wenxuwan commented on code in PR #1244:
URL: 
https://github.com/apache/rocketmq-client-go/pull/1244#discussion_r4236715642


##########
internal/remote/tcp_conn.go:
##########
@@ -38,19 +38,47 @@
        d.KeepAlive = config.KeepAliveDuration
        d.Deadline = time.Now().Add(config.ConnectionTimeout)
 
-       var conn net.Conn
-       var err error
-       if config.UseTls {
-               conn, err = tls.DialWithDialer(&d, "tcp", addr, &tls.Config{
-                       InsecureSkipVerify: true,
-               })
-       } else {
-               conn, err = d.DialContext(ctx, "tcp", addr)
-       }
-
+       conn, err := d.DialContext(ctx, "tcp", addr)
        if err != nil {
                return nil, err
        }
+       if config.UseTls {
+               host, _, _ := net.SplitHostPort(addr)
+               tlsConn := tls.Client(conn, &tls.Config{ServerName: host, 
InsecureSkipVerify: true})

Review Comment:
   This setting was already present before this PR. I kept it unchanged while 
making the TLS handshake cancellable on shutdown. Enabling certificate 
verification here could break existing deployments using self-signed 
certificates.
   
   I suggest handling certificate verification and CA configuration in a 
separate PR



-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: [email protected]

For queries about this service, please contact Infrastructure at:
[email protected]

Reply via email to