core: Reject conflicting TLS policies on shared listeners. (#8565)

* core: Reject conflicting TLS policies on shared listeners.

This PR tries to fix the issue when multiple zones share a DoT listener, CoreDNS can apply one sibling block’s tls.Config to all zones, allowing weaker TLS or client-auth settings to override a stricter zone.

Signed-off-by: Yong Tang <yong.tang.github@outlook.com>

* Fix ACME

Signed-off-by: Yong Tang <yong.tang.github@outlook.com>

---------

Signed-off-by: Yong Tang <yong.tang.github@outlook.com>
This commit is contained in:
Yong Tang
2026-09-21 23:56:27 -07:00
committed by GitHub
parent 559e57ec55
commit 8d66643935
12 changed files with 308 additions and 47 deletions

View File

@@ -244,8 +244,9 @@ type acmeBackend interface {
type acmeBackendFactory func([]*acmeEntry, *acmeDNS01Solver) (acmeBackend, error)
type acmeEntry struct {
options acmeOptions
key acmeConfigKey
options acmeOptions
key acmeConfigKey
tlsConfigIdentity *dnsserver.TLSConfigIdentity
mu sync.RWMutex
manager certificateManager
@@ -330,7 +331,11 @@ func (r *acmeRuntime) add(options acmeOptions) (*acmeEntry, error) {
}
}
entry := &acmeEntry{options: options, key: key}
entry := &acmeEntry{
options: options,
key: key,
tlsConfigIdentity: dnsserver.NewTLSConfigIdentity(),
}
r.entries[key] = entry
for _, domain := range options.domains {
r.domainOwners[domain] = key

View File

@@ -72,6 +72,34 @@ func TestParseACMETLS(t *testing.T) {
}
}
func TestEquivalentACMEConfigsShareTLSListener(t *testing.T) {
root := t.TempDir()
runtime := newACMERuntime(nil)
config := func(zone string) *dnsserver.Config {
c := caddy.NewTestController("dns", `tls {
acme dns.example
}`)
c.Set(acmeRuntimeStorageKey{}, runtime)
cfg := dnsserver.GetConfig(c)
cfg.Root = root
cfg.Zone = zone
if err := setup(c); err != nil {
t.Fatalf("setup %s failed: %v", zone, err)
}
return cfg
}
first := config("a.example.")
second := config("b.example.")
if first.TLSConfig == second.TLSConfig {
t.Fatal("equivalent ACME entries unexpectedly reused the same tls.Config")
}
if _, err := dnsserver.NewServerTLS("tls://127.0.0.1:0", []*dnsserver.Config{first, second}); err != nil {
t.Fatalf("equivalent ACME configs rejected: %v", err)
}
}
func TestACMEDirectiveOrder(t *testing.T) {
indexes := make(map[string]int)
for i, directive := range dnsserver.Directives {

View File

@@ -190,6 +190,7 @@ func parseACMETLS(c *caddy.Controller, config *dnsserver.Config) (*ctls.Config,
return nil, err
}
runtime.installChallengeHandlers(c)
config.SetTLSConfigIdentity(entry.tlsConfigIdentity)
return entry.tlsConfig(), nil
}