From bcbfe25d08b90a133ac9da87c832889eb1975fe0 Mon Sep 17 00:00:00 2001 From: neil Date: Sat, 4 Jul 2026 18:50:29 +0800 Subject: [PATCH] haproxy.sh: use two-argument -header form for LibreSSL (#3438) --- deploy/haproxy.sh | 10 ++++++++-- 1 file changed, 8 insertions(+), 2 deletions(-) diff --git a/deploy/haproxy.sh b/deploy/haproxy.sh index b618a65b..66a2e83e 100644 --- a/deploy/haproxy.sh +++ b/deploy/haproxy.sh @@ -272,12 +272,18 @@ haproxy_deploy() { _cafile_argument="" fi _debug _cafile_argument "${_cafile_argument}" - # if OpenSSL/LibreSSL is v1.1 or above, the format for the -header option has changed + # OpenSSL 1.1+ expects -header Host=value (one argument), while + # LibreSSL keeps the old two-argument form -header Host value at any + # version (3.x/4.x), so it must be detected by name, not by number. + _openssl_name=$(${ACME_OPENSSL_BIN:-openssl} version | cut -d' ' -f1) _openssl_version=$(${ACME_OPENSSL_BIN:-openssl} version | cut -d' ' -f2) + _debug _openssl_name "${_openssl_name}" _debug _openssl_version "${_openssl_version}" _openssl_major=$(echo "${_openssl_version}" | cut -d '.' -f1) _openssl_minor=$(echo "${_openssl_version}" | cut -d '.' -f2) - if [ "${_openssl_major}" -eq "1" ] && [ "${_openssl_minor}" -ge "1" ] || [ "${_openssl_major}" -ge "2" ]; then + if [ "${_openssl_name}" = "LibreSSL" ]; then + _header_sep=" " + elif [ "${_openssl_major}" -eq "1" ] && [ "${_openssl_minor}" -ge "1" ] || [ "${_openssl_major}" -ge "2" ]; then _header_sep="=" else _header_sep=" "