Commit 6646d38c authored by Rainer Jung's avatar Rainer Jung
Browse files

Merge revisions 906039, 906057, 906485, 906491, 908015, 916733, 916817

from trunk resp. 917044 from 2.2.x:

New releases of OpenSSL will only allow secure renegotiation by
default.  Add an "SSLInsecureRenegotiation" directive to enable
renegotiation against unpatched clients, to ease transition.

Submitted by: jorton
Backport by: rjung
Reviewed by: pgollucci, wrowe


git-svn-id: https://svn.apache.org/repos/asf/httpd/httpd/branches/2.0.x@1002233 13f79535-47bb-0310-9956-ffa450edef68
parent 3ecd6d7f
Loading
Loading
Loading
Loading
+8 −0
Changes for CHANGES: 8 added lines, 0 removed lines.
Original line number Diff line number Diff line
@@ -15,6 +15,14 @@ Changes with Apache 2.0.64
     mod_proxy_ftp: NULL pointer dereference on error paths.
     [Stefan Fritsch <sf fritsch.de>, Joe Orton]

  *) SECURITY: CVE-2009-3555 (cve.mitre.org)
     mod_ssl: Comprehensive fix of the TLS renegotiation prefix injection
     attack when compiled against OpenSSL version 0.9.8m or later. Introduces
     the 'SSLInsecureRenegotiation' directive to reopen this vulnerability
     and offer unsafe legacy renegotiation with clients which do not yet
     support the new secure renegotiation protocol, RFC 5746.
     [Joe Orton, and with thanks to the OpenSSL Team]

  *) SECURITY: CVE-2009-3555 (cve.mitre.org)
     mod_ssl: A partial fix for the TLS renegotiation prefix injection attack
     for OpenSSL versions prior to 0.9.8l; reject any client-initiated
+0 −15
Changes for STATUS: 0 added lines, 15 removed lines.
Original line number Diff line number Diff line
@@ -122,21 +122,6 @@ RELEASE SHOWSTOPPERS:
PATCHES ACCEPTED TO BACKPORT FROM TRUNK:
  [ start all new proposals below, under PATCHES PROPOSED. ]

  * mod_ssl: Implement SSLInsecureRenegotiation
    Trunk version of patch:
      http://svn.apache.org/viewcvs.cgi?rev=906039&view=rev
      http://svn.apache.org/viewcvs.cgi?rev=906057&view=rev
      http://svn.apache.org/viewcvs.cgi?rev=906485&view=rev
      http://svn.apache.org/viewcvs.cgi?rev=906491&view=rev
      http://svn.apache.org/viewcvs.cgi?rev=908015&view=rev
      http://svn.apache.org/viewcvs.cgi?rev=916733&view=rev
      http://svn.apache.org/viewcvs.cgi?rev=916817&view=rev
    Patch in 2.2.x branch:
      http://svn.apache.org/viewvc?rev=917044&view=rev
    Backport:
      http://people.apache.org/~rjung/patches/SSLInsecureRenegotiation_httpd_2_0_x-backport-r917044.patch 
    +1: rjung, pgollucci (+1 2.0.64 w/ this), wrowe

PATCHES PROPOSED TO BACKPORT FROM TRUNK:
  [ please place SVN revisions from trunk here, so it is easy to
    identify exactly what the proposed changes are!  Add all new
+42 −0
Changes for docs/manual/mod/mod_ssl.xml: 42 added lines, 0 removed lines.
Original line number Diff line number Diff line
@@ -1511,4 +1511,46 @@ SSLUserName SSL_CLIENT_S_DN_CN
</usage>
</directivesynopsis>

<directivesynopsis>
<name>SSLInsecureRenegotiation</name>
<description>Option to enable support for insecure renegotiation</description>
<syntax>SSLInsecureRenegotiation <em>flag</em></syntax>
<default>SSLInsecureRenegotiation off</default>
<contextlist><context>server config</context>
<context>virtual host</context></contextlist>
<compatibility>Available in httpd 2.0.64 and later, if using OpenSSL 0.9.8m or later</compatibility>

<usage>
<p>As originally specified, all versions of the SSL and TLS protocols
(up to and including TLS/1.2) were vulnerable to a Man-in-the-Middle
attack
(<a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CAN-2009-3555">CVE-2009-3555</a>)
during a renegotiation.  This vulnerability allowed an attacker to
"prefix" a chosen plaintext to the HTTP request as seen by the web
server.  A protocol extension was developed which fixed this
vulnerability if supported by both client and server.</p>

<p>If <module>mod_ssl</module> is linked against OpenSSL version 0.9.8m
or later, by default renegotiation is only supported with
clients supporting the new protocol extension.  If this directive is
enabled, renegotiation will be allowed with old (unpatched) clients,
albeit insecurely.</p>

<note type="warning"><title>Security warning</title>
<p>If this directive is enabled, SSL connections will be vulnerable to
the Man-in-the-Middle prefix attack as described
in <a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CAN-2009-3555">CVE-2009-3555</a>.</p>
</note>

<example><title>Example</title>
SSLInsecureRenegotiation on
</example>

<p>The <code>SSL_SECURE_RENEG</code> environment variable can be used
from an SSI or CGI script to determine whether secure renegotiation is
supported for a given SSL connection.</p>

</usage>
</directivesynopsis>

</modulesynopsis>
+2 −0
Changes for modules/ssl/mod_ssl.c: 2 added lines, 0 removed lines.
Original line number Diff line number Diff line
@@ -136,6 +136,8 @@ static const command_rec ssl_config_cmds[] = {
                "(`[+-][SSLv2|SSLv3|TLSv1] ...' - see manual)")
    SSL_CMD_ALL(UserName, TAKE1,
		"Set user name to SSL variable value")
    SSL_CMD_SRV(InsecureRenegotiation, FLAG,
                "Enable support for insecure renegotiation")

    /* 
     * Proxy configuration for remote SSL connections
+2 −0
Changes for modules/ssl/mod_ssl.h: 2 added lines, 0 removed lines.
Original line number Diff line number Diff line
@@ -496,6 +496,7 @@ struct SSLSrvConfigRec {
    const char      *vhost_id;
    int              vhost_id_len;
    int              session_cache_timeout;
    BOOL             insecure_reneg;
    modssl_ctx_t    *server;
    modssl_ctx_t    *proxy;
};
@@ -559,6 +560,7 @@ const char *ssl_cmd_SSLOptions(cmd_parms *, void *, const char *);
const char  *ssl_cmd_SSLRequireSSL(cmd_parms *, void *);
const char  *ssl_cmd_SSLRequire(cmd_parms *, void *, const char *);
const char  *ssl_cmd_SSLUserName(cmd_parms *, void *, const char *);
const char  *ssl_cmd_SSLInsecureRenegotiation(cmd_parms *cmd, void *dcfg, int flag);

const char *ssl_cmd_SSLProxyEngine(cmd_parms *cmd, void *dcfg, int flag);
const char  *ssl_cmd_SSLProxyProtocol(cmd_parms *, void *, const char *);
Loading