Diff

core/certmanager.lua @ 9852:6ea3cafb6ac3

core.certmanager: Do not ask for client certificates by default Since it's mostly only mod_s2s that needs to request client certificates it makes some sense to have mod_s2s ask for this, instead of having eg mod_http ask to disable it.
author Kim Alvefur <zash@zash.se>
date Sun, 10 Mar 2019 19:58:28 +0100
parent 8828:2a0d7fa4c56a
child 10224:94e341dee51c
line wrap: on
line diff
--- a/core/certmanager.lua	Sun Mar 10 19:32:33 2019 +0100
+++ b/core/certmanager.lua	Sun Mar 10 19:58:28 2019 +0100
@@ -106,7 +106,7 @@
 	capath = "/etc/ssl/certs";
 	depth = 9;
 	protocol = "tlsv1+";
-	verify = (ssl_x509 and { "peer", "client_once", }) or "none";
+	verify = "none";
 	options = {
 		cipher_server_preference = luasec_has.options.cipher_server_preference;
 		no_ticket = luasec_has.options.no_ticket;