You can not select more than 25 topics
Topics must start with a letter or number, can include dashes ('-') and can be up to 35 characters long.
22 lines
873 B
22 lines
873 B
From Mon Sep 17 00:00:00 2001 |
|
From: Matt McCutchen <matt@mattmccutchen.net> |
|
Date: Wed, 26 Aug 2020 12:16:08 -0400 |
|
|
|
rsync-ssl: Verify the hostname in the certificate when using openssl. |
|
--- |
|
rsync-ssl | 2 +- |
|
1 file changed, 1 insertion(+), 1 deletion(-) |
|
|
|
diff --git a/rsync-ssl b/rsync-ssl |
|
index 8101975a..46701af1 100755 |
|
--- a/rsync-ssl |
|
+++ b/rsync-ssl |
|
@@ -129,7 +129,7 @@ function rsync_ssl_helper { |
|
fi |
|
|
|
if [[ $RSYNC_SSL_TYPE == openssl ]]; then |
|
- exec $RSYNC_SSL_OPENSSL s_client $caopt $certopt -quiet -verify_quiet -servername $hostname -connect $hostname:$port |
|
+ exec $RSYNC_SSL_OPENSSL s_client $caopt $certopt -quiet -verify_quiet -servername $hostname -verify_hostname $hostname -connect $hostname:$port |
|
elif [[ $RSYNC_SSL_TYPE == gnutls ]]; then |
|
exec $RSYNC_SSL_GNUTLS --logfile=/dev/null $gnutls_cert_opt $gnutls_opts $hostname:$port |
|
else
|
|
|