Fix noisy SSL error

Signed-off-by: Bryan Frimin <bryan@getprobo.com>
This commit is contained in:
Bryan Frimin
2025-10-14 14:20:58 +02:00
parent 9e0e48dd4e
commit 1b01659fbc
2 changed files with 20 additions and 3 deletions

View File

@@ -32,8 +32,15 @@ type (
cache sync.Map
encryptionKey cipher.EncryptionKey
}
// NoSNIError is returned when a TLS client doesn't provide SNI (Server Name Indication)
NoSNIError struct{}
)
func (e *NoSNIError) Error() string {
return "no SNI provided"
}
func NewSelector(
pg *pg.Client,
encryptionKey cipher.EncryptionKey,
@@ -49,7 +56,7 @@ func (s *Selector) GetCertificate(hello *tls.ClientHelloInfo) (*tls.Certificate,
// Empty domain, return error
if domain == "" {
return nil, fmt.Errorf("no SNI provided")
return nil, &NoSNIError{}
}
if cached, ok := s.cache.Load(domain); ok {

View File

@@ -614,8 +614,18 @@ func (impl *Implm) runTrustCenterServer(
)
httpsServer.TLSConfig = &tls.Config{
GetCertificate: certSelector.GetCertificate,
MinVersion: tls.VersionTLS12,
GetCertificate: func(hello *tls.ClientHelloInfo) (*tls.Certificate, error) {
cert, err := certSelector.GetCertificate(hello)
// Silently reject connections without SNI (load balancers, health checks, scanners)
if err != nil {
var noSNIErr *certmanager.NoSNIError
if errors.As(err, &noSNIErr) {
return nil, nil
}
}
return cert, err
},
MinVersion: tls.VersionTLS12,
CipherSuites: []uint16{
tls.TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384,
tls.TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256,