mirror of
https://github.com/coredns/coredns.git
synced 2026-10-09 12:05:22 -04:00
core: Reject conflicting TLS policies on shared listeners. (#8565)
* core: Reject conflicting TLS policies on shared listeners. This PR tries to fix the issue when multiple zones share a DoT listener, CoreDNS can apply one sibling block’s tls.Config to all zones, allowing weaker TLS or client-auth settings to override a stricter zone. Signed-off-by: Yong Tang <yong.tang.github@outlook.com> * Fix ACME Signed-off-by: Yong Tang <yong.tang.github@outlook.com> --------- Signed-off-by: Yong Tang <yong.tang.github@outlook.com>
This commit is contained in:
@@ -244,8 +244,9 @@ type acmeBackend interface {
|
||||
type acmeBackendFactory func([]*acmeEntry, *acmeDNS01Solver) (acmeBackend, error)
|
||||
|
||||
type acmeEntry struct {
|
||||
options acmeOptions
|
||||
key acmeConfigKey
|
||||
options acmeOptions
|
||||
key acmeConfigKey
|
||||
tlsConfigIdentity *dnsserver.TLSConfigIdentity
|
||||
|
||||
mu sync.RWMutex
|
||||
manager certificateManager
|
||||
@@ -330,7 +331,11 @@ func (r *acmeRuntime) add(options acmeOptions) (*acmeEntry, error) {
|
||||
}
|
||||
}
|
||||
|
||||
entry := &acmeEntry{options: options, key: key}
|
||||
entry := &acmeEntry{
|
||||
options: options,
|
||||
key: key,
|
||||
tlsConfigIdentity: dnsserver.NewTLSConfigIdentity(),
|
||||
}
|
||||
r.entries[key] = entry
|
||||
for _, domain := range options.domains {
|
||||
r.domainOwners[domain] = key
|
||||
|
||||
@@ -72,6 +72,34 @@ func TestParseACMETLS(t *testing.T) {
|
||||
}
|
||||
}
|
||||
|
||||
func TestEquivalentACMEConfigsShareTLSListener(t *testing.T) {
|
||||
root := t.TempDir()
|
||||
runtime := newACMERuntime(nil)
|
||||
|
||||
config := func(zone string) *dnsserver.Config {
|
||||
c := caddy.NewTestController("dns", `tls {
|
||||
acme dns.example
|
||||
}`)
|
||||
c.Set(acmeRuntimeStorageKey{}, runtime)
|
||||
cfg := dnsserver.GetConfig(c)
|
||||
cfg.Root = root
|
||||
cfg.Zone = zone
|
||||
if err := setup(c); err != nil {
|
||||
t.Fatalf("setup %s failed: %v", zone, err)
|
||||
}
|
||||
return cfg
|
||||
}
|
||||
|
||||
first := config("a.example.")
|
||||
second := config("b.example.")
|
||||
if first.TLSConfig == second.TLSConfig {
|
||||
t.Fatal("equivalent ACME entries unexpectedly reused the same tls.Config")
|
||||
}
|
||||
if _, err := dnsserver.NewServerTLS("tls://127.0.0.1:0", []*dnsserver.Config{first, second}); err != nil {
|
||||
t.Fatalf("equivalent ACME configs rejected: %v", err)
|
||||
}
|
||||
}
|
||||
|
||||
func TestACMEDirectiveOrder(t *testing.T) {
|
||||
indexes := make(map[string]int)
|
||||
for i, directive := range dnsserver.Directives {
|
||||
|
||||
@@ -190,6 +190,7 @@ func parseACMETLS(c *caddy.Controller, config *dnsserver.Config) (*ctls.Config,
|
||||
return nil, err
|
||||
}
|
||||
runtime.installChallengeHandlers(c)
|
||||
config.SetTLSConfigIdentity(entry.tlsConfigIdentity)
|
||||
return entry.tlsConfig(), nil
|
||||
}
|
||||
|
||||
|
||||
Reference in New Issue
Block a user