2018-02-19 12:38:54 +03:00
|
|
|
From 0000000000000000000000000000000000000000 Mon Sep 17 00:00:00 2001
|
2017-04-05 11:49:19 +03:00
|
|
|
From: Wolfgang Bumiller <w.bumiller@proxmox.com>
|
2020-04-07 17:53:19 +03:00
|
|
|
Date: Mon, 6 Apr 2020 12:16:33 +0200
|
|
|
|
Subject: [PATCH] PVE: [Config] ui/spice: default to pve certificates
|
2017-04-05 11:49:19 +03:00
|
|
|
|
2019-06-06 13:58:15 +03:00
|
|
|
Signed-off-by: Thomas Lamprecht <t.lamprecht@proxmox.com>
|
2017-04-05 11:49:19 +03:00
|
|
|
---
|
|
|
|
ui/spice-core.c | 15 +++++++++------
|
|
|
|
1 file changed, 9 insertions(+), 6 deletions(-)
|
|
|
|
|
|
|
|
diff --git a/ui/spice-core.c b/ui/spice-core.c
|
2020-03-10 17:12:50 +03:00
|
|
|
index ecc2ec2c55..ca04965ead 100644
|
2017-04-05 11:49:19 +03:00
|
|
|
--- a/ui/spice-core.c
|
|
|
|
+++ b/ui/spice-core.c
|
2019-11-20 17:45:35 +03:00
|
|
|
@@ -668,32 +668,35 @@ void qemu_spice_init(void)
|
2017-04-05 11:49:19 +03:00
|
|
|
|
|
|
|
if (tls_port) {
|
|
|
|
x509_dir = qemu_opt_get(opts, "x509-dir");
|
|
|
|
- if (!x509_dir) {
|
|
|
|
- x509_dir = ".";
|
|
|
|
- }
|
|
|
|
|
|
|
|
str = qemu_opt_get(opts, "x509-key-file");
|
|
|
|
if (str) {
|
|
|
|
x509_key_file = g_strdup(str);
|
|
|
|
- } else {
|
|
|
|
+ } else if (x509_dir) {
|
|
|
|
x509_key_file = g_strdup_printf("%s/%s", x509_dir,
|
|
|
|
X509_SERVER_KEY_FILE);
|
|
|
|
+ } else {
|
|
|
|
+ x509_key_file = g_strdup("/etc/pve/local/pve-ssl.key");
|
|
|
|
}
|
|
|
|
|
|
|
|
str = qemu_opt_get(opts, "x509-cert-file");
|
|
|
|
if (str) {
|
|
|
|
x509_cert_file = g_strdup(str);
|
|
|
|
- } else {
|
|
|
|
+ } else if (x509_dir) {
|
|
|
|
x509_cert_file = g_strdup_printf("%s/%s", x509_dir,
|
|
|
|
X509_SERVER_CERT_FILE);
|
|
|
|
+ } else {
|
|
|
|
+ x509_cert_file = g_strdup("/etc/pve/local/pve-ssl.pem");
|
|
|
|
}
|
|
|
|
|
|
|
|
str = qemu_opt_get(opts, "x509-cacert-file");
|
|
|
|
if (str) {
|
|
|
|
x509_cacert_file = g_strdup(str);
|
|
|
|
- } else {
|
|
|
|
+ } else if (x509_dir) {
|
|
|
|
x509_cacert_file = g_strdup_printf("%s/%s", x509_dir,
|
|
|
|
X509_CA_CERT_FILE);
|
|
|
|
+ } else {
|
|
|
|
+ x509_cacert_file = g_strdup("/etc/pve/pve-root-ca.pem");
|
|
|
|
}
|
|
|
|
|
|
|
|
x509_key_password = qemu_opt_get(opts, "x509-key-password");
|