diff options
| author | Ben Pfaff <blp@nicira.com> | 2010-08-05 09:24:00 -0700 |
|---|---|---|
| committer | Ben Pfaff <blp@nicira.com> | 2010-08-05 09:24:00 -0700 |
| commit | 6f1e91b1d7c058d701145080c344bbc531b394ed (patch) | |
| tree | e5fa86b7ff37d384b99399fe1d9ba9a409d541a0 /lib/stream-ssl.h | |
| parent | 55574bb0d21541c13fe67545a74448b36063e461 (diff) | |
| download | openvswitch-6f1e91b1d7c058d701145080c344bbc531b394ed.tar.gz | |
stream-ssl: Make changing keys and certificate at runtime reliable.
OpenSSL is picky about the order in which keys and certificates are
changed: you have to change the certificate first, then the key. It
doesn't document this, but deep in the source code, in a function that sets
a new certificate, it has this comment:
/* don't fail for a cert/key mismatch, just free
* current private key (when switching to a different
* cert & key, first this function should be used,
* then ssl_set_pkey */
Brilliant, guys, thanks a lot.
Bug #2921.
Diffstat (limited to 'lib/stream-ssl.h')
| -rw-r--r-- | lib/stream-ssl.h | 8 |
1 files changed, 7 insertions, 1 deletions
diff --git a/lib/stream-ssl.h b/lib/stream-ssl.h index dd2a16ee8..ba6e422ed 100644 --- a/lib/stream-ssl.h +++ b/lib/stream-ssl.h @@ -1,5 +1,5 @@ /* - * Copyright (c) 2008, 2009 Nicira Networks. + * Copyright (c) 2008, 2009, 2010 Nicira Networks. * * Licensed under the Apache License, Version 2.0 (the "License"); * you may not use this file except in compliance with the License. @@ -20,9 +20,15 @@ #ifdef HAVE_OPENSSL bool stream_ssl_is_configured(void); + void stream_ssl_set_private_key_file(const char *file_name); void stream_ssl_set_certificate_file(const char *file_name); void stream_ssl_set_ca_cert_file(const char *file_name, bool bootstrap); + +void stream_ssl_set_key_and_cert(const char *private_key_file, + const char *certificate_file); + + void stream_ssl_set_peer_ca_cert_file(const char *file_name); /* Define the long options for SSL support. |
