<feed xmlns='http://www.w3.org/2005/Atom'>
<title>mod_nss.git/docs, branch master</title>
<subtitle>Unnamed repository; edit this file 'description' to name the repository.</subtitle>
<link rel='alternate' type='text/html' href='https://fedorapeople.org/cgit/rcritten/public_git/mod_nss.git/'/>
<entry>
<title>Check filesystem permissions on NSS database at startup</title>
<updated>2016-03-01T16:42:27+00:00</updated>
<author>
<name>Rob Crittenden</name>
<email>rcritten@redhat.com</email>
</author>
<published>2016-03-01T03:33:23+00:00</published>
<link rel='alternate' type='text/html' href='https://fedorapeople.org/cgit/rcritten/public_git/mod_nss.git/commit/?id=105d65bfedfa0e381dcebd197ef67aab799fc8b1'/>
<id>105d65bfedfa0e381dcebd197ef67aab799fc8b1</id>
<content type='text'>
See if the configured user has read access to the NSS database
during initialization so the server can gracefully shutdown
rather than ending up in a forking loop because the database is
owned by root and is therefore unreadable once Apache starts
forking.

Adds a new configuration option, NSSSkipPermissionCheck &lt;on/off&gt;,
to skip this check in case something goes wrong.

https://fedorahosted.org/mod_nss/ticket/3
</content>
<content type='xhtml'>
<div xmlns='http://www.w3.org/1999/xhtml'>
<pre>
See if the configured user has read access to the NSS database
during initialization so the server can gracefully shutdown
rather than ending up in a forking loop because the database is
owned by root and is therefore unreadable once Apache starts
forking.

Adds a new configuration option, NSSSkipPermissionCheck &lt;on/off&gt;,
to skip this check in case something goes wrong.

https://fedorahosted.org/mod_nss/ticket/3
</pre>
</div>
</content>
</entry>
<entry>
<title>Add server support for DHE ciphers</title>
<updated>2016-02-29T21:09:17+00:00</updated>
<author>
<name>Christian Heimes</name>
<email>cheimes@redhat.com</email>
</author>
<published>2016-02-08T14:52:25+00:00</published>
<link rel='alternate' type='text/html' href='https://fedorapeople.org/cgit/rcritten/public_git/mod_nss.git/commit/?id=9205812071bcd7bcf098efd80b82ec2bc1a62da4'/>
<id>9205812071bcd7bcf098efd80b82ec2bc1a62da4</id>
<content type='text'>
Similar patch was provided by Vitezslav Cizek &lt;vcizek@suse.com&gt;

Heavily modified by Rob Crittenden &lt;rcritten@redhat.com&gt;

https://fedorahosted.org/mod_nss/ticket/15
</content>
<content type='xhtml'>
<div xmlns='http://www.w3.org/1999/xhtml'>
<pre>
Similar patch was provided by Vitezslav Cizek &lt;vcizek@suse.com&gt;

Heavily modified by Rob Crittenden &lt;rcritten@redhat.com&gt;

https://fedorahosted.org/mod_nss/ticket/15
</pre>
</div>
</content>
</entry>
<entry>
<title>Cleanup to remove a slew of trailing whitespace</title>
<updated>2015-10-02T20:51:57+00:00</updated>
<author>
<name>Rob Crittenden</name>
<email>rcritten@redhat.com</email>
</author>
<published>2015-10-02T19:34:36+00:00</published>
<link rel='alternate' type='text/html' href='https://fedorapeople.org/cgit/rcritten/public_git/mod_nss.git/commit/?id=44409398b2bb63a092e16db686f4ddcd2cd88554'/>
<id>44409398b2bb63a092e16db686f4ddcd2cd88554</id>
<content type='text'>
</content>
<content type='xhtml'>
<div xmlns='http://www.w3.org/1999/xhtml'>
<pre>
</pre>
</div>
</content>
</entry>
<entry>
<title>Add support for Server Name Indication (SNI)</title>
<updated>2015-10-02T20:51:56+00:00</updated>
<author>
<name>Rob Crittenden</name>
<email>rcritten@redhat.com</email>
</author>
<published>2015-09-24T21:13:20+00:00</published>
<link rel='alternate' type='text/html' href='https://fedorapeople.org/cgit/rcritten/public_git/mod_nss.git/commit/?id=00fe09480dfd28674661830d8a045e0f560bbe51'/>
<id>00fe09480dfd28674661830d8a045e0f560bbe51</id>
<content type='text'>
Uses a hash table to pair up server names and nicknames and
a lookup is done during the handshake to determine which
nickname to be used, and therefore which VirtualHost.

Based heavily on patch from Stanislav Tokos &lt;stokos@suse.de&gt;
</content>
<content type='xhtml'>
<div xmlns='http://www.w3.org/1999/xhtml'>
<pre>
Uses a hash table to pair up server names and nicknames and
a lookup is done during the handshake to determine which
nickname to be used, and therefore which VirtualHost.

Based heavily on patch from Stanislav Tokos &lt;stokos@suse.de&gt;
</pre>
</div>
</content>
</entry>
<entry>
<title>Add 'v' to refererences of protocols (e.g. SSLv3)</title>
<updated>2015-07-29T12:45:50+00:00</updated>
<author>
<name>Matthew Harmsen</name>
<email>mharmsen@redhat.com</email>
</author>
<published>2015-07-28T20:17:57+00:00</published>
<link rel='alternate' type='text/html' href='https://fedorapeople.org/cgit/rcritten/public_git/mod_nss.git/commit/?id=bb1011ce19730ec168512205dfcf5f0b5d9e4657'/>
<id>bb1011ce19730ec168512205dfcf5f0b5d9e4657</id>
<content type='text'>
BZ #1066236
</content>
<content type='xhtml'>
<div xmlns='http://www.w3.org/1999/xhtml'>
<pre>
BZ #1066236
</pre>
</div>
</content>
</entry>
<entry>
<title>Add support for TLS Session Tickets (RFC 5077)</title>
<updated>2015-06-11T17:44:04+00:00</updated>
<author>
<name>Rob Crittenden</name>
<email>rcritten@redhat.com</email>
</author>
<published>2015-06-11T17:44:04+00:00</published>
<link rel='alternate' type='text/html' href='https://fedorapeople.org/cgit/rcritten/public_git/mod_nss.git/commit/?id=b77f4c23aa0f8af00d119299339d0f766a071e48'/>
<id>b77f4c23aa0f8af00d119299339d0f766a071e48</id>
<content type='text'>
New server/vhost config option, NSSSessionTickets, to enable
or disable TLS Session Tickets support. This is off by default
in NSS.
</content>
<content type='xhtml'>
<div xmlns='http://www.w3.org/1999/xhtml'>
<pre>
New server/vhost config option, NSSSessionTickets, to enable
or disable TLS Session Tickets support. This is off by default
in NSS.
</pre>
</div>
</content>
</entry>
<entry>
<title>Add RenegBufferSize option</title>
<updated>2015-06-10T22:02:17+00:00</updated>
<author>
<name>Rob Crittenden</name>
<email>rcritten@redhat.com</email>
</author>
<published>2015-06-10T22:01:45+00:00</published>
<link rel='alternate' type='text/html' href='https://fedorapeople.org/cgit/rcritten/public_git/mod_nss.git/commit/?id=a62526d425dcbeaa1486cf685c2927afa0459e1d'/>
<id>a62526d425dcbeaa1486cf685c2927afa0459e1d</id>
<content type='text'>
Control the buffer size used on a POST when SSL renegotiation is
being done. The default is 128K.

Resolves BZ 1214366
</content>
<content type='xhtml'>
<div xmlns='http://www.w3.org/1999/xhtml'>
<pre>
Control the buffer size used on a POST when SSL renegotiation is
being done. The default is 128K.

Resolves BZ 1214366
</pre>
</div>
</content>
</entry>
<entry>
<title>Add compatibility for mod_ssl-style cipher definitions</title>
<updated>2014-12-02T18:59:03+00:00</updated>
<author>
<name>Rob Crittenden</name>
<email>rcritten@redhat.com</email>
</author>
<published>2014-11-12T16:48:23+00:00</published>
<link rel='alternate' type='text/html' href='https://fedorapeople.org/cgit/rcritten/public_git/mod_nss.git/commit/?id=2d1650900f4d47dc43400d826c0f7e1a7c5229b8'/>
<id>2d1650900f4d47dc43400d826c0f7e1a7c5229b8</id>
<content type='text'>
- Add Camelia ciphers
- Remove Fortezza ciphers
- Add TLSv1.2-specific ciphers

Resolves BZ: #862938
</content>
<content type='xhtml'>
<div xmlns='http://www.w3.org/1999/xhtml'>
<pre>
- Add Camelia ciphers
- Remove Fortezza ciphers
- Add TLSv1.2-specific ciphers

Resolves BZ: #862938
</pre>
</div>
</content>
</entry>
<entry>
<title>Completely remove support for SSLv2</title>
<updated>2014-11-12T16:35:06+00:00</updated>
<author>
<name>Rob Crittenden</name>
<email>rcritten@redhat.com</email>
</author>
<published>2014-11-06T21:44:20+00:00</published>
<link rel='alternate' type='text/html' href='https://fedorapeople.org/cgit/rcritten/public_git/mod_nss.git/commit/?id=f8b6ab7dab90e92537de3cddc01d915d31bb87fc'/>
<id>f8b6ab7dab90e92537de3cddc01d915d31bb87fc</id>
<content type='text'>
</content>
<content type='xhtml'>
<div xmlns='http://www.w3.org/1999/xhtml'>
<pre>
</pre>
</div>
</content>
</entry>
<entry>
<title>Add support for sqlite NSS databases</title>
<updated>2014-10-28T21:41:22+00:00</updated>
<author>
<name>Rob Crittenden</name>
<email>rcritten@redhat.com</email>
</author>
<published>2014-10-28T21:41:22+00:00</published>
<link rel='alternate' type='text/html' href='https://fedorapeople.org/cgit/rcritten/public_git/mod_nss.git/commit/?id=b5d1505fc81a33aa10d013efd247d00f631fc681'/>
<id>b5d1505fc81a33aa10d013efd247d00f631fc681</id>
<content type='text'>
We do a chdir() to the NSS database location so that libnssckbi.so
is available when the database is opened. Strip off a sql: prefix
if one is available. This allows the new sqlite format to work.

Add an additional test pass configuring NSS using the sqlite format.
This requires a bit of a hack to pass in the value to python but
it will work for now.

Resolves: #1057650
</content>
<content type='xhtml'>
<div xmlns='http://www.w3.org/1999/xhtml'>
<pre>
We do a chdir() to the NSS database location so that libnssckbi.so
is available when the database is opened. Strip off a sql: prefix
if one is available. This allows the new sqlite format to work.

Add an additional test pass configuring NSS using the sqlite format.
This requires a bit of a hack to pass in the value to python but
it will work for now.

Resolves: #1057650
</pre>
</div>
</content>
</entry>
</feed>
