Commit 19a4d04
authored
Enable TLS certificate verification for Elasticsearch client (#179)
Instead of silently disabling TLS verification when tlsServerName is
not provided, always verify server certificates. An empty ServerName
defers to http.Transport's default hostname check against the request
URL; set tlsServerName only when the certificate DNS name differs from
the host used to reach the server.
Related-To: OSPRH-33323
Signed-off-by: Daniel Pawlik <dpawlik@redhat.com>1 parent 8bf99fd commit 19a4d04
2 files changed
Lines changed: 8 additions & 9 deletions
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
44 | 44 | | |
45 | 45 | | |
46 | 46 | | |
| 47 | + | |
47 | 48 | | |
48 | 49 | | |
49 | 50 | | |
50 | | - | |
51 | | - | |
52 | | - | |
53 | | - | |
54 | | - | |
55 | 51 | | |
56 | 52 | | |
57 | 53 | | |
| |||
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
123 | 123 | | |
124 | 124 | | |
125 | 125 | | |
126 | | - | |
| 126 | + | |
127 | 127 | | |
128 | 128 | | |
129 | 129 | | |
130 | | - | |
| 130 | + | |
| 131 | + | |
131 | 132 | | |
132 | | - | |
| 133 | + | |
| 134 | + | |
133 | 135 | | |
134 | | - | |
| 136 | + | |
| 137 | + | |
135 | 138 | | |
136 | 139 | | |
137 | 140 | | |
| |||
0 commit comments