+ /* If the -u option is used and we don't know this hostname's server
+ * certificate then just pass through the connection and let the client
+ * verify the server certificate. */
+ if (global_passthrough_unknown) {
+ char path[1024];
+ FILE *file = NULL;
+
+ if (-2 == server_certificate_path(&file, host, path, sizeof(path))) {
+ /* We've established a connection, tell the client. */
+ fprintf(client_fd, "HTTP/1.0 200 Connection established\r\n");
+ fprintf(client_fd, "\r\n");
+ fflush(client_fd);
+
+ LOG(LOG_DEBUG, "transferring data");
+
+ /* Proxy data between client and server until one side is done
+ * (EOF or error). */
+ transfer_data(client_socket, server_socket);
+
+ LOG(LOG_DEBUG, "finished transferring data");
+
+ goto out;
+ }
+ /* server_certificate_path() may have opened the file, close it. */
+ if (NULL != file) {
+ fclose(file);
+ }
+ }
+
+ /* Initialize TLS client credentials to talk to the server. */