From: Ilya Shipitsin Date: Fri, 19 Mar 2021 17:31:14 +0000 (+0500) Subject: REGTESTS: revert workaround for a crash with recent libressl on http-reuse sni X-Git-Tag: v2.4-dev14~77 X-Git-Url: http://git.ipfire.org/?a=commitdiff_plain;h=19d14710e941a366afd5b4ff8720090c011c83c1;p=thirdparty%2Fhaproxy.git REGTESTS: revert workaround for a crash with recent libressl on http-reuse sni LibreSSL-3.2.5 has fixed "use-after-free" in tls session resumption, let us enable session resumption back --- diff --git a/reg-tests/connection/http_reuse_conn_hash.vtc b/reg-tests/connection/http_reuse_conn_hash.vtc index 81d16f9637..991e86f7a8 100644 --- a/reg-tests/connection/http_reuse_conn_hash.vtc +++ b/reg-tests/connection/http_reuse_conn_hash.vtc @@ -9,11 +9,9 @@ haproxy h1 -conf { mode http # sni - # ssl-reuse is disabled because it seems to be the origin of a crash with - # libressl from 3.2.2 on the CI (cf github issue #1115) listen sender-sni bind "fd@${feS_sni}" - server srv2 ${h1_feR_ssl_addr}:${h1_feR_ssl_port} ssl sni "req.hdr(x-sni)" verify none pool-low-conn 2 no-ssl-reuse + server srv2 ${h1_feR_ssl_addr}:${h1_feR_ssl_port} ssl sni "req.hdr(x-sni)" verify none pool-low-conn 2 # set-dst # specify dst1_addr for server, which should be identical to dst2_addr