wenxuwan commented on code in PR #1244:
URL:
https://github.com/apache/rocketmq-client-go/pull/1244#discussion_r4236715642
##########
internal/remote/tcp_conn.go:
##########
@@ -38,19 +38,47 @@
d.KeepAlive = config.KeepAliveDuration
d.Deadline = time.Now().Add(config.ConnectionTimeout)
- var conn net.Conn
- var err error
- if config.UseTls {
- conn, err = tls.DialWithDialer(&d, "tcp", addr, &tls.Config{
- InsecureSkipVerify: true,
- })
- } else {
- conn, err = d.DialContext(ctx, "tcp", addr)
- }
-
+ conn, err := d.DialContext(ctx, "tcp", addr)
if err != nil {
return nil, err
}
+ if config.UseTls {
+ host, _, _ := net.SplitHostPort(addr)
+ tlsConn := tls.Client(conn, &tls.Config{ServerName: host,
InsecureSkipVerify: true})
Review Comment:
This setting was already present before this PR. I kept it unchanged while
making the TLS handshake cancellable on shutdown. Enabling certificate
verification here could break existing deployments using self-signed
certificates.
I suggest handling certificate verification and CA configuration in a
separate PR
--
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.
To unsubscribe, e-mail: [email protected]
For queries about this service, please contact Infrastructure at:
[email protected]