Uploaded image for project: 'MariaDB MaxScale'
  1. MariaDB MaxScale
  2. MXS-5976

Select TLS certificate based on the SNI value

    XMLWordPrintable

Details

    • New Feature
    • Status: Closed (View Workflow)
    • Major
    • Resolution: Fixed
    • None
    • 26.10.0
    • mariadbclient
    • None

    Description

      Add support for multiple TLS certificates for a listener and select the certificate based on the SNI value that the client sends. If no SNI value is sent, use the default TLS certificate.

      The certificates should be defined by a certificate directory option from where they are loaded. The matching of the certificate to the SNI value should be done based on the certificate itself and not the filename.

      Implementation wise, the certificate can be selected inside the callback set by the SSL_CTX_set_tlsext_servername_callback function.

      A related feature is the ability to then select which service is used that's also based on the SNI value. For this, see MXS-6010.

      Attachments

        Issue Links

          Activity

            People

              esa.korhonen Esa Korhonen
              serg Sergei Golubchik
              Votes:
              0 Vote for this issue
              Watchers:
              8 Start watching this issue

              Dates

                Created:
                Updated:
                Resolved:

                Time Tracking

                  Estimated:
                  Original Estimate - 10d Original Estimate - 10d
                  10d
                  Remaining:
                  Remaining Estimate - 0d
                  0d
                  Logged:
                  Time Spent - 17d
                  17d

                  Git Integration

                    Error rendering 'com.xiplink.jira.git.jira_git_plugin:git-issue-webpanel'. Please contact your Jira administrators.