From 65fdde9e210d5471ef22202011161aaa0fdc55f5 Mon Sep 17 00:00:00 2001 From: =?UTF-8?q?Lo=C3=AFc=20Gomez?= Date: Sun, 4 Feb 2024 14:49:35 +0900 Subject: [PATCH] Also reload SSL context on bip reload, allowing for SSL cert updates --- src/bip_main.c | 16 ++++++++++++++++ 1 file changed, 16 insertions(+) diff --git a/src/bip_main.c b/src/bip_main.c index 7558d7e..f2a869e 100644 --- a/src/bip_main.c +++ b/src/bip_main.c @@ -340,6 +340,22 @@ int main(int argc, char **argv) /* re-open to allow logfile rotate */ log_file_setup(); + +#ifdef HAVE_LIBSSL + /* reload SSL context if server-side SSL is enabled and SSL files + * seem accessible */ + if (conf_css) { + if (check_ssl_files(SOFT_FAIL)) { + if (set_ssl_context(SSLCTX_FORCE_UPDATE) == 1) + mylog(LOG_DEBUG, "SSL context has been updated"); + else + mylog(LOG_DEBUG, "SSL context has not been updated"); + } else { + mylog(LOG_ERROR, "Unable to update SSL context, " + "file checks failed"); + } + } +#endif } return 1; }