From a860656e9b3861171436d7cbc7420b56a89548a9 Mon Sep 17 00:00:00 2001 From: Masaori Koshiba Date: Mon, 18 Nov 2024 08:26:05 +0900 Subject: [PATCH] Fix setting TLS groups with BoringSSL (#11840) * Fix setting TLS groups with BoringSSL * Get rid of #ifdef for old openssl --- src/iocore/net/SSLUtils.cc | 9 ++------- 1 file changed, 2 insertions(+), 7 deletions(-) diff --git a/src/iocore/net/SSLUtils.cc b/src/iocore/net/SSLUtils.cc index b3f932d32d9..7c469b2ff66 100644 --- a/src/iocore/net/SSLUtils.cc +++ b/src/iocore/net/SSLUtils.cc @@ -1530,20 +1530,15 @@ SSLMultiCertConfigLoader::_set_cipher_suites([[maybe_unused]] SSL_CTX *ctx) } bool -SSLMultiCertConfigLoader::_set_curves([[maybe_unused]] SSL_CTX *ctx) +SSLMultiCertConfigLoader::_set_curves(SSL_CTX *ctx) { -#if defined(SSL_CTX_set1_groups_list) || defined(SSL_CTX_set1_curves_list) if (this->_params->server_groups_list != nullptr) { -#ifdef SSL_CTX_set1_groups_list if (!SSL_CTX_set1_groups_list(ctx, this->_params->server_groups_list)) { -#else - if (!SSL_CTX_set1_curves_list(ctx, this->_params->server_groups_list)) { -#endif SSLError("invalid groups list for server in %s", ts::filename::RECORDS); return false; } } -#endif + return true; }