summaryrefslogtreecommitdiff
path: root/www/ap-ssl
AgeCommit message (Collapse)AuthorFilesLines
2004-03-26PKGREVISION bump after openssl-security-fix-update to 0.9.6m.wiz1-2/+2
Buildlink files: RECOMMENDED version changed to current version.
2003-11-12PKGREVISION++ after openssl update.jschauma1-1/+2
2003-11-02Updated ap-ssl to 2.8.16.grant2-7/+7
Major changes since 2.8.15: *) Upgraded to Apache 1.3.29 *) Avoid memory corruption in certificate handling caused by a heap memory double-freeing situation. *) Allow "HTTPS" variable to be passed through by suEXEC. *) Clear the OpenSSL error code in pass phrase reading code to workaround the following situation: multiple keys, all with different passphrases -- entering the correct pass phrase at each prompt leads to an OpenSSL error message after the last prompt. *) Reverted the recent change where ap_cleanup_for_exec() called ap_kill_alloc_shared(). This caused nasty side-effects in other processes and is not necessary at all (because shared memory segments are not inherited across exec). *) mod_ssl was checking the OpenSSL error reason code against SSL_R_HTTP_REQUEST and concluded the result is an SSL error. Since OpenSSL reason codes are not unique, this isn't always the case. It now additionally checks that the library is the SSL library.
2003-09-12kill all references to gcc.buildlink2.mk and compiler.mk, and definegrant1-2/+1
USE_GCC2 or USE_GCC3 where appropriate. the functionality of the old gcc.buildlink2.mk has been rolled into compiler.mk now, which is automatically used. more changes to come later...
2003-07-19Update "ap-ssl" package to version 2.8.15. Changes since version 2.8.14:tron2-7/+7
- Upgraded to Apache 1.3.28 - Take over security fix from Apache 2.0 related to per-directory renogotiations.
2003-07-17s/netbsd.org/NetBSD.org/grant1-2/+2
2003-05-27use mk/gcc.buildlink2.mkgrant1-2/+2
2003-05-06Drop trailing whitespace. Ok'ed by wiz.jmmv1-4/+4
2003-04-15include lang/gcc/buildlink2.mk, so this can find libgcc from lang/gccgrant1-1/+2
if we're using it.
2003-04-10Update to 2.8.14:wiz3-8/+21
Changes with mod_ssl 2.8.14 (18-Mar-2002 to 21-Mar-2003) *) Fixed logic in the destruction of a temporary certificate structure and this way avoid a crash due to freeing NULL object. *) Removed one newly introduced X509_free() call in the context of SSL_get_certificate(), because this function does not increment a reference count (although SSL_get_peer_certificate() does). *) Fixed hash-table based shared memory session cache (shmht) implementation by making sure that the underlying hash table library does not crash if memory cannot be allocated. Changes with mod_ssl 2.8.13 (23-Oct-2002 to 18-Mar-2003) *) Always enforce RSA blinding on RSA private keys in order to be resistent to timing attacks. *) Added timeout also to the "pre-sucking" of the trailing data in POST request handling. *) Correctly shutdown shared memory pools on fork+exec situations. *) Bugfix SSL client certificate verification: OpenSSL was not informed with SSL_set_verify_result(ssl, X509_V_OK) in case mod_ssl forced the verification to be ok. *) Consistently use OPENSSL_free() instead of plain free() to deallocate memory chunks allocated inside OpenSSL. *) Fixed various memory leaks related to X509 certificates. New patch-ac sent to maintainer.
2003-03-14(1) Publicly export the value of _OPSYS_RPATH_NAME as RPATH_FLAG;jlam1-4/+4
Makefiles simply need to use this value often, for better or for worse. (2) Create a new variable FIX_RPATH that lists variables that should be cleansed of -R or -rpath values if ${_USE_RPATH} is "no". By default, FIX_RPATH contains LIBS, X11_LDFLAGS, and LDFLAGS, and additional variables may be appended from package Makefiles.
2003-01-28Instead of including bsd.pkg.install.mk directly in a package Makefile,jlam1-2/+2
have it be automatically included by bsd.pkg.mk if USE_PKGINSTALL is set to "YES". This enforces the requirement that bsd.pkg.install.mk be included at the end of a package Makefile. Idea suggested by Julio M. Merino Vidal <jmmv at menta.net>.
2002-12-03allow 'mkcert' to work on Solaris by using ${SH} rather than /bin/sh.grant2-33/+38
2002-11-19Bump PKGREVISION of ap-ssl: no longer install apache_start.conf; Apache/SSLjlam4-15/+16
users should just add: apache_start="startssl" to /etc/rc.conf.
2002-11-18Fix BUILDLINK_DEPENDS.apachemartti1-2/+2
2002-10-25Update "apache" package to version 1.3.27nb1 which is now based versiontron1-2/+2
2.8.12-1.3.27 of "mod_ssl" module so that one doesn't need two version of the "mod_ssl" sources to build "apache".
2002-10-25Update ap-ssl package to 2.8.12.taca2-6/+6
Changes with mod_ssl 2.8.12 (04-Oct-2002 to 23-Oct-2002) *) Fixed potential Cross-Site-Scripting bug. *) Allow also 8192 bytes of shared memory data size.
2002-10-04Update "ap-ssl" package to version 2.8.11. Changes since 2.8.10:tron2-8/+7
- Upgraded to Apache 1.3.27. - Fixed internal error handling for CRL verification. - Initialize OpenSSL ENGINE before initializing OpenSSL to workaround problems with the PRNG. - Also find "openssl" executable in "sbin" directories. - Honor specified number of maximum bytes on SSLRandomSeed if reading from EGD. - Fixed generation of SSL_CLIENT_CERT_CHAIN_[0-9] variables.
2002-09-27Update BUILDLINK_DEPENDS.apache to apache-1.3.26nb5.taca1-2/+2
Should I bump ap-ssl's PKG_REVISION, too?
2002-09-24Complete standardization of messages according to latest pkglint.wiz1-3/+3
2002-08-26format and word Apache module MESSAGEs consistently.grant1-1/+1
2002-08-25Merge packages from the buildlink2 branch back into the main trunk thatjlam2-7/+14
have been converted to USE_BUILDLINK2.
2002-08-01Crank PKGREVISION here, too.mycroft1-1/+2
2002-08-01Grrrr, stupid static version number for apache.mycroft1-2/+2
2002-07-31Want apache-1.3.26nb3 now.wiz1-2/+2
2002-06-24Fix version number in dependence on "apache" package.tron1-2/+2
2002-06-24Update ap-ssl to 2.8.10 (mod_ssl 2.8.10).taca2-6/+6
Changes with mod_ssl 2.8.10 (19-Jun-2002 to 24-Jun-2002) *) Fixed off-by-one buffer overflow bug in the compatibility functionality (mapping of old directives to new ones). *) Fixed memory leak in processing of CA certificates. *) In case there is actually a certificate chain in the session cache, we now use the value of SSL_get_peer_certificate(ssl) to verify as it will have been removed from the chain before it was put in the cache. *) Seed the PRNG with a maximum of 1K from the internal scoreboard.
2002-06-19Add missing "source/" to master site entries for "ftp.funet.fi".tron1-2/+2
2002-06-19Fix dependence on "apachage" package.tron1-2/+2
2002-06-19update for now-available mod_ssl-2.8.9-1.3.26jdolecek2-11/+6
2002-06-19add hack to compile with Apache 1.3.26; this should be removed oncejdolecek1-1/+6
newer version of mod_ssl would be available.
2002-06-19Add a two mirror sites because the main site isn't that fast.tron1-3/+5
2002-06-18Update version number in dependence on "apache".tron1-2/+2
2002-04-02Update www/ap-ssl to 2.8.8. Changes from version 2.8.7 include:jlam2-7/+7
*) Upgraded to Apache 1.3.24 *) Support leading whitespaces in commands of SSLLog "|..." directives. *) Fixed timeout handling on connection establishment by correctly resetting the timeout on errors. *) Fixed two memory leaks related to CA certificate configuration. *) Fixed memory leak related to temporary DH key handling. *) Fixed memory leak on shutdown if CRLs are used. *) Fixed remaining SIGBUS problems on SPARC inside SHMCB session cache implementation.
2002-02-28Update www/ap-ssl to 2.8.7 from the mod_ssl-2.8.7-1.3.23 distribution.jlam2-8/+8
Relevant changes from version 2.8.6 include: *) Fixed potential buffer overflow in DBM and SHMHT session cache if very very large certificate chains are used. *) Compliance with POSIX 1003.1-2001 (SUSv3) by replacing obsolete "head -1" and "tail -1" constructs with sed variants in scripts.
2002-02-01Update www/ap-ssl to 2.8.6:jlam2-15/+11
*) Upgraded to Apache 1.3.23 *) Fixed a subtle indexing bug in SHMCB. Each sub-cache used an indexing structure that (correctly) used index values (and ranges) as "unsigned int", but the meta-structure in the header had these ranged as "unsigned char". *) Perform the SHMCB remove operation under mutual exclusion to prevent a inter-process synchronization problem. *) Made sure that mod_ssl does not segfault in case of SCOREBOARD_SIZE < 1024. *) Merged in the SDBM patch from Uwe Ohse which fixes a problem with sdbms .dir file, which arrises when a second .dir block is needed for the first time. read() returns 0 in that case, and the library forgot to initialize that new block. A related problem is that the calculation of db->maxbno is wrong. It just appends 4096*BYTESIZ bits, which is not enough except for small databases (.dir basically doubles everytime it's too small).
2002-01-01Move ownership of SSL-related config directories from www/apache to thisjlam1-22/+21
package.
2001-12-02bsd.pkg.install.mk calls the INSTALL script at the right timesjlam1-3/+1
automatically, so no need to do it ourselves.
2001-11-26Forgot a CONFDIR -> PKG_SYSCONFDIR replacement.jlam3-6/+6
2001-11-25PKG_SYSCONFDIR is where the configuration files for a package may be found.jlam1-13/+11
This value may be customized in various ways: PKG_SYSCONFBASE is the main config directory under which all package configuration files are to be found. PKG_SYSCONFSUBDIR is the subdirectory of PKG_SYSCONFBASE under which the configuration files for a particular package may be found. PKG_SYSCONFDIR.${PKGBASE} overrides the value of ${PKG_SYSCONFDIR} for a particular package. Users will typically want to set PKG_SYSCONFBASE to /etc, or accept the default location of ${PREFIX}/etc. This obsoletes the use of CONFDIR, which was active for only 6 days, so no need to have a workaround to still accept old CONFDIR settings.
2001-11-19Adapt to use shared INSTALL/DEINSTALL scripts by using the logic injlam3-183/+36
bsd.pkg.install.mk: * Remove old DEINSTALL/INSTALL scripts. * Move some text printed at POST-INSTALL time into the MESSAGE file. * Adjust rc.d scripts to respect rc.conf settings, so that the script may be directly copied into /etc/rc.d.
2001-11-01Move pkg/ files into package's toplevel directoryzuntum5-4/+4
2001-10-17Update ap-ssl to 2.8.5 from the mod_ssl-2.8.5-1.3.22 distribution.jlam3-13/+15
Changes from version 2.8.4 include: *) Upgraded to Apache 1.3.22 *) Fixed check whether server certificate wildcard CommonName (CN) matches the configured server name. *) Fixed buffer overflow.
2001-09-27Mechanical changes to 375 files to change dependency patterns of the formjlam1-2/+2
foo-* to foo-[0-9]*. This is to cause the dependencies to match only the packages whose base package name is "foo", and not those named "foo-bar". A concrete example is p5-Net-* matching p5-Net-DNS as well as p5-Net. Also change dependency examples in Packages.txt to reflect this.
2001-07-13In package Makefiles, create FILES_SUBST instead of duplicating sedjlam2-3/+5
expression for substituting in DEINSTALL/INSTALL scripts. Use "${CMP} -s" instead of "diff -q" since the former is more portable across OSes.
2001-06-09Update ap-ssl to 2.8.4 using mod_ssl-2.8.4-1.3.20. Relevant changes fromjlam2-8/+8
version 2.8.3 include: *) Upgraded to Apache 1.3.20
2001-06-09Update ap-ssl to 2.8.4 using mod_ssl-2.8.4-1.3.20. The only relevant changejlam1-17/+19
from version 2.8.3 is upgrading the mod_ssl sources to patch against Apache 1.3.20. The pkgsrc changes include unifying repeated SED replacement info for various files into one location, FILES_SUBST.
2001-05-14Update ap-ssl to 2.8.3. Changes from version 2.8.2 include:jlam2-7/+7
*) Allow loadcacert.cgi script to work inside mod_perl. *) Fixed typo in the directive descriptions in mod_ssl.c *) Fixed ENGINE support: the engine support is are now already loaded at configure time. Else mod_ssl fails to find them.
2001-04-30Add APACHE_SYSCONFDIR to BUILD_DEFS.jlam1-1/+3
2001-04-29Need apache>=1.3.19nb1, the apache package version with the mod_ssl-2.8.2jlam1-2/+2
patches.