Further fix SSL configuration for SocketService
Completely eliminate the try blocks, and allow the 'ssl' value to be pre-defined by a child class.
Austin S. Hemmelgarn committed
May 2, 2018 at 09:31 UTC
bc06bf1fc5000c291445c90f61d22a92dd70fad5
1 file changed
+16
-13
python.d/python_modules/bases/FrameworkServices/SocketService.py
+16
-13
@@ -273,24 +273,27 @@ class SocketService(SimpleService):
273
except (KeyError, TypeError):
274
self.debug('No port specified. Using: "{0}"'.format(self.port))
275
276
- try:
277
- self.ssl = bool(self.configuration['ssl'])
278
- if self.ssl and not _SSL_SUPPORT:
279
- self.warning('SSL requested but not SSL module found, disabling SSL support.')
280
- self.ssl = False
281
- except (KeyError, TypeError):
282
- if _SSL_SUPPORT:
283
- self.debug('No SSL preference specified, not using SSL.')
276
+ self.ssl = bool(self.configuration.get('ssl', self.ssl))
277
+ if self.ssl and not _SSL_SUPPORT:
278
+ self.warning('SSL requested but not SSL module found, disabling SSL support.')
279
self.ssl = False
280
+ if _SSL_SUPPORT and not self.ssl:
281
+ self.debug('No SSL preference specified, not using SSL.')
282
283
if self.ssl and _SSL_SUPPORT:
287
- try:
288
- self.key = str(self.configuration['ssl_key'])
289
- self.cert = str(self.configuration['ssl_cert'])
290
- except (KeyError, TypeError):
291
- self.debug('No SSL client certificate configuration found.')
284
+ self.key = str(self.configuration.get('ssl_key'))
285
+ self.cert = str(self.configuration.get('ssl_cert'))
286
+ if not self.cert:
287
+ # If there's not a valid certificate, clear the key too.
288
+ self.debug('No valid SSL client certificate configuration found.')
289
self.key = None
290
self.cert = None
291
+ elif not self.key:
292
+ # If a key isn't listed, the config may still be
293
+ # valid, because there may be a key attached to the
294
+ # certificate.
295
+ self.notice('No SSL client key specified, assuming it\'s attached to the certificate.')
296
+ self.key = None
297
298
try:
299
self.request = str(self.configuration['request'])