Uploaded image for project: 'Traffic Server'
  1. Traffic Server
  2. TS-3243

Warnings from loading legitimate TLS certificates

    XMLWordPrintableJSON

Details

    • Bug
    • Status: Closed
    • Major
    • Resolution: Fixed
    • None
    • 5.3.0
    • SSL
    • None

    Description

      When loading a legitimate certificate (from Go Daddy), which has a domain name of trafficserver.apache.org as well as some SNs which includes trafficserver.apache.org as well, we get these warnings:

      [Dec 17 16:01:19.540] Server {0x2b58fdcadf40} NOTE: loading SSL certificate configuration from /usr/local/etc/trafficserver/ssl_multicert.config
      [Dec 17 16:01:19.545] Server {0x2b58fdcadf40} WARNING: previously indexed 'trafficserver.apache.org' with SSL_CTX 0x1, cannot index it with SSL_CTX #2 now
      

      I've looked at a couple certs from GD, and this practice seems normal. I don't think we should warn on this case, if the domain name for the cert is duplicated in the SN, just ignore the latter right ?

      Attachments

        Activity

          People

            shinrich Susan Hinrichs
            zwoop Leif Hedstrom
            Votes:
            0 Vote for this issue
            Watchers:
            4 Start watching this issue

            Dates

              Created:
              Updated:
              Resolved: