8335b1
diff --git a/docs/manual/mod/mod_ssl.html.en b/docs/manual/mod/mod_ssl.html.en
8335b1
index ca178ab..4580f1c 100644
8335b1
--- a/docs/manual/mod/mod_ssl.html.en
8335b1
+++ b/docs/manual/mod/mod_ssl.html.en
8335b1
@@ -57,6 +57,7 @@ to provide the cryptography engine.

8335b1
 
  • SSLCertificateKeyFile
  • 8335b1
     
  • SSLCipherSuite
  • 8335b1
     
  • SSLCompression
  • 8335b1
    +
  • SSLSessionTickets
  • 8335b1
     
  • SSLCryptoDevice
  • 8335b1
     
  • SSLEngine
  • 8335b1
     
  • SSLFIPS
  • 8335b1
    @@ -797,6 +798,26 @@ CRIME attack).

    8335b1
     
    8335b1
     
    8335b1
     
    8335b1
    +
    8335b1
    +
    top
    8335b1
    +
    8335b1
    +
    8335b1
    +Description:Enable or disable use of TLS session tickets
    8335b1
    +Syntax:SSLSessionTickets on|off
    8335b1
    +Default:SSLCompression on
    8335b1
    +Context:server config, virtual host
    8335b1
    +Status:Extension
    8335b1
    +Module:mod_ssl
    8335b1
    +Compatibility:Available.
    8335b1
    +
    8335b1
    +

    This directive allows to enable or disable the use of TLS session tickets(RFC 5077).

    8335b1
    +
    8335b1
    +

    TLS session tickets are enabled by default. Using them without restarting

    8335b1
    +the web server with an appropriate frequency (e.g. daily) compromises perfect
    8335b1
    +forward secrecy.

    8335b1
    +
    8335b1
    +
    8335b1
    +
    8335b1
     
    top
    8335b1
     
    8335b1
     
    8335b1
    diff --git a/modules/ssl/mod_ssl.c b/modules/ssl/mod_ssl.c
    8335b1
    index bbe1d20..4a8b661 100644
    8335b1
    --- a/modules/ssl/mod_ssl.c
    8335b1
    +++ b/modules/ssl/mod_ssl.c
    8335b1
    @@ -141,6 +141,9 @@ static const command_rec ssl_config_cmds[] = {
    8335b1
         SSL_CMD_SRV(Compression, FLAG,
    8335b1
                     "Enable SSL level compression"
    8335b1
                     "(`on', `off')")
    8335b1
    +    SSL_CMD_SRV(SessionTickets, FLAG,
    8335b1
    +                "Enable or disable TLS session tickets"
    8335b1
    +                "(`on', `off')")
    8335b1
         SSL_CMD_SRV(InsecureRenegotiation, FLAG,
    8335b1
                     "Enable support for insecure renegotiation")
    8335b1
         SSL_CMD_ALL(UserName, TAKE1,
    8335b1
    diff --git a/modules/ssl/ssl_engine_config.c b/modules/ssl/ssl_engine_config.c
    8335b1
    index 9530fcc..86a7f0f 100644
    8335b1
    --- a/modules/ssl/ssl_engine_config.c
    8335b1
    +++ b/modules/ssl/ssl_engine_config.c
    8335b1
    @@ -216,6 +216,7 @@ static SSLSrvConfigRec *ssl_config_server_new(apr_pool_t *p)
    8335b1
     #ifndef OPENSSL_NO_COMP
    8335b1
         sc->compression            = UNSET;
    8335b1
     #endif
    8335b1
    +    sc->session_tickets        = UNSET;
    8335b1
     
    8335b1
         modssl_ctx_init_proxy(sc, p);
    8335b1
     
    8335b1
    @@ -346,6 +347,7 @@ void *ssl_config_server_merge(apr_pool_t *p, void *basev, void *addv)
    8335b1
     #ifndef OPENSSL_NO_COMP
    8335b1
         cfgMergeBool(compression);
    8335b1
     #endif
    8335b1
    +    cfgMergeBool(session_tickets);
    8335b1
     
    8335b1
         modssl_ctx_cfg_merge_proxy(base->proxy, add->proxy, mrg->proxy);
    8335b1
     
    8335b1
    @@ -720,6 +722,17 @@ const char *ssl_cmd_SSLHonorCipherOrder(cmd_parms *cmd, void *dcfg, int flag)
    8335b1
     #endif
    8335b1
     }
    8335b1
     
    8335b1
    +const char *ssl_cmd_SSLSessionTickets(cmd_parms *cmd, void *dcfg, int flag)
    8335b1
    +{
    8335b1
    +    SSLSrvConfigRec *sc = mySrvConfig(cmd->server);
    8335b1
    +#ifndef SSL_OP_NO_TICKET
    8335b1
    +    return "This version of OpenSSL does not support using "
    8335b1
    +           "SSLSessionTickets.";
    8335b1
    +#endif
    8335b1
    +    sc->session_tickets = flag ? TRUE : FALSE;
    8335b1
    +    return NULL;
    8335b1
    +}
    8335b1
    +
    8335b1
     const char *ssl_cmd_SSLInsecureRenegotiation(cmd_parms *cmd, void *dcfg, int flag)
    8335b1
     {
    8335b1
     #ifdef SSL_OP_ALLOW_UNSAFE_LEGACY_RENEGOTIATION
    8335b1
    diff --git a/modules/ssl/ssl_engine_init.c b/modules/ssl/ssl_engine_init.c
    8335b1
    index 568627f..672760c 100644
    8335b1
    --- a/modules/ssl/ssl_engine_init.c
    8335b1
    +++ b/modules/ssl/ssl_engine_init.c
    8335b1
    @@ -566,6 +566,16 @@ static void ssl_init_ctx_protocol(server_rec *s,
    8335b1
         }
    8335b1
     #endif
    8335b1
     
    8335b1
    +#ifdef SSL_OP_NO_TICKET
    8335b1
    +    /*
    8335b1
    +     * Configure using RFC 5077 TLS session tickets
    8335b1
    +     * for session resumption.
    8335b1
    +     */
    8335b1
    +    if (sc->session_tickets == FALSE) {
    8335b1
    +        SSL_CTX_set_options(ctx, SSL_OP_NO_TICKET);
    8335b1
    +    }
    8335b1
    +#endif
    8335b1
    +
    8335b1
     #ifdef SSL_OP_ALLOW_UNSAFE_LEGACY_RENEGOTIATION
    8335b1
         if (sc->insecure_reneg == TRUE) {
    8335b1
             SSL_CTX_set_options(ctx, SSL_OP_ALLOW_UNSAFE_LEGACY_RENEGOTIATION);
    8335b1
    diff --git a/modules/ssl/ssl_private.h b/modules/ssl/ssl_private.h
    8335b1
    index 0cc6d3f..b601316 100644
    8335b1
    --- a/modules/ssl/ssl_private.h
    8335b1
    +++ b/modules/ssl/ssl_private.h
    8335b1
    @@ -701,6 +701,7 @@ struct SSLSrvConfigRec {
    8335b1
     #ifndef OPENSSL_NO_COMP
    8335b1
         BOOL             compression;
    8335b1
     #endif
    8335b1
    +    BOOL             session_tickets;
    8335b1
     };
    8335b1
     
    8335b1
     /**
    8335b1
    @@ -756,6 +757,7 @@ const char  *ssl_cmd_SSLCARevocationFile(cmd_parms *, void *, const char *);
    8335b1
     const char  *ssl_cmd_SSLCARevocationCheck(cmd_parms *, void *, const char *);
    8335b1
     const char  *ssl_cmd_SSLHonorCipherOrder(cmd_parms *cmd, void *dcfg, int flag);
    8335b1
     const char  *ssl_cmd_SSLCompression(cmd_parms *, void *, int flag);
    8335b1
    +const char  *ssl_cmd_SSLSessionTickets(cmd_parms *, void *, int flag);
    8335b1
     const char  *ssl_cmd_SSLVerifyClient(cmd_parms *, void *, const char *);
    8335b1
     const char  *ssl_cmd_SSLVerifyDepth(cmd_parms *, void *, const char *);
    8335b1
     const char  *ssl_cmd_SSLSessionCache(cmd_parms *, void *, const char *);