310abe64ef
Fix CAN-2004-0885: * modules/ssl/ssl_engine_kernel.c (ssl_hook_Access): Ensure that a correct cipher suite has been negotiated, else deny access. * modules/ssl/ssl_engine_init.c (ssl_init_ctx_protocol): With OpenSSL 0.9.7, prevent session resumption during a renegotiation to force the client to negotiate a new (and acceptable) cipher suite. Credits: Hartmut Keil, Joe Orton |
||
---|---|---|
.. | ||
apache.sh | ||
apache2libs.sh | ||
exp-apr-kqueue.patch | ||
exp-windowsupdate.patch | ||
patch-configure.in | ||
patch-docs:conf:httpd-std.conf.in | ||
patch-docs:conf:ssl-std.conf.in | ||
patch-Makefile.in | ||
patch-modules:ssl:mod_ssl.h | ||
patch-secfix-CAN-2004-0885 | ||
patch-server:main.c | ||
patch-src:apr:build:buildcheck.sh | ||
patch-srclib:apr-util:config.layout | ||
patch-srclib:apr-util:misc:apr_reslist.c | ||
patch-srclib:apr-util:xml:expat:buildconf.sh | ||
patch-srclib:apr-utils:build:dbm.m4 | ||
patch-srclib:apr:buildconf | ||
patch-srclib:apr:config.layout | ||
patch-srclib:apr:threadproc:unix:procsup.c | ||
patch-support:apachectl.in | ||
patch-support:log_server_status.in |