This patch https://issues.apache.org/bugzilla/show_bug.cgi?id=49717 adds an SSLTimeout directive which is a timeout on the initial ssl handshake separate from the general Timeout. See the issue description for a bit more detail.
Why should this not be added? and/or Why should this be added? How should it be improved? Thanks, Andy
