diff --git a/envoy/COMMIT b/envoy/COMMIT index 3515ccfc9..5bd8be92c 100644 --- a/envoy/COMMIT +++ b/envoy/COMMIT @@ -1 +1 @@ -a4b06fdf51be789c69c65104c67fe69b67e88c35 +ab9ff8e5aa5735d3bb796bd27c44638c292c5593 diff --git a/envoy/extensions/transport_sockets/tls/v3/common.pb.go b/envoy/extensions/transport_sockets/tls/v3/common.pb.go index 66b89e7d4..f835095ca 100755 --- a/envoy/extensions/transport_sockets/tls/v3/common.pb.go +++ b/envoy/extensions/transport_sockets/tls/v3/common.pb.go @@ -519,12 +519,13 @@ type TlsCertificate struct { // ` documentation for further details. WatchedDirectory *v3.WatchedDirectory `protobuf:"bytes,7,opt,name=watched_directory,json=watchedDirectory,proto3" json:"watched_directory,omitempty"` // BoringSSL private key method provider. This is an alternative to :ref:`private_key - // ` field. This can't be - // marked as “oneof“ due to API compatibility reasons. Setting both :ref:`private_key - // ` and - // :ref:`private_key_provider - // ` fields will result in an - // error. + // ` field. + // When both :ref:`private_key ` and + // :ref:`private_key_provider ` fields are set, + // “private_key_provider“ takes precedence. + // If “private_key_provider“ is unavailable and :ref:`fallback + // ` + // is enabled, “private_key“ will be used. PrivateKeyProvider *PrivateKeyProvider `protobuf:"bytes,6,opt,name=private_key_provider,json=privateKeyProvider,proto3" json:"private_key_provider,omitempty"` // The password to decrypt the TLS private key. If this field is not set, it is assumed that the // TLS private key is not password encrypted.