Commit d4e118c5da for bind
commit d4e118c5da43e59d7a1b76983e61286cd81b0f24
Author: Mark Andrews <marka@isc.org>
Date: Wed Sep 9 11:34:58 2026 +1000
Fix empty SSLKEYLOGFILE environment variable handling
If named is started with an empty SSLKEYLOGFILE environment variable
it could trigger a REQUIRE failure. Treat an empty SSLKEYLOGFILE
environment variable as if it doesn't exist.
diff --git a/bin/named/log.c b/bin/named/log.c
index c2a2acc855..00f98e8557 100644
--- a/bin/named/log.c
+++ b/bin/named/log.c
@@ -180,7 +180,7 @@ named_log_setdefaultsslkeylogfile(isc_logconfig_t *lcfg) {
},
};
- if (sslkeylogfile_path == NULL ||
+ if (sslkeylogfile_path == NULL || *sslkeylogfile_path == 0 ||
strcmp(sslkeylogfile_path, "config") == 0)
{
return;
diff --git a/lib/isc/tls.c b/lib/isc/tls.c
index ff42be2428..07167a0fb7 100644
--- a/lib/isc/tls.c
+++ b/lib/isc/tls.c
@@ -94,7 +94,8 @@ sslkeylogfile_append(const SSL *ssl ISC_ATTR_UNUSED, const char *line) {
*/
static void
sslkeylogfile_init(isc_tlsctx_t *ctx) {
- if (getenv("SSLKEYLOGFILE") != NULL) {
+ const char *sslkeylogfile = getenv("SSLKEYLOGFILE");
+ if (sslkeylogfile != NULL && *sslkeylogfile != 0) {
SSL_CTX_set_keylog_callback(ctx, sslkeylogfile_append);
}
}