aboutsummaryrefslogtreecommitdiff
path: root/middleware/tls/tls.go
diff options
context:
space:
mode:
authorGravatar Miek Gieben <miek@miek.nl> 2017-03-13 20:24:37 +0000
committerGravatar GitHub <noreply@github.com> 2017-03-13 20:24:37 +0000
commitbfaf9e0aecc74d4e6897cdb9c6ef51b4b21ffd4e (patch)
tree1eb571726beee206742fa69d6d97ef80d6dcd48f /middleware/tls/tls.go
parent4985d698e2d1e7c8335bff3b39c1d593cf1f02e6 (diff)
downloadcoredns-bfaf9e0aecc74d4e6897cdb9c6ef51b4b21ffd4e.tar.gz
coredns-bfaf9e0aecc74d4e6897cdb9c6ef51b4b21ffd4e.tar.zst
coredns-bfaf9e0aecc74d4e6897cdb9c6ef51b4b21ffd4e.zip
core: add more transports (#574)
* core: add listening for other protocols Allow CoreDNS to listen for TLS request coming over port 853. This can be enabled with `tls://` in the config file. Implement listening for grps:// as well. a Corefile like: ~~~ . tls://.:1853 { whoami tls } ~~~ Means we listen on 1853 for tls requests, the `tls` config item allows configuration for TLS parameters. We *might* be tempted to use Caddy's Let's Encrypt implementation here. * Refactor coredns/grpc into CoreDNS This makes gRPC a first class citizen in CoreDNS. Add defines as being just another server. * some cleanups * unexport the servers * Move protobuf dir * Hook up TLS properly * Fix test * listen for TLS as well. README updates * disable test, fix package * fix test * Fix tests * Fix remaining test * Some tests * Make the test work * Add grpc test from #580 * fix crash * Fix tests * Close conn * README cleanups * README * link RFC
Diffstat (limited to 'middleware/tls/tls.go')
-rw-r--r--middleware/tls/tls.go37
1 files changed, 37 insertions, 0 deletions
diff --git a/middleware/tls/tls.go b/middleware/tls/tls.go
new file mode 100644
index 000000000..2e2586ce5
--- /dev/null
+++ b/middleware/tls/tls.go
@@ -0,0 +1,37 @@
+package tls
+
+import (
+ "github.com/coredns/coredns/core/dnsserver"
+ "github.com/coredns/coredns/middleware"
+ "github.com/coredns/coredns/middleware/pkg/tls"
+
+ "github.com/mholt/caddy"
+)
+
+func init() {
+ caddy.RegisterPlugin("tls", caddy.Plugin{
+ ServerType: "dns",
+ Action: setup,
+ })
+}
+
+func setup(c *caddy.Controller) error {
+ config := dnsserver.GetConfig(c)
+
+ if config.TLSConfig != nil {
+ return middleware.Error("tls", c.Errf("TLS already configured for this server instance"))
+ }
+
+ for c.Next() {
+ args := c.RemainingArgs()
+ if len(args) != 3 {
+ return middleware.Error("tls", c.ArgErr())
+ }
+ tls, err := tls.NewTLSConfig(args[0], args[1], args[2])
+ if err != nil {
+ return middleware.Error("tls", c.ArgErr())
+ }
+ config.TLSConfig = tls
+ }
+ return nil
+}