Commit eddd0000 authored by Justin Erenkrantz's avatar Justin Erenkrantz
Browse files

Remove SSLLog and SSLLogLevel directives in favor of having mod_ssl use the

standard ErrorLog directives.


git-svn-id: https://svn.apache.org/repos/asf/httpd/httpd/trunk@95129 13f79535-47bb-0310-9956-ffa450edef68
parent 8b6d6dc9
Loading
Loading
Loading
Loading
+3 −0
Changes for CHANGES: 3 added lines, 0 removed lines.
Original line number Diff line number Diff line
Changes with Apache 2.0.37
  *) Remove SSLLog and SSLLogLevel directives in favor of having
     mod_ssl use the standard ErrorLog directives.  [Justin Erenkrantz]
  *) OS/390: LIBPATH no longer has to be manually uncommented in
     envvars to get apachectl to set up httpd properly.  [Jeff Trawick]
+0 −10
Changes for docs/conf/ssl-std.conf: 0 added lines, 10 removed lines.
Original line number Diff line number Diff line
@@ -82,16 +82,6 @@ SSLRandomSeed connect builtin
#SSLRandomSeed connect file:/dev/random  512
#SSLRandomSeed connect file:/dev/urandom 512

#   Logging:
#   The home of the dedicated SSL protocol logfile. Errors are
#   additionally duplicated in the general error log file.  Put
#   this somewhere where it cannot be used for symlink attacks on
#   a real server (i.e. somewhere where only root can write).
#   Log levels are (ascending order: higher ones include lower ones):
#   none, error, warn, info, trace, debug.
SSLLog      logs/ssl_engine_log
SSLLogLevel info

##
## SSL Virtual Host Context
##
+0 −72
Changes for docs/manual/mod/mod_ssl.xml: 0 added lines, 72 removed lines.
Original line number Diff line number Diff line
@@ -901,78 +901,6 @@ SSLVerifyDepth 10
</usage>
</directivesynopsis>

<directivesynopsis>
<name>SSLLog</name>
<description>Where to write the dedicated SSL engine logfile</description>
<syntax>SSLLog <em>file-path</em></syntax>
<contextlist><context>server config</context>
<context>virtual host</context></contextlist>

<usage>
<p>
This directive sets the name of the dedicated SSL protocol engine logfile.
Error type messages are additionally duplicated to the general Apache error
log file (directive <code>ErrorLog</code>). Put this somewhere where it cannot
be used for symlink attacks on a real server (i.e. somewhere where only root
can write). If the <em>file-path</em> does not begin with a slash
('<code>/</code>') then it is assumed to be relative to the <em>Server
Root</em>. If <em>file-path</em> begins with a bar ('<code>|</code>') then the
following string is assumed to be a path to an executable program to which a
reliable pipe can be established. The directive should occur only once per
virtual server config.</p>
<example><title>Example</title>
SSLLog /usr/local/apache/logs/ssl_engine_log
</example>
</usage>
</directivesynopsis>

<directivesynopsis>
<name>SSLLogLevel</name>
<description>Logging level for the dedicated SSL engine 
logfile</description>
<syntax>SSLLogLevel <em>level</em></syntax>
<default>SSLLogLevel none</default>
<contextlist><context>server config</context>
<context>virtual host</context></contextlist>

<usage>
<p>
This directive sets the verbosity degree of the dedicated SSL protocol engine
logfile. The <em>level</em> is one of the following (in ascending order where
higher levels include lower levels):</p>
<ul>
<li><code>none</code><br />
    no dedicated SSL logging is done, but messages of level
    ``<code>error</code>'' are still written to the general Apache error
    logfile.
</li>
<li><code>error</code><br />
    log messages of error type only, i.e. messages which show fatal situations
    (processing is stopped). Those messages are also duplicated to the
    general Apache error logfile.
</li>
<li><code>warn</code><br />
    log also warning messages, i.e. messages which show non-fatal problems
    (processing is continued).
</li>
<li><code>info</code><br />
    log also informational messages, i.e. messages which show major
    processing steps.
</li>
<li><code>trace</code><br />
    log also trace messages, i.e. messages which show minor processing steps.
</li>
<li><code>debug</code><br />
    log also debugging messages, i.e. messages which show development and
    low-level I/O information.
</li>
</ul>
<example><title>Example</title>
SSLLogLevel warn
</example>
</usage>
</directivesynopsis>

<directivesynopsis>
<name>SSLOptions</name>
<description>Configure various SSL engine run-time options</description>
+6 −8
Changes for modules/ssl/mod_ssl.c: 6 added lines, 8 removed lines.
Original line number Diff line number Diff line
@@ -141,12 +141,6 @@ static const command_rec ssl_config_cmds[] = {
    SSL_CMD_SRV(SessionCacheTimeout, TAKE1,
                "SSL Session Cache object lifetime "
                "(`N' - number of seconds)")
    SSL_CMD_SRV(Log, TAKE1,
                "SSL logfile for SSL-related messages "
                "(`/path/to/file', `|/path/to/program')")
    SSL_CMD_SRV(LogLevel, TAKE1,
                "SSL logfile verbosity level "
                "(`none', `error', `warn', `info', `debug')")
    SSL_CMD_SRV(Protocol, RAW_ARGS,
                "Enable or disable various SSL protocols"
                "(`[+-][SSLv2|SSLv3|TLSv1] ...' - see manual)")
@@ -201,6 +195,12 @@ static const command_rec ssl_config_cmds[] = {
               "Require a boolean expression to evaluate to true for granting access"
               "(arbitrary complex boolean expression - see manual)")

    /* Deprecated directives. */
    AP_INIT_RAW_ARGS("SSLLog", ap_set_deprecated, NULL, OR_ALL, 
      "SSLLog directive is no longer supported - use ErrorLog."),
    AP_INIT_RAW_ARGS("SSLLogLevel", ap_set_deprecated, NULL, OR_ALL, 
      "SSLLogLevel directive is no longer supported - use LogLevel."),
    
    AP_END_CMD
};

@@ -302,8 +302,6 @@ static int ssl_hook_pre_connection(conn_rec *c, void *csd)
        return DECLINED;
    }

    sslconn->log_level = sc->log_level;

    /*
     * Remember the connection information for
     * later access inside callback functions
+0 −29
Changes for modules/ssl/mod_ssl.h: 0 added lines, 29 removed lines.
Original line number Diff line number Diff line
@@ -203,25 +203,6 @@ ap_set_module_config(c->conn_config, &ssl_module, val)
#define myCtxVarSet(mc,num,val)  mc->rCtx.pV##num = val
#define myCtxVarGet(mc,num,type) (type)(mc->rCtx.pV##num)

/*
 * SSL Logging
 */
#define SSL_LOG_NONE    (1<<0)
#define SSL_LOG_ERROR   (1<<1)
#define SSL_LOG_WARN    (1<<2)
#define SSL_LOG_INFO    (1<<3)
#define SSL_LOG_TRACE   (1<<4)
#define SSL_LOG_DEBUG   (1<<5)
#define SSL_LOG_MASK    (SSL_LOG_ERROR|SSL_LOG_WARN|SSL_LOG_INFO|SSL_LOG_TRACE|SSL_LOG_DEBUG)

#define SSL_ADD_NONE     (1<<8)
#define SSL_ADD_ERRNO    (1<<9)
#define SSL_ADD_SSLERR   (1<<10)
#define SSL_NO_TIMESTAMP (1<<11)
#define SSL_NO_LEVELID   (1<<12)
#define SSL_NO_NEWLINE   (1<<13)
#define SSL_INIT         (1<<14)

/*
 * Defaults for the configuration
 */
@@ -431,13 +412,10 @@ typedef struct {
    const char *verify_info;
    const char *verify_error;
    int verify_depth;
    int log_level; /* for avoiding expensive logging */
    int is_proxy;
    int disabled;
} SSLConnRec;

#define SSLConnLogApplies(sslconn, level) (sslconn->log_level >= level)

typedef struct {
    pid_t           pid;
    apr_pool_t     *pPool;
@@ -528,9 +506,6 @@ struct SSLSrvConfigRec {
    BOOL             proxy_enabled;
    const char      *vhost_id;
    int              vhost_id_len;
    const char      *log_file_name;
    apr_file_t      *log_file;
    int              log_level;
    int              session_cache_timeout;
    modssl_ctx_t    *server;
    modssl_ctx_t    *proxy;
@@ -586,8 +561,6 @@ const char *ssl_cmd_SSLVerifyClient(cmd_parms *, void *, const char *);
const char  *ssl_cmd_SSLVerifyDepth(cmd_parms *, void *, const char *);
const char  *ssl_cmd_SSLSessionCache(cmd_parms *, void *, const char *);
const char  *ssl_cmd_SSLSessionCacheTimeout(cmd_parms *, void *, const char *);
const char  *ssl_cmd_SSLLog(cmd_parms *, void *, const char *);
const char  *ssl_cmd_SSLLogLevel(cmd_parms *, void *, const char *);
const char  *ssl_cmd_SSLProtocol(cmd_parms *, void *, const char *);
const char  *ssl_cmd_SSLOptions(cmd_parms *, void *, const char *);
const char  *ssl_cmd_SSLRequireSSL(cmd_parms *, void *);
@@ -704,8 +677,6 @@ int ssl_mutex_on(server_rec *);
int          ssl_mutex_off(server_rec *);

/*  Logfile Support  */
void         ssl_log_open(server_rec *, server_rec *, apr_pool_t *);
void         ssl_log(server_rec *, int, const char *, ...);
void         ssl_die(void);
void         ssl_log_ssl_error(const char *, int, int, server_rec *);

Loading