[Asterisk-code-review] http.c: Reload TLS even if http.conf hasn't changed (asterisk[master])

George Joseph asteriskteam at digium.com
Thu Oct 4 07:23:49 CDT 2018

George Joseph has submitted this change and it was merged. ( https://gerrit.asterisk.org/10398 )

Change subject: http.c: Reload TLS even if http.conf hasn't changed

http.c: Reload TLS even if http.conf hasn't changed

There is currently no way to indicate to Asterisk that TLS certificates
and/or keys have been updated other than by modifying http.conf or
restarting Asterisk.

There is already code in main/tcptls.c that determines if a reload is
actually necessary based on the hashes of the certicate and dependent
files, so this change merely gives us a way to request a reload without
explicitly modifying http.conf.

Change-Id: Ie795420dcc7eb3d91336820688a29adbcc321276
M main/http.c
1 file changed, 9 insertions(+), 1 deletion(-)

  Corey Farrell: Looks good to me, but someone else must approve
  Joshua Colp: Looks good to me, approved
  George Joseph: Approved for Submit

diff --git a/main/http.c b/main/http.c
index 5d0b89e..dcf90ae 100644
--- a/main/http.c
+++ b/main/http.c
@@ -2066,7 +2066,15 @@
 	int http_tls_was_enabled = 0;
 	cfg = ast_config_load2("http.conf", "http", config_flags);
+	if (!cfg || cfg == CONFIG_STATUS_FILEINVALID) {
+		return 0;
+	}
+	/* Even if the http.conf hasn't been updated, the TLS certs/keys may have been */
+		if (http_tls_cfg.enabled && ast_ssl_setup(https_desc.tls_cfg)) {
+			ast_tcptls_server_start(&https_desc);
+		}
 		return 0;

To view, visit https://gerrit.asterisk.org/10398
To unsubscribe, or for help writing mail filters, visit https://gerrit.asterisk.org/settings

Gerrit-Project: asterisk
Gerrit-Branch: master
Gerrit-MessageType: merged
Gerrit-Change-Id: Ie795420dcc7eb3d91336820688a29adbcc321276
Gerrit-Change-Number: 10398
Gerrit-PatchSet: 2
Gerrit-Owner: Sean Bright <sean.bright at gmail.com>
Gerrit-Reviewer: Corey Farrell <git at cfware.com>
Gerrit-Reviewer: George Joseph <gjoseph at digium.com>
Gerrit-Reviewer: Jenkins2 (1000185)
Gerrit-Reviewer: Joshua Colp <jcolp at digium.com>
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://lists.digium.com/pipermail/asterisk-code-review/attachments/20181004/784259e9/attachment.html>

More information about the asterisk-code-review mailing list