Changes with Apache 2.3.0
[Remove entries to the current 2.0 and 2.2 section below, when backported]
+ *) Teach mod_ssl to use arbitraty OIDs in an SSLRequire directive,
+ allowing string-valued client certificate attributes to be used for
+ access control, as in: SSLRequire "value" in OID("1.3.6.1.4.1.18060.1")
+ [Martin Kraemer, David Reid]
+
Changes with Apache 2.1.7
*) SECURITY: CAN-2005-2491 (cve.mitre.org):
Fix integer overflows in PCRE in quantifier parsing which could
links for clients not using an Authorization header. [Graham Leggett,
Jon Snow <jsnow27 gatesec.net>]
- *) Teach mod_ssl to use arbitraty OIDs in an SSLRequire directive,
- allowing string-valued client certificate attributes to be used for
- access control, as in: SSLRequire "value" in OID("1.3.6.1.4.1.18060.1")
- [Martin Kraemer, David Reid]
-
*) mod_cache: Restore the HTTP status of cached responses.
[Hansjoerg Pehofer <hansjoerg.pehofer uibk.ac.at>]