<!-- Kamailio Pull Request Template -->
<!--
IMPORTANT:
- for detailed contributing guidelines, read:
https://github.com/kamailio/kamailio/blob/master/.github/CONTRIBUTING.md
- pull requests must be done to master branch, unless they are backports
of fixes from master branch to a stable branch
- backports to stable branches must be done with 'git cherry-pick -x ...'
- code is contributed under BSD for core and main components (tm, sl, auth, tls)
- code is contributed GPLv2 or a compatible license for the other components
- GPL code is contributed with OpenSSL licensing exception
-->
#### Pre-Submission Checklist
<!-- Go over all points below, and after creating the PR, tick all the checkboxes that apply -->
<!-- All points should be verified, otherwise, read the CONTRIBUTING guidelines from above-->
<!-- If you're unsure about any of these, don't hesitate to ask on sr-dev mailing list -->
- [ /] Commit message has the format required by CONTRIBUTING guide
- [ /] Commits are split per component (core, individual modules, libs, utils, ...)
- [ /] Each component has a single commit (if not, squash them into one commit)
- [ /] No commits to README files for modules (changes must be done to docbook files
in `doc/` subfolder, the README file is autogenerated)
#### Type Of Change
- [ ] Small bug fix (non-breaking change which fixes an issue)
- [/ ] New feature (non-breaking change which adds new functionality)
- [ ] Breaking change (fix or feature that would change existing functionality)
#### Checklist:
<!-- Go over all points below, and after creating the PR, tick the checkboxes that apply -->
- [ ] PR should be backported to stable branches
- [ /] Tested changes locally
- [ ] Related to issue #XXXX (replace XXXX with an open issue number)
#### Description
A couple of commits into db_redis and ndb_redis adding TLS support and also password support to db_redis.
This mainly includes checking if proper parameter is provided (for ndb_redis is `tls` option in the DB URL and, for db_redis, a new `opt_tls` parameter) and creates a temporary SSL context that is used to initialise the redis context.
Also added `ca_path` parameter to both modules to be able to define a valid folder containing the root certificates used to validate TLS' certificate chain.
db_redis is also updated with a `db_pass` parameter to provide a DB access password.
TLS support is automatically enabled by checking libhiredis_ssl.so existence in each Makefile and defining a `WITH_SSL` flag that enables all the corresponding code lines.
You can view, comment on, or merge this pull request online at:
https://github.com/kamailio/kamailio/pull/3477
-- Commit Summary --
* db_redis: Adding TLS support
* ndb_redis: Adding TLS support
-- File Changes --
M src/modules/db_redis/Makefile (24)
M src/modules/db_redis/db_redis_mod.c (13)
M src/modules/db_redis/doc/db_redis.xml (5)
M src/modules/db_redis/doc/db_redis_admin.xml (59)
M src/modules/db_redis/redis_connection.c (98)
M src/modules/db_redis/redis_connection.h (6)
M src/modules/ndb_redis/Makefile (15)
M src/modules/ndb_redis/doc/ndb_redis.xml (5)
M src/modules/ndb_redis/doc/ndb_redis_admin.xml (26)
M src/modules/ndb_redis/ndb_redis_mod.c (10)
M src/modules/ndb_redis/redis_client.c (69)
M src/modules/ndb_redis/redis_client.h (7)
-- Patch Links --
https://github.com/kamailio/kamailio/pull/3477.patchhttps://github.com/kamailio/kamailio/pull/3477.diff
--
Reply to this email directly or view it on GitHub:
https://github.com/kamailio/kamailio/pull/3477
You are receiving this because you are subscribed to this thread.
Message ID: <kamailio/kamailio/pull/3477(a)github.com>
Module: kamailio
Branch: master
Commit: 79d5ab3b86c0a1cc1b06efeee78ef5baa8d084f9
URL: https://github.com/kamailio/kamailio/commit/79d5ab3b86c0a1cc1b06efeee78ef5b…
Author: Joel Centelles <joel_centellesmartin(a)baxter.com>
Committer: Daniel-Constantin Mierla <miconda(a)gmail.com>
Date: 2023-06-20T10:45:31+02:00
ndb_redis: Adding TLS support
Checks for the tls parameter in the BD schema and, if it's enabled, creates a temporary TLS conext that is used to initialize the redis context.
Adds 1 new parameter:
* ca_path: For specifying a folder containing valid certification chains.
---
Modified: src/modules/ndb_redis/Makefile
Modified: src/modules/ndb_redis/doc/ndb_redis.xml
Modified: src/modules/ndb_redis/doc/ndb_redis_admin.xml
Modified: src/modules/ndb_redis/ndb_redis_mod.c
Modified: src/modules/ndb_redis/redis_client.c
Modified: src/modules/ndb_redis/redis_client.h
---
Diff: https://github.com/kamailio/kamailio/commit/79d5ab3b86c0a1cc1b06efeee78ef5b…
Patch: https://github.com/kamailio/kamailio/commit/79d5ab3b86c0a1cc1b06efeee78ef5b…
Module: kamailio
Branch: master
Commit: 67c77289afb994178afc1fd7558833097eb2f5b9
URL: https://github.com/kamailio/kamailio/commit/67c77289afb994178afc1fd75588330…
Author: Joel Centelles <joel_centellesmartin(a)baxter.com>
Committer: Daniel-Constantin Mierla <miconda(a)gmail.com>
Date: 2023-06-20T10:45:31+02:00
db_redis: Adding TLS support
Enhancing security options by enabling TLS connections and password definition.
Added 3 new parameters:
* opt_tls: For enabling TLS connections.
* ca_path: For specifying a folder containing valid certification chains.
* password: For providing DB access password.
If opt_tls is provided a temporary SSL context is created to pass it to existing cluster or normal redis context.
TLS support is automatically enabled/disabled by checking libhiredis_ssl.so existence.
---
Modified: src/modules/db_redis/Makefile
Modified: src/modules/db_redis/db_redis_mod.c
Modified: src/modules/db_redis/doc/db_redis.xml
Modified: src/modules/db_redis/doc/db_redis_admin.xml
Modified: src/modules/db_redis/redis_connection.c
Modified: src/modules/db_redis/redis_connection.h
---
Diff: https://github.com/kamailio/kamailio/commit/67c77289afb994178afc1fd75588330…
Patch: https://github.com/kamailio/kamailio/commit/67c77289afb994178afc1fd75588330…