mirror of
https://github.com/caddyserver/caddy.git
synced 2025-01-13 22:51:08 -05:00
dfbc2e81e3
quic-go now vendors all of its dependencies, so we don't need to vendor them here. Created by running: gvt delete github.com/lucas-clemente/quic-go gvt delete github.com/bifurcation/mint gvt delete github.com/lucas-clemente/aes12 gvt delete github.com/lucas-clemente/fnv128a gvt delete github.com/lucas-clemente/quic-go-certificates gvt delete github.com/aead/chacha20 gvt delete github.com/hashicorp/golang-lru gvt fetch -tag v0.10.0-no-integrationtests github.com/lucas-clemente/quic-go
52 lines
1.4 KiB
Go
52 lines
1.4 KiB
Go
package quic
|
|
|
|
import (
|
|
gocrypto "crypto"
|
|
"crypto/tls"
|
|
"crypto/x509"
|
|
"errors"
|
|
|
|
"github.com/bifurcation/mint"
|
|
"github.com/lucas-clemente/quic-go/internal/protocol"
|
|
)
|
|
|
|
func tlsToMintConfig(tlsConf *tls.Config, pers protocol.Perspective) (*mint.Config, error) {
|
|
mconf := &mint.Config{
|
|
NonBlocking: true,
|
|
CipherSuites: []mint.CipherSuite{
|
|
mint.TLS_AES_128_GCM_SHA256,
|
|
mint.TLS_AES_256_GCM_SHA384,
|
|
},
|
|
}
|
|
if tlsConf != nil {
|
|
mconf.ServerName = tlsConf.ServerName
|
|
mconf.InsecureSkipVerify = tlsConf.InsecureSkipVerify
|
|
mconf.Certificates = make([]*mint.Certificate, len(tlsConf.Certificates))
|
|
mconf.RootCAs = tlsConf.RootCAs
|
|
mconf.VerifyPeerCertificate = tlsConf.VerifyPeerCertificate
|
|
for i, certChain := range tlsConf.Certificates {
|
|
mconf.Certificates[i] = &mint.Certificate{
|
|
Chain: make([]*x509.Certificate, len(certChain.Certificate)),
|
|
PrivateKey: certChain.PrivateKey.(gocrypto.Signer),
|
|
}
|
|
for j, cert := range certChain.Certificate {
|
|
c, err := x509.ParseCertificate(cert)
|
|
if err != nil {
|
|
return nil, err
|
|
}
|
|
mconf.Certificates[i].Chain[j] = c
|
|
}
|
|
}
|
|
switch tlsConf.ClientAuth {
|
|
case tls.NoClientCert:
|
|
case tls.RequireAnyClientCert:
|
|
mconf.RequireClientAuth = true
|
|
default:
|
|
return nil, errors.New("mint currently only support ClientAuthType RequireAnyClientCert")
|
|
}
|
|
}
|
|
if err := mconf.Init(pers == protocol.PerspectiveClient); err != nil {
|
|
return nil, err
|
|
}
|
|
return mconf, nil
|
|
}
|