From c94a8137de380318fb52959eb22d1269efdb0a61 Mon Sep 17 00:00:00 2001 From: Alexey Sokolov Date: Wed, 26 Nov 2014 21:36:17 +0000 Subject: [PATCH] Update Csocket to 5746796ca55d21fa185caf7c58d015f650b77768 --- include/znc/Csocket.h | 2 +- src/Csocket.cpp | 20 +++++++++++++++----- 2 files changed, 16 insertions(+), 6 deletions(-) diff --git a/include/znc/Csocket.h b/include/znc/Csocket.h index 670d6150..8a9704b5 100644 --- a/include/znc/Csocket.h +++ b/include/znc/Csocket.h @@ -1178,7 +1178,7 @@ private: void FREE_SSL(); void FREE_CTX(); - void ConfigureCTXOptions( SSL_CTX * pCTX ); + bool ConfigureCTXOptions( SSL_CTX * pCTX ); #endif /* HAVE_LIBSSL */ diff --git a/src/Csocket.cpp b/src/Csocket.cpp index d690ad5f..92ccd3ef 100644 --- a/src/Csocket.cpp +++ b/src/Csocket.cpp @@ -1382,10 +1382,16 @@ bool Csock::AcceptSSL() } #ifdef HAVE_LIBSSL -void Csock::ConfigureCTXOptions( SSL_CTX * pCTX ) +bool Csock::ConfigureCTXOptions( SSL_CTX * pCTX ) { if( pCTX ) { + if( SSL_CTX_set_cipher_list( pCTX, m_sCipherType.c_str() ) <= 0 ) + { + CS_DEBUG( "Could not assign cipher [" << m_sCipherType << "]" ); + return( false ); + } + long uCTXOptions = 0; if( m_uDisableProtocols > 0 ) { @@ -1415,6 +1421,7 @@ void Csock::ConfigureCTXOptions( SSL_CTX * pCTX ) if( uCTXOptions ) SSL_CTX_set_options( pCTX, uCTXOptions ); } + return true; } #endif /* HAVE_LIBSSL */ @@ -1521,7 +1528,12 @@ bool Csock::SSLClientSetup() } } - ConfigureCTXOptions( m_ssl_ctx ); + if( !ConfigureCTXOptions( m_ssl_ctx ) ) + { + SSL_CTX_free( m_ssl_ctx ); + m_ssl_ctx = NULL; + return( false ); + } m_ssl = SSL_new( m_ssl_ctx ); if( !m_ssl ) @@ -1701,13 +1713,11 @@ SSL_CTX * Csock::SetupServerCTX() ERR_clear_error(); #endif - if( SSL_CTX_set_cipher_list( pCTX, m_sCipherType.c_str() ) <= 0 ) + if( !ConfigureCTXOptions( pCTX ) ) { - CS_DEBUG( "Could not assign cipher [" << m_sCipherType << "]" ); SSL_CTX_free( pCTX ); return( NULL ); } - ConfigureCTXOptions( pCTX ); return( pCTX ); } #endif /* HAVE_LIBSSL */