aboutsummaryrefslogtreecommitdiffstats
diff options
context:
space:
mode:
authorKim Alvefur <zash@zash.se>2013-08-05 20:47:38 +0200
committerKim Alvefur <zash@zash.se>2013-08-05 20:47:38 +0200
commit847d74e1c751d5d3d0bb8f9dfdfd6aa74c3a071a (patch)
tree6d2e180589faba849006a0d850bcb4d7de396664
parent0266ad8496143fba9c8f1b25e21e3f52575fa5c0 (diff)
downloadprosody-847d74e1c751d5d3d0bb8f9dfdfd6aa74c3a071a.tar.gz
prosody-847d74e1c751d5d3d0bb8f9dfdfd6aa74c3a071a.zip
mod_s2s: Improve policy check
-rw-r--r--plugins/mod_s2s/mod_s2s.lua2
1 files changed, 1 insertions, 1 deletions
diff --git a/plugins/mod_s2s/mod_s2s.lua b/plugins/mod_s2s/mod_s2s.lua
index ccf85012..95015526 100644
--- a/plugins/mod_s2s/mod_s2s.lua
+++ b/plugins/mod_s2s/mod_s2s.lua
@@ -642,7 +642,7 @@ function check_auth_policy(event)
must_secure = false;
end
- if must_secure and not session.cert_identity_status then
+ if must_secure and (session.cert_chain_status ~= "valid" or session.cert_identity_status ~= "valid") then
module:log("warn", "Forbidding insecure connection to/from %s", host);
if session.direction == "incoming" then
session:close({ condition = "not-authorized", text = "Your server's certificate is invalid, expired, or not trusted by "..session.to_host });