Hacktoberfest 2026: le issue che i maintainer hanno segnato per ottobre, aperte e adatte ai principianti. Sfoglia le issue Hacktoberfest

ssl_multicert: entries without dest_ip can override the default certificate

Aperta
#13,798 0 commenti 0 reazioni 0 assegnatari Vedi su GitHub

I maintainer di solito rispondono entro 2 giorni

Nessuno ha ancora preso questa issue.

Valutazione

Difficoltà
4/5
Tempo stimato
3-5 giorni
Idoneità per principianti
48/100
Tipo di issue
Bug
Chiarezza
Abbastanza chiara
Stato di attività
Attiva
Stack tecnologico
cpp
Ambito
networking

Direzione di ricerca

Start by tracing how ssl_multicert entries are parsed and how the configuration converter handles omitted dest_ip; the issue does not name specific files or tests. Check the relevant tests for YAML and legacy ssl_multicert.config inputs, then run them. Done means omitted dest_ip stays empty, converted entries no longer gain "*", and the explicitly configured default certificate is used for clients without a matching SNI.

Scritto dal modello di indicizzazione a partire dal testo della issue.

Descrizione

On master, an entry without dest_ip is treated as dest_ip: "*". It competes with the explicitly configured default certificate.

For example:

ssl_multicert:
  - ssl_cert_name: named.pem
    ssl_key_name: named.key

  - dest_ip: "*"
    ssl_cert_name: default.pem
    ssl_key_name: default.key

Expected: Clients with no SNI or an unmatched SNI receive default.pem.

Actual: The first entry to register "*" wins. Startup loads certificates concurrently, so the default can change between restarts. With the default reload concurrency of one, the first entry wins, making named.pem the default after a reload.

This affects both YAML and legacy ssl_multicert.config files on master. It does not affect 10.2.x and should be fixed before 11.0.

Workaround: Set dest_ip: "" on entries that should not be the default.

The fix should preserve an omitted dest_ip as empty. The configuration converter also needs updating: it currently writes dest_ip: "*" into entries that omitted it, so previously converted files will need correction.

Lingua principale
C++
Stelle
2k
Fork
878
Merge medio
3g 16h
PR unite (30g)
91

Preparare l'ambiente

Come iniziare

  1. Leggi tutta la issue e poi la guida ai contributi del progetto.
  2. Commenta sulla issue per dire che te ne occupi tu — evita che due persone facciano lo stesso lavoro.
  3. Fai un fork del repository e lavora su un branch.
  4. Apri una pull request che faccia riferimento al numero della issue.

Altre issue di apache/trafficserver

Tutte le issue di apache/trafficserver

Issue simili

Altre issue su C++

Ricevi le nuove issue nella tua casella

Un breve riepilogo di issue GitHub adatte ai principianti.