Commit Graph

167 Commits (master)

Author SHA1 Message Date
Matthew Wild 8d281ac121 certmanager: Remove obsolete index log (replaced by shell command) 9 months ago
Matthew Wild bc13ac7e71 certmanager: Improve logging for all cases where certs are skipped 9 months ago
Matthew Wild faf20e5dc9 certmanager: Add more debug logging around cert indexing 10 months ago
Kim Alvefur 346f58c9d9 core.certmanager: Move LuaSec verification tweaks to mod_s2s 11 months ago
Kim Alvefur cf446f4188 core.certmanager: Include ffdhe2048 from RFC 7919 as default DH param 1 year ago
Kim Alvefur e8128c1d60 core.certmanager: Validate that 'tls_profile' is one of the valid values 2 years ago
Kim Alvefur 59f9a608fd core.certmanager: Update Mozilla TLS config to version 5.7 3 years ago
Kim Alvefur 1f668fed00 core.certmanager: Expand debug messages about cert lookups in index 4 years ago
Kim Alvefur dd1e42f499 core.certmanager: Ensure key exists for fullchain 4 years ago
Kim Alvefur 406b90d31d core.certmanager: Turn soft dependency on LuaSec into a hard 4 years ago
Kim Alvefur 7b6a2f64e2 core.certmanager: Handle dane context setting same way on reload as on initialization 2 years ago
Kim Alvefur 2c9c0fab32 core.certmanager: Tweak log level of message about SNI being required 2 years ago
Kim Alvefur e6f0e0b9d0 net.tls_luasec: Expose method for loading a certificate 3 years ago
Kim Alvefur 296710c701 net.certmanager: Move LuaSec feature detection to net.tls_luasec 3 years ago
Kim Alvefur d47a7bb3bd core: Prefix module imports with prosody namespace 3 years ago
Jonas Schäfer 9f7c3b9ba6 net: refactor sslconfig to not depend on LuaSec 4 years ago
Jonas Schäfer 38346dd6f1 net: isolate LuaSec-specifics 4 years ago
Matthew Wild f0c2ed1201 certmanager: Disable renegotiation by default 5 years ago
Kim Alvefur b369dea3d8 core.certmanager: Test for SSL options in absence of LuaSec config 5 years ago
Kim Alvefur a174420e52 core.certmanager: Attempt to directly access LuaSec config table 5 years ago
Kim Alvefur 5291ea4c7c core.certmanager: Move EECDH ciphers before EDH in default cipherstring (fixes #1513) 6 years ago
Kim Alvefur 96620cafe5 core.certmanager: Look for privkey.pem to go with fullchain.pem (fix #1526) 6 years ago
Kim Alvefur 26b898bc52 core.certmanager: Relax certificate filename check #1713 4 years ago
Kim Alvefur 73c3ab7888 core.certmanager: Use 'tls_profile' instead of 'tls_preset' to match documentation 4 years ago
Kim Alvefur 8edd063114 core.certmanager: Apply TLS preset before global settings (thanks Menel) 4 years ago
Kim Alvefur 3b2c39901a core.certmanager: Disable DANE name checks (not needed for XMPP) 4 years ago
Kim Alvefur f343cf5ba0 core.certmanager: Add curveslist to 'old' Mozilla TLS preset 4 years ago
Kim Alvefur da1bffce1d core.certmanager: Check index for wildcard certs 4 years ago
Jonas Schäfer 7c93370ad5 prosodyctl cert: use the indexing functions for better UX 4 years ago
Kim Alvefur 46a6dafd28 core.certmanager: Rename preset option to 'tls_preset' 4 years ago
Kim Alvefur 184b0a62cb core.certmanager: Add "legacy" preset for keeping previous default settings 4 years ago
Kim Alvefur 99a73bdcf6 core.certmanager: Add TLS 1.3 cipher suites to Mozilla TLS presets 4 years ago
Kim Alvefur d2ff803262 core.certmanager: Presets based on Mozilla SSL Configuration Generator 6 years ago
Kim Alvefur 4d26d4cb15 core.certmanager: Support 'use_dane' setting to enable DANE support 5 years ago
Kim Alvefur 8df4b320f4 core.certmanager: Skip service certificate lookup for https client 5 years ago
Kim Alvefur 37ad3b8fb2 core.certmanager: Catch error from lfs 5 years ago
Kim Alvefur 2c902f163f core.certmanager: Resolve certs path relative to config dir 5 years ago
Kim Alvefur f2a8b90b30 core.certmanager: Skip directly to guessing of key from cert filename 5 years ago
Kim Alvefur 2d707a905f core.certmanager: Join paths with OS-aware util.paths function 5 years ago
Kim Alvefur c372b19359 core.certmanager: Build an index over certificates 5 years ago
Kim Alvefur 003e8f633a core.certmanager: Check for complete filename 5 years ago
Kim Alvefur 3fd016e66a core.certmanager: Add comments explaining the 'verifyext' TLS settings 5 years ago
Kim Alvefur fb5e6faad6 core.certmanager: Add TODO about LuaSec issue 6 years ago
Kim Alvefur 1f33d9c6bb core.portmanager: Fix TLS context inheritance for SNI hosts (completes SNI support) 6 years ago
Kim Alvefur 5bba716be9 core.certmanager: Lower severity for tls config not having cert 6 years ago
Kim Alvefur f39535cfd0 core.certmanager: Remove unused import [luacheck] 6 years ago
Kim Alvefur b16782257d Remove COMPAT with temporary luasec fork 6 years ago
Kim Alvefur df3f84ce54 core.certmanager: Move EECDH ciphers before EDH in default cipherstring 6 years ago
Kim Alvefur 400d3337aa core.certmanager: Allow all non-whitespace in service name (fixes #1019) 8 years ago
Kim Alvefur b8915c9db4 certmanager: Check for missing certificate before key in configuration (should be marginally less confusing) 8 years ago