Diff

plugins/mod_s2s/mod_s2s.lua @ 10471:ae906d51e3d2

mod_s2s: Improve log message about forbidding insecure connections This new wording generator is nice.
author Kim Alvefur <zash@zash.se>
date Sat, 30 Nov 2019 23:29:15 +0100
parent 10465:09697a673015
child 10472:676e6a1b23d4
line wrap: on
line diff
--- a/plugins/mod_s2s/mod_s2s.lua	Sat Nov 30 21:56:21 2019 +0100
+++ b/plugins/mod_s2s/mod_s2s.lua	Sat Nov 30 23:29:15 2019 +0100
@@ -763,8 +763,8 @@
 	end
 
 	if must_secure and (session.cert_chain_status ~= "valid" or session.cert_identity_status ~= "valid") then
-		module:log("warn", "Forbidding insecure connection to/from %s", host or session.ip or "(unknown host)");
 		local reason = friendly_cert_error(session);
+		module:log("warn", "Forbidding insecure connection to/from %s because its certificate %s", host or session.ip or "(unknown host)", reason);
 		-- XEP-0178 recommends closing outgoing connections without warning
 		-- but does not give a rationale for this.
 		-- In practice most cases are configuration mistakes or forgotten