From 3aaf292ba8c222003048e695bf9b9ec43191ff01 Mon Sep 17 00:00:00 2001 From: Dmitry Azhichakov Date: Fri, 13 Feb 2015 10:33:55 +0300 Subject: [PATCH] Fix "forcing" client certificate for SMTP --- conf/app.ini | 4 ++++ modules/mailer/mailer.go | 14 ++++++++------ modules/setting/setting.go | 16 +++++++++------- 3 files changed, 21 insertions(+), 13 deletions(-) diff --git a/conf/app.ini b/conf/app.ini index e80d77a9ca..6a7c67ca07 100644 --- a/conf/app.ini +++ b/conf/app.ini @@ -105,6 +105,10 @@ SUBJECT = %(APP_NAME)s HOST = ; Do not verify the certificate of the server. Only use this for self-signed certificates SKIP_VERIFY = +; Use client certificate +; USE_CERTIFICATE = true +; CERT_FILE = custom/mailer/cert.pem +; KEY_FILE = custom/mailer/key.pem ; Mail from address, RFC 5322. This can be just an email address, or the "Name" format FROM = ; Mailer user name and password diff --git a/modules/mailer/mailer.go b/modules/mailer/mailer.go index 792e443543..f658427c1a 100644 --- a/modules/mailer/mailer.go +++ b/modules/mailer/mailer.go @@ -72,15 +72,17 @@ func sendMail(settings *setting.Mailer, recipients []string, msgContent []byte) return err } - cert, err := tls.LoadX509KeyPair(settings.CertFile, settings.KeyFile) - if err != nil { - return err - } - tlsconfig := &tls.Config{ InsecureSkipVerify: settings.SkipVerify, ServerName: host, - Certificates: []tls.Certificate{cert}, + } + + if settings.UseCertificate { + cert, err := tls.LoadX509KeyPair(settings.CertFile, settings.KeyFile) + if err != nil { + return err + } + tlsconfig.Certificates = []tls.Certificate{cert} } conn, err := net.Dial("tcp", net.JoinHostPort(host, port)) diff --git a/modules/setting/setting.go b/modules/setting/setting.go index cf19b1aa8b..32284b4236 100644 --- a/modules/setting/setting.go +++ b/modules/setting/setting.go @@ -451,6 +451,7 @@ type Mailer struct { From string User, Passwd string SkipVerify bool + UseCertificate bool CertFile, KeyFile string } @@ -479,13 +480,14 @@ func newMailService() { } MailService = &Mailer{ - Name: sec.Key("NAME").MustString(AppName), - Host: sec.Key("HOST").String(), - User: sec.Key("USER").String(), - Passwd: sec.Key("PASSWD").String(), - SkipVerify: sec.Key("SKIP_VERIFY").MustBool(), - CertFile: sec.Key("CERT_FILE").String(), - KeyFile: sec.Key("KEY_FILE").String(), + Name: sec.Key("NAME").MustString(AppName), + Host: sec.Key("HOST").String(), + User: sec.Key("USER").String(), + Passwd: sec.Key("PASSWD").String(), + SkipVerify: sec.Key("SKIP_VERIFY").MustBool(), + UseCertificate: sec.Key("USE_CERTIFICATE").MustBool(), + CertFile: sec.Key("CERT_FILE").String(), + KeyFile: sec.Key("KEY_FILE").String(), } MailService.From = sec.Key("FROM").MustString(MailService.User) log.Info("Mail Service Enabled")