Software /
code /
prosody-modules
File
mod_auth_ccert/README.markdown @ 5553:67152838afbc
mod_http_oauth2: Improve error messages for URI properties
Since there are separate validation checks for URI properties, including
that they should use https, with better and more specific error reporting.
Reverts 'luaPattern' to 'pattern' which is not currently supported by
util.jsonschema, but allows anything that retrieves the schema over http
to validate against it, should they wish to do so.
author | Kim Alvefur <zash@zash.se> |
---|---|
date | Sat, 17 Jun 2023 18:15:00 +0200 |
parent | 4433:0e3f5f70a51d |
line wrap: on
line source
--- labels: - 'Stage-Alpha' - 'Type-Auth' summary: Client Certificate authentication module ... Introduction ============ This module implements PKI-style client certificate authentication. You will therefore need your own Certificate Authority. How to set that up is beyond the current scope of this document. Configuration ============= authentication = "ccert" certificate_match = "xmppaddr" -- or "email" c2s_ssl = { cafile = "/path/to/your/ca.pem"; capath = false; -- Disable capath inherited from built-in default verify = {"peer"; "client_once"}; -- Ask for client certificate verifyext = { -- Don't validate client certs as if they were server certs lsec_ignore_purpose = false } } Compatibility ============= ----------------- -------------- trunk Works 0.10 and later Works 0.9 and earlier Doesn't work ----------------- --------------