mirror of
https://github.com/coredns/coredns.git
synced 2026-10-09 03:55:21 -04:00
core: Reject conflicting TLS policies on shared listeners. (#8565)
* core: Reject conflicting TLS policies on shared listeners. This PR tries to fix the issue when multiple zones share a DoT listener, CoreDNS can apply one sibling block’s tls.Config to all zones, allowing weaker TLS or client-auth settings to override a stricter zone. Signed-off-by: Yong Tang <yong.tang.github@outlook.com> * Fix ACME Signed-off-by: Yong Tang <yong.tang.github@outlook.com> --------- Signed-off-by: Yong Tang <yong.tang.github@outlook.com>
This commit is contained in:
@@ -77,18 +77,15 @@ func (l *limitQUICListener) Accept(ctx context.Context) (*quic.Conn, error) {
|
||||
|
||||
// NewServerHTTPS3 builds the HTTP/3 (DoH3) server.
|
||||
func NewServerHTTPS3(addr string, group []*Config) (*ServerHTTPS3, error) {
|
||||
tlsConfig, err := sharedTLSConfig(addr, group)
|
||||
if err != nil {
|
||||
return nil, err
|
||||
}
|
||||
s, err := NewServer(addr, group)
|
||||
if err != nil {
|
||||
return nil, err
|
||||
}
|
||||
|
||||
// Extract TLS config (CoreDNS guarantees it is consistent)
|
||||
var tlsConfig *tls.Config
|
||||
for _, z := range s.zones {
|
||||
for _, conf := range z {
|
||||
tlsConfig = conf.TLSConfig
|
||||
}
|
||||
}
|
||||
if tlsConfig == nil {
|
||||
return nil, fmt.Errorf("DoH3 requires TLS, no TLS config found")
|
||||
}
|
||||
|
||||
Reference in New Issue
Block a user