ssl_multicert: entries without dest_ip can override the default certificate
I maintainer di solito rispondono entro 2 giorni
Nessuno ha ancora preso questa issue.
Valutazione
- Difficoltà
- 4/5
- Tempo stimato
- 3-5 giorni
- Idoneità per principianti
- 48/100
- Tipo di issue
- Bug
- Chiarezza
- Abbastanza chiara
- Stato di attività
- Attiva
- Stack tecnologico
- cpp
- Ambito
- networking
Direzione di ricerca
Start by tracing how ssl_multicert entries are parsed and how the configuration converter handles omitted dest_ip; the issue does not name specific files or tests. Check the relevant tests for YAML and legacy ssl_multicert.config inputs, then run them. Done means omitted dest_ip stays empty, converted entries no longer gain "*", and the explicitly configured default certificate is used for clients without a matching SNI.
Scritto dal modello di indicizzazione a partire dal testo della issue.
Descrizione
On master, an entry without dest_ip is treated as dest_ip: "*". It competes with the explicitly configured default certificate.
For example:
ssl_multicert:
- ssl_cert_name: named.pem
ssl_key_name: named.key
- dest_ip: "*"
ssl_cert_name: default.pem
ssl_key_name: default.key
Expected: Clients with no SNI or an unmatched SNI receive default.pem.
Actual: The first entry to register "*" wins. Startup loads certificates concurrently, so the default can change between restarts. With the default reload concurrency of one, the first entry wins, making named.pem the default after a reload.
This affects both YAML and legacy ssl_multicert.config files on master. It does not affect 10.2.x and should be fixed before 11.0.
Workaround: Set dest_ip: "" on entries that should not be the default.
The fix should preserve an omitted dest_ip as empty. The configuration converter also needs updating: it currently writes dest_ip: "*" into entries that omitted it, so previously converted files will need correction.
- Lingua principale
- C++
- Stelle
- 2k
- Fork
- 878
- Merge medio
- 3g 16h
- PR unite (30g)
- 91
Preparare l'ambiente
- Nessun Dockerfile né file Docker Compose
- Nessun modello di pull request
- Leggi la guida per i contributori
Come iniziare
- Leggi tutta la issue e poi la guida ai contributi del progetto.
- Commenta sulla issue per dire che te ne occupi tu — evita che due persone facciano lo stesso lavoro.
- Fai un fork del repository e lavora su un branch.
- Apri una pull request che faccia riferimento al numero della issue.
Altre issue di apache/trafficserver
-
Bug HTTP Support
Difficoltà 2/5 1-3 ore Idoneità per principianti 74/100
apache/trafficserver#13118 ·
I maintainer di solito rispondono entro 2 giorni
-
header_rewrite: rm-destination after set-destination URL crashes traffic_serverForse già presa @moonchen l’ha presa 5 giorni fa. ApertaBug Crash header_rewrite Plugins
apache/trafficserver#13800 · 1 assegnatario ·
I maintainer di solito rispondono entro 2 giorni
-
Difficoltà 4/5 3-5 giorni Idoneità per principianti 48/100
apache/trafficserver#13784 ·
I maintainer di solito rispondono entro 2 giorni
-
Plugins
Difficoltà 5/5 Più di una settimana Idoneità per principianti 35/100
apache/trafficserver#13774 ·
I maintainer di solito rispondono entro 2 giorni
-
New Feature
Difficoltà 5/5 Più di una settimana Idoneità per principianti 25/100
apache/trafficserver#13773 ·
I maintainer di solito rispondono entro 2 giorni
Tutte le issue di apache/trafficserver
Issue simili
-
new contributor
Difficoltà 2/5 1-3 ore Idoneità per principianti 65/100
OpenMS/OpenMS#10512 · 1 commento ·
I maintainer di solito rispondono entro 1 giorno
-
Difficoltà 2/5 1-3 ore Idoneità per principianti 75/100
mesonbuild/wrapdb#2961 ·
I maintainer di solito rispondono entro 1 giorno
-
80 Instance - Raid - Northrend
Difficoltà 2/5 1-3 ore Idoneità per principianti 62/100
azerothcore/azerothcore-wotlk#28075 ·
I maintainer di solito rispondono entro 1 giorno
-
SCA cis_ubuntu24-04 35664 / cis_ubuntu26-04 41664 "Ensure sudo log file exists": sudoers.d rule is missing the r: prefix, so it can never matchForse già presa Una pull request collegata a questa issue è aperta o già unita. Aperta
Difficoltà 2/5 1-3 ore Idoneità per principianti 78/100
I maintainer di solito rispondono entro 1 giorno
-
Difficoltà 2/5 1-3 ore Idoneità per principianti 68/100
MrNeRF/LichtFeld-Studio#3205 ·
I maintainer di solito rispondono entro 1 giorno