svn commit: r1805530 - in /tomcat/trunk/java/org/apache/tomcat/util/net: AprEndpoint.java openssl/OpenSSLContext.java

2017-08-19 Thread rjung
Author: rjung Date: Sat Aug 19 22:20:56 2017 New Revision: 1805530 URL: http://svn.apache.org/viewvc?rev=1805530&view=rev Log: Tone down log message for new OpenSSLConf from info to debug. Modified: tomcat/trunk/java/org/apache/tomcat/util/net/AprEndpoint.java tomcat/trunk/java/org/apache

Re: OpenSSL SSL_CONF_cmd API

2017-08-19 Thread Rainer Jung
Am 16.08.2017 um 23:38 schrieb Rainer Jung: Am 16.08.2017 um 14:45 schrieb Rainer Jung: Am 13.08.2017 um 19:37 schrieb Mark Thomas: On 13/08/17 16:42, Rainer Jung wrote: Hi, OpenSSl has an API named SSL_CONF_cmd. Te API allows application using OpenSSL to no longer implement an application sp

Config warning when using OpenSSL config items and useOpenSSL=true

2017-08-19 Thread Rainer Jung
Assume tcantive and OpenSSL is available. When using the AprLifecycleListener with useOpenssl="true" (default) and useAprConnector="false" (also default) with a Java NIO or NIO2 connector and *not* setting the sslImplementationName one gets warnings for each config item which is OpenSSL only.

svn commit: r1805529 - in /tomcat/trunk/java/org/apache/tomcat/util/net: AprEndpoint.java SSLHostConfig.java openssl/OpenSSLContext.java

2017-08-19 Thread rjung
Author: rjung Date: Sat Aug 19 21:35:50 2017 New Revision: 1805529 URL: http://svn.apache.org/viewvc?rev=1805529&view=rev Log: Update enabledProtocols and enabledCiphers in SSLHostConfig after OpenSSLConf has been applied. This is needed, because the Manager webapp feature of listing the current

svn commit: r1805528 - in /tomcat/trunk: java/org/apache/catalina/startup/ java/org/apache/tomcat/util/net/ java/org/apache/tomcat/util/net/openssl/ webapps/docs/

2017-08-19 Thread rjung
Author: rjung Date: Sat Aug 19 21:32:23 2017 New Revision: 1805528 URL: http://svn.apache.org/viewvc?rev=1805528&view=rev Log: Add support for the OpenSSL SSL_CONF API when using TLS with OpenSSL implementation. This will need tcnative 1.2.13. It can be used by adding OpenSSLConf elements undern

svn commit: r1805527 - in /tomcat/trunk/java/org/apache/tomcat/jni: SSL.java SSLConf.java

2017-08-19 Thread rjung
Author: rjung Date: Sat Aug 19 20:50:13 2017 New Revision: 1805527 URL: http://svn.apache.org/viewvc?rev=1805527&view=rev Log: Add access to tcnative SSL_CONF API and some constants used by it. Using the new API needs tcnative 1.2.13 though. Added: tomcat/trunk/java/org/apache/tomcat/jni/SSL

svn commit: r1805526 - /tomcat/trunk/java/org/apache/tomcat/jni/SSLContext.java

2017-08-19 Thread rjung
Author: rjung Date: Sat Aug 19 20:49:09 2017 New Revision: 1805526 URL: http://svn.apache.org/viewvc?rev=1805526&view=rev Log: Add access to new native API SSLContext.getCiphers(). This needs tcnative 1.2.13 though. Modified: tomcat/trunk/java/org/apache/tomcat/jni/SSLContext.java Modified:

svn commit: r1805525 - in /tomcat/trunk: java/org/apache/tomcat/util/net/openssl/OpenSSLContext.java java/org/apache/tomcat/util/net/openssl/OpenSSLEngine.java webapps/docs/changelog.xml

2017-08-19 Thread rjung
Author: rjung Date: Sat Aug 19 20:31:31 2017 New Revision: 1805525 URL: http://svn.apache.org/viewvc?rev=1805525&view=rev Log: When using a Java connector in combination with the OpenSSL TLS implementation, do not configure each SSL connection object via the OpenSSLEngine. For OpenSSL the SSL obje

svn commit: r1805524 - /tomcat/trunk/java/org/apache/tomcat/util/net/openssl/OpenSSLEngine.java

2017-08-19 Thread rjung
Author: rjung Date: Sat Aug 19 20:20:49 2017 New Revision: 1805524 URL: http://svn.apache.org/viewvc?rev=1805524&view=rev Log: AVAILABLE_CIPHER_SUITES contains the ciphers with JSSE names, so the check needs to be done before replacing with the OpenSSL name. Modified: tomcat/trunk/java/org/ap

svn commit: r1805523 - /tomcat/trunk/java/org/apache/tomcat/jni/SSL.java

2017-08-19 Thread rjung
Author: rjung Date: Sat Aug 19 20:14:48 2017 New Revision: 1805523 URL: http://svn.apache.org/viewvc?rev=1805523&view=rev Log: Fix a comment typo. Modified: tomcat/trunk/java/org/apache/tomcat/jni/SSL.java Modified: tomcat/trunk/java/org/apache/tomcat/jni/SSL.java URL: http://svn.apache.org

svn commit: r1805522 - in /tomcat/native/trunk: native/include/ssl_private.h native/src/sslconf.c xdocs/miscellaneous/changelog.xml

2017-08-19 Thread rjung
Author: rjung Date: Sat Aug 19 20:10:13 2017 New Revision: 1805522 URL: http://svn.apache.org/viewvc?rev=1805522&view=rev Log: Add support for the OpenSSL SSL_CONF API. Added: tomcat/native/trunk/native/src/sslconf.c (with props) Modified: tomcat/native/trunk/native/include/ssl_private.

svn commit: r1805521 - in /tomcat/native/trunk: native/src/sslcontext.c xdocs/miscellaneous/changelog.xml

2017-08-19 Thread rjung
Author: rjung Date: Sat Aug 19 20:07:54 2017 New Revision: 1805521 URL: http://svn.apache.org/viewvc?rev=1805521&view=rev Log: Add SSLContext.getCiphers(). Note that for OpenSSL < 1.1.0 there is no SSL_CTX_get_ciphers(), so we create a temporary SSL from the SSL_CTX and use SSL_get_ciphers() in t

[Bug 61289] NullPointerException in Response.generateCookieString()

2017-08-19 Thread bugzilla
https://bz.apache.org/bugzilla/show_bug.cgi?id=61289 Chuck Caldarale changed: What|Removed |Added Resolution|--- |INVALID Status|REOPENED

[Bug 61289] NullPointerException in Response.generateCookieString()

2017-08-19 Thread bugzilla
https://bz.apache.org/bugzilla/show_bug.cgi?id=61289 hugo changed: What|Removed |Added Status|RESOLVED|REOPENED Resolution|INVALID