summaryrefslogtreecommitdiff
path: root/lib/stream-ssl.h
diff options
context:
space:
mode:
authorBen Pfaff <blp@nicira.com>2010-08-05 09:24:00 -0700
committerBen Pfaff <blp@nicira.com>2010-08-05 09:24:00 -0700
commit6f1e91b1d7c058d701145080c344bbc531b394ed (patch)
treee5fa86b7ff37d384b99399fe1d9ba9a409d541a0 /lib/stream-ssl.h
parent55574bb0d21541c13fe67545a74448b36063e461 (diff)
downloadopenvswitch-6f1e91b1d7c058d701145080c344bbc531b394ed.tar.gz
stream-ssl: Make changing keys and certificate at runtime reliable.
OpenSSL is picky about the order in which keys and certificates are changed: you have to change the certificate first, then the key. It doesn't document this, but deep in the source code, in a function that sets a new certificate, it has this comment: /* don't fail for a cert/key mismatch, just free * current private key (when switching to a different * cert & key, first this function should be used, * then ssl_set_pkey */ Brilliant, guys, thanks a lot. Bug #2921.
Diffstat (limited to 'lib/stream-ssl.h')
-rw-r--r--lib/stream-ssl.h8
1 files changed, 7 insertions, 1 deletions
diff --git a/lib/stream-ssl.h b/lib/stream-ssl.h
index dd2a16ee8..ba6e422ed 100644
--- a/lib/stream-ssl.h
+++ b/lib/stream-ssl.h
@@ -1,5 +1,5 @@
/*
- * Copyright (c) 2008, 2009 Nicira Networks.
+ * Copyright (c) 2008, 2009, 2010 Nicira Networks.
*
* Licensed under the Apache License, Version 2.0 (the "License");
* you may not use this file except in compliance with the License.
@@ -20,9 +20,15 @@
#ifdef HAVE_OPENSSL
bool stream_ssl_is_configured(void);
+
void stream_ssl_set_private_key_file(const char *file_name);
void stream_ssl_set_certificate_file(const char *file_name);
void stream_ssl_set_ca_cert_file(const char *file_name, bool bootstrap);
+
+void stream_ssl_set_key_and_cert(const char *private_key_file,
+ const char *certificate_file);
+
+
void stream_ssl_set_peer_ca_cert_file(const char *file_name);
/* Define the long options for SSL support.