Add a strongswan.conf option to disable loading of all certificates from a pkcs11 module
This commit is contained in:
@@ -82,13 +82,18 @@ static void token_event_cb(private_pkcs11_plugin_t *this, pkcs11_library_t *p11,
|
|||||||
this->handle_events_lock->read_lock(this->handle_events_lock);
|
this->handle_events_lock->read_lock(this->handle_events_lock);
|
||||||
if (add && this->handle_events)
|
if (add && this->handle_events)
|
||||||
{
|
{
|
||||||
creds = pkcs11_creds_create(p11, slot);
|
if (lib->settings->get_bool(lib->settings,
|
||||||
if (creds)
|
"libstrongswan.plugins.pkcs11.modules.%s.load_certs",
|
||||||
|
TRUE, p11->get_name(p11)))
|
||||||
{
|
{
|
||||||
this->mutex->lock(this->mutex);
|
creds = pkcs11_creds_create(p11, slot);
|
||||||
this->creds->insert_last(this->creds, creds);
|
if (creds)
|
||||||
this->mutex->unlock(this->mutex);
|
{
|
||||||
lib->credmgr->add_set(lib->credmgr, &creds->set);
|
this->mutex->lock(this->mutex);
|
||||||
|
this->creds->insert_last(this->creds, creds);
|
||||||
|
this->mutex->unlock(this->mutex);
|
||||||
|
lib->credmgr->add_set(lib->credmgr, &creds->set);
|
||||||
|
}
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
else if (this->handle_events)
|
else if (this->handle_events)
|
||||||
|
|||||||
Reference in New Issue
Block a user