[pbs-devel] [PATCH proxmox-backup] fix #3763: disable renegotiation

Fabian Grünbichler f.gruenbichler at proxmox.com
Wed Dec 15 15:18:36 CET 2021


requires openssl crate with fix[0], like our packaged one.

0: https://github.com/sfackler/rust-openssl/pull/1584

Tested-by: Stoiko Ivanov s.ivanov at proxmox.com
Reviewed-by: Stoiko Ivanov s.ivanov at proxmox.com

Signed-off-by: Fabian Grünbichler <f.gruenbichler at proxmox.com>
---
sending as patch since we could also wait for the PR to land and bump
the dep then accordingly..

 Cargo.toml                      | 2 +-
 src/bin/proxmox-backup-proxy.rs | 1 +
 2 files changed, 2 insertions(+), 1 deletion(-)

diff --git a/Cargo.toml b/Cargo.toml
index d7ad2085..d1fe9c67 100644
--- a/Cargo.toml
+++ b/Cargo.toml
@@ -64,7 +64,7 @@ log = "0.4"
 nix = "0.19.1"
 num-traits = "0.2"
 once_cell = "1.3.1"
-openssl = "0.10"
+openssl = "0.10.38" # currently patched!
 pam = "0.7"
 pam-sys = "0.5"
 percent-encoding = "2.1"
diff --git a/src/bin/proxmox-backup-proxy.rs b/src/bin/proxmox-backup-proxy.rs
index 07a53687..5e5babd1 100644
--- a/src/bin/proxmox-backup-proxy.rs
+++ b/src/bin/proxmox-backup-proxy.rs
@@ -348,6 +348,7 @@ fn make_tls_acceptor() -> Result<SslAcceptor, Error> {
         .map_err(|err| format_err!("unable to read proxy key {} - {}", key_path, err))?;
     acceptor.set_certificate_chain_file(cert_path)
         .map_err(|err| format_err!("unable to read proxy cert {} - {}", cert_path, err))?;
+    acceptor.set_options(openssl::ssl::SslOptions::NO_RENEGOTIATION);
     acceptor.check_private_key().unwrap();
 
     Ok(acceptor.build())
-- 
2.30.2






More information about the pbs-devel mailing list