moonchen opened a new issue, #13798:
URL: https://github.com/apache/trafficserver/issues/13798
On master, an entry without `dest_ip` is treated as `dest_ip: "*"`. It
competes with the explicitly configured default certificate.
For example:
```yaml
ssl_multicert:
- ssl_cert_name: named.pem
ssl_key_name: named.key
- dest_ip: "*"
ssl_cert_name: default.pem
ssl_key_name: default.key
```
**Expected:** Clients with no SNI or an unmatched SNI receive `default.pem`.
**Actual:** The first entry to register `"*"` wins. Startup loads
certificates concurrently, so the default can change between restarts. With the
default reload concurrency of one, the first entry wins, making `named.pem` the
default after a reload.
This affects both YAML and legacy `ssl_multicert.config` files on master. It
does not affect 10.2.x and should be fixed before 11.0.
**Workaround:** Set `dest_ip: ""` on entries that should not be the default.
The fix should preserve an omitted `dest_ip` as empty. The configuration
converter also needs updating: it currently writes `dest_ip: "*"` into entries
that omitted it, so previously converted files will need correction.
--
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.
To unsubscribe, e-mail: [email protected]
For queries about this service, please contact Infrastructure at:
[email protected]