summaryrefslogtreecommitdiff
path: root/src
diff options
context:
space:
mode:
authorLaurent Bercot <ska-skaware@skarnet.org>2016-11-25 20:36:50 +0000
committerLaurent Bercot <ska-skaware@skarnet.org>2016-11-25 20:36:50 +0000
commita6b3bddb41db1771ac9190a77caac1c7217e7e4b (patch)
tree2fa7fd3f0b06f3f1e30e7de434513118176e3c4c /src
parent8d532683386121e70810b0d7c6642cc2c2b89cb0 (diff)
downloads6-networking-a6b3bddb41db1771ac9190a77caac1c7217e7e4b.tar.xz
SNI support for libtls
Diffstat (limited to 'src')
-rw-r--r--src/stls/stls_s6tlsc.c14
1 files changed, 6 insertions, 8 deletions
diff --git a/src/stls/stls_s6tlsc.c b/src/stls/stls_s6tlsc.c
index 3f8e9cd..aa82087 100644
--- a/src/stls/stls_s6tlsc.c
+++ b/src/stls/stls_s6tlsc.c
@@ -13,10 +13,9 @@
#define diecfg(cfg, s) strerr_diefu3x(96, (s), ": ", tls_config_error(cfg))
#define diectx(e, ctx, s) strerr_diefu3x(e, (s), ": ", tls_error(ctx))
-int stls_s6tlsc (char const *const *argv, char const *const *envp, tain_t const *tto, uint32_t preoptions, uint32_t options, uid_t uid, gid_t gid, unsigned int verbosity, int *sfd)
+int stls_s6tlsc (char const *const *argv, char const *const *envp, tain_t const *tto, uint32_t preoptions, uint32_t options, uid_t uid, gid_t gid, unsigned int verbosity, char const *servername, int *sfd)
{
int fds[4] = { sfd[0], sfd[1], sfd[0], sfd[1] } ;
- struct tls *cctx ;
struct tls *ctx ;
struct tls_config *cfg ;
pid_t pid ;
@@ -79,16 +78,15 @@ int stls_s6tlsc (char const *const *argv, char const *const *envp, tain_t const
if (gid && setgid(gid) < 0) strerr_diefu1sys(111, "setgid") ;
if (uid && setuid(uid) < 0) strerr_diefu1sys(111, "setuid") ;
- if (tls_accept_fds(ctx, &cctx, fds[2], fds[3]) < 0)
- diectx(97, ctx, "tls_accept_fds") ;
-
- tls_free(ctx) ;
+ if (tls_connect_fds(ctx, fds[2], fds[3], servername) < 0)
+ diectx(97, ctx, "tls_connect_fds") ;
{
int wstat ;
- int r = stls_run(cctx, fds, verbosity, options, tto) ;
+ int r = stls_run(ctx, fds, verbosity, options, tto) ;
if (r < 0) strerr_diefu1sys(111, "run SSL engine") ;
- else if (r) diectx(98, cctx, "run SSL engine") ;
+ else if (r) diectx(98, ctx, "run SSL engine") ;
+ tls_free(ctx) ;
if (wait_pid(pid, &wstat) < 0) strerr_diefu1sys(111, "wait_pid") ;
return wait_estatus(wstat) ;
}