Skip to content

SSL cert inheritance from mod_ssl and SNI - #11

Open
xl32 wants to merge 4 commits into
machine-moon:trunkfrom
xl32:ssl-cert-inheritance
Open

xl32 wants to merge 4 commits into
machine-moon:trunkfrom
xl32:ssl-cert-inheritance

Conversation

@xl32

@xl32 xl32 commented Sep 8, 2026 •

Copy link
Copy Markdown
Contributor

@machine-moon, I believe these updates/fixes are super important for CodeIT repo users and your work also. This allow admins to use mod_http3 nearly the same super easy way they use HTTP/2. No more special files ownership on key and extra directives.

mod_http3 now takes its certificates from mod_ssl (Protocols h3 on an SSLEngine on host is the whole configuration) and loads them before httpd drops privileges, so a root-only key works over QUIC exactly as it does over TCP and the separate H3CertificateXXXPath directives — a second source of truth that drifted on renewal — are gone. On top of that, each virtual host presents its own certificate by SNI, and two latent bugs found along the way are fixed: hosts without H3* directives silently shared the main server's config (per-host H3AltSvc* were ignored), and the test suite's stop.conf never actually stopped the server, which had been masking results.

@xl32 xl32 changed the title Ssl cert inheritance and SNI SSL cert inheritance from mod_ssl and SNI Sep 8, 2026
@machine-moon machine-moon self-assigned this Oct 9, 2026
@machine-moon machine-moon added the enhancement New feature or request label Oct 9, 2026
xl32 added 4 commits October 9, 2026 11:01
Worker threads allocate from stream subpools while the event thread
allocates from the session pool. All of them use one allocator, which
had no mutex, so concurrent allocations corrupted the heap and crashed
the child under load. Set a mutex on the allocator, as mod_http2 does.
A pending handshake counts as an MPM connection. The event thread
advanced pending handshakes only when not draining, so a handshake in
flight at a graceful restart did not finish or time out. The old child
then never reached zero connections and kept the port.
nghttp3_conn_resume_stream puts a blocked stream back in the write
queue. The module blocked the stream only on the first refusal, so
when the peer kept its window shut, nghttp3 offered the stream again
and again and the event thread used 100% CPU.
A host with "h3" in Protocols now serves HTTP/3 with the certificate
mod_ssl already resolved for it (SSLCertificateFile and mod_md alike),
the way mod_http2 rides mod_ssl. The certificate and key are loaded in
the ap_ssl_add_cert_files hook, during startup while httpd still runs
privileged, so a key readable only by root loads for QUIC as it does for
mod_ssl instead of failing in the unprivileged child.

H3CertificatePath and H3CertificateKeyPath are removed; drop them from
existing configurations.

Each virtual host on a shared port now presents its own certificate over
HTTP/3, chosen by the client SNI; an unmatched name gets the listener
default. Names come from ServerName, ServerAlias and the wildcard
ServerAlias names that httpd keeps in wild_names, and every entry is
matched with ap_strcasecmp_match, the matcher httpd uses for its own
virtual hosts. A cert_cb on the listener context applies the matched
host certificate, key and chain to the connection: SSL_set_SSL_CTX does
not switch the certificate of a QUIC connection.

Landing it exposed that the module ran with AP_MODULE_FLAG_NONE, so a host
without H3 directives shared the main server configuration; per-host
H3AltSvc and H3AltSvcMaxAge were silently ignored. Set ALWAYS_MERGE.

Test suite: stop.conf never named a pid file, so on builds whose default is
run/httpd.pid "apachectl -k stop" stopped nothing and every restart talked
to the previous server.

Author: Alexander Gerasimov <codeguard gmail.com>
@xl32
xl32 force-pushed the ssl-cert-inheritance branch from 6b3726f to edaf884 Compare October 9, 2026 10:11

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

enhancement New feature or request

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants