Kim Alvefur
|
02cead40db
|
mod_tls: Fix order of debug messages and tls context creation
Originally added in 5b048ccd106f
Merged wrong in ca01c449357f
|
2021-05-05 16:25:33 +02:00 |
|
Kim Alvefur
|
03a1ac4f69
|
mod_tls: Bail out if session got destroyed while sending <proceed/>
Can happen in case opportunistic_writes is enabled and the session got
destroyed while writing that tag.
Thanks Ge0rG
|
2021-04-15 15:57:24 +02:00 |
|
Kim Alvefur
|
da0482b226
|
mod_tls: Ignore lack of STARTTLS offer only when s2s_require_encryption set
|
2021-01-29 23:23:25 +01:00 |
|
Kim Alvefur
|
eb9e818e43
|
mod_tls: Attempt STARTTLS even if not advertised as per RFC 7590
|
2021-01-29 23:17:08 +01:00 |
|
Kim Alvefur
|
47bd554448
|
Merge 0.11->trunk
|
2020-04-26 21:03:40 +02:00 |
|
Kim Alvefur
|
7c18043404
|
mod_tls: Log when certificates are (re)loaded
Meant to reduce user confusion over what's reloaded and not.
|
2020-04-26 20:58:51 +02:00 |
|
Kim Alvefur
|
86ed7cd44e
|
mod_tls: Log debug message for each kind of TLS context created
Creating TLS contexts triggers a lot of messages from certmanager that
don't really describe their purpose. This is meant to provide hints
about that.
|
2019-04-23 19:13:50 +02:00 |
|
Kim Alvefur
|
f0abacc215
|
mod_tls: Rebuild SSL context objects on configuration reload - #701
|
2017-04-25 21:50:36 +02:00 |
|
Kim Alvefur
|
b1b108de84
|
mod_tls: Switch to hook_tag from hook_stanza which was renamed in 2087d42f1e77
|
2017-03-06 15:55:37 +01:00 |
|
Kim Alvefur
|
3405d89baa
|
mod_tls: Suppress debug message if already using encryption
|
2017-02-25 01:16:31 +01:00 |
|
Kim Alvefur
|
a193e1d9f4
|
mod_tls: Log reasons for not being able to do TLS
|
2017-02-15 23:03:22 +01:00 |
|
Kim Alvefur
|
c8b213ff4f
|
mod_tls: Check that connection has starttls method first to prevent offering starttls over tls (thanks Remko and Tobias)
|
2017-01-27 12:21:09 +01:00 |
|
Kim Alvefur
|
c7da30f634
|
mod_tls: Return session.ssl_ctx if not nil, like when doing the full session type check
|
2017-01-25 11:12:43 +01:00 |
|
Kim Alvefur
|
3258500edb
|
mod_tls: Add debug logging for when TLS should be doable but no ssl context was set
|
2017-01-25 11:06:30 +01:00 |
|
Kim Alvefur
|
272e5d06b4
|
mod_tls: Verify that TLS is available before proceeding
|
2017-01-23 10:46:42 +01:00 |
|
Kim Alvefur
|
a7a8fa91e3
|
mod_tls: Only accept <proceed> on outgoing s2s connections
|
2017-01-23 10:45:20 +01:00 |
|
Kim Alvefur
|
1a12e55904
|
mod_tls: Ignore unused argument [luacheck]
|
2016-11-02 23:19:41 +01:00 |
|
Kim Alvefur
|
57fe905a8c
|
mod_tls: Fix ssl option fallback to a "parent" host if current host does not have ssl options set (thanks 70b1)
|
2015-11-09 13:40:06 +01:00 |
|
Kim Alvefur
|
edc8079032
|
mod_tls: Remove unused reference to global ssl config option (certmanager adds that to the context)
|
2015-11-09 13:39:23 +01:00 |
|
Kim Alvefur
|
7b18c25101
|
mod_tls: Fix inhertinance of 'ssl' option from "parent" host to subdomain (fixes #511)
|
2015-09-15 17:51:56 +02:00 |
|
Kim Alvefur
|
72dde1c231
|
mod_tls: Treat session.ssl_ctx being false as a signal that TLS is disabled
|
2015-05-18 21:48:58 +02:00 |
|
Kim Alvefur
|
3f9b683457
|
mod_tls: Build <starttls/> as a stanza instead of with string concatenation
|
2015-05-18 21:43:24 +02:00 |
|
Kim Alvefur
|
49ba0ce08d
|
certmanager, mod_tls: Return final ssl config as third return value (fix for c6caaa440e74, portmanager assumes non-falsy second return value is an error) (thanks deoren)
|
2014-11-22 11:51:54 +01:00 |
|
Kim Alvefur
|
184d6ce60b
|
mod_tls: Keep ssl config around and attach them to sessions
|
2014-11-19 14:47:49 +01:00 |
|
Kim Alvefur
|
ac43c71ec2
|
mod_legacyauth, mod_saslauth, mod_tls: Pass require_encryption as default option to s2s_require_encryption so the later overrides the former
|
2014-10-21 12:49:03 +02:00 |
|
Kim Alvefur
|
8003a40b0a
|
mod_lastactivity, mod_legacyauth, mod_presence, mod_saslauth, mod_tls: Use the newer stanza:get_child APIs and optimize away some table lookups
|
2014-07-04 22:52:34 +02:00 |
|
Kim Alvefur
|
4e88341951
|
mod_tls: Simplify and use new ssl config merging in certmanager
|
2014-07-03 15:35:45 +02:00 |
|
Matthew Wild
|
996847e180
|
Merge 0.9->0.10
|
2014-01-18 18:46:12 +00:00 |
|
Florian Zeitz
|
1d833bb807
|
Remove all trailing whitespace
|
2013-08-09 17:48:21 +02:00 |
|
Kim Alvefur
|
7c51e9ec71
|
mod_tls: Remove debug statement
|
2013-06-16 15:01:31 +02:00 |
|
Kim Alvefur
|
410ab5d97b
|
mod_tls: Let s2s_secure_auth override s2s_require_encryption and warn if they differ
|
2014-01-15 22:47:50 +01:00 |
|
Kim Alvefur
|
573c5bea61
|
mod_tls: Rename variables to be less confusing
|
2014-01-15 21:57:15 +01:00 |
|
Matthew Wild
|
342de92462
|
mod_tls: Log error when TLS initialization fails
|
2014-01-12 06:16:49 -05:00 |
|
Kim Alvefur
|
3786afa97f
|
mod_tls: Refactor to allow separate SSL configuration for c2s and s2s connections
|
2013-06-13 17:47:45 +02:00 |
|
Kim Alvefur
|
16c7c4e78d
|
mod_tls: More use of config sections removed
|
2013-03-23 02:35:50 +01:00 |
|
Kim Alvefur
|
27dc3a5b9a
|
mod_announce, mod_auth_anonymous, mod_c2s, mod_c2s, mod_component, mod_iq, mod_message, mod_presence, mod_tls: Access prosody.{hosts,bare_sessions,full_sessions} instead of the old globals
|
2013-03-23 01:27:16 +01:00 |
|
Kim Alvefur
|
aac3fbdf9b
|
Merge 0.11->trunk
|
2019-04-24 18:06:48 +02:00 |
|
Kim Alvefur
|
b246b00f85
|
mod_tls: Restore querying for certificates on s2s
The 'ssl_config' setting in the mod_s2s network service is not used.
Only direct TLS ports use this currently.
|
2019-03-11 13:07:59 +01:00 |
|
Kim Alvefur
|
e6b7c91ebc
|
mod_tls: Keep TLS context errors and repeat them again for each session
|
2018-12-28 00:04:26 +01:00 |
|
Matthew Wild
|
32d3713a7a
|
mod_tls: Fix log statement (thanks Zash)
|
2012-01-18 15:07:26 +00:00 |
|
Matthew Wild
|
2d8a08de12
|
mod_tls: Fix for components to more reliably inherit SSL settings from their parenthost (thanks Link Mauve)
|
2011-04-06 14:45:44 +01:00 |
|
Matthew Wild
|
2f3b7c048e
|
mod_tls: Drop 'TLS negotiation started for ...' to debug level from info
|
2011-02-22 18:29:35 +00:00 |
|
Waqas Hussain
|
86eb430400
|
mod_tls: Let hosts without an 'ssl' option inherit it from their parent hosts.
|
2010-11-10 02:26:18 +05:00 |
|
Matthew Wild
|
8e91da96f8
|
mod_tls: Pass the hostname rather than host session to certmanager.create_context() (thanks darkrain)
|
2010-11-08 03:12:30 +00:00 |
|
Matthew Wild
|
c6045f3c70
|
certmanager, hostmanager, mod_tls: Move responsibility for creating per-host SSL contexts to mod_tls, meaning reloading certs is now as trivial as reloading mod_tls
|
2010-11-06 18:28:15 +00:00 |
|
Matthew Wild
|
16fa172b23
|
mod_tls: Remove extraneous flag to starttls() for s2sout connecections
|
2010-07-22 13:13:28 +01:00 |
|
Matthew Wild
|
d16d14ade1
|
Merge 0.6->0.7
|
2010-03-24 22:34:59 +00:00 |
|
Matthew Wild
|
67a0c4e8db
|
mod_tls: Add s2s_allow_encryption option which, when set to false, disabled TLS for s2s
|
2010-03-24 20:00:22 +00:00 |
|
Matthew Wild
|
46c0b8c7f9
|
Merge 0.6->0.7
|
2010-03-22 17:24:55 +00:00 |
|
Matthew Wild
|
2bc0606453
|
Update copyright headers for 2010
|
2010-03-22 17:06:15 +00:00 |
|