Skip to content
Merged
Changes from 3 commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
32 changes: 32 additions & 0 deletions listener.go
Original file line number Diff line number Diff line change
Expand Up @@ -74,11 +74,18 @@ func NewListener(l net.Listener, storage TLSStorage, caCert *x509.Certificate, c
setter.SetFactory(dynamicListener.factory)
}

if config.RegenerateCerts != nil && config.RegenerateCerts() {
if err := dynamicListener.regenerateCerts(); err != nil {
return nil, nil, err
}
}

if config.ExpirationDaysCheck == 0 {
config.ExpirationDaysCheck = 30
}

tlsListener := tls.NewListener(dynamicListener.WrapExpiration(config.ExpirationDaysCheck), dynamicListener.tlsConfig)

return tlsListener, dynamicListener.cacheHandler(), nil
}

Expand Down Expand Up @@ -129,6 +136,7 @@ type Config struct {
MaxSANs int
ExpirationDaysCheck int
CloseConnOnCertChange bool
RegenerateCerts func() bool
FilterCN func(...string) []string
}

Expand Down Expand Up @@ -180,6 +188,30 @@ func (l *listener) WrapExpiration(days int) net.Listener {
}
}

// regenerateCerts regenerates the used certificates and
// updates the secret.
func (l *listener) regenerateCerts() error {
l.Lock()
defer l.Unlock()

secret, err := l.storage.Get()
if err != nil {
return err
}

newSecret, err := l.factory.Renew(secret)
if err != nil {
return err
}
if err := l.storage.Update(newSecret); err != nil {
return err
}
// clear version to force cert reload
l.version = ""

return nil
}

func (l *listener) checkExpiration(days int) error {
l.Lock()
defer l.Unlock()
Expand Down