Re: Will Post-SSL-Renegotiation be coded for Apache 2.x?

Joe Orton <[email protected]>
Newsgroups gmane.comp.apache.mod-ssl.user
Message-ID <[email protected]>
On Thu, Oct 07, 2004 at 02:32:18PM -0400, Adolfo Bello wrote:
> Hi list:
> 
> I don't know if this is the right list to place this question.
> 
> I've been eagerly awaiting the solution of the certificate renegotiation
> with post problem for Apache2. However, I just took a look at Apache 2.1
> code and found the same comment in ssl_engine_io.c regarding the
> problem: this has not been re-implemented for Apache 2.
> 
> Will the solution be developed? If so, is there any time frame for this
> re-implementation to be released?

It looks like it'll have to be done in 2.0 like it is in 1.3, which is
unfortunate.  If you add yourself to the CC field of the bug below,
you'll find out when someone gets a round tuit.

http://nagoya.apache.org/bugzilla/show_bug.cgi?id=12355

It's a surprisingly difficult problem: it would really be best to solve
at the OpenSSL layer.

joe
______________________________________________________________________
Apache Interface to OpenSSL (mod_ssl)                   www.modssl.org
User Support Mailing List                      [email protected]
Automated List Manager                            [email protected]
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.