| 330 | */ |
| 331 | |
| 332 | int redisInitiateSSLWithContext(redisContext *c, redisSSLContext *redis_ssl_ctx) |
| 333 | { |
| 334 | if (!c || !redis_ssl_ctx) |
| 335 | return REDIS_ERR; |
| 336 | |
| 337 | /* We want to verify that redisSSLConnect() won't fail on this, as it will |
| 338 | * not own the SSL object in that case and we'll end up leaking. |
| 339 | */ |
| 340 | if (c->privctx) |
| 341 | return REDIS_ERR; |
| 342 | |
| 343 | SSL *ssl = SSL_new(redis_ssl_ctx->ssl_ctx); |
| 344 | if (!ssl) { |
| 345 | __redisSetError(c, REDIS_ERR_OTHER, "Couldn't create new SSL instance"); |
| 346 | goto error; |
| 347 | } |
| 348 | |
| 349 | if (redis_ssl_ctx->server_name) { |
| 350 | if (!SSL_set_tlsext_host_name(ssl, redis_ssl_ctx->server_name)) { |
| 351 | __redisSetError(c, REDIS_ERR_OTHER, "Failed to set server_name/SNI"); |
| 352 | goto error; |
| 353 | } |
| 354 | } |
| 355 | |
| 356 | return redisSSLConnect(c, ssl); |
| 357 | |
| 358 | error: |
| 359 | if (ssl) |
| 360 | SSL_free(ssl); |
| 361 | return REDIS_ERR; |
| 362 | } |
| 363 | |
| 364 | static int maybeCheckWant(redisSSL *rssl, int rv) { |
| 365 | /** |