kpumuk opened a new pull request, #3626:
URL: https://github.com/apache/thrift/pull/3626
<!-- Explain the changes in the pull request below: -->
Some TLS terminators, proxies, and load balancers require SNI in the
`ClientHello` to route the connection or select the correct certificate. Ruby
clients previously performed post-handshake hostname verification, but did not
send a server hostname during the handshake.
Ruby `Thrift::SSLSocket` now sets the OpenSSL server hostname before
starting the TLS handshake, allowing clients to send SNI for hostname-based SSL
connections.
It also adds an optional `server_hostname:` override for cases where the
client connects to one address but needs to indicate and verify a different DNS
name.
<!-- We recommend you review the checklist/tips before submitting a pull
request. -->
- [x] Did you create an [Apache
Jira](https://issues.apache.org/jira/projects/THRIFT/issues/) ticket?
THRIFT-6078
- [x] If a ticket exists: Does your pull request title follow the pattern
"THRIFT-NNNN: describe my issue"?
- [x] Did you squash your changes to a single commit? (not required, but
preferred)
- [x] Did you do your best to avoid breaking changes? If one was needed,
did you label the Jira ticket with "Breaking-Change"?
- [ ] If your change does not involve any code, include `[skip ci]` anywhere
in the commit message to free up build resources.
<!--
The Contributing Guide at:
https://github.com/apache/thrift/blob/master/CONTRIBUTING.md
has more details and tips for committing properly.
-->
--
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.
To unsubscribe, e-mail: [email protected]
For queries about this service, please contact Infrastructure at:
[email protected]