mod_s2s_auth_dane: Pause s2sin while doing SRV and TLSA lookups, fixes race condition (Can haz util.async plz)
|
Kim Alvefur |
Thu, 20 Mar 2014 15:31:15 +0100 |
mod_s2s_auth_dane: Fix tb when no hostname sent by remote
|
Kim Alvefur |
Wed, 19 Mar 2014 19:48:06 +0100 |
mod_s2s_auth_dane: Verify that the SRV is secure
|
Kim Alvefur |
Wed, 19 Mar 2014 14:33:10 +0100 |
mod_s2s_auth_dane: Abort module loading if luaunbound is unavailable
|
Kim Alvefur |
Wed, 19 Mar 2014 14:04:09 +0100 |
mod_s2s_auth_dane: Drop support for domains without SRV for now
|
Kim Alvefur |
Tue, 18 Mar 2014 16:09:51 +0100 |
mod_s2s_auth_dane: Fix for a17c2c4043e5
|
Kim Alvefur |
Tue, 18 Mar 2014 16:02:24 +0100 |
mod_s2s_auth_dane: Skip TLSA lookups if SRV is insecure
|
Kim Alvefur |
Tue, 18 Mar 2014 15:54:08 +0100 |
mod_s2s_auth_dane: Hack for domains without SRV
|
Kim Alvefur |
Tue, 18 Mar 2014 15:36:23 +0100 |
mod_s2s_auth_dane: Don't pass nil to hash functions in case of unsupported selectors
|
Kim Alvefur |
Tue, 18 Mar 2014 15:20:28 +0100 |
mod_s2s_auth_dane: Back to _port._tcp.srvtarget.example.net
|
Kim Alvefur |
Tue, 18 Mar 2014 15:12:11 +0100 |
mod_s2s_auth_dane: Bogus replies should have no RRdata
|
Kim Alvefur |
Fri, 14 Mar 2014 14:30:33 +0100 |
mod_s2s_auth_dane: Comments and TODOs
|
Kim Alvefur |
Fri, 14 Mar 2014 14:23:27 +0100 |
mod_s2s_auth_dane: Make supported DANE usages configurable, default to DANE-EE
|
Kim Alvefur |
Fri, 14 Mar 2014 14:18:18 +0100 |
mod_s2s_auth_dane: Simplify, but diverge from DANE-SRV draft. Will now look for _xmpp-server.example.com IN TLSA for both directions
|
Kim Alvefur |
Fri, 14 Mar 2014 14:15:56 +0100 |
mod_s2s_auth_dane: Only invalidate trust if we found any supported DANE records
|
Kim Alvefur |
Tue, 11 Mar 2014 21:13:40 +0100 |
mod_s2s_auth_dane: Improve handling of bogus data
|
Kim Alvefur |
Sun, 09 Mar 2014 23:17:17 +0100 |
mod_s2s_auth_dane: Only do TLSA lookup if it hasn't been attempted already
|
Kim Alvefur |
Sun, 09 Mar 2014 23:08:41 +0100 |
mod_s2s_auth_dane: Fix inverted nil check
|
Kim Alvefur |
Sun, 09 Mar 2014 14:09:24 +0100 |
mod_s2s_auth_dane: Do DANE lookups on outgoing stream features
|
Kim Alvefur |
Sun, 09 Mar 2014 13:44:29 +0100 |
mod_s2s_auth_dane: Improve logging
|
Kim Alvefur |
Sun, 09 Mar 2014 13:43:27 +0100 |
mod_s2s_auth_dane: More comment changes
|
Kim Alvefur |
Sun, 09 Mar 2014 13:42:36 +0100 |
mod_s2s_auth_dane: Implement experimental method for doing DANE with client certificates on s2sin
|
Kim Alvefur |
Sat, 08 Mar 2014 00:00:26 +0100 |
mod_s2s_auth_dane: Add some comments
|
Kim Alvefur |
Fri, 07 Mar 2014 23:30:34 +0100 |
mod_s2s_auth_dane: Don't allow unencrypted connections if TLSA exists
|
Kim Alvefur |
Wed, 05 Mar 2014 17:44:27 +0100 |
mod_s2s_auth_dane: Verify that the pubkey method exists when the SPKI selector is used
|
Kim Alvefur |
Wed, 05 Mar 2014 17:42:15 +0100 |
mod_s2s_auth_dane: Delay s2sout state machine until we get TLSA reply
|
Kim Alvefur |
Wed, 05 Mar 2014 17:40:44 +0100 |
mod_s2s_auth_dane: Comment updates
|
Kim Alvefur |
Wed, 05 Mar 2014 17:38:36 +0100 |
Backed out changeset 853a382c9bd6
|
Kim Alvefur |
Fri, 28 Feb 2014 15:37:55 +0100 |
mod_turncredentials: Advertise the XEP-0215 feature (thanks Gryffus)
|
Kim Alvefur |
Fri, 28 Feb 2014 15:36:06 +0100 |
mod_s2s_auth_dane: Fix typo in comment (thanks albert)
|
Kim Alvefur |
Sat, 04 Jan 2014 23:12:32 +0100 |