core: Reject conflicting TLS policies on shared listeners. (#8565)

* core: Reject conflicting TLS policies on shared listeners.

This PR tries to fix the issue when multiple zones share a DoT listener, CoreDNS can apply one sibling block’s tls.Config to all zones, allowing weaker TLS or client-auth settings to override a stricter zone.

Signed-off-by: Yong Tang <yong.tang.github@outlook.com>

* Fix ACME

Signed-off-by: Yong Tang <yong.tang.github@outlook.com>

---------

Signed-off-by: Yong Tang <yong.tang.github@outlook.com>
This commit is contained in:
Yong Tang
2026-09-21 23:56:27 -07:00
committed by GitHub
parent 559e57ec55
commit 8d66643935
12 changed files with 308 additions and 47 deletions

View File

@@ -244,8 +244,9 @@ type acmeBackend interface {
type acmeBackendFactory func([]*acmeEntry, *acmeDNS01Solver) (acmeBackend, error)
type acmeEntry struct {
options acmeOptions
key acmeConfigKey
options acmeOptions
key acmeConfigKey
tlsConfigIdentity *dnsserver.TLSConfigIdentity
mu sync.RWMutex
manager certificateManager
@@ -330,7 +331,11 @@ func (r *acmeRuntime) add(options acmeOptions) (*acmeEntry, error) {
}
}
entry := &acmeEntry{options: options, key: key}
entry := &acmeEntry{
options: options,
key: key,
tlsConfigIdentity: dnsserver.NewTLSConfigIdentity(),
}
r.entries[key] = entry
for _, domain := range options.domains {
r.domainOwners[domain] = key