mirror of
https://github.com/apache/httpd.git
synced 2025-08-08 15:02:10 +03:00
Remove the hardcoded algorithm-type dependency for the SSLCertificateFile
and SSLCertificateKeyFile directives, and deprecate SSLCertificateChainFile Splitting the patch into smaller pieces turned out to be infeasible, unfortunately, due to the heavily intertwined code in ssl_engine_config.c, ssl_engine_init.c and ssl_engine_pphrase.c, which all depends on the modssl_pk_server_t data structure. For better comprehensibility, a detailed listing of the changes follows: ssl_private.h - drop the X509 certs and EVP_PKEY keys arrays from modssl_pk_server_t - use apr_array_header_t for cert_files and key_files - drop tPublicCert from SSLModConfigRec - drop the ssl_algo_t struct and the SSL_ALGO_* and SSL_AIDX_* constants ssl_engine_config.c - change to apr_array_header_t for SSLCertificate[Key]File - drop ssl_cmd_check_aidx_max, i.e. allow an arbitrary number of certs and keys (in theory; currently OpenSSL does not support more than one cert/key per algorithm type) - add deprecation warning for SSLCertificateChainFile ssl_engine_init.c - configure server certs/keys in ssl_init_server_certs (no longer via ssl_pphrase_Handle in ssl_init_Module) - in ssl_init_server_certs, read in certificates and keys with standard OpenSSL API functions (SSL_CTX_use_*_file), and only fall back to ssl_load_encrypted_pkey when encountering an encrypted private key - drop ssl_server_import_cert, ssl_server_import_key, ssl_init_server_check, and ssl_init_ctx_cleanup_server - move the "problematic re-initialization" check to ssl_init_server_ctx ssl_engine_pphrase.c - use servername:port:index as the key identifier, instead of the previously used servername:port:algorithm - ssl_pphrase_Handle overhaul: remove all cert/public-key handling, make it only load a single (encrypted) private key, and rename to ssl_load_encrypted_pkey - in the passphrase prompt message, show the private key file name instead of the vhost id and the algorithm name - do no longer supply the algorithm name as an argument to "exec"-type passphrase prompting programs ssl_util.c - drop ssl_util_algotypeof, ssl_util_algotypestr, ssl_asn1_keystr, and ssl_asn1_table_keyfmt ssl_util_ssl.{c,h} - drop SSL_read_X509 - constify the filename arg for SSL_read_PrivateKey git-svn-id: https://svn.apache.org/repos/asf/httpd/httpd/trunk@1553824 13f79535-47bb-0310-9956-ffa450edef68
This commit is contained in:
@@ -70,52 +70,11 @@ void SSL_set_app_data2(SSL *ssl, void *arg)
|
||||
|
||||
/* _________________________________________________________________
|
||||
**
|
||||
** High-Level Certificate / Private Key Loading
|
||||
** High-Level Private Key Loading
|
||||
** _________________________________________________________________
|
||||
*/
|
||||
|
||||
X509 *SSL_read_X509(char* filename, X509 **x509, pem_password_cb *cb)
|
||||
{
|
||||
X509 *rc;
|
||||
BIO *bioS;
|
||||
BIO *bioF;
|
||||
|
||||
/* 1. try PEM (= DER+Base64+headers) */
|
||||
if ((bioS=BIO_new_file(filename, "r")) == NULL)
|
||||
return NULL;
|
||||
rc = PEM_read_bio_X509 (bioS, x509, cb, NULL);
|
||||
BIO_free(bioS);
|
||||
|
||||
if (rc == NULL) {
|
||||
/* 2. try DER+Base64 */
|
||||
if ((bioS=BIO_new_file(filename, "r")) == NULL)
|
||||
return NULL;
|
||||
|
||||
if ((bioF = BIO_new(BIO_f_base64())) == NULL) {
|
||||
BIO_free(bioS);
|
||||
return NULL;
|
||||
}
|
||||
bioS = BIO_push(bioF, bioS);
|
||||
rc = d2i_X509_bio(bioS, NULL);
|
||||
BIO_free_all(bioS);
|
||||
|
||||
if (rc == NULL) {
|
||||
/* 3. try plain DER */
|
||||
if ((bioS=BIO_new_file(filename, "r")) == NULL)
|
||||
return NULL;
|
||||
rc = d2i_X509_bio(bioS, NULL);
|
||||
BIO_free(bioS);
|
||||
}
|
||||
}
|
||||
if (rc != NULL && x509 != NULL) {
|
||||
if (*x509 != NULL)
|
||||
X509_free(*x509);
|
||||
*x509 = rc;
|
||||
}
|
||||
return rc;
|
||||
}
|
||||
|
||||
EVP_PKEY *SSL_read_PrivateKey(char* filename, EVP_PKEY **key, pem_password_cb *cb, void *s)
|
||||
EVP_PKEY *SSL_read_PrivateKey(const char* filename, EVP_PKEY **key, pem_password_cb *cb, void *s)
|
||||
{
|
||||
EVP_PKEY *rc;
|
||||
BIO *bioS;
|
||||
|
Reference in New Issue
Block a user