS#11 URIs</a> are
recognized as certificate identifiers, and can be used in conjunction
with the OpenSSL <code>pkcs11</code> engine configured with <directive
module="mod_ssl">SSLCryptoDevice</directive>.  If <directive
with the OpenSSL <code>pkcs11</code> engine.  If <directive
module="mod_ssl">SSLCertificateKeyFile</directive> is omitted, the
certificate and private key can be loaded through the single
identifier specified with <directive
@@ -975,8 +974,6 @@ thus using a custom/suitable length.
# Example using a PEM-encoded file.
SSLCertificateFile "/usr/local/apache2/conf/ssl.crt/server.crt"
# Example use of a certificate and private key from a PKCS#11 token:
SSLCryptoDevice pkcs11
...
SSLCertificateFile "pkcs11:token=My%20Token%20Name;id=45"
</highlight>
</example>
@@ -1013,19 +1010,16 @@ an embedded key must be configured after the certificates using a separate
key file.</p>

<p>As an alternative to storing private keys in files, a key
identifier can be specified to identify a private key stored in a
identifier can be used to identify a private key stored in a
token.  Currently, only <a href="https://tools.ietf.org/html/rfc7512">PKCS#11 URIs</a> are recognized as private key
identifiers, and can be used in conjunction with the OpenSSL
<code>pkcs11</code> engine configured with <directive
module="mod_ssl">SSLCryptoDevice</directive>.</p>
<code>pkcs11</code> engine.</p>

<example><title>Example</title>
<highlight language="config">
# To use a private key from a PEM-encoded file:
SSLCertificateKeyFile "/usr/local/apache2/conf/ssl.key/server.key"
# To use a private key from a PKCS#11 token:
SSLCryptoDevice pkcs11
...
SSLCertificateKeyFile "pkcs11:token=My%20Token%20Name;id=45"
</highlight>
</example>