Implemented SLL passphrase, although this should be deprecated

SVN revision: 2306
This commit is contained in:
Stefan Ritt 2010-07-28 14:57:04 +00:00
parent 33e48edef9
commit a3c6b4f0ae

View File

@ -27871,7 +27871,7 @@ void hup_handler(int sig)
SSL_CTX *init_ssl(void) SSL_CTX *init_ssl(void)
{ {
char str[256]; char str[256], pwd[256];
SSL_METHOD *meth; SSL_METHOD *meth;
SSL_CTX *ctx; SSL_CTX *ctx;
@ -27881,6 +27881,10 @@ SSL_CTX *init_ssl(void)
meth = SSLv23_method(); meth = SSLv23_method();
ctx = SSL_CTX_new(meth); ctx = SSL_CTX_new(meth);
if (getcfg("global", "SSL Passphrase", pwd, sizeof(pwd))) {
SSL_CTX_set_default_passwd_cb_userdata(ctx, pwd);
}
strlcpy(str, resource_dir, sizeof(str)); strlcpy(str, resource_dir, sizeof(str));
strlcat(str, "ssl/server.crt", sizeof(str)); strlcat(str, "ssl/server.crt", sizeof(str));
if (!file_exist(str)) { if (!file_exist(str)) {
@ -27896,6 +27900,7 @@ SSL_CTX *init_ssl(void)
eprintf("Key file \"%s\" not found, aborting\n", str); eprintf("Key file \"%s\" not found, aborting\n", str);
return NULL; return NULL;
} }
if (SSL_CTX_use_PrivateKey_file(ctx, str, SSL_FILETYPE_PEM) == 0) if (SSL_CTX_use_PrivateKey_file(ctx, str, SSL_FILETYPE_PEM) == 0)
return NULL; return NULL;
if (SSL_CTX_check_private_key(ctx) < 0) if (SSL_CTX_check_private_key(ctx) < 0)