aboutsummaryrefslogtreecommitdiffstats
diff options
context:
space:
mode:
authorKim Alvefur <zash@zash.se>2013-09-03 13:13:31 +0200
committerKim Alvefur <zash@zash.se>2013-09-03 13:13:31 +0200
commit62e1985a37122c772085a1110ee594a5621cb9e1 (patch)
tree65bba637145ae1096e20575dfa0ff8ce66e38b11
parentc35dad055c7d0e8f5fb76794ff756671937c38e5 (diff)
downloadprosody-62e1985a37122c772085a1110ee594a5621cb9e1.tar.gz
prosody-62e1985a37122c772085a1110ee594a5621cb9e1.zip
certmanager: Allow for specifying the dhparam option as a path to a file instead of a callback
-rw-r--r--core/certmanager.lua11
1 files changed, 11 insertions, 0 deletions
diff --git a/core/certmanager.lua b/core/certmanager.lua
index 5aec22b3..c1ce468d 100644
--- a/core/certmanager.lua
+++ b/core/certmanager.lua
@@ -72,6 +72,17 @@ function create_context(host, mode, user_ssl_config)
dhparam = user_ssl_config.dhparam;
};
+ -- LuaSec expects dhparam to be a callback that takes two arguments.
+ -- We ignore those because it is mostly used for having a separate
+ -- set of params for EXPORT ciphers, which we don't have by default.
+ if type(user_ssl_config.dhparam) == "string" then
+ local f, err = io_open(resolve_path(user_ssl_config.dhparam));
+ if not f then return nil, "Could not open DH parameters: "..err end
+ local dhparam = f:read("*a");
+ f:close();
+ user_ssl_config.dhparam = function() return dhparam; end
+ end
+
local ctx, err = ssl_newcontext(ssl_config);
-- COMPAT: LuaSec 0.4.1 ignores the cipher list from the config, so we have to take