mirror of
https://github.com/3proxy/3proxy.git
synced 2026-09-29 16:55:51 +08:00
Compare commits
No commits in common. "661631138a14b0c1f2106595a2227543cd1a39a4" and "36979639b74ceabb3a1005a75753bd7352fc2eb1" have entirely different histories.
661631138a
...
36979639b7
@ -277,7 +277,7 @@ static FILTER_ACTION pcre_filter_buffer(void *fc, struct clientparam *param, uns
|
|||||||
#define pcrefd ((struct pcre_filter_data *)fc)
|
#define pcrefd ((struct pcre_filter_data *)fc)
|
||||||
|
|
||||||
for(acl = pcrefd->acl; acl; acl=acl->next){
|
for(acl = pcrefd->acl; acl; acl=acl->next){
|
||||||
if(pl->ACLMatches(acl, param)){
|
if(pl->ACLMatches(pcrefd->acl, param)){
|
||||||
match = 1;
|
match = 1;
|
||||||
break;
|
break;
|
||||||
}
|
}
|
||||||
|
|||||||
@ -830,14 +830,6 @@ int MODULEMAINFUNC (int argc, char** argv){
|
|||||||
#ifndef _WIN32
|
#ifndef _WIN32
|
||||||
opt = 1;
|
opt = 1;
|
||||||
if(srv.so._setsockopt(srv.so.state, sock, SOL_SOCKET, SO_REUSEADDR, (char *)&opt, sizeof(int)))perror("setsockopt()");
|
if(srv.so._setsockopt(srv.so.state, sock, SOL_SOCKET, SO_REUSEADDR, (char *)&opt, sizeof(int)))perror("setsockopt()");
|
||||||
#else
|
|
||||||
/* A UDP service on Windows answers from a second socket bound to
|
|
||||||
the address it listens on, and Windows only allows that bind
|
|
||||||
when both sockets ask for it. */
|
|
||||||
if(isudp){
|
|
||||||
opt = 1;
|
|
||||||
if(srv.so._setsockopt(srv.so.state, sock, SOL_SOCKET, SO_REUSEADDR, (char *)&opt, sizeof(int)))perror("setsockopt()");
|
|
||||||
}
|
|
||||||
#endif
|
#endif
|
||||||
#ifdef SO_REUSEPORT
|
#ifdef SO_REUSEPORT
|
||||||
opt = 1;
|
opt = 1;
|
||||||
|
|||||||
28
src/ssllib.c
28
src/ssllib.c
@ -84,11 +84,7 @@ static int copy_ext(X509 *dst_cert, X509 *src_cert, int nid)
|
|||||||
}
|
}
|
||||||
|
|
||||||
#ifndef WITH_WOLFSSL
|
#ifndef WITH_WOLFSSL
|
||||||
/* issuer is the certificate the extension should describe as the issuer,
|
static int add_ext(X509 *cert, int nid, const char *value)
|
||||||
* which matters for an authority key identifier: it names the key that
|
|
||||||
* signs, not the key being signed.
|
|
||||||
*/
|
|
||||||
static int add_ext_issuer(X509 *cert, X509 *issuer, int nid, const char *value)
|
|
||||||
{
|
{
|
||||||
X509_EXTENSION *ex;
|
X509_EXTENSION *ex;
|
||||||
X509V3_CTX ctx;
|
X509V3_CTX ctx;
|
||||||
@ -96,8 +92,10 @@ static int add_ext_issuer(X509 *cert, X509 *issuer, int nid, const char *value)
|
|||||||
/* This sets the 'context' of the extensions. */
|
/* This sets the 'context' of the extensions. */
|
||||||
/* No configuration database */
|
/* No configuration database */
|
||||||
X509V3_set_ctx_nodb(&ctx);
|
X509V3_set_ctx_nodb(&ctx);
|
||||||
/* No request and no CRL */
|
/* Issuer and subject certs: both the target since it is self signed,
|
||||||
X509V3_set_ctx(&ctx, issuer, cert, NULL, NULL, 0);
|
* no request and no CRL
|
||||||
|
*/
|
||||||
|
X509V3_set_ctx(&ctx, cert, cert, NULL, NULL, 0);
|
||||||
/* value is char * prior to OpenSSL 1.1.0 */
|
/* value is char * prior to OpenSSL 1.1.0 */
|
||||||
ex = X509V3_EXT_conf_nid(NULL, &ctx, nid, (char *)value);
|
ex = X509V3_EXT_conf_nid(NULL, &ctx, nid, (char *)value);
|
||||||
if (!ex)
|
if (!ex)
|
||||||
@ -107,12 +105,6 @@ static int add_ext_issuer(X509 *cert, X509 *issuer, int nid, const char *value)
|
|||||||
X509_EXTENSION_free(ex);
|
X509_EXTENSION_free(ex);
|
||||||
return err > 0;
|
return err > 0;
|
||||||
}
|
}
|
||||||
|
|
||||||
static int add_ext(X509 *cert, int nid, const char *value)
|
|
||||||
{
|
|
||||||
/* Issuer and subject: both the target, for a self signed certificate */
|
|
||||||
return add_ext_issuer(cert, cert, nid, value);
|
|
||||||
}
|
|
||||||
#endif
|
#endif
|
||||||
|
|
||||||
SSL_CERT ssl_copy_cert(SSL_CERT cert, SSL_CONFIG *config)
|
SSL_CERT ssl_copy_cert(SSL_CERT cert, SSL_CONFIG *config)
|
||||||
@ -207,16 +199,6 @@ SSL_CERT ssl_copy_cert(SSL_CERT cert, SSL_CONFIG *config)
|
|||||||
add_ext(dst_cert, NID_basic_constraints, "critical,CA:FALSE");
|
add_ext(dst_cert, NID_basic_constraints, "critical,CA:FALSE");
|
||||||
if(!copy_ext(dst_cert, src_cert, NID_ext_key_usage))
|
if(!copy_ext(dst_cert, src_cert, NID_ext_key_usage))
|
||||||
add_ext(dst_cert, NID_ext_key_usage, "serverAuth");
|
add_ext(dst_cert, NID_ext_key_usage, "serverAuth");
|
||||||
/* A verifier following RFC 5280 strictly looks for the issuer through a
|
|
||||||
* key identifier and refuses a certificate carrying none: OpenSSL does
|
|
||||||
* with x509_strict, and Python has since 3.13. The identifiers are
|
|
||||||
* generated rather than copied, so they name the CA signing here
|
|
||||||
* instead of the one that signed upstream. keyid,issuer keeps working
|
|
||||||
* when the CA certificate has no subject key identifier of its own.
|
|
||||||
*/
|
|
||||||
add_ext(dst_cert, NID_subject_key_identifier, "hash");
|
|
||||||
add_ext_issuer(dst_cert, config->CA_cert, NID_authority_key_identifier,
|
|
||||||
"keyid,issuer");
|
|
||||||
#else
|
#else
|
||||||
copy_ext(dst_cert, src_cert, NID_basic_constraints);
|
copy_ext(dst_cert, src_cert, NID_basic_constraints);
|
||||||
copy_ext(dst_cert, src_cert, NID_ext_key_usage);
|
copy_ext(dst_cert, src_cert, NID_ext_key_usage);
|
||||||
|
|||||||
Loading…
Reference in New Issue
Block a user