]> git.proxmox.com Git - mirror_qemu.git/commit - qemu-nbd.c
block/nbd: don't restrict TLS usage to IP sockets
authorDaniel P. Berrangé <berrange@redhat.com>
Fri, 4 Mar 2022 19:36:03 +0000 (19:36 +0000)
committerEric Blake <eblake@redhat.com>
Mon, 7 Mar 2022 21:58:42 +0000 (15:58 -0600)
commite8ae8b1a75e8f6420c37be31797bd13aa7e95778
treee8184f49199a8a0ecc046a11c0e293bf3e644eb3
parent003b2b252112572cd8c92bffe5e532a53b28d1e4
block/nbd: don't restrict TLS usage to IP sockets

The TLS usage for NBD was restricted to IP sockets because validating
x509 certificates requires knowledge of the hostname that the client
is connecting to.

TLS does not have to use x509 certificates though, as PSK (pre-shared
keys) provide an alternative credential option. These have no
requirement for a hostname and can thus be trivially used for UNIX
sockets.

Furthermore, with the ability to overide the default hostname for
TLS validation in the previous patch, it is now also valid to want
to use x509 certificates with FD passing and UNIX sockets.

Reviewed-by: Eric Blake <eblake@redhat.com>
Signed-off-by: Daniel P. Berrangé <berrange@redhat.com>
Message-Id: <20220304193610.3293146-6-berrange@redhat.com>
Signed-off-by: Eric Blake <eblake@redhat.com>
block/nbd.c
blockdev-nbd.c
qemu-nbd.c