@@ -32,8 +32,15 @@ type (
|
|||||||
cache sync.Map
|
cache sync.Map
|
||||||
encryptionKey cipher.EncryptionKey
|
encryptionKey cipher.EncryptionKey
|
||||||
}
|
}
|
||||||
|
|
||||||
|
// NoSNIError is returned when a TLS client doesn't provide SNI (Server Name Indication)
|
||||||
|
NoSNIError struct{}
|
||||||
)
|
)
|
||||||
|
|
||||||
|
func (e *NoSNIError) Error() string {
|
||||||
|
return "no SNI provided"
|
||||||
|
}
|
||||||
|
|
||||||
func NewSelector(
|
func NewSelector(
|
||||||
pg *pg.Client,
|
pg *pg.Client,
|
||||||
encryptionKey cipher.EncryptionKey,
|
encryptionKey cipher.EncryptionKey,
|
||||||
@@ -49,7 +56,7 @@ func (s *Selector) GetCertificate(hello *tls.ClientHelloInfo) (*tls.Certificate,
|
|||||||
|
|
||||||
// Empty domain, return error
|
// Empty domain, return error
|
||||||
if domain == "" {
|
if domain == "" {
|
||||||
return nil, fmt.Errorf("no SNI provided")
|
return nil, &NoSNIError{}
|
||||||
}
|
}
|
||||||
|
|
||||||
if cached, ok := s.cache.Load(domain); ok {
|
if cached, ok := s.cache.Load(domain); ok {
|
||||||
|
|||||||
@@ -614,8 +614,18 @@ func (impl *Implm) runTrustCenterServer(
|
|||||||
)
|
)
|
||||||
|
|
||||||
httpsServer.TLSConfig = &tls.Config{
|
httpsServer.TLSConfig = &tls.Config{
|
||||||
GetCertificate: certSelector.GetCertificate,
|
GetCertificate: func(hello *tls.ClientHelloInfo) (*tls.Certificate, error) {
|
||||||
MinVersion: tls.VersionTLS12,
|
cert, err := certSelector.GetCertificate(hello)
|
||||||
|
// Silently reject connections without SNI (load balancers, health checks, scanners)
|
||||||
|
if err != nil {
|
||||||
|
var noSNIErr *certmanager.NoSNIError
|
||||||
|
if errors.As(err, &noSNIErr) {
|
||||||
|
return nil, nil
|
||||||
|
}
|
||||||
|
}
|
||||||
|
return cert, err
|
||||||
|
},
|
||||||
|
MinVersion: tls.VersionTLS12,
|
||||||
CipherSuites: []uint16{
|
CipherSuites: []uint16{
|
||||||
tls.TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384,
|
tls.TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384,
|
||||||
tls.TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256,
|
tls.TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256,
|
||||||
|
|||||||
Reference in New Issue
Block a user