Uploaded image for project: 'Traffic Server'
  1. Traffic Server
  2. TS-3376

Missing cert chain file gives no errors or warnings

    XMLWordPrintableJSON

Details

    • Improvement
    • Status: Closed
    • Major
    • Resolution: Fixed
    • None
    • 5.3.0
    • SSL
    • None

    Description

      With an ssl_multicert.config of

      
      

      ATS will start up without any (as far as I could tell) errors, even when the cert chain file is completely missing. It just silently accepts the config, and brings ATS up in a poor state as far as TLS is concerned.

      IMO, we should at a minimum write some very serious warnings and errors on this, but maybe even refuse to startup (or reload) the config if the cert chain file is missing. This is serious enough that the server is in a non-functional state if it happens.

      Attachments

        Issue Links

          Activity

            People

              shinrich Susan Hinrichs
              zwoop Leif Hedstrom
              Votes:
              0 Vote for this issue
              Watchers:
              4 Start watching this issue

              Dates

                Created:
                Updated:
                Resolved: