# HG changeset patch
# User Matthew Wild <mwild1@gmail.com>
# Date 1454968204 0
# Node ID a461946fe8651baf2226e42b88aeaef3ac6aee0c
# Parent  81e54032d14d6544ab5bb681864d37e7acd24917# Parent  c793f9d13a36aa615bed64fcaea05ef66e9966c5
Merge

diff -r 81e54032d14d -r a461946fe865 core/certmanager.lua
--- a/core/certmanager.lua	Mon Feb 08 14:48:50 2016 +0100
+++ b/core/certmanager.lua	Mon Feb 08 21:50:04 2016 +0000
@@ -63,14 +63,13 @@
 		local key_path = certs .. key_try[i]:format(name);
 
 		if stat(crt_path, "mode") == "file" then
-			if stat(key_path, "mode") == "file" then
-				return { certificate = crt_path, key = key_path };
-			end
 			if key_path:sub(-4) == ".crt" then
 				key_path = key_path:sub(1, -4) .. "key";
 				if stat(key_path, "mode") == "file" then
 					return { certificate = crt_path, key = key_path };
 				end
+			elseif stat(key_path, "mode") == "file" then
+				return { certificate = crt_path, key = key_path };
 			end
 		end
 	end
@@ -120,7 +119,6 @@
 local function create_context(host, mode, ...)
 	local cfg = new_config();
 	cfg:apply(core_defaults);
-	cfg:apply(global_ssl_config);
 	local service_name, port = host:match("^(%w+) port (%d+)$");
 	if service_name then
 		cfg:apply(find_service_cert(service_name, tonumber(port)));
@@ -132,6 +130,7 @@
 		-- We can't read the password interactively when daemonized
 		password = function() log("error", "Encrypted certificate for %s requires 'ssl' 'password' to be set in config", host); end;
 	});
+	cfg:apply(global_ssl_config);
 
 	for i = select('#', ...), 1, -1 do
 		cfg:apply(select(i, ...));