Log

plugins/mod_tls.lua @ 12517:a8c17c95ef4d

description author age
mod_tls: pass target hostname to starttls Jonas Schäfer Fri, 17 Sep 2021 21:43:54 +0200
mod_tls: tell network backend to stop reading while preparing TLS Jonas Schäfer Sat, 02 Apr 2022 11:18:57 +0200
mod_tls: Do not offer TLS if the connection is considered secure Jonas Schäfer Fri, 17 Sep 2021 21:18:30 +0200
various: Require encryption by default for real Kim Alvefur Sat, 25 Dec 2021 16:23:40 +0100
mod_tls: Set ALPN on outgoing connections Kim Alvefur Tue, 25 Jan 2022 13:20:26 +0100
mod_s2s: Retrieve TLS context for outgoing Direct TLS connections from mod_tls Kim Alvefur Fri, 21 Jan 2022 18:42:38 +0100
mod_tls: Attempt STARTTLS on outgoing unencrypted legacy s2s connections Kim Alvefur Wed, 01 Sep 2021 19:05:24 +0200
Fix various spelling errors (thanks codespell) Kim Alvefur Tue, 27 Jul 2021 00:13:18 +0200
mod_tls: Add "support" for <failure> by closing gracefully Kim Alvefur Fri, 21 May 2021 19:04:01 +0200
mod_tls: Fix order of debug messages and tls context creation Kim Alvefur Wed, 05 May 2021 16:25:33 +0200
mod_tls: Bail out if session got destroyed while sending <proceed/> Kim Alvefur Thu, 15 Apr 2021 15:57:24 +0200
mod_tls: Ignore lack of STARTTLS offer only when s2s_require_encryption set Kim Alvefur Fri, 29 Jan 2021 23:23:25 +0100
mod_tls: Attempt STARTTLS even if not advertised as per RFC 7590 Kim Alvefur Fri, 29 Jan 2021 23:17:08 +0100
Merge 0.11->trunk Kim Alvefur Sun, 26 Apr 2020 21:03:40 +0200
mod_tls: Log when certificates are (re)loaded 0.11 Kim Alvefur Sun, 26 Apr 2020 20:58:51 +0200
Merge 0.11->trunk Kim Alvefur Wed, 24 Apr 2019 18:06:48 +0200
mod_tls: Log debug message for each kind of TLS context created 0.11 Kim Alvefur Tue, 23 Apr 2019 19:13:50 +0200
mod_tls: Restore querying for certificates on s2s Kim Alvefur Mon, 11 Mar 2019 13:07:59 +0100
mod_tls: Keep TLS context errors and repeat them again for each session Kim Alvefur Fri, 28 Dec 2018 00:04:26 +0100
mod_tls: Rebuild SSL context objects on configuration reload - #701 Kim Alvefur Tue, 25 Apr 2017 21:50:36 +0200
mod_tls: Switch to hook_tag from hook_stanza which was renamed in 2087d42f1e77 Kim Alvefur Mon, 06 Mar 2017 15:55:37 +0100
mod_tls: Suppress debug message if already using encryption Kim Alvefur Sat, 25 Feb 2017 01:16:31 +0100
mod_tls: Log reasons for not being able to do TLS Kim Alvefur Wed, 15 Feb 2017 23:03:22 +0100
mod_tls: Check that connection has starttls method first to prevent offering starttls over tls (thanks Remko and Tobias) Kim Alvefur Fri, 27 Jan 2017 12:21:09 +0100
mod_tls: Return session.ssl_ctx if not nil, like when doing the full session type check Kim Alvefur Wed, 25 Jan 2017 11:12:43 +0100
mod_tls: Add debug logging for when TLS should be doable but no ssl context was set Kim Alvefur Wed, 25 Jan 2017 11:06:30 +0100
mod_tls: Verify that TLS is available before proceeding Kim Alvefur Mon, 23 Jan 2017 10:46:42 +0100
mod_tls: Only accept <proceed> on outgoing s2s connections Kim Alvefur Mon, 23 Jan 2017 10:45:20 +0100
mod_tls: Ignore unused argument [luacheck] Kim Alvefur Wed, 02 Nov 2016 23:19:41 +0100
mod_tls: Fix ssl option fallback to a "parent" host if current host does not have ssl options set (thanks 70b1) Kim Alvefur Mon, 09 Nov 2015 13:40:06 +0100
mod_tls: Remove unused reference to global ssl config option (certmanager adds that to the context) Kim Alvefur Mon, 09 Nov 2015 13:39:23 +0100
mod_tls: Fix inhertinance of 'ssl' option from "parent" host to subdomain (fixes #511) Kim Alvefur Tue, 15 Sep 2015 17:51:56 +0200
mod_tls: Treat session.ssl_ctx being false as a signal that TLS is disabled Kim Alvefur Mon, 18 May 2015 21:48:58 +0200
mod_tls: Build <starttls/> as a stanza instead of with string concatenation Kim Alvefur Mon, 18 May 2015 21:43:24 +0200
certmanager, mod_tls: Return final ssl config as third return value (fix for c6caaa440e74, portmanager assumes non-falsy second return value is an error) (thanks deoren) Kim Alvefur Sat, 22 Nov 2014 11:51:54 +0100
mod_tls: Keep ssl config around and attach them to sessions Kim Alvefur Wed, 19 Nov 2014 14:47:49 +0100
mod_legacyauth, mod_saslauth, mod_tls: Pass require_encryption as default option to s2s_require_encryption so the later overrides the former Kim Alvefur Tue, 21 Oct 2014 12:49:03 +0200
mod_lastactivity, mod_legacyauth, mod_presence, mod_saslauth, mod_tls: Use the newer stanza:get_child APIs and optimize away some table lookups Kim Alvefur Fri, 04 Jul 2014 22:52:34 +0200
mod_tls: Simplify and use new ssl config merging in certmanager Kim Alvefur Thu, 03 Jul 2014 15:35:45 +0200
Merge 0.9->0.10 Matthew Wild Sat, 18 Jan 2014 18:46:12 +0000
mod_tls: Let s2s_secure_auth override s2s_require_encryption and warn if they differ Kim Alvefur Wed, 15 Jan 2014 22:47:50 +0100
mod_tls: Rename variables to be less confusing Kim Alvefur Wed, 15 Jan 2014 21:57:15 +0100
Merge 0.9->0.10 Matthew Wild Sun, 12 Jan 2014 06:19:37 -0500
mod_tls: Log error when TLS initialization fails 0.9.3 Matthew Wild Sun, 12 Jan 2014 06:16:49 -0500
Remove all trailing whitespace Florian Zeitz Fri, 09 Aug 2013 17:48:21 +0200
mod_tls: Remove debug statement Kim Alvefur Sun, 16 Jun 2013 15:01:31 +0200
mod_tls: Refactor to allow separate SSL configuration for c2s and s2s connections Kim Alvefur Thu, 13 Jun 2013 17:47:45 +0200
mod_tls: More use of config sections removed Kim Alvefur Sat, 23 Mar 2013 02:35:50 +0100
mod_announce, mod_auth_anonymous, mod_c2s, mod_c2s, mod_component, mod_iq, mod_message, mod_presence, mod_tls: Access prosody.{hosts,bare_sessions,full_sessions} instead of the old globals Kim Alvefur Sat, 23 Mar 2013 01:27:16 +0100
mod_tls: Fix log statement (thanks Zash) Matthew Wild Wed, 18 Jan 2012 15:07:26 +0000
mod_tls: Fix for components to more reliably inherit SSL settings from their parenthost (thanks Link Mauve) Matthew Wild Wed, 06 Apr 2011 14:45:44 +0100
mod_tls: Drop 'TLS negotiation started for ...' to debug level from info Matthew Wild Tue, 22 Feb 2011 18:29:35 +0000
mod_tls: Let hosts without an 'ssl' option inherit it from their parent hosts. Waqas Hussain Wed, 10 Nov 2010 02:26:18 +0500
mod_tls: Pass the hostname rather than host session to certmanager.create_context() (thanks darkrain) Matthew Wild Mon, 08 Nov 2010 03:12:30 +0000
certmanager, hostmanager, mod_tls: Move responsibility for creating per-host SSL contexts to mod_tls, meaning reloading certs is now as trivial as reloading mod_tls Matthew Wild Sat, 06 Nov 2010 18:28:15 +0000
mod_tls: Remove extraneous flag to starttls() for s2sout connecections Matthew Wild Thu, 22 Jul 2010 13:13:28 +0100
Merge 0.6->0.7 Matthew Wild Wed, 24 Mar 2010 22:34:59 +0000
mod_tls: Add s2s_allow_encryption option which, when set to false, disabled TLS for s2s Matthew Wild Wed, 24 Mar 2010 20:00:22 +0000
Merge 0.6->0.7 Matthew Wild Mon, 22 Mar 2010 17:24:55 +0000
Update copyright headers for 2010 Matthew Wild Mon, 22 Mar 2010 17:06:15 +0000
Merge 0.6.2/waqas with 0.6.2/MattJ Matthew Wild Wed, 03 Mar 2010 22:05:05 +0000
mod_tls: Don't offer TLS on hosts that don't have any certs Matthew Wild Fri, 12 Feb 2010 21:33:22 +0000
mod_tls: Fixed an extra :up() in s2s stream feature generation. Waqas Hussain Fri, 12 Feb 2010 03:14:53 +0500
mod_tls: Respond with proper error when TLS cannot be negotiated. Waqas Hussain Fri, 12 Feb 2010 02:39:50 +0500
mod_tls: Set the sslctx on outgoing connections (possibly the cause of outgoing s2s connections not being encrypted) Matthew Wild Sun, 31 Jan 2010 15:39:49 +0000
mod_tls: Only negotiate TLS on outgoing s2s connections if we have an SSL context (thanks Flo...) Matthew Wild Tue, 16 Feb 2010 17:15:43 +0000
mod_tls: Ban TLS after auth, not before. Waqas Hussain Sun, 14 Feb 2010 10:00:39 +0500
mod_tls: Fixed traceback during S2S TLS (nil global access). Waqas Hussain Sun, 14 Feb 2010 09:59:57 +0500
mod_tls: Refactor to simplify detection of whether we can do TLS on a connection Matthew Wild Fri, 12 Feb 2010 21:57:46 +0000
mod_tls: Don't offer TLS on hosts that don't have any certs Matthew Wild Fri, 12 Feb 2010 21:33:22 +0000
s2smanager, mod_compression, mod_tls: Changed event.session to event.origin for s2s-stream-features event for consistency. Waqas Hussain Fri, 12 Feb 2010 04:30:17 +0500
mod_tls: Hook stream-features event using new events API. Waqas Hussain Fri, 12 Feb 2010 03:50:44 +0500
mod_tls: Cleanup. Waqas Hussain Fri, 12 Feb 2010 03:46:48 +0500
mod_tls: Fixed an extra :up() in s2s stream feature generation. Waqas Hussain Fri, 12 Feb 2010 03:14:53 +0500
mod_tls: Remove origin type check when TLS is requested (thanks MattJ). Waqas Hussain Fri, 12 Feb 2010 02:43:02 +0500
mod_tls: Respond with proper error when TLS cannot be negotiated. Waqas Hussain Fri, 12 Feb 2010 02:39:50 +0500
mod_tls: Inlined some code. Waqas Hussain Fri, 12 Feb 2010 02:32:27 +0500
mod_tls: Merged duplicate code. Waqas Hussain Fri, 12 Feb 2010 02:15:54 +0500
mod_tls: Switched to new events API. Waqas Hussain Fri, 12 Feb 2010 01:56:18 +0500
mod_tls: Slight refactoring. Waqas Hussain Fri, 12 Feb 2010 01:47:10 +0500
mod_tls: Don't advertise TLS after authentication. Waqas Hussain Wed, 10 Feb 2010 01:36:22 +0500
mod_tls: Remove some redundant variable declarations Matthew Wild Sun, 31 Jan 2010 15:40:28 +0000
mod_tls: Set the sslctx on outgoing connections (possibly the cause of outgoing s2s connections not being encrypted) Matthew Wild Sun, 31 Jan 2010 15:39:49 +0000
mod_tls: Update for new server SSL syntax Matthew Wild Sun, 31 Jan 2010 15:39:04 +0000
mod_tls: Switch to : syntax for connection methods Matthew Wild Sat, 21 Nov 2009 17:16:46 +0000
mod_tls: Offer the host-specific cert (when there is one) to incoming c2s/s2s connections, fixes #30 (thanks, albert, Flo, johnny, and all who nagged me :) ) Matthew Wild Sat, 17 Oct 2009 16:25:28 +0100
mod_tls: Don't try to start TLS if we can't actually do it (thanks Florob) Matthew Wild Fri, 09 Oct 2009 17:48:45 +0100
mod_tls: Catch s2s-stream-features and add starttls feature if possible Matthew Wild Thu, 08 Oct 2009 23:41:59 +0100
mod_tls: Mark sessions as not secure when negotiating outward TLS, so they get marked secure later. Fixes missing (encrypted) for outgoing sessions in s2s:show(). Thanks albert, McKael :) Matthew Wild Tue, 06 Oct 2009 10:34:13 +0100
mod_tls: require_s2s_encryption -> s2s_require_encryption Matthew Wild Mon, 05 Oct 2009 15:00:05 +0100
require_encryption deprecated, use c2s_require_encryption instead Matthew Wild Mon, 05 Oct 2009 14:59:30 +0100
mod_tls: Mark starttls feature as <required/> if require_s2s_encryption is enabled Matthew Wild Mon, 05 Oct 2009 14:52:30 +0100
mod_tls: Mark session as not secure before negotiating TLS Matthew Wild Mon, 05 Oct 2009 14:51:53 +0100
mod_tls: Only advertise TLS if the server told us which host they are connecting to Matthew Wild Mon, 05 Oct 2009 10:10:53 +0100
mod_tls: :up() out of the starttls tag in stream:features Matthew Wild Sun, 04 Oct 2009 13:24:04 +0100
Minor changes; outgoing TLS works. Paul Aurich Sat, 03 Oct 2009 19:20:20 -0700
mod_tls: Advertise and handle TLS for s2s connections Matthew Wild Sun, 04 Oct 2009 14:06:45 +0100
Another unwanted spaces at the end of a line. Tobias Markmann Thu, 13 Aug 2009 11:35:50 +0200
mod_tls: Updated to use module:get_option instead of configmanager Waqas Hussain Sat, 08 Aug 2009 23:41:45 +0500
Remove version number from copyright headers Matthew Wild Fri, 10 Jul 2009 03:11:45 +0100
mod_tls: Add <required/> to stream feature when TLS is required Matthew Wild Fri, 29 May 2009 18:17:03 +0100
sessionmanager, mod_tls: Mark a session as secure when TLS is active Matthew Wild Fri, 29 May 2009 14:28:53 +0100
0.3->0.4 Matthew Wild Fri, 20 Mar 2009 20:16:25 +0000
Update copyright notices for 2009 Matthew Wild Fri, 30 Jan 2009 17:59:26 +0000
0.2->0.3 Matthew Wild Fri, 30 Jan 2009 17:40:25 +0000
GPL->MIT! Matthew Wild Fri, 30 Jan 2009 17:22:56 +0000
mod_saslauth, mod_tls: minor code cleanup Waqas Hussain Tue, 13 Jan 2009 19:37:12 +0500
Remove a FIXME from mod_tls Matthew Wild Mon, 15 Dec 2008 18:06:59 +0000
0.1 -> 0.2 Matthew Wild Wed, 10 Dec 2008 15:44:03 +0000
Insert copyright/license headers Matthew Wild Wed, 03 Dec 2008 14:39:07 +0000
Bumper commit for the new modulemanager API \o/ Updates all the modules, though some more changes may be in store. Matthew Wild Thu, 27 Nov 2008 03:12:12 +0000
Use a stanza for c2s stream features instead of an array of strings. Removes a FIXME. Matthew Wild Thu, 20 Nov 2008 01:33:25 +0000
Fixed mod_tls to use session.send for sending stanzas Waqas Hussain Sun, 16 Nov 2008 05:03:21 +0500
Unused variables in mod_tls Waqas Hussain Sun, 16 Nov 2008 02:52:54 +0500
TLS/SASL no longer should include the connhandler module Matthew Wild Thu, 23 Oct 2008 03:53:51 +0100
Abstract connections with "connection listeners" Matthew Wild Wed, 22 Oct 2008 17:36:21 +0100
forgot to commit mod_tls, oops :) Matthew Wild Tue, 07 Oct 2008 23:13:30 +0100