Loading CHANGES +4 −0 Changes for CHANGES: 4 added lines, 0 removed lines. Original line number Diff line number Diff line -*- coding: utf-8 -*- Changes with Apache 2.5.1 *) mod_ssl: Fix a regression that the configuration settings for verify mode and verify depth were taken from the frontend connection in case of connections by the proxy to the backend. PR 62769. [Ruediger Pluem] *) ab: Add client certificate support. [Graham Leggett] *) mod_proxy_hcheck: Fix issues with TCP health checks. PR 61499 Loading modules/ssl/ssl_engine_kernel.c +16 −5 Changes for modules/ssl/ssl_engine_kernel.c: 16 added lines, 5 removed lines. Original line number Diff line number Diff line Loading @@ -1750,7 +1750,8 @@ int ssl_callback_SSLVerify(int ok, X509_STORE_CTX *ctx) /* Get verify ingredients */ int errnum = X509_STORE_CTX_get_error(ctx); int errdepth = X509_STORE_CTX_get_error_depth(ctx); int depth, verify; int depth = UNSET; int verify = SSL_CVERIFY_UNSET; /* * Log verification information Loading @@ -1766,10 +1767,15 @@ int ssl_callback_SSLVerify(int ok, X509_STORE_CTX *ctx) /* * Check for optionally acceptable non-verifiable issuer situation */ if (dc && (dc->nVerifyClient != SSL_CVERIFY_UNSET)) { verify = dc->nVerifyClient; if (dc) { if (sslconn->is_proxy) { verify = dc->proxy->auth.verify_mode; } else { verify = dc->nVerifyClient; } } if (!dc || (verify == SSL_CVERIFY_UNSET)) { verify = mctx->auth.verify_mode; } Loading Loading @@ -1873,10 +1879,15 @@ int ssl_callback_SSLVerify(int ok, X509_STORE_CTX *ctx) /* * Finally check the depth of the certificate verification */ if (dc && (dc->nVerifyDepth != UNSET)) { depth = dc->nVerifyDepth; if (dc) { if (sslconn->is_proxy) { depth = dc->proxy->auth.verify_depth; } else { depth = dc->nVerifyDepth; } } if (!dc || (depth == UNSET)) { depth = mctx->auth.verify_depth; } Loading Loading
CHANGES +4 −0 Changes for CHANGES: 4 added lines, 0 removed lines. Original line number Diff line number Diff line -*- coding: utf-8 -*- Changes with Apache 2.5.1 *) mod_ssl: Fix a regression that the configuration settings for verify mode and verify depth were taken from the frontend connection in case of connections by the proxy to the backend. PR 62769. [Ruediger Pluem] *) ab: Add client certificate support. [Graham Leggett] *) mod_proxy_hcheck: Fix issues with TCP health checks. PR 61499 Loading
modules/ssl/ssl_engine_kernel.c +16 −5 Changes for modules/ssl/ssl_engine_kernel.c: 16 added lines, 5 removed lines. Original line number Diff line number Diff line Loading @@ -1750,7 +1750,8 @@ int ssl_callback_SSLVerify(int ok, X509_STORE_CTX *ctx) /* Get verify ingredients */ int errnum = X509_STORE_CTX_get_error(ctx); int errdepth = X509_STORE_CTX_get_error_depth(ctx); int depth, verify; int depth = UNSET; int verify = SSL_CVERIFY_UNSET; /* * Log verification information Loading @@ -1766,10 +1767,15 @@ int ssl_callback_SSLVerify(int ok, X509_STORE_CTX *ctx) /* * Check for optionally acceptable non-verifiable issuer situation */ if (dc && (dc->nVerifyClient != SSL_CVERIFY_UNSET)) { verify = dc->nVerifyClient; if (dc) { if (sslconn->is_proxy) { verify = dc->proxy->auth.verify_mode; } else { verify = dc->nVerifyClient; } } if (!dc || (verify == SSL_CVERIFY_UNSET)) { verify = mctx->auth.verify_mode; } Loading Loading @@ -1873,10 +1879,15 @@ int ssl_callback_SSLVerify(int ok, X509_STORE_CTX *ctx) /* * Finally check the depth of the certificate verification */ if (dc && (dc->nVerifyDepth != UNSET)) { depth = dc->nVerifyDepth; if (dc) { if (sslconn->is_proxy) { depth = dc->proxy->auth.verify_depth; } else { depth = dc->nVerifyDepth; } } if (!dc || (depth == UNSET)) { depth = mctx->auth.verify_depth; } Loading