Hi Daniel, Thanks very much for fixing these SSL reload and cleanup issues. I also ran into the SNI reload issue while reviewing the DH parameter patch and wrote a patch to try to fix it. I then checked whether the same problem had already been reported, which led me to this thread.
I've reviewed all five patches in v5. They look good to me, and I didn't find any further problems. The attached patch adds tests on top of v5 for a few cases missing from 004_sni.pl: 1. Enabling SNI by reloading with an encrypted per-host key and its own passphrase command. The existing encrypted-key tests start with SNI already enabled. 2. Turning SNI off while ssl_cert_file points to a missing file, with a default host configured. The default and named hosts use different certificates, so verify-full checks that the failed reload leaves the named host's certificate in use. 3. Retrying the reload after restoring a valid global certificate and key. The test checks that SNI host selection is disabled and a new connection verifies the global certificate. The added tests pass with v5. Regards, Rui
nocfbot-0001-Test-SNI-certificate-selection-across-configuration-reloads.patch
Description: Binary data
