mirror of
https://github.com/rustfs/rustfs.git
synced 2026-08-09 06:39:25 +00:00
feat(ecstore): Skip rustls provider install if already present (#2145)
Signed-off-by: houseme <housemecn@gmail.com> Co-authored-by: Copilot <175728472+Copilot@users.noreply.github.com> Co-authored-by: Copilot <198982749+Copilot@users.noreply.github.com> Co-authored-by: houseme <4829346+houseme@users.noreply.github.com>
This commit is contained in:
@@ -67,6 +67,7 @@ use rustfs_metrics::init_metrics_system;
|
||||
use rustfs_obs::{init_obs, set_global_guard};
|
||||
use rustfs_scanner::init_data_scanner;
|
||||
use rustfs_utils::{get_env_bool_with_aliases, net::parse_and_resolve_address};
|
||||
use rustls::crypto::aws_lc_rs::default_provider;
|
||||
use std::io::{Error, Result};
|
||||
use std::sync::Arc;
|
||||
use tokio_util::sync::CancellationToken;
|
||||
@@ -141,6 +142,11 @@ async fn async_main() -> Result<()> {
|
||||
// Initialize trusted proxies system
|
||||
rustfs_trusted_proxies::init();
|
||||
|
||||
// Make sure to use a modern encryption suite
|
||||
if default_provider().install_default().is_err() {
|
||||
// A crypto provider is already installed (e.g. by the host process); this is fine.
|
||||
debug!("rustls crypto provider already installed, skipping aws-lc-rs default install");
|
||||
}
|
||||
// Initialize TLS if a certificate path is provided
|
||||
if let Some(tls_path) = &config.tls_path {
|
||||
match init_cert(tls_path).await {
|
||||
|
||||
@@ -102,8 +102,6 @@ pub(crate) async fn init_cert(tls_path: &str) -> Result<(), RustFSError> {
|
||||
info!("No TLS path configured; skipping certificate initialization");
|
||||
return Ok(());
|
||||
}
|
||||
// Make sure to use a modern encryption suite
|
||||
let _ = rustls::crypto::aws_lc_rs::default_provider().install_default();
|
||||
|
||||
let tls_dir = PathBuf::from(tls_path);
|
||||
|
||||
|
||||
Reference in New Issue
Block a user