From 5725e3832819c6d971f6d3b4cf4ded822011a695 Mon Sep 17 00:00:00 2001 From: Robin Appelman Date: Tue, 15 Mar 2022 15:50:08 +0100 Subject: [PATCH] don't try to get custom certs for s3 primary storage Signed-off-by: Robin Appelman --- lib/private/Files/ObjectStore/S3.php | 1 + lib/private/Files/ObjectStore/S3ConnectionTrait.php | 12 +++++++++--- 2 files changed, 10 insertions(+), 3 deletions(-) diff --git a/lib/private/Files/ObjectStore/S3.php b/lib/private/Files/ObjectStore/S3.php index 074f3a1df91..6492145fb63 100644 --- a/lib/private/Files/ObjectStore/S3.php +++ b/lib/private/Files/ObjectStore/S3.php @@ -30,6 +30,7 @@ class S3 implements IObjectStore { use S3ObjectTrait; public function __construct($parameters) { + $parameters['primary_storage'] = true; $this->parseParams($parameters); } diff --git a/lib/private/Files/ObjectStore/S3ConnectionTrait.php b/lib/private/Files/ObjectStore/S3ConnectionTrait.php index 676bfa5d78e..888497d03bb 100644 --- a/lib/private/Files/ObjectStore/S3ConnectionTrait.php +++ b/lib/private/Files/ObjectStore/S3ConnectionTrait.php @@ -122,8 +122,14 @@ trait S3ConnectionTrait { ) ); - /** @var ICertificateManager $certManager */ - $certManager = \OC::$server->get(ICertificateManager::class); + // since we store the certificate bundles on the primary storage, we can't get the bundle while setting up the primary storage + if (!isset($this->params['primary_storage'])) { + /** @var ICertificateManager $certManager */ + $certManager = \OC::$server->get(ICertificateManager::class); + $certPath = $certManager->getAbsoluteBundlePath(); + } else { + $certPath = \OC::$SERVERROOT . '/resources/config/ca-bundle.crt'; + } $options = [ 'version' => isset($this->params['version']) ? $this->params['version'] : 'latest', @@ -134,7 +140,7 @@ trait S3ConnectionTrait { 'signature_provider' => \Aws\or_chain([self::class, 'legacySignatureProvider'], ClientResolver::_default_signature_provider()), 'csm' => false, 'use_arn_region' => false, - 'http' => ['verify' => $certManager->getAbsoluteBundlePath()], + 'http' => ['verify' => $certPath], ]; if ($this->getProxy()) { $options['http']['proxy'] = $this->getProxy();