Hi Daniel,

Thanks very much for fixing these SSL reload and cleanup issues. I also
ran into the SNI reload issue while reviewing the DH parameter patch
and wrote a patch to try to fix it. I then checked whether the same
problem had already been reported, which led me to this thread.

I've reviewed all five patches in v5. They look good to me, and I
didn't find any further problems. The attached patch adds tests on top
of v5 for a few cases missing from 004_sni.pl:

1. Enabling SNI by reloading with an encrypted per-host key and its own
   passphrase command. The existing encrypted-key tests start with SNI
   already enabled.

2. Turning SNI off while ssl_cert_file points to a missing file, with a
   default host configured. The default and named hosts use different
   certificates, so verify-full checks that the failed reload leaves
   the named host's certificate in use.

3. Retrying the reload after restoring a valid global certificate and
   key. The test checks that SNI host selection is disabled and a new
   connection verifies the global certificate.

The added tests pass with v5.

Regards,
Rui

Attachment: nocfbot-0001-Test-SNI-certificate-selection-across-configuration-reloads.patch
Description: Binary data

Reply via email to