sandeepkunusoth commented on issue #13926:
URL: https://github.com/apache/apisix/issues/13926#issuecomment-5593677115
SNI is important here because redis_ssl = true only enables TLS; it does not
tell the TLS server which hostname we are trying to reach. For Redis endpoints
that use hostname/SNI-based routing, the hostname has to be sent in the TLS
ClientHello.
This is also consistent with how common Redis clients handle TLS. For
example, go-redis sets tls.Config{ServerName: h} when using a rediss:// URL, so
the Redis hostname is used as the TLS server name:
https://github.com/redis/go-redis/blob/master/options.go
redis-py also explicitly added SNI support by passing the Redis host as
server_hostname during the TLS handshake:
https://github.com/redis/redis-py/pull/1087
So I think APISIX should similarly set sock_opts.server_name when redis_ssl
is enabled, using redis_server_name when provided and otherwise redis_host.
This keeps the behavior aligned with common Redis clients and allows APISIX to
connect to Redis endpoints that require SNI.
--
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.
To unsubscribe, e-mail: [email protected]
For queries about this service, please contact Infrastructure at:
[email protected]