Latest update - 9060
This commit is contained in:
+1
-1
Submodule lib/boringssl updated: 898de8d09e...92de195169
@@ -56,6 +56,10 @@ static char *ngx_http_ssl_conf_command_check(ngx_conf_t *cf, void *post,
|
|||||||
void *data);
|
void *data);
|
||||||
|
|
||||||
static ngx_int_t ngx_http_ssl_init(ngx_conf_t *cf);
|
static ngx_int_t ngx_http_ssl_init(ngx_conf_t *cf);
|
||||||
|
#if (NGX_QUIC_OPENSSL_COMPAT)
|
||||||
|
static ngx_int_t ngx_http_ssl_quic_compat_init(ngx_conf_t *cf,
|
||||||
|
ngx_http_conf_addr_t *addr);
|
||||||
|
#endif
|
||||||
|
|
||||||
|
|
||||||
static ngx_conf_bitmask_t ngx_http_ssl_protocols[] = {
|
static ngx_conf_bitmask_t ngx_http_ssl_protocols[] = {
|
||||||
@@ -1403,14 +1407,11 @@ ngx_http_ssl_init(ngx_conf_t *cf)
|
|||||||
continue;
|
continue;
|
||||||
}
|
}
|
||||||
|
|
||||||
cscf = addr[a].default_server;
|
|
||||||
sscf = cscf->ctx->srv_conf[ngx_http_ssl_module.ctx_index];
|
|
||||||
|
|
||||||
if (addr[a].opt.quic) {
|
if (addr[a].opt.quic) {
|
||||||
name = "quic";
|
name = "quic";
|
||||||
|
|
||||||
#if (NGX_QUIC_OPENSSL_COMPAT)
|
#if (NGX_QUIC_OPENSSL_COMPAT)
|
||||||
if (ngx_quic_compat_init(cf, sscf->ssl.ctx) != NGX_OK) {
|
if (ngx_http_ssl_quic_compat_init(cf, &addr[a]) != NGX_OK) {
|
||||||
return NGX_ERROR;
|
return NGX_ERROR;
|
||||||
}
|
}
|
||||||
#endif
|
#endif
|
||||||
@@ -1419,6 +1420,9 @@ ngx_http_ssl_init(ngx_conf_t *cf)
|
|||||||
name = "ssl";
|
name = "ssl";
|
||||||
}
|
}
|
||||||
|
|
||||||
|
cscf = addr[a].default_server;
|
||||||
|
sscf = cscf->ctx->srv_conf[ngx_http_ssl_module.ctx_index];
|
||||||
|
|
||||||
if (sscf->certificates) {
|
if (sscf->certificates) {
|
||||||
|
|
||||||
if (addr[a].opt.quic && !(sscf->protocols & NGX_SSL_TLSv1_3)) {
|
if (addr[a].opt.quic && !(sscf->protocols & NGX_SSL_TLSv1_3)) {
|
||||||
@@ -1466,3 +1470,31 @@ ngx_http_ssl_init(ngx_conf_t *cf)
|
|||||||
|
|
||||||
return NGX_OK;
|
return NGX_OK;
|
||||||
}
|
}
|
||||||
|
|
||||||
|
|
||||||
|
#if (NGX_QUIC_OPENSSL_COMPAT)
|
||||||
|
|
||||||
|
static ngx_int_t
|
||||||
|
ngx_http_ssl_quic_compat_init(ngx_conf_t *cf, ngx_http_conf_addr_t *addr)
|
||||||
|
{
|
||||||
|
ngx_uint_t s;
|
||||||
|
ngx_http_ssl_srv_conf_t *sscf;
|
||||||
|
ngx_http_core_srv_conf_t **cscfp, *cscf;
|
||||||
|
|
||||||
|
cscfp = addr->servers.elts;
|
||||||
|
for (s = 0; s < addr->servers.nelts; s++) {
|
||||||
|
|
||||||
|
cscf = cscfp[s];
|
||||||
|
sscf = cscf->ctx->srv_conf[ngx_http_ssl_module.ctx_index];
|
||||||
|
|
||||||
|
if (sscf->certificates || sscf->reject_handshake) {
|
||||||
|
if (ngx_quic_compat_init(cf, sscf->ssl.ctx) != NGX_OK) {
|
||||||
|
return NGX_ERROR;
|
||||||
|
}
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
return NGX_OK;
|
||||||
|
}
|
||||||
|
|
||||||
|
#endif
|
||||||
Reference in New Issue
Block a user