Annotate

README @ 13801:a5d5fefb8b68 13.0

mod_tls: Enable Prosody's certificate checking for incoming s2s connections (fixes #1916) (thanks Damian, Zash) Various options in Prosody allow control over the behaviour of the certificate verification process For example, some deployments choose to allow falling back to traditional "dialback" authentication (XEP-0220), while others verify via DANE, hard-coded fingerprints, or other custom plugins. Implementing this flexibility requires us to override OpenSSL's default certificate verification, to allow Prosody to verify the certificate itself, apply custom policies and make decisions based on the outcome. To enable our custom logic, we have to suppress OpenSSL's default behaviour of aborting the connection with a TLS alert message. With LuaSec, this can be achieved by using the verifyext "lsec_continue" flag. We also need to use the lsec_ignore_purpose flag, because XMPP s2s uses server certificates as "client" certificates (for mutual TLS verification in outgoing s2s connections). Commit 99d2100d2918 moved these settings out of the defaults and into mod_s2s, because we only really need these changes for s2s, and they should be opt-in, rather than automatically applied to all TLS services we offer. That commit was incomplete, because it only added the flags for incoming direct TLS connections. StartTLS connections are handled by mod_tls, which was not applying the lsec_* flags. It previously worked because they were already in the defaults. This resulted in incoming s2s connections with "invalid" certificates being aborted early by OpenSSL, even if settings such as `s2s_secure_auth = false` or DANE were present in the config. Outgoing s2s connections inherit verify "none" from the defaults, which means OpenSSL will receive the cert but will not terminate the connection when it is deemed invalid. This means we don't need lsec_continue there, and we also don't need lsec_ignore_purpose (because the remote peer is a "server"). Wondering why we can't just use verify "none" for incoming s2s? It's because in that mode, OpenSSL won't request a certificate from the peer for incoming connections. Setting verify "peer" is how you ask OpenSSL to request a certificate from the client, but also what triggers its built-in verification.
author Matthew Wild <mwild1@gmail.com>
date Tue, 01 Apr 2025 17:26:56 +0100
parent 12223:a68f1617721b
Ignore whitespace changes - Everywhere: Within whitespace: At end of lines:
rev   line source
1192
b1b42ce4f0f6 Finally add README and INSTALL files
Matthew Wild <mwild1@gmail.com>
parents:
diff changeset
1 # Prosody IM Server
b1b42ce4f0f6 Finally add README and INSTALL files
Matthew Wild <mwild1@gmail.com>
parents:
diff changeset
2
b1b42ce4f0f6 Finally add README and INSTALL files
Matthew Wild <mwild1@gmail.com>
parents:
diff changeset
3 ## Description
b1b42ce4f0f6 Finally add README and INSTALL files
Matthew Wild <mwild1@gmail.com>
parents:
diff changeset
4
12223
a68f1617721b README: Reflow text to ~78 columns
Kim Alvefur <zash@zash.se>
parents: 10692
diff changeset
5 Prosody is a server for Jabber/XMPP written in Lua. It aims to be easy to use
a68f1617721b README: Reflow text to ~78 columns
Kim Alvefur <zash@zash.se>
parents: 10692
diff changeset
6 and light on resources. For developers, it aims to give a flexible system on
a68f1617721b README: Reflow text to ~78 columns
Kim Alvefur <zash@zash.se>
parents: 10692
diff changeset
7 which to rapidly develop added functionality or rapidly prototype new
a68f1617721b README: Reflow text to ~78 columns
Kim Alvefur <zash@zash.se>
parents: 10692
diff changeset
8 protocols.
1192
b1b42ce4f0f6 Finally add README and INSTALL files
Matthew Wild <mwild1@gmail.com>
parents:
diff changeset
9
b1b42ce4f0f6 Finally add README and INSTALL files
Matthew Wild <mwild1@gmail.com>
parents:
diff changeset
10 ## Useful links
b1b42ce4f0f6 Finally add README and INSTALL files
Matthew Wild <mwild1@gmail.com>
parents:
diff changeset
11
7359
a5a080c12c96 Update every link to the documentation to use HTTPS
Emmanuel Gil Peyrot <linkmauve@linkmauve.fr>
parents: 2665
diff changeset
12 Homepage: https://prosody.im/
a5a080c12c96 Update every link to the documentation to use HTTPS
Emmanuel Gil Peyrot <linkmauve@linkmauve.fr>
parents: 2665
diff changeset
13 Download: https://prosody.im/download
a5a080c12c96 Update every link to the documentation to use HTTPS
Emmanuel Gil Peyrot <linkmauve@linkmauve.fr>
parents: 2665
diff changeset
14 Documentation: https://prosody.im/doc/
9945
606b2567ff18 README: Add link to current issue tracker
Kim Alvefur <zash@zash.se>
parents: 9944
diff changeset
15 Issue tracker: https://issues.prosody.im/
1192
b1b42ce4f0f6 Finally add README and INSTALL files
Matthew Wild <mwild1@gmail.com>
parents:
diff changeset
16
b1b42ce4f0f6 Finally add README and INSTALL files
Matthew Wild <mwild1@gmail.com>
parents:
diff changeset
17 Jabber/XMPP Chat:
b1b42ce4f0f6 Finally add README and INSTALL files
Matthew Wild <mwild1@gmail.com>
parents:
diff changeset
18 Address:
1391
b910ef82622d README: Update for new MUC address
Matthew Wild <mwild1@gmail.com>
parents: 1192
diff changeset
19 prosody@conference.prosody.im
1192
b1b42ce4f0f6 Finally add README and INSTALL files
Matthew Wild <mwild1@gmail.com>
parents:
diff changeset
20 Web interface:
10692
a0480ee2233a README: Update link to web chat
Kim Alvefur <zash@zash.se>
parents: 9945
diff changeset
21 https://chat.prosody.im/
12223
a68f1617721b README: Reflow text to ~78 columns
Kim Alvefur <zash@zash.se>
parents: 10692
diff changeset
22
1192
b1b42ce4f0f6 Finally add README and INSTALL files
Matthew Wild <mwild1@gmail.com>
parents:
diff changeset
23 Mailing lists:
b1b42ce4f0f6 Finally add README and INSTALL files
Matthew Wild <mwild1@gmail.com>
parents:
diff changeset
24 User support and discussion:
7359
a5a080c12c96 Update every link to the documentation to use HTTPS
Emmanuel Gil Peyrot <linkmauve@linkmauve.fr>
parents: 2665
diff changeset
25 https://groups.google.com/group/prosody-users
12223
a68f1617721b README: Reflow text to ~78 columns
Kim Alvefur <zash@zash.se>
parents: 10692
diff changeset
26
1192
b1b42ce4f0f6 Finally add README and INSTALL files
Matthew Wild <mwild1@gmail.com>
parents:
diff changeset
27 Development discussion:
7359
a5a080c12c96 Update every link to the documentation to use HTTPS
Emmanuel Gil Peyrot <linkmauve@linkmauve.fr>
parents: 2665
diff changeset
28 https://groups.google.com/group/prosody-dev
12223
a68f1617721b README: Reflow text to ~78 columns
Kim Alvefur <zash@zash.se>
parents: 10692
diff changeset
29
1192
b1b42ce4f0f6 Finally add README and INSTALL files
Matthew Wild <mwild1@gmail.com>
parents:
diff changeset
30 ## Installation
b1b42ce4f0f6 Finally add README and INSTALL files
Matthew Wild <mwild1@gmail.com>
parents:
diff changeset
31
12223
a68f1617721b README: Reflow text to ~78 columns
Kim Alvefur <zash@zash.se>
parents: 10692
diff changeset
32 See the accompanying INSTALL file for help on building Prosody from source.
a68f1617721b README: Reflow text to ~78 columns
Kim Alvefur <zash@zash.se>
parents: 10692
diff changeset
33 Alternatively see our guide at https://prosody.im/doc/install
1192
b1b42ce4f0f6 Finally add README and INSTALL files
Matthew Wild <mwild1@gmail.com>
parents:
diff changeset
34
b1b42ce4f0f6 Finally add README and INSTALL files
Matthew Wild <mwild1@gmail.com>
parents:
diff changeset
35