Skip to content

Commit ddb9cfe

Browse files
committed
logsrvd_relay_tls_ctx: Do not fall back on server TLS context
If a TLS-capable relay is enabled, logsrvd_config->relay.ssl_ctx will be set. Unlike the relay TLS settings, there is no reason to fall back on the main server TLS context if there is no relay TLS context. Found by the ZeroPath AI Security Engineer <https://zeropath.com>
1 parent adf735c commit ddb9cfe

File tree

1 file changed

+1
-3
lines changed

1 file changed

+1
-3
lines changed

logsrvd/logsrvd_conf.c

Lines changed: 1 addition & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -334,9 +334,7 @@ logsrvd_conf_relay_retry_interval(void)
334334
SSL_CTX *
335335
logsrvd_relay_tls_ctx(void)
336336
{
337-
if (logsrvd_config->relay.ssl_ctx != NULL)
338-
return logsrvd_config->relay.ssl_ctx;
339-
return logsrvd_config->server.ssl_ctx;
337+
return logsrvd_config->relay.ssl_ctx;
340338
}
341339

342340
bool

0 commit comments

Comments
 (0)