moonchen opened a new issue, #13798:
URL: https://github.com/apache/trafficserver/issues/13798

   On master, an entry without `dest_ip` is treated as `dest_ip: "*"`. It 
competes with the explicitly configured default certificate.
   
   For example:
   
   ```yaml
   ssl_multicert:
     - ssl_cert_name: named.pem
       ssl_key_name: named.key
   
     - dest_ip: "*"
       ssl_cert_name: default.pem
       ssl_key_name: default.key
   ```
   
   **Expected:** Clients with no SNI or an unmatched SNI receive `default.pem`.
   
   **Actual:** The first entry to register `"*"` wins. Startup loads 
certificates concurrently, so the default can change between restarts. With the 
default reload concurrency of one, the first entry wins, making `named.pem` the 
default after a reload.
   
   This affects both YAML and legacy `ssl_multicert.config` files on master. It 
does not affect 10.2.x and should be fixed before 11.0.
   
   **Workaround:** Set `dest_ip: ""` on entries that should not be the default.
   
   The fix should preserve an omitted `dest_ip` as empty. The configuration 
converter also needs updating: it currently writes `dest_ip: "*"` into entries 
that omitted it, so previously converted files will need correction.
   


-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: [email protected]

For queries about this service, please contact Infrastructure at:
[email protected]

Reply via email to