[
https://issues.apache.org/jira/browse/TS-1779?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=13649391#comment-13649391
]
James Peach commented on TS-1779:
---------------------------------
I think that this is the fix:
{code}
diff --git a/iocore/net/SSLCertLookup.cc b/iocore/net/SSLCertLookup.cc
index 021e1a5..85105d8 100644
--- a/iocore/net/SSLCertLookup.cc
+++ b/iocore/net/SSLCertLookup.cc
@@ -247,6 +247,7 @@ SSLCertLookup::buildTable()
addr = NULL;
sslCert = NULL;
priKey = NULL;
+ sslCa = NULL;
}
} // else
} // if(*line != '\0' && *line != '#')
{code}
> Crash using SNI and ssl_ca_name
> -------------------------------
>
> Key: TS-1779
> URL: https://issues.apache.org/jira/browse/TS-1779
> Project: Traffic Server
> Issue Type: Bug
> Components: SSL
> Reporter: Rodney
> Assignee: James Peach
> Labels: A
> Fix For: 3.3.3
>
>
> When I add 'ssl_ca_name' to include a chain cert CA the traffic server fails
> to start with a core dump. It seems to be okay if I just have one entry in
> 'ssl_multicert.config' file but as soon as I use SNI the traffic server will
> not start with a core dump.
> This witnessed on 3.2.0 and currently 3.2.4 with Debian Squeeze.
> Example entries:
> ssl_cert_name=my1.crt ssl_key_name=my1.key ssl_ca_name=my1CA.crt
> ssl_cert_name=my2.crt ssl_key_name=my2.key ssl_ca_name=my2CA.crt
> #Default
> dest_ip=* ssl_cert_name=my1.crt ssl_key_name=my1.key ssl_ca_name=my1CA.crt
--
This message is automatically generated by JIRA.
If you think it was sent incorrectly, please contact your JIRA administrators
For more information on JIRA, see: http://www.atlassian.com/software/jira