mirror of
https://github.com/apache/httpd.git
synced 2025-08-08 15:02:10 +03:00
Extend the scope of SSLSessionCacheTimeout to sessions
resumed by TLS session resumption (RFC 5077). git-svn-id: https://svn.apache.org/repos/asf/httpd/httpd/trunk@1610311 13f79535-47bb-0310-9956-ffa450edef68
This commit is contained in:
3
CHANGES
3
CHANGES
@@ -1,6 +1,9 @@
|
||||
-*- coding: utf-8 -*-
|
||||
Changes with Apache 2.5.0
|
||||
|
||||
*) mod_ssl: Extend the scope of SSLSessionCacheTimeout to sessions
|
||||
resumed by TLS session resumption (RFC 5077). [Rainer Jung]
|
||||
|
||||
*) mod_proxy_ajp: Forward local IP address as a custom request attribute
|
||||
like we already do for the remote port. [Rainer Jung]
|
||||
|
||||
|
@@ -500,7 +500,8 @@ in the Session Cache</description>
|
||||
<usage>
|
||||
<p>
|
||||
This directive sets the timeout in seconds for the information stored in the
|
||||
global/inter-process SSL Session Cache and the OpenSSL internal memory cache.
|
||||
global/inter-process SSL Session Cache, the OpenSSL internal memory cache and
|
||||
for sessions resumed by TLS session resumption (RFC 5077).
|
||||
It can be set as low as 15 for testing, but should be set to higher
|
||||
values like 300 in real life.</p>
|
||||
<example><title>Example</title>
|
||||
|
@@ -1468,6 +1468,10 @@ static apr_status_t ssl_init_server_ctx(server_rec *s,
|
||||
}
|
||||
#endif
|
||||
|
||||
SSL_CTX_set_timeout(sc->server->ssl_ctx,
|
||||
sc->session_cache_timeout == UNSET ?
|
||||
SSL_SESSION_CACHE_TIMEOUT : sc->session_cache_timeout);
|
||||
|
||||
return APR_SUCCESS;
|
||||
}
|
||||
|
||||
|
Reference in New Issue
Block a user