我了解了针对TLS压缩的CRIME攻击(CVE-2012-4929,CRIME是针对ssl&tls的BEAST攻击的继承者),并且我想通过禁用SSL压缩来保护我的Web服务器免受此攻击,该SSL压缩已添加到Apache 2.2.22(请参见Bug 53219)。
我正在运行httpd-2.2.15附带的Scientific Linux 6.3。httpd 2.2上游版本的安全修补程序应反向移植到该版本。
# rpm -q httpd
httpd-2.2.15-15.sl6.1.x86_64
# httpd -V
Server version: Apache/2.2.15 (Unix)
Server built: Feb 14 2012 09:47:14
Server's Module Magic Number: 20051115:24
Server loaded: APR 1.3.9, APR-Util 1.3.9
Compiled using: APR 1.3.9, APR-Util 1.3.9
我在配置中尝试关闭SSLCompression,但是导致出现以下错误消息:
# /etc/init.d/httpd restart
Stopping httpd: [ OK ]
Starting httpd: Syntax error on line 147 of /etc/httpd/httpd.conf:
Invalid command 'SSLCompression', perhaps misspelled or defined by a module not included in the server configuration
[FAILED]
可以使用此版本的Apache Webserver禁用SSLCompression吗?