diff options
author | Richard van der Hoff <richard@matrix.org> | 2019-02-11 21:30:59 +0000 |
---|---|---|
committer | Richard van der Hoff <richard@matrix.org> | 2019-02-11 21:32:01 +0000 |
commit | 9645728619828fda050fa08aaa25628f5db5d775 (patch) | |
tree | 0a620a397ce4f64d8ecf15af9329fa17f9a95aea /synapse/crypto/context_factory.py | |
parent | Logging improvements around TLS certs (diff) | |
download | synapse-9645728619828fda050fa08aaa25628f5db5d775.tar.xz |
Don't create server contexts when TLS is disabled
we aren't going to use them anyway.
Diffstat (limited to 'synapse/crypto/context_factory.py')
-rw-r--r-- | synapse/crypto/context_factory.py | 4 |
1 files changed, 1 insertions, 3 deletions
diff --git a/synapse/crypto/context_factory.py b/synapse/crypto/context_factory.py index 286ad80100..85f2848fb1 100644 --- a/synapse/crypto/context_factory.py +++ b/synapse/crypto/context_factory.py @@ -43,9 +43,7 @@ class ServerContextFactory(ContextFactory): logger.exception("Failed to enable elliptic curve for TLS") context.set_options(SSL.OP_NO_SSLv2 | SSL.OP_NO_SSLv3) context.use_certificate_chain_file(config.tls_certificate_file) - - if not config.no_tls: - context.use_privatekey(config.tls_private_key) + context.use_privatekey(config.tls_private_key) # https://hynek.me/articles/hardening-your-web-servers-ssl-ciphers/ context.set_cipher_list( |