Software /
code /
prosody
File
teal-src/util/hashes.d.tl @ 11749:83d6d6a70edf
net.http: fail open if surrounding code does not configure TLS
Previously, if surrounding code was not configuring the TLS context
used default in net.http, it would not validate certificates at all.
This is not a security issue with prosody, because prosody updates the
context with `verify = "peer"` as well as paths to CA certificates in
util.startup.init_http_client.
Nevertheless... Let's not leave this pitfall out there in the open.
author | Jonas Schäfer <jonas@wielicki.name> |
---|---|
date | Sun, 29 Aug 2021 15:04:47 +0200 |
parent | 11576:fbd1ebd86369 |
child | 12561:adfb46a3e8a7 |
line wrap: on
line source
local type hash = function (msg : string, hex : boolean) : string local type hmac = function (key : string, msg : string, hex : boolean) : string local type kdf = function (pass : string, salt : string, i : integer) : string local record lib sha1 : hash sha256 : hash sha224 : hash sha384 : hash sha512 : hash md5 : hash hmac_sha1 : hmac hmac_sha256 : hmac hmac_sha512 : hmac hmac_md5 : hmac scram_Hi_sha1 : kdf pbkdf2_hmac_sha1 : kdf pbkdf2_hmac_sha256 : kdf equals : function (string, string) : boolean version : string _LIBCRYPTO_VERSION : string end return lib