Loading CHANGES +3 −0 Changes for CHANGES: 3 added lines, 0 removed lines. Original line number Diff line number Diff line Changes with Apache 2.0.37 *) Remove SSLLog and SSLLogLevel directives in favor of having mod_ssl use the standard ErrorLog directives. [Justin Erenkrantz] *) OS/390: LIBPATH no longer has to be manually uncommented in envvars to get apachectl to set up httpd properly. [Jeff Trawick] Loading docs/conf/ssl-std.conf +0 −10 Changes for docs/conf/ssl-std.conf: 0 added lines, 10 removed lines. Original line number Diff line number Diff line Loading @@ -82,16 +82,6 @@ SSLRandomSeed connect builtin #SSLRandomSeed connect file:/dev/random 512 #SSLRandomSeed connect file:/dev/urandom 512 # Logging: # The home of the dedicated SSL protocol logfile. Errors are # additionally duplicated in the general error log file. Put # this somewhere where it cannot be used for symlink attacks on # a real server (i.e. somewhere where only root can write). # Log levels are (ascending order: higher ones include lower ones): # none, error, warn, info, trace, debug. SSLLog logs/ssl_engine_log SSLLogLevel info ## ## SSL Virtual Host Context ## Loading docs/manual/mod/mod_ssl.xml +0 −72 Changes for docs/manual/mod/mod_ssl.xml: 0 added lines, 72 removed lines. Original line number Diff line number Diff line Loading @@ -901,78 +901,6 @@ SSLVerifyDepth 10 </usage> </directivesynopsis> <directivesynopsis> <name>SSLLog</name> <description>Where to write the dedicated SSL engine logfile</description> <syntax>SSLLog <em>file-path</em></syntax> <contextlist><context>server config</context> <context>virtual host</context></contextlist> <usage> <p> This directive sets the name of the dedicated SSL protocol engine logfile. Error type messages are additionally duplicated to the general Apache error log file (directive <code>ErrorLog</code>). Put this somewhere where it cannot be used for symlink attacks on a real server (i.e. somewhere where only root can write). If the <em>file-path</em> does not begin with a slash ('<code>/</code>') then it is assumed to be relative to the <em>Server Root</em>. If <em>file-path</em> begins with a bar ('<code>|</code>') then the following string is assumed to be a path to an executable program to which a reliable pipe can be established. The directive should occur only once per virtual server config.</p> <example><title>Example</title> SSLLog /usr/local/apache/logs/ssl_engine_log </example> </usage> </directivesynopsis> <directivesynopsis> <name>SSLLogLevel</name> <description>Logging level for the dedicated SSL engine logfile</description> <syntax>SSLLogLevel <em>level</em></syntax> <default>SSLLogLevel none</default> <contextlist><context>server config</context> <context>virtual host</context></contextlist> <usage> <p> This directive sets the verbosity degree of the dedicated SSL protocol engine logfile. The <em>level</em> is one of the following (in ascending order where higher levels include lower levels):</p> <ul> <li><code>none</code><br /> no dedicated SSL logging is done, but messages of level ``<code>error</code>'' are still written to the general Apache error logfile. </li> <li><code>error</code><br /> log messages of error type only, i.e. messages which show fatal situations (processing is stopped). Those messages are also duplicated to the general Apache error logfile. </li> <li><code>warn</code><br /> log also warning messages, i.e. messages which show non-fatal problems (processing is continued). </li> <li><code>info</code><br /> log also informational messages, i.e. messages which show major processing steps. </li> <li><code>trace</code><br /> log also trace messages, i.e. messages which show minor processing steps. </li> <li><code>debug</code><br /> log also debugging messages, i.e. messages which show development and low-level I/O information. </li> </ul> <example><title>Example</title> SSLLogLevel warn </example> </usage> </directivesynopsis> <directivesynopsis> <name>SSLOptions</name> <description>Configure various SSL engine run-time options</description> Loading modules/ssl/mod_ssl.c +6 −8 Changes for modules/ssl/mod_ssl.c: 6 added lines, 8 removed lines. Original line number Diff line number Diff line Loading @@ -141,12 +141,6 @@ static const command_rec ssl_config_cmds[] = { SSL_CMD_SRV(SessionCacheTimeout, TAKE1, "SSL Session Cache object lifetime " "(`N' - number of seconds)") SSL_CMD_SRV(Log, TAKE1, "SSL logfile for SSL-related messages " "(`/path/to/file', `|/path/to/program')") SSL_CMD_SRV(LogLevel, TAKE1, "SSL logfile verbosity level " "(`none', `error', `warn', `info', `debug')") SSL_CMD_SRV(Protocol, RAW_ARGS, "Enable or disable various SSL protocols" "(`[+-][SSLv2|SSLv3|TLSv1] ...' - see manual)") Loading Loading @@ -201,6 +195,12 @@ static const command_rec ssl_config_cmds[] = { "Require a boolean expression to evaluate to true for granting access" "(arbitrary complex boolean expression - see manual)") /* Deprecated directives. */ AP_INIT_RAW_ARGS("SSLLog", ap_set_deprecated, NULL, OR_ALL, "SSLLog directive is no longer supported - use ErrorLog."), AP_INIT_RAW_ARGS("SSLLogLevel", ap_set_deprecated, NULL, OR_ALL, "SSLLogLevel directive is no longer supported - use LogLevel."), AP_END_CMD }; Loading Loading @@ -302,8 +302,6 @@ static int ssl_hook_pre_connection(conn_rec *c, void *csd) return DECLINED; } sslconn->log_level = sc->log_level; /* * Remember the connection information for * later access inside callback functions Loading modules/ssl/mod_ssl.h +0 −29 Changes for modules/ssl/mod_ssl.h: 0 added lines, 29 removed lines. Original line number Diff line number Diff line Loading @@ -203,25 +203,6 @@ ap_set_module_config(c->conn_config, &ssl_module, val) #define myCtxVarSet(mc,num,val) mc->rCtx.pV##num = val #define myCtxVarGet(mc,num,type) (type)(mc->rCtx.pV##num) /* * SSL Logging */ #define SSL_LOG_NONE (1<<0) #define SSL_LOG_ERROR (1<<1) #define SSL_LOG_WARN (1<<2) #define SSL_LOG_INFO (1<<3) #define SSL_LOG_TRACE (1<<4) #define SSL_LOG_DEBUG (1<<5) #define SSL_LOG_MASK (SSL_LOG_ERROR|SSL_LOG_WARN|SSL_LOG_INFO|SSL_LOG_TRACE|SSL_LOG_DEBUG) #define SSL_ADD_NONE (1<<8) #define SSL_ADD_ERRNO (1<<9) #define SSL_ADD_SSLERR (1<<10) #define SSL_NO_TIMESTAMP (1<<11) #define SSL_NO_LEVELID (1<<12) #define SSL_NO_NEWLINE (1<<13) #define SSL_INIT (1<<14) /* * Defaults for the configuration */ Loading Loading @@ -431,13 +412,10 @@ typedef struct { const char *verify_info; const char *verify_error; int verify_depth; int log_level; /* for avoiding expensive logging */ int is_proxy; int disabled; } SSLConnRec; #define SSLConnLogApplies(sslconn, level) (sslconn->log_level >= level) typedef struct { pid_t pid; apr_pool_t *pPool; Loading Loading @@ -528,9 +506,6 @@ struct SSLSrvConfigRec { BOOL proxy_enabled; const char *vhost_id; int vhost_id_len; const char *log_file_name; apr_file_t *log_file; int log_level; int session_cache_timeout; modssl_ctx_t *server; modssl_ctx_t *proxy; Loading Loading @@ -586,8 +561,6 @@ const char *ssl_cmd_SSLVerifyClient(cmd_parms *, void *, const char *); const char *ssl_cmd_SSLVerifyDepth(cmd_parms *, void *, const char *); const char *ssl_cmd_SSLSessionCache(cmd_parms *, void *, const char *); const char *ssl_cmd_SSLSessionCacheTimeout(cmd_parms *, void *, const char *); const char *ssl_cmd_SSLLog(cmd_parms *, void *, const char *); const char *ssl_cmd_SSLLogLevel(cmd_parms *, void *, const char *); const char *ssl_cmd_SSLProtocol(cmd_parms *, void *, const char *); const char *ssl_cmd_SSLOptions(cmd_parms *, void *, const char *); const char *ssl_cmd_SSLRequireSSL(cmd_parms *, void *); Loading Loading @@ -704,8 +677,6 @@ int ssl_mutex_on(server_rec *); int ssl_mutex_off(server_rec *); /* Logfile Support */ void ssl_log_open(server_rec *, server_rec *, apr_pool_t *); void ssl_log(server_rec *, int, const char *, ...); void ssl_die(void); void ssl_log_ssl_error(const char *, int, int, server_rec *); Loading Loading
CHANGES +3 −0 Changes for CHANGES: 3 added lines, 0 removed lines. Original line number Diff line number Diff line Changes with Apache 2.0.37 *) Remove SSLLog and SSLLogLevel directives in favor of having mod_ssl use the standard ErrorLog directives. [Justin Erenkrantz] *) OS/390: LIBPATH no longer has to be manually uncommented in envvars to get apachectl to set up httpd properly. [Jeff Trawick] Loading
docs/conf/ssl-std.conf +0 −10 Changes for docs/conf/ssl-std.conf: 0 added lines, 10 removed lines. Original line number Diff line number Diff line Loading @@ -82,16 +82,6 @@ SSLRandomSeed connect builtin #SSLRandomSeed connect file:/dev/random 512 #SSLRandomSeed connect file:/dev/urandom 512 # Logging: # The home of the dedicated SSL protocol logfile. Errors are # additionally duplicated in the general error log file. Put # this somewhere where it cannot be used for symlink attacks on # a real server (i.e. somewhere where only root can write). # Log levels are (ascending order: higher ones include lower ones): # none, error, warn, info, trace, debug. SSLLog logs/ssl_engine_log SSLLogLevel info ## ## SSL Virtual Host Context ## Loading
docs/manual/mod/mod_ssl.xml +0 −72 Changes for docs/manual/mod/mod_ssl.xml: 0 added lines, 72 removed lines. Original line number Diff line number Diff line Loading @@ -901,78 +901,6 @@ SSLVerifyDepth 10 </usage> </directivesynopsis> <directivesynopsis> <name>SSLLog</name> <description>Where to write the dedicated SSL engine logfile</description> <syntax>SSLLog <em>file-path</em></syntax> <contextlist><context>server config</context> <context>virtual host</context></contextlist> <usage> <p> This directive sets the name of the dedicated SSL protocol engine logfile. Error type messages are additionally duplicated to the general Apache error log file (directive <code>ErrorLog</code>). Put this somewhere where it cannot be used for symlink attacks on a real server (i.e. somewhere where only root can write). If the <em>file-path</em> does not begin with a slash ('<code>/</code>') then it is assumed to be relative to the <em>Server Root</em>. If <em>file-path</em> begins with a bar ('<code>|</code>') then the following string is assumed to be a path to an executable program to which a reliable pipe can be established. The directive should occur only once per virtual server config.</p> <example><title>Example</title> SSLLog /usr/local/apache/logs/ssl_engine_log </example> </usage> </directivesynopsis> <directivesynopsis> <name>SSLLogLevel</name> <description>Logging level for the dedicated SSL engine logfile</description> <syntax>SSLLogLevel <em>level</em></syntax> <default>SSLLogLevel none</default> <contextlist><context>server config</context> <context>virtual host</context></contextlist> <usage> <p> This directive sets the verbosity degree of the dedicated SSL protocol engine logfile. The <em>level</em> is one of the following (in ascending order where higher levels include lower levels):</p> <ul> <li><code>none</code><br /> no dedicated SSL logging is done, but messages of level ``<code>error</code>'' are still written to the general Apache error logfile. </li> <li><code>error</code><br /> log messages of error type only, i.e. messages which show fatal situations (processing is stopped). Those messages are also duplicated to the general Apache error logfile. </li> <li><code>warn</code><br /> log also warning messages, i.e. messages which show non-fatal problems (processing is continued). </li> <li><code>info</code><br /> log also informational messages, i.e. messages which show major processing steps. </li> <li><code>trace</code><br /> log also trace messages, i.e. messages which show minor processing steps. </li> <li><code>debug</code><br /> log also debugging messages, i.e. messages which show development and low-level I/O information. </li> </ul> <example><title>Example</title> SSLLogLevel warn </example> </usage> </directivesynopsis> <directivesynopsis> <name>SSLOptions</name> <description>Configure various SSL engine run-time options</description> Loading
modules/ssl/mod_ssl.c +6 −8 Changes for modules/ssl/mod_ssl.c: 6 added lines, 8 removed lines. Original line number Diff line number Diff line Loading @@ -141,12 +141,6 @@ static const command_rec ssl_config_cmds[] = { SSL_CMD_SRV(SessionCacheTimeout, TAKE1, "SSL Session Cache object lifetime " "(`N' - number of seconds)") SSL_CMD_SRV(Log, TAKE1, "SSL logfile for SSL-related messages " "(`/path/to/file', `|/path/to/program')") SSL_CMD_SRV(LogLevel, TAKE1, "SSL logfile verbosity level " "(`none', `error', `warn', `info', `debug')") SSL_CMD_SRV(Protocol, RAW_ARGS, "Enable or disable various SSL protocols" "(`[+-][SSLv2|SSLv3|TLSv1] ...' - see manual)") Loading Loading @@ -201,6 +195,12 @@ static const command_rec ssl_config_cmds[] = { "Require a boolean expression to evaluate to true for granting access" "(arbitrary complex boolean expression - see manual)") /* Deprecated directives. */ AP_INIT_RAW_ARGS("SSLLog", ap_set_deprecated, NULL, OR_ALL, "SSLLog directive is no longer supported - use ErrorLog."), AP_INIT_RAW_ARGS("SSLLogLevel", ap_set_deprecated, NULL, OR_ALL, "SSLLogLevel directive is no longer supported - use LogLevel."), AP_END_CMD }; Loading Loading @@ -302,8 +302,6 @@ static int ssl_hook_pre_connection(conn_rec *c, void *csd) return DECLINED; } sslconn->log_level = sc->log_level; /* * Remember the connection information for * later access inside callback functions Loading
modules/ssl/mod_ssl.h +0 −29 Changes for modules/ssl/mod_ssl.h: 0 added lines, 29 removed lines. Original line number Diff line number Diff line Loading @@ -203,25 +203,6 @@ ap_set_module_config(c->conn_config, &ssl_module, val) #define myCtxVarSet(mc,num,val) mc->rCtx.pV##num = val #define myCtxVarGet(mc,num,type) (type)(mc->rCtx.pV##num) /* * SSL Logging */ #define SSL_LOG_NONE (1<<0) #define SSL_LOG_ERROR (1<<1) #define SSL_LOG_WARN (1<<2) #define SSL_LOG_INFO (1<<3) #define SSL_LOG_TRACE (1<<4) #define SSL_LOG_DEBUG (1<<5) #define SSL_LOG_MASK (SSL_LOG_ERROR|SSL_LOG_WARN|SSL_LOG_INFO|SSL_LOG_TRACE|SSL_LOG_DEBUG) #define SSL_ADD_NONE (1<<8) #define SSL_ADD_ERRNO (1<<9) #define SSL_ADD_SSLERR (1<<10) #define SSL_NO_TIMESTAMP (1<<11) #define SSL_NO_LEVELID (1<<12) #define SSL_NO_NEWLINE (1<<13) #define SSL_INIT (1<<14) /* * Defaults for the configuration */ Loading Loading @@ -431,13 +412,10 @@ typedef struct { const char *verify_info; const char *verify_error; int verify_depth; int log_level; /* for avoiding expensive logging */ int is_proxy; int disabled; } SSLConnRec; #define SSLConnLogApplies(sslconn, level) (sslconn->log_level >= level) typedef struct { pid_t pid; apr_pool_t *pPool; Loading Loading @@ -528,9 +506,6 @@ struct SSLSrvConfigRec { BOOL proxy_enabled; const char *vhost_id; int vhost_id_len; const char *log_file_name; apr_file_t *log_file; int log_level; int session_cache_timeout; modssl_ctx_t *server; modssl_ctx_t *proxy; Loading Loading @@ -586,8 +561,6 @@ const char *ssl_cmd_SSLVerifyClient(cmd_parms *, void *, const char *); const char *ssl_cmd_SSLVerifyDepth(cmd_parms *, void *, const char *); const char *ssl_cmd_SSLSessionCache(cmd_parms *, void *, const char *); const char *ssl_cmd_SSLSessionCacheTimeout(cmd_parms *, void *, const char *); const char *ssl_cmd_SSLLog(cmd_parms *, void *, const char *); const char *ssl_cmd_SSLLogLevel(cmd_parms *, void *, const char *); const char *ssl_cmd_SSLProtocol(cmd_parms *, void *, const char *); const char *ssl_cmd_SSLOptions(cmd_parms *, void *, const char *); const char *ssl_cmd_SSLRequireSSL(cmd_parms *, void *); Loading Loading @@ -704,8 +677,6 @@ int ssl_mutex_on(server_rec *); int ssl_mutex_off(server_rec *); /* Logfile Support */ void ssl_log_open(server_rec *, server_rec *, apr_pool_t *); void ssl_log(server_rec *, int, const char *, ...); void ssl_die(void); void ssl_log_ssl_error(const char *, int, int, server_rec *); Loading