s2smanager: Make require_s2s_encryption do what it says on the tin

vault/0.11
Matthew Wild 16 years ago
parent 2c384fccc2
commit 4a7e2575df
  1. 10
      core/s2smanager.lua

@ -453,6 +453,16 @@ function verify_dialback(id, to, from, key)
end
function make_authenticated(session, host)
if not session.secure then
local local_host = session.direction == "incoming" and session.to_host or session.from_host;
if config.get(local_host, "core", "require_s2s_encryption")) then
session:close({
condition = "policy-violation",
text = "Encrypted server-to-server communication is required but was not "
..((session.direction == "outgoing" and "offered") or "used")
});
end
end
if session.type == "s2sout_unauthed" then
session.type = "s2sout";
elseif session.type == "s2sin_unauthed" then

Loading…
Cancel
Save