[prev in list] [next in list] [prev in thread] [next in thread] 

List:       stunnel-users
Subject:    [stunnel-users] Debian Bug#460019: cert= produces output on stderr
From:       Luis Rodrigo Gallardo Cruz <rodrigo () nul-unu ! com>
Date:       2008-01-11 7:22:11
Message-ID: 20080111072211.GB32152 () lisa ! rodrigo ! nul-unu ! com
[Download RAW message or body]

[Attachment #2 (multipart/signed)]


----- Forwarded message from Bryan Donlan <bd@fushizen.net> -----

Version: 3:4.21-1

With the following configuration:
output = /srv/stun/log
compression = zlib
CApath = /srv/stun/keys
cert = /srv/stun/server.pem
connect = localhost:9999
verify = 3

The following is output on stderr:
2008.01.10 02:54:19 LOG5[11786:3083495088]: Peer certificate location /srv/stun/keys

This confuses clients when stunnel is driven direcly from xinetd. This
output, if it is produced at all, should be placed in the log file.

----- End forwarded message -----

The issue is that verify_init (verify.c:103) calls

  s_log(LOG_NOTICE, "Peer certificate location %s", section->ca_dir);

apparently before the logfile is setup. Could the log file
initialization be moved earlier in the starup sequence? Or maybe this
log call's severity could be lowered.

["signature.asc" (application/pgp-signature)]

_______________________________________________
stunnel-users mailing list
stunnel-users@mirt.net
http://stunnel.mirt.net/mailman/listinfo/stunnel-users


[prev in list] [next in list] [prev in thread] [next in thread] 

Configure | About | News | Add a list | Sponsored by KoreLogic