mirror of
https://github.com/puma/puma.git
synced 2022-11-09 13:48:40 -05:00
f5ccd03b26
* Extract class for building SSL context This commit extracts the `MiniSSL::Context` creation into its own `MiniSSL::ContextBuilder` class along the same lines as in [#1989]. This will allow us to reuse this code for adding SSL support to the control app (issue [#2015]). Since we will need the `MiniSSL` require and check in both places, I moved that into the `ContextBuilder` class as well. [#1989]: https://github.com/puma/puma/pull/1989 [#2015]: https://github.com/puma/puma/pull/2015 * Add SSL support for the control app This starts to address [#2015]. I think we will need to add SSL support to the control cli as well. [#2015]: https://github.com/puma/puma/issues/2015
76 lines
2.2 KiB
Ruby
76 lines
2.2 KiB
Ruby
module Puma
|
|
module MiniSSL
|
|
class ContextBuilder
|
|
def initialize(params, events)
|
|
require 'puma/minissl'
|
|
MiniSSL.check
|
|
|
|
@params = params
|
|
@events = events
|
|
end
|
|
|
|
def context
|
|
ctx = MiniSSL::Context.new
|
|
|
|
if defined?(JRUBY_VERSION)
|
|
unless params['keystore']
|
|
events.error "Please specify the Java keystore via 'keystore='"
|
|
end
|
|
|
|
ctx.keystore = params['keystore']
|
|
|
|
unless params['keystore-pass']
|
|
events.error "Please specify the Java keystore password via 'keystore-pass='"
|
|
end
|
|
|
|
ctx.keystore_pass = params['keystore-pass']
|
|
ctx.ssl_cipher_list = params['ssl_cipher_list'] if params['ssl_cipher_list']
|
|
else
|
|
unless params['key']
|
|
events.error "Please specify the SSL key via 'key='"
|
|
end
|
|
|
|
ctx.key = params['key']
|
|
|
|
unless params['cert']
|
|
events.error "Please specify the SSL cert via 'cert='"
|
|
end
|
|
|
|
ctx.cert = params['cert']
|
|
|
|
if ['peer', 'force_peer'].include?(params['verify_mode'])
|
|
unless params['ca']
|
|
events.error "Please specify the SSL ca via 'ca='"
|
|
end
|
|
end
|
|
|
|
ctx.ca = params['ca'] if params['ca']
|
|
ctx.ssl_cipher_filter = params['ssl_cipher_filter'] if params['ssl_cipher_filter']
|
|
end
|
|
|
|
ctx.no_tlsv1 = true if params['no_tlsv1'] == 'true'
|
|
ctx.no_tlsv1_1 = true if params['no_tlsv1_1'] == 'true'
|
|
|
|
if params['verify_mode']
|
|
ctx.verify_mode = case params['verify_mode']
|
|
when "peer"
|
|
MiniSSL::VERIFY_PEER
|
|
when "force_peer"
|
|
MiniSSL::VERIFY_PEER | MiniSSL::VERIFY_FAIL_IF_NO_PEER_CERT
|
|
when "none"
|
|
MiniSSL::VERIFY_NONE
|
|
else
|
|
events.error "Please specify a valid verify_mode="
|
|
MiniSSL::VERIFY_NONE
|
|
end
|
|
end
|
|
|
|
ctx
|
|
end
|
|
|
|
private
|
|
|
|
attr_reader :params, :events
|
|
end
|
|
end
|
|
end
|