plugins/mod_tls.lua
Tue, 18 Jul 2023 12:38:16 +0200 Kim Alvefur plugins: Use boolean config method in some places
Wed, 19 Apr 2023 11:14:11 +0200 Kim Alvefur mod_tls: Drop request for client certificates on outgoing connections
Fri, 24 Mar 2023 13:15:28 +0100 Kim Alvefur plugins: Prefix module imports with prosody namespace
Tue, 02 Aug 2022 19:26:26 +0200 Kim Alvefur mod_tls: Record STARTTLS state so it can be shown in Shell
Fri, 17 Sep 2021 21:43:54 +0200 Jonas Schäfer mod_tls: pass target hostname to starttls
Sat, 02 Apr 2022 11:18:57 +0200 Jonas Schäfer mod_tls: tell network backend to stop reading while preparing TLS
Fri, 17 Sep 2021 21:18:30 +0200 Jonas Schäfer mod_tls: Do not offer TLS if the connection is considered secure
Sat, 25 Dec 2021 16:23:40 +0100 Kim Alvefur various: Require encryption by default for real
Tue, 25 Jan 2022 13:20:26 +0100 Kim Alvefur mod_tls: Set ALPN on outgoing connections
Fri, 21 Jan 2022 18:42:38 +0100 Kim Alvefur mod_s2s: Retrieve TLS context for outgoing Direct TLS connections from mod_tls
Wed, 01 Sep 2021 19:05:24 +0200 Kim Alvefur mod_tls: Attempt STARTTLS on outgoing unencrypted legacy s2s connections
Tue, 27 Jul 2021 00:13:18 +0200 Kim Alvefur Fix various spelling errors (thanks codespell)
Fri, 21 May 2021 19:04:01 +0200 Kim Alvefur mod_tls: Add "support" for <failure> by closing gracefully
Wed, 05 May 2021 16:25:33 +0200 Kim Alvefur mod_tls: Fix order of debug messages and tls context creation
Thu, 15 Apr 2021 15:57:24 +0200 Kim Alvefur mod_tls: Bail out if session got destroyed while sending <proceed/>
Fri, 29 Jan 2021 23:23:25 +0100 Kim Alvefur mod_tls: Ignore lack of STARTTLS offer only when s2s_require_encryption set
Fri, 29 Jan 2021 23:17:08 +0100 Kim Alvefur mod_tls: Attempt STARTTLS even if not advertised as per RFC 7590
Sun, 26 Apr 2020 21:03:40 +0200 Kim Alvefur Merge 0.11->trunk
Sun, 26 Apr 2020 20:58:51 +0200 Kim Alvefur mod_tls: Log when certificates are (re)loaded 0.11
Wed, 24 Apr 2019 18:06:48 +0200 Kim Alvefur Merge 0.11->trunk
Tue, 23 Apr 2019 19:13:50 +0200 Kim Alvefur mod_tls: Log debug message for each kind of TLS context created 0.11
Mon, 11 Mar 2019 13:07:59 +0100 Kim Alvefur mod_tls: Restore querying for certificates on s2s
Fri, 28 Dec 2018 00:04:26 +0100 Kim Alvefur mod_tls: Keep TLS context errors and repeat them again for each session
Tue, 25 Apr 2017 21:50:36 +0200 Kim Alvefur mod_tls: Rebuild SSL context objects on configuration reload - #701
Mon, 06 Mar 2017 15:55:37 +0100 Kim Alvefur mod_tls: Switch to hook_tag from hook_stanza which was renamed in 2087d42f1e77
Sat, 25 Feb 2017 01:16:31 +0100 Kim Alvefur mod_tls: Suppress debug message if already using encryption
Wed, 15 Feb 2017 23:03:22 +0100 Kim Alvefur mod_tls: Log reasons for not being able to do TLS
Fri, 27 Jan 2017 12:21:09 +0100 Kim Alvefur mod_tls: Check that connection has starttls method first to prevent offering starttls over tls (thanks Remko and Tobias)
Wed, 25 Jan 2017 11:12:43 +0100 Kim Alvefur mod_tls: Return session.ssl_ctx if not nil, like when doing the full session type check
Wed, 25 Jan 2017 11:06:30 +0100 Kim Alvefur mod_tls: Add debug logging for when TLS should be doable but no ssl context was set
Mon, 23 Jan 2017 10:46:42 +0100 Kim Alvefur mod_tls: Verify that TLS is available before proceeding
Mon, 23 Jan 2017 10:45:20 +0100 Kim Alvefur mod_tls: Only accept <proceed> on outgoing s2s connections
Wed, 02 Nov 2016 23:19:41 +0100 Kim Alvefur mod_tls: Ignore unused argument [luacheck]
Mon, 09 Nov 2015 13:40:06 +0100 Kim Alvefur mod_tls: Fix ssl option fallback to a "parent" host if current host does not have ssl options set (thanks 70b1)
Mon, 09 Nov 2015 13:39:23 +0100 Kim Alvefur mod_tls: Remove unused reference to global ssl config option (certmanager adds that to the context)
Tue, 15 Sep 2015 17:51:56 +0200 Kim Alvefur mod_tls: Fix inhertinance of 'ssl' option from "parent" host to subdomain (fixes #511)
Mon, 18 May 2015 21:48:58 +0200 Kim Alvefur mod_tls: Treat session.ssl_ctx being false as a signal that TLS is disabled
Mon, 18 May 2015 21:43:24 +0200 Kim Alvefur mod_tls: Build <starttls/> as a stanza instead of with string concatenation
Sat, 22 Nov 2014 11:51:54 +0100 Kim Alvefur certmanager, mod_tls: Return final ssl config as third return value (fix for c6caaa440e74, portmanager assumes non-falsy second return value is an error) (thanks deoren)
Wed, 19 Nov 2014 14:47:49 +0100 Kim Alvefur mod_tls: Keep ssl config around and attach them to sessions
Tue, 21 Oct 2014 12:49:03 +0200 Kim Alvefur mod_legacyauth, mod_saslauth, mod_tls: Pass require_encryption as default option to s2s_require_encryption so the later overrides the former
Fri, 04 Jul 2014 22:52:34 +0200 Kim Alvefur mod_lastactivity, mod_legacyauth, mod_presence, mod_saslauth, mod_tls: Use the newer stanza:get_child APIs and optimize away some table lookups
Thu, 03 Jul 2014 15:35:45 +0200 Kim Alvefur mod_tls: Simplify and use new ssl config merging in certmanager
Sat, 18 Jan 2014 18:46:12 +0000 Matthew Wild Merge 0.9->0.10
Wed, 15 Jan 2014 22:47:50 +0100 Kim Alvefur mod_tls: Let s2s_secure_auth override s2s_require_encryption and warn if they differ
Wed, 15 Jan 2014 21:57:15 +0100 Kim Alvefur mod_tls: Rename variables to be less confusing
Sun, 12 Jan 2014 06:19:37 -0500 Matthew Wild Merge 0.9->0.10
Sun, 12 Jan 2014 06:16:49 -0500 Matthew Wild mod_tls: Log error when TLS initialization fails 0.9.3
Fri, 09 Aug 2013 17:48:21 +0200 Florian Zeitz Remove all trailing whitespace
Sun, 16 Jun 2013 15:01:31 +0200 Kim Alvefur mod_tls: Remove debug statement
Thu, 13 Jun 2013 17:47:45 +0200 Kim Alvefur mod_tls: Refactor to allow separate SSL configuration for c2s and s2s connections
Sat, 23 Mar 2013 02:35:50 +0100 Kim Alvefur mod_tls: More use of config sections removed
Sat, 23 Mar 2013 01:27:16 +0100 Kim Alvefur mod_announce, mod_auth_anonymous, mod_c2s, mod_c2s, mod_component, mod_iq, mod_message, mod_presence, mod_tls: Access prosody.{hosts,bare_sessions,full_sessions} instead of the old globals
Wed, 18 Jan 2012 15:07:26 +0000 Matthew Wild mod_tls: Fix log statement (thanks Zash)
Wed, 06 Apr 2011 14:45:44 +0100 Matthew Wild mod_tls: Fix for components to more reliably inherit SSL settings from their parenthost (thanks Link Mauve)
Tue, 22 Feb 2011 18:29:35 +0000 Matthew Wild mod_tls: Drop 'TLS negotiation started for ...' to debug level from info
Wed, 10 Nov 2010 02:26:18 +0500 Waqas Hussain mod_tls: Let hosts without an 'ssl' option inherit it from their parent hosts.
Mon, 08 Nov 2010 03:12:30 +0000 Matthew Wild mod_tls: Pass the hostname rather than host session to certmanager.create_context() (thanks darkrain)
Sat, 06 Nov 2010 18:28:15 +0000 Matthew Wild certmanager, hostmanager, mod_tls: Move responsibility for creating per-host SSL contexts to mod_tls, meaning reloading certs is now as trivial as reloading mod_tls
Thu, 22 Jul 2010 13:13:28 +0100 Matthew Wild mod_tls: Remove extraneous flag to starttls() for s2sout connecections
less more (0) -100 -60 tip