Hi,
First of all, I'm a newbie in SSL, Apache and Apache module writing and
would truly appreciate any help, tips or trick. I'm trying to write a C
module that allows dynamic SSL renegotiation, that is, the module has the
option of invoking SSL-renegotiate during the handler phase. The main
intent is to allow the client to send different user certificate while on
the same session. I created a function by adopting most of the codes from
ssl_hook_Access of ssl_engine_kernel.c. When I tried to call this module
from the browser, it manages to force the browser to pop up the client
certificate window, but gives the error "The document contains no data"
after the continue button is pressed - despite the coded HTML response in
the module. Any help will be appreciated.
The code is attached... thanks beforehand.
-CG
int handle_dynamic_ssl_renegotiation(request_rec *r) {
SSLDirConfigRec *dc;
SSL *ssl;
X509 *cert;
char *cp;
int i;
ssl = ap_ctx_get(r->connection->client->ctx, "ssl");
/* SSL must be on */
if (ssl == NULL)
return DECLINED;
/* full renegotiation */
ssl_log(r->server, SSL_LOG_INFO, "Requesting dynamic connection
renegotiation");
ssl_log(r->server, SSL_LOG_TRACE, "Performing dynamic renegotiation: full
handshake protocol");
if (r->main != NULL)
SSL_set_session_id_context(ssl, (unsigned char*)&(r->main),
sizeof(r->main));
else
SSL_set_session_id_context(ssl, (unsigned char*)&r, sizeof(r));
SSL_renegotiate(ssl);
SSL_do_handshake(ssl);
if (SSL_get_state(ssl) != SSL_ST_OK) {
ssl_log(r->server, SSL_LOG_ERROR, "Dynamic renegotiation request
failed");
return FORBIDDEN;
}
ssl_log(r->server, SSL_LOG_INFO, "Awaiting dynamic renegotiation
handshake");
SSL_set_state(ssl, SSL_ST_ACCEPT);
SSL_do_handshake(ssl);
if (SSL_get_state(ssl) != SSL_ST_OK) {
ssl_log(r->server, SSL_LOG_ERROR, "Dynamic renegotiation handshake
failed: Not accepted by client!?");
return FORBIDDEN;
}
/* Remember the peer certificate's DN */
if ((cert = SSL_get_peer_certificate(ssl)) != NULL) {
cp = X509_NAME_oneline(X509_get_subject_name(cert), NULL, 0);
ap_ctx_set(r->connection->client->ctx, "ssl::client::dn",
ap_pstrdup(r->connection->pool, cp));
free(cp);
}
/* Finally check for acceptable renegotiation result */
if (dc->nVerifyClient != SSL_CVERIFY_NONE) {
if (dc->nVerifyClient == SSL_CVERIFY_REQUIRE
&& SSL_get_verify_result(ssl) != X509_V_OK) {
ssl_log(r->server, SSL_LOG_ERROR, "Dynamic renegotiation
handshake failed: Client verification failed");
return FORBIDDEN;
}
if (dc->nVerifyClient == SSL_CVERIFY_REQUIRE
&& SSL_get_peer_certificate(ssl) == NULL) {
ssl_log(r->server, SSL_LOG_ERROR, "Dynamic renegotiation
handshake failed: Client certificate missing");
return FORBIDDEN;
}
}
/* FIXME: Must check other stuff so that no downgrade of mod_ssl
directives!! */
return OK;
}
______________________________________________________________________
Apache Interface to OpenSSL (mod_ssl) www.modssl.org
User Support Mailing List [EMAIL PROTECTED]
Automated List Manager [EMAIL PROTECTED]