mirror of
https://github.com/coredns/coredns.git
synced 2026-10-09 03:55:21 -04:00
core: Reject conflicting TLS policies on shared listeners. (#8565)
* core: Reject conflicting TLS policies on shared listeners. This PR tries to fix the issue when multiple zones share a DoT listener, CoreDNS can apply one sibling block’s tls.Config to all zones, allowing weaker TLS or client-auth settings to override a stricter zone. Signed-off-by: Yong Tang <yong.tang.github@outlook.com> * Fix ACME Signed-off-by: Yong Tang <yong.tang.github@outlook.com> --------- Signed-off-by: Yong Tang <yong.tang.github@outlook.com>
This commit is contained in:
@@ -244,8 +244,9 @@ type acmeBackend interface {
|
||||
type acmeBackendFactory func([]*acmeEntry, *acmeDNS01Solver) (acmeBackend, error)
|
||||
|
||||
type acmeEntry struct {
|
||||
options acmeOptions
|
||||
key acmeConfigKey
|
||||
options acmeOptions
|
||||
key acmeConfigKey
|
||||
tlsConfigIdentity *dnsserver.TLSConfigIdentity
|
||||
|
||||
mu sync.RWMutex
|
||||
manager certificateManager
|
||||
@@ -330,7 +331,11 @@ func (r *acmeRuntime) add(options acmeOptions) (*acmeEntry, error) {
|
||||
}
|
||||
}
|
||||
|
||||
entry := &acmeEntry{options: options, key: key}
|
||||
entry := &acmeEntry{
|
||||
options: options,
|
||||
key: key,
|
||||
tlsConfigIdentity: dnsserver.NewTLSConfigIdentity(),
|
||||
}
|
||||
r.entries[key] = entry
|
||||
for _, domain := range options.domains {
|
||||
r.domainOwners[domain] = key
|
||||
|
||||
Reference in New Issue
Block a user