Skip to content

Commit fa283d4

Browse files
committed
Drop TLS authentication mode invalid
The mode `invalid` is treated the same as `no`, and the ReadMe also says the default to be `no`. Also `invalid` has currently no string representation.
1 parent 0a7251c commit fa283d4

File tree

4 files changed

+3
-4
lines changed

4 files changed

+3
-4
lines changed

src/netlog/netlog-dtls.c

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -113,7 +113,7 @@ int dtls_connect(DTLSManager *m, SocketAddress *address) {
113113
m->bio = TAKE_PTR(bio);
114114

115115
/* Certification verification */
116-
if (m->auth_mode != OPEN_SSL_CERTIFICATE_AUTH_MODE_NONE && m->auth_mode != OPEN_SSL_CERTIFICATE_AUTH_MODE_INVALID) {
116+
if (m->auth_mode != OPEN_SSL_CERTIFICATE_AUTH_MODE_NONE) {
117117
log_debug("DTLS: enable certificate verification");
118118

119119
SSL_set_ex_data(ssl, 0, m);

src/netlog/netlog-manager.c

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -634,7 +634,7 @@ int manager_new(const char *state_file, const char *cursor, Manager **ret) {
634634
.state_file = strdup(state_file),
635635
.protocol = SYSLOG_TRANSMISSION_PROTOCOL_UDP,
636636
.log_format = SYSLOG_TRANSMISSION_LOG_FORMAT_RFC_5424,
637-
.auth_mode = OPEN_SSL_CERTIFICATE_AUTH_MODE_INVALID,
637+
.auth_mode = OPEN_SSL_CERTIFICATE_AUTH_MODE_NONE,
638638
.connection_retry_usec = DEFAULT_CONNECTION_RETRY_USEC,
639639
.ratelimit = (const RateLimit) {
640640
RATELIMIT_INTERVAL_USEC,

src/netlog/netlog-tls.c

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -212,7 +212,7 @@ int tls_connect(TLSManager *m, SocketAddress *address) {
212212
"TLS: Failed to SSL_set_fd: %s",
213213
ERR_error_string(ERR_get_error(), NULL));
214214
/* Certification verification */
215-
if (m->auth_mode != OPEN_SSL_CERTIFICATE_AUTH_MODE_NONE && m->auth_mode != OPEN_SSL_CERTIFICATE_AUTH_MODE_INVALID) {
215+
if (m->auth_mode != OPEN_SSL_CERTIFICATE_AUTH_MODE_NONE) {
216216
log_debug("TLS: enable certificate verification");
217217

218218
SSL_set_ex_data(ssl, 0, m);

src/netlog/netlog-tls.h

Lines changed: 0 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -14,7 +14,6 @@ typedef enum OpenSSLCertificateAuthMode {
1414
OPEN_SSL_CERTIFICATE_AUTH_MODE_DENY = 1 << 2,
1515
OPEN_SSL_CERTIFICATE_AUTH_MODE_WARN = 1 << 3,
1616
OPEN_SSL_CERTIFICATE_AUTH_MODE_MAX = 1 << 4,
17-
OPEN_SSL_CERTIFICATE_AUTH_MODE_INVALID = -1,
1817
} OpenSSLCertificateAuthMode;
1918

2019
typedef struct TLSManager TLSManager;

0 commit comments

Comments
 (0)