netdata/daemon: SSL fix - broken compilation case when ssl library not present! (#6201)
* SSL_fix fix the compilation case the library is not present!
thiagoftsm committed
Jun 3, 2019 at 19:25 UTC
5182677831814289d27afb0b48043ab63f2b6d1b
6 files changed
+30
-17
libnetdata/libnetdata.h
+3
-1
@@ -298,7 +298,9 @@ extern char *netdata_configured_host_prefix;
298
#include "clocks/clocks.h"
299
#include "popen/popen.h"
300
#include "simple_pattern/simple_pattern.h"
301
-#include "socket/security.h"
301
+#ifdef ENABLE_HTTPS
302
+# include "socket/security.h"
303
+#endif
304
#include "socket/socket.h"
305
#include "config/appconfig.h"
306
#include "log/log.h"
libnetdata/socket/security.c
+5
-1
@@ -1,5 +1,7 @@
1
#include "../libnetdata.h"
2
3
+#ifdef ENABLE_HTTPS
4
+
5
SSL_CTX *netdata_cli_ctx=NULL;
6
SSL_CTX *netdata_srv_ctx=NULL;
7
const char *security_key=NULL;
@@ -212,4 +214,6 @@ int security_test_certificate(SSL *ssl){
214
ret = 0;
215
}
216
return ret;
215
-}
\ No newline at end of file
217
+}
218
+
219
+#endif
libnetdata/socket/security.h
+18
-14
@@ -1,21 +1,24 @@
1
#ifndef NETDATA_SECURITY_H
2
# define NETDATA_SECURITY_H
3
4
-# include <openssl/ssl.h>
5
-# include <openssl/err.h>
6
-# if (SSLEAY_VERSION_NUMBER >= 0x0907000L) && (OPENSSL_VERSION_NUMBER < 0x10100000L)
7
-# include <openssl/conf.h>
8
-# endif
4
+# define NETDATA_SSL_HANDSHAKE_COMPLETE 0 //All the steps were successful
5
+# define NETDATA_SSL_START 1 //Starting handshake, conn variable is NULL
6
+# define NETDATA_SSL_WANT_READ 2 //The connection wanna read from socket
7
+# define NETDATA_SSL_WANT_WRITE 4 //The connection wanna write on socket
8
+# define NETDATA_SSL_NO_HANDSHAKE 8 //Continue without encrypt connection.
9
+# define NETDATA_SSL_OPTIONAL 16 //Flag to define the HTTP request
10
+# define NETDATA_SSL_FORCE 32 //We only accepts HTTPS request
11
+# define NETDATA_SSL_INVALID_CERTIFICATE 64 //Accepts invalid certificate
12
+# define NETDATA_SSL_VALID_CERTIFICATE 128 //Accepts invalid certificate
13
+
14
+# ifdef ENABLE_HTTPS
15
+
16
+# include <openssl/ssl.h>
17
+# include <openssl/err.h>
18
+# if (SSLEAY_VERSION_NUMBER >= 0x0907000L) && (OPENSSL_VERSION_NUMBER < 0x10100000L)
19
+# include <openssl/conf.h>
20
+# endif
21
10
-#define NETDATA_SSL_HANDSHAKE_COMPLETE 0 //All the steps were successful
11
-#define NETDATA_SSL_START 1 //Starting handshake, conn variable is NULL
12
-#define NETDATA_SSL_WANT_READ 2 //The connection wanna read from socket
13
-#define NETDATA_SSL_WANT_WRITE 4 //The connection wanna write on socket
14
-#define NETDATA_SSL_NO_HANDSHAKE 8 //Continue without encrypt connection.
15
-#define NETDATA_SSL_OPTIONAL 16 //Flag to define the HTTP request
16
-#define NETDATA_SSL_FORCE 32 //We only accepts HTTPS request
17
-#define NETDATA_SSL_INVALID_CERTIFICATE 64 //Accepts invalid certificate
18
-#define NETDATA_SSL_VALID_CERTIFICATE 128 //Accepts invalid certificate
22
struct netdata_ssl{
23
SSL *conn; //SSL connection
24
int flags;
@@ -35,4 +38,5 @@ void security_start_ssl(int type);
38
int security_process_accept(SSL *ssl,int msg);
39
int security_test_certificate(SSL *ssl);
40
41
+# endif //ENABLE_HTTPS
42
#endif //NETDATA_SECURITY_H
libnetdata/socket/socket.c
+2
@@ -302,6 +302,7 @@ void listen_sockets_close(LISTEN_SOCKETS *sockets) {
302
}
303
304
WEB_CLIENT_ACL socket_ssl_acl(char *ssl){
305
+#ifdef ENABLE_HTTPS
306
if (!strcmp(ssl,"optional")){
307
netdata_use_ssl_on_http = NETDATA_SSL_OPTIONAL;
308
return WEB_CLIENT_ACL_DASHBOARD | WEB_CLIENT_ACL_REGISTRY | WEB_CLIENT_ACL_BADGE | WEB_CLIENT_ACL_MGMT | WEB_CLIENT_ACL_NETDATACONF | WEB_CLIENT_ACL_STREAMING;
@@ -310,6 +311,7 @@ WEB_CLIENT_ACL socket_ssl_acl(char *ssl){
311
netdata_use_ssl_on_stream = NETDATA_SSL_FORCE;
312
return WEB_CLIENT_ACL_DASHBOARD | WEB_CLIENT_ACL_REGISTRY | WEB_CLIENT_ACL_BADGE | WEB_CLIENT_ACL_MGMT | WEB_CLIENT_ACL_NETDATACONF | WEB_CLIENT_ACL_STREAMING;
313
}
314
+#endif
315
316
return WEB_CLIENT_ACL_NONE;
317
}
libnetdata/socket/socket.h
-1
@@ -3,7 +3,6 @@
3
#ifndef NETDATA_SOCKET_H
4
#define NETDATA_SOCKET_H
5
6
-#include <openssl/ossl_typ.h>
6
#include "../libnetdata.h"
7
8
#ifndef MAX_LISTEN_FDS
streaming/rrdpush.c
+2
@@ -1210,7 +1210,9 @@ static void *rrdpush_receiver_thread(void *ptr) {
1210
, rpt->update_every
1211
, rpt->client_ip
1212
, rpt->client_port
1213
+#ifdef ENABLE_HTTPS
1214
, &rpt->ssl
1215
+#endif
1216
);
1217
1218
netdata_thread_cleanup_pop(1);