mesos-reviews mailing list archives

Site index · List index
Message view « Date » · « Thread »
Top « Date » · « Thread »
From Benno Evers <>
Subject Re: Review Request 70749: Introduced RFC6125-compliant hostname validation scheme.
Date Tue, 02 Jul 2019 17:49:16 GMT

This is an automatically generated e-mail. To reply, visit:

(Updated July 2, 2019, 5:49 p.m.)

Review request for mesos, Alexander Rukletsov, Benjamin Mahler, Joseph Wu, and Till Toenshoff.


Rebased onto latest master; changed title.

Summary (updated)

Introduced RFC6125-compliant hostname validation scheme.

Bugs: MESOS-9809

Repository: mesos


This commit introduces a new libprocess SSL flag
`hostname_validation_scheme`, which can be used to select
between the previous hostname validation behaviour and a new
option to use standardized OpenSSL algorithms to handle
hostname validation as part of the

As a nice side-effect, the new scheme gets rid of reverse DNS
lookups during TLS connection establishment, which used to be
a common source of hard-to-debug unresponsiveness in Mesos

See `docs/` in the follow-up commit for details of and
differences between the schemes.

Diffs (updated)

  3rdparty/libprocess/include/process/ssl/flags.hpp f3483f97f93bb29117b2c78f0f2ed9735d9c4b3a

  3rdparty/libprocess/src/openssl.hpp 17bec246e516261f8d772f1647c17f092fae82d1 
  3rdparty/libprocess/src/openssl.cpp 19d25a89f7dda1f6c66dd1ffc5051e35457d26b0 
  3rdparty/libprocess/src/posix/libevent/libevent_ssl_socket.hpp 6ef5a86566af3439cfe0b06ab3576076623f7be0

  3rdparty/libprocess/src/posix/libevent/libevent_ssl_socket.cpp 7e2229a9ed815727500bd457356e5531607fa6cf



Testing (updated)

See added unit tests later in this chain.


Benno Evers

  • Unnamed multipart/alternative (inline, None, 0 bytes)
View raw message