Author |
|
spil
Joined: 27 Aug 2007 Posts: 6
|
Posted: Wed 20 May '15 9:23 Post subject: SSLOpenSSLConfCmd invalid command |
|
|
Trying to set a specific dhparams file after yesterday's disclosure of the logjam vulnerability I found that the VC10 apache build 2.4.12/1.0.1m does not support the SSLOpenSSLConfCmd configuration directive
AH00526: Syntax error on line 130 of conf/httpd.conf:
Invalid command 'SSLOpenSSLConfCmd', perhaps misspelled or defined by a module not included in the server configuration
Any pointers? |
|
Back to top |
|
Steffen Moderator
Joined: 15 Oct 2005 Posts: 3093 Location: Hilversum, NL, EU
|
Posted: Wed 20 May '15 9:53 Post subject: |
|
|
Directive is available in httpd 2.4.8 and later, if using OpenSSL 1.0.2 or later. |
|
Back to top |
|
glsmith Moderator
Joined: 16 Oct 2007 Posts: 2268 Location: Sun Diego, USA
|
Posted: Wed 20 May '15 12:02 Post subject: |
|
|
I don't use that directive (even though I could) and when I test my server I get
Quote: | Good News! This site uses strong (2048-bit or better) key exchange parameters and is safe from the Logjam attack. |
I assume you are getting this directive reading this info from https://weakdh.org/sysadmin.html |
|
Back to top |
|
toothrot
Joined: 20 May 2015 Posts: 1
|
Posted: Wed 20 May '15 23:02 Post subject: |
|
|
Steffen wrote: | 1.0.2 or later. |
Anyone know whether binaries with OpenSSL 1.0.2 will be uploaded at some point? |
|
Back to top |
|
Smitty
Joined: 03 Jan 2008 Posts: 197
|
Posted: Fri 22 May '15 16:05 Post subject: |
|
|
I have the same question. Can we get an Apachelounge version built with OpenSSL 1.0.2a? |
|
Back to top |
|
James Blond Moderator
Joined: 19 Jan 2006 Posts: 7373 Location: Germany, Next to Hamburg
|
Posted: Fri 22 May '15 16:46 Post subject: |
|
|
In my last try in February httpd apache did not compile against 1.0.2 aka the build broke with that version. |
|
Back to top |
|
Smitty
Joined: 03 Jan 2008 Posts: 197
|
Posted: Fri 22 May '15 16:52 Post subject: |
|
|
Did the problem get fixed in 1.0.2a that was released in March? I'm surprised if an issue has existed this long and hasn't been fixed. The 1.0.1 branch is only supported until December 2016. |
|
Back to top |
|
James Blond Moderator
Joined: 19 Jan 2006 Posts: 7373 Location: Germany, Next to Hamburg
|
Posted: Tue 26 May '15 17:57 Post subject: |
|
|
Only 1,5 years? Isn't that long enough to wait for apache compile against 1.0.2 ? |
|
Back to top |
|
Smitty
Joined: 03 Jan 2008 Posts: 197
|
Posted: Tue 26 May '15 20:18 Post subject: |
|
|
LOL! Never hurts to be prepared ahead of time! |
|
Back to top |
|
James Blond Moderator
Joined: 19 Jan 2006 Posts: 7373 Location: Germany, Next to Hamburg
|
|
Back to top |
|