Skip to content
Open
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
2 changes: 2 additions & 0 deletions README.md
Original file line number Diff line number Diff line change
Expand Up @@ -151,6 +151,8 @@ behavior.
* [ssl_client_hello_by_lua_file](https://github.com/openresty/lua-nginx-module#ssl_client_hello_by_lua_file)
* [ssl_certificate_by_lua_block](https://github.com/openresty/lua-nginx-module#ssl_certificate_by_lua_block)
* [ssl_certificate_by_lua_file](https://github.com/openresty/lua-nginx-module#ssl_certificate_by_lua_file)
* [proxy_ssl_certificate_by_lua_block](https://github.com/openresty/lua-nginx-module#proxy_ssl_certificate_by_lua_block)
* [proxy_ssl_certificate_by_lua_file](https://github.com/openresty/lua-nginx-module#proxy_ssl_certificate_by_lua_file)
* [proxy_ssl_verify_by_lua_block](https://github.com/openresty/lua-nginx-module#proxy_ssl_verify_by_lua_block)
* [proxy_ssl_verify_by_lua_file](https://github.com/openresty/lua-nginx-module#proxy_ssl_verify_by_lua_file)
* [lua_shared_dict](https://github.com/openresty/lua-nginx-module#lua_shared_dict)
Expand Down
2 changes: 2 additions & 0 deletions config
Original file line number Diff line number Diff line change
Expand Up @@ -278,6 +278,7 @@ STREAM_LUA_SRCS=" \
$ngx_addon_dir/src/ngx_stream_lua_semaphore.c \
$ngx_addon_dir/src/ngx_stream_lua_ssl_client_helloby.c \
$ngx_addon_dir/src/ngx_stream_lua_ssl_certby.c \
$ngx_addon_dir/src/ngx_stream_lua_proxy_ssl_certby.c \
$ngx_addon_dir/src/ngx_stream_lua_proxy_ssl_verifyby.c \
$ngx_addon_dir/src/ngx_stream_lua_log_ringbuf.c \
$ngx_addon_dir/src/ngx_stream_lua_input_filters.c \
Expand Down Expand Up @@ -323,6 +324,7 @@ STREAM_LUA_DEPS=" \
$ngx_addon_dir/src/ngx_stream_lua_semaphore.h \
$ngx_addon_dir/src/ngx_stream_lua_ssl_client_helloby.h \
$ngx_addon_dir/src/ngx_stream_lua_ssl_certby.h \
$ngx_addon_dir/src/ngx_stream_lua_proxy_ssl_certby.h \
$ngx_addon_dir/src/ngx_stream_lua_proxy_ssl_verifyby.h \
$ngx_addon_dir/src/ngx_stream_lua_log_ringbuf.h \
$ngx_addon_dir/src/ngx_stream_lua_input_filters.h \
Expand Down
5 changes: 5 additions & 0 deletions src/ngx_stream_lua_common.h
Original file line number Diff line number Diff line change
Expand Up @@ -138,6 +138,7 @@

#ifdef HAVE_PROXY_SSL_PATCH
#define NGX_STREAM_LUA_CONTEXT_PROXY_SSL_VERIFY 0x0100
#define NGX_STREAM_LUA_CONTEXT_PROXY_SSL_CERT 0x0200
#endif


Expand Down Expand Up @@ -277,6 +278,10 @@ struct ngx_stream_lua_srv_conf_s {

#ifdef HAVE_PROXY_SSL_PATCH
struct {
ngx_stream_lua_srv_conf_handler_pt proxy_ssl_cert_handler;
ngx_str_t proxy_ssl_cert_src;
u_char *proxy_ssl_cert_src_key;

ngx_stream_lua_srv_conf_handler_pt proxy_ssl_verify_handler;
ngx_str_t proxy_ssl_verify_src;
u_char *proxy_ssl_verify_src_key;
Expand Down
2 changes: 2 additions & 0 deletions src/ngx_stream_lua_control.c
Original file line number Diff line number Diff line change
Expand Up @@ -117,6 +117,7 @@ ngx_stream_lua_ffi_exit(ngx_stream_lua_request_t *r, int status, u_char *err,
| NGX_STREAM_LUA_CONTEXT_SSL_CLIENT_HELLO
| NGX_STREAM_LUA_CONTEXT_SSL_CERT
#ifdef HAVE_PROXY_SSL_PATCH
| NGX_STREAM_LUA_CONTEXT_PROXY_SSL_CERT
| NGX_STREAM_LUA_CONTEXT_PROXY_SSL_VERIFY
#endif
| NGX_STREAM_LUA_CONTEXT_PREREAD,
Expand All @@ -127,6 +128,7 @@ ngx_stream_lua_ffi_exit(ngx_stream_lua_request_t *r, int status, u_char *err,

if (ctx->context & (NGX_STREAM_LUA_CONTEXT_SSL_CERT
#ifdef HAVE_PROXY_SSL_PATCH
| NGX_STREAM_LUA_CONTEXT_PROXY_SSL_CERT
| NGX_STREAM_LUA_CONTEXT_PROXY_SSL_VERIFY
#endif
| NGX_STREAM_LUA_CONTEXT_SSL_CLIENT_HELLO ))
Expand Down
3 changes: 3 additions & 0 deletions src/ngx_stream_lua_coroutine.c
Original file line number Diff line number Diff line change
Expand Up @@ -206,6 +206,7 @@ ngx_stream_lua_coroutine_resume(lua_State *L)
| NGX_STREAM_LUA_CONTEXT_SSL_CLIENT_HELLO
| NGX_STREAM_LUA_CONTEXT_SSL_CERT
#ifdef HAVE_PROXY_SSL_PATCH
| NGX_STREAM_LUA_CONTEXT_PROXY_SSL_CERT
| NGX_STREAM_LUA_CONTEXT_PROXY_SSL_VERIFY
#endif
| NGX_STREAM_LUA_CONTEXT_PREREAD
Expand Down Expand Up @@ -270,6 +271,7 @@ ngx_stream_lua_coroutine_yield(lua_State *L)
| NGX_STREAM_LUA_CONTEXT_SSL_CLIENT_HELLO
| NGX_STREAM_LUA_CONTEXT_SSL_CERT
#ifdef HAVE_PROXY_SSL_PATCH
| NGX_STREAM_LUA_CONTEXT_PROXY_SSL_CERT
| NGX_STREAM_LUA_CONTEXT_PROXY_SSL_VERIFY
#endif
| NGX_STREAM_LUA_CONTEXT_PREREAD
Expand Down Expand Up @@ -433,6 +435,7 @@ ngx_stream_lua_coroutine_status(lua_State *L)
| NGX_STREAM_LUA_CONTEXT_SSL_CLIENT_HELLO
| NGX_STREAM_LUA_CONTEXT_SSL_CERT
#ifdef HAVE_PROXY_SSL_PATCH
| NGX_STREAM_LUA_CONTEXT_PROXY_SSL_CERT
| NGX_STREAM_LUA_CONTEXT_PROXY_SSL_VERIFY
#endif
| NGX_STREAM_LUA_CONTEXT_PREREAD
Expand Down
31 changes: 31 additions & 0 deletions src/ngx_stream_lua_module.c
Original file line number Diff line number Diff line change
Expand Up @@ -32,6 +32,7 @@
#include "ngx_stream_lua_ssl_certby.h"

#ifdef HAVE_PROXY_SSL_PATCH
#include "ngx_stream_lua_proxy_ssl_certby.h"
#include "ngx_stream_lua_proxy_ssl_verifyby.h"
#endif

Expand Down Expand Up @@ -428,6 +429,20 @@ static ngx_command_t ngx_stream_lua_cmds[] = {

#ifdef HAVE_PROXY_SSL_PATCH
/* same context as proxy_pass directive */
{ ngx_string("proxy_ssl_certificate_by_lua_block"),
NGX_STREAM_SRV_CONF|NGX_CONF_BLOCK|NGX_CONF_NOARGS,
ngx_stream_lua_proxy_ssl_cert_by_lua_block,
NGX_STREAM_SRV_CONF_OFFSET,
0,
(void *) ngx_stream_lua_proxy_ssl_cert_handler_inline },

{ ngx_string("proxy_ssl_certificate_by_lua_file"),
NGX_STREAM_SRV_CONF|NGX_CONF_TAKE1,
ngx_stream_lua_proxy_ssl_cert_by_lua,
NGX_STREAM_SRV_CONF_OFFSET,
0,
(void *) ngx_stream_lua_proxy_ssl_cert_handler_file },

{ ngx_string("proxy_ssl_verify_by_lua_block"),
NGX_STREAM_SRV_CONF|NGX_CONF_BLOCK|NGX_CONF_NOARGS,
ngx_stream_lua_proxy_ssl_verify_by_lua_block,
Expand Down Expand Up @@ -855,6 +870,10 @@ ngx_stream_lua_create_srv_conf(ngx_conf_t *cf)
* lscf->srv.ssl_client_hello_src = { 0, NULL };
* lscf->srv.ssl_client_hello_src_key = NULL;
*
* lscf->ups.proxy_ssl_cert_handler = NULL;
* lscf->ups.proxy_ssl_cert_src = { 0, NULL };
* lscf->ups.proxy_ssl_cert_src_key = NULL;
*
* lscf->ups.proxy_ssl_verify_handler = NULL;
* lscf->ups.proxy_ssl_verify_src = { 0, NULL };
* lscf->ups.proxy_ssl_verify_src_key = NULL;
Expand Down Expand Up @@ -1038,6 +1057,18 @@ ngx_stream_lua_merge_srv_conf(ngx_conf_t *cf, void *parent, void *child)
#endif

#ifdef HAVE_PROXY_SSL_PATCH
if (conf->ups.proxy_ssl_cert_src.len == 0) {
conf->ups.proxy_ssl_cert_src = prev->ups.proxy_ssl_cert_src;
conf->ups.proxy_ssl_cert_handler = prev->ups.proxy_ssl_cert_handler;
conf->ups.proxy_ssl_cert_src_key = prev->ups.proxy_ssl_cert_src_key;
}

if (conf->ups.proxy_ssl_cert_src.len) {
if (ngx_stream_lua_proxy_ssl_cert_set_callback(cf) != NGX_OK) {
return NGX_CONF_ERROR;
}
}

if (conf->ups.proxy_ssl_verify_src.len == 0) {
conf->ups.proxy_ssl_verify_src = prev->ups.proxy_ssl_verify_src;
conf->ups.proxy_ssl_verify_handler = prev->ups.proxy_ssl_verify_handler;
Expand Down
4 changes: 4 additions & 0 deletions src/ngx_stream_lua_phase.c
Original file line number Diff line number Diff line change
Expand Up @@ -67,6 +67,10 @@ ngx_stream_lua_ngx_get_phase(lua_State *L)
break;

#ifdef HAVE_PROXY_SSL_PATCH
case NGX_STREAM_LUA_CONTEXT_PROXY_SSL_CERT:
lua_pushliteral(L, "proxy_ssl_cert");
break;

case NGX_STREAM_LUA_CONTEXT_PROXY_SSL_VERIFY:
lua_pushliteral(L, "proxy_ssl_verify");
break;
Expand Down
Loading