Add 'hostname' param to wrapConnectedSocket
This commit is contained in:
parent
27b571dd95
commit
e0059287bb
3 changed files with 195 additions and 180 deletions
|
|
@ -647,9 +647,12 @@ when defineSsl:
|
|||
sslSetBio(socket.sslHandle, socket.bioIn, socket.bioOut)
|
||||
|
||||
proc wrapConnectedSocket*(ctx: SslContext, socket: AsyncSocket,
|
||||
handshake: SslHandshakeType) =
|
||||
handshake: SslHandshakeType,
|
||||
hostname: string = nil) =
|
||||
## Wraps a connected socket in an SSL context. This function effectively
|
||||
## turns ``socket`` into an SSL socket.
|
||||
## ``hostname`` should be specified so that the client knows which hostname
|
||||
## the server certificate should be validated against.
|
||||
##
|
||||
## This should be called on a connected socket, and will perform
|
||||
## an SSL handshake immediately.
|
||||
|
|
@ -660,6 +663,10 @@ when defineSsl:
|
|||
|
||||
case handshake
|
||||
of handshakeAsClient:
|
||||
if not hostname.isNil and not isIpAddress(hostname):
|
||||
# Set the SNI address for this connection. This call can fail if
|
||||
# we're not using TLSv1+.
|
||||
discard SSL_set_tlsext_host_name(socket.sslHandle, hostname)
|
||||
sslSetConnectState(socket.sslHandle)
|
||||
of handshakeAsServer:
|
||||
sslSetAcceptState(socket.sslHandle)
|
||||
|
|
|
|||
Loading…
Add table
Add a link
Reference in a new issue