← history for internal/db/tls.go
36678f05internal/db/tls.go36 lines⬡ raw↓ download
 1
 2
 3
 4
 5
 6
 7
 8
 9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
/**
 * CQL Minus - cqlminus
 *
 * This file is licensed under the Affero General Public License version 3 or
 * later. See the COPYING file.
 *
 * @author Paolo Lulli <kevwe.com>
 * @copyright Paolo Lulli 2026
 */

package db

import (
    "cqlminus/internal/config"
    "crypto/tls"

    "github.com/gocql/gocql"
)

func buildSslOptions(cfg *config.Config) *gocql.SslOptions {
    opts := &gocql.SslOptions{
        CaPath:                 cfg.TlsCA,
        CertPath:               cfg.TlsCertificate,
        KeyPath:                cfg.TlsKeyFile,
        EnableHostVerification: cfg.TlsVerifyServer == "true",
    }

    if cfg.Endpoint != "" {
        opts.Config = &tls.Config{
            ServerName:         cfg.Endpoint,
            InsecureSkipVerify: cfg.TlsVerifyServer == "false",
        }
    }

    return opts
}