moonchen opened a new issue, #13793: URL: https://github.com/apache/trafficserver/issues/13793
With BoringSSL, an `ssl_multicert.yaml` entry with a specific `dest_ip` that holds both an RSA and an EC certificate gives the EC context to every client that reaches the address lookup. `SSLCertLookup::find(const IpEndpoint &)` returns the EC context whenever one exists and does not consider the client's key type, so a client that supports only RSA cannot complete the handshake. OpenSSL builds select between the certificates natively and are not affected. #13712 fixed the same problem for the `*` default entry. -- This is an automated message from the Apache Git Service. To respond to the message, please log on to GitHub and use the URL above to go to the specific comment. To unsubscribe, e-mail: [email protected] For queries about this service, please contact Infrastructure at: [email protected]
