Commit message (Collapse) | Author | Age | Files | Lines | |
---|---|---|---|---|---|
* | mod_c2s, mod_s2s: Log cipher and encryption info in a more compact and ↵ | Kim Alvefur | 2013-08-14 | 1 | -2/+1 |
| | | | | (hopefully) less confusing way | ||||
* | mod_s2s: Captitalize log messages that begin with a stream direction | Kim Alvefur | 2013-08-14 | 1 | -2/+2 |
| | |||||
* | mod_s2s: Lower "Beginning new connection attempt" message from info to debug ↵ | Kim Alvefur | 2013-08-14 | 1 | -1/+1 |
| | | | | level | ||||
* | mod_s2s/s2sout.lib: Improve error message logged at 'info' level when ↵ | Matthew Wild | 2013-08-14 | 1 | -1/+1 |
| | | | | failing to connect to a host. Now 'Failed in all attempts to connect to XYZ' | ||||
* | Remove all trailing whitespace | Florian Zeitz | 2013-08-09 | 2 | -37/+37 |
| | |||||
* | Merge 0.9->trunk | Kim Alvefur | 2013-08-06 | 1 | -2/+3 |
|\ | |||||
| * | mod_admin_telnet, mod_s2s: Fix reporting of certificate chain validation details | Kim Alvefur | 2013-08-06 | 1 | -1/+1 |
| | | |||||
| * | mod_s2s: Improve policy check | Kim Alvefur | 2013-08-05 | 1 | -1/+1 |
| | | |||||
| * | mod_s2s: Log certificate identity validation result | Kim Alvefur | 2013-08-04 | 1 | -0/+1 |
| | | |||||
* | | mod_c2s, mod_s2s: Log a message that stream encryption has been enabled with ↵ | Kim Alvefur | 2013-08-02 | 1 | -4/+7 |
| | | | | | | | | some details | ||||
* | | mod_s2s: Add missing global hook for read-timeout | Kim Alvefur | 2013-06-26 | 1 | -0/+2 |
| | | |||||
* | | Merge 0.9->trunk | Matthew Wild | 2013-06-18 | 1 | -21/+12 |
|\| | |||||
| * | mod_s2s/s2sout.lib: Remove unused variables and imports | Matthew Wild | 2013-06-18 | 1 | -6/+2 |
| | | |||||
| * | mod_s2s/s2sout.lib: Remove reference to undefined global | Matthew Wild | 2013-06-18 | 1 | -1/+0 |
| | | |||||
| * | mod_s2s/s2sout.lib: Use new util.net.local_addresses() to fetch local ↵ | Matthew Wild | 2013-06-18 | 1 | -12/+5 |
| | | | | | | | | interface addresses | ||||
| * | mod_s2s/s2sout.lib: Only attempt to create an IPv6 socket if LuaSocket ↵ | Matthew Wild | 2013-06-18 | 1 | -2/+5 |
| | | | | | | | | supports IPv6 | ||||
* | | mod_c2s, mod_s2s: Fire an event on read timeouts | Kim Alvefur | 2013-06-11 | 1 | -1/+6 |
| | | |||||
* | | mod_s2s: Set s2s_session.ip | Kim Alvefur | 2013-06-09 | 1 | -0/+1 |
| | | |||||
* | | mod_c2s, mod_c2s: Send a whitespace on read timeout, to prod TCP into ↵ | Kim Alvefur | 2013-05-30 | 1 | -0/+7 |
| | | | | | | | | detecting if the connection died | ||||
* | | mod_s2s: Remove unnecessary debug message | Matthew Wild | 2013-05-28 | 1 | -1/+0 |
|/ | |||||
* | mod_s2s: Fix interaction between s2s_secure_auth and s2s_require_encryption, ↵ | Matthew Wild | 2013-05-18 | 1 | -2/+2 |
| | | | | in particular ensure that when s2s_require_encryption is NOT set, do not require encryption on s2s_insecure_domains. | ||||
* | util.rfc{3484,6724}: Update to RFC 6724 | Florian Zeitz | 2013-04-30 | 1 | -3/+3 |
| | |||||
* | mod_s2s: Ensure that to/from on stream headers are always correct, fixes #338 | Matthew Wild | 2013-04-29 | 1 | -6/+7 |
| | |||||
* | mod_s2s: Obey tcp_keepalives option for s2s too, and make it individually ↵ | Matthew Wild | 2013-04-26 | 1 | -1/+2 |
| | | | | configurable through s2s_tcp_keepalives (thanks yeled) | ||||
* | mod_c2s, mod_s2s, net.http, net.http.server: Improve tracebacks (omit ↵ | Matthew Wild | 2013-04-22 | 1 | -1/+1 |
| | | | | traceback function), to make it clearer where an error occured | ||||
* | mod_s2s: Add missing space | Kim Alvefur | 2013-04-15 | 1 | -1/+1 |
| | |||||
* | mod_s2s: Adjust priority of route/remote hooks to negative values (like most ↵ | Kim Alvefur | 2013-04-08 | 1 | -2/+2 |
| | | | | other internal hooks) | ||||
* | mod_s2s: Add COMPAT cahin verification code for older LuaSec versions | Kim Alvefur | 2013-04-04 | 1 | -2/+11 |
| | |||||
* | mod_s2s: Close incoming s2s with stream error when secure and we don't trust ↵ | Matthew Wild | 2013-04-01 | 1 | -1/+5 |
| | | | | their certificate | ||||
* | mod_s2s: Prevent s2s to and from hosts we serve locally | Kim Alvefur | 2013-03-27 | 1 | -0/+12 |
| | |||||
* | mod_s2s: Prevent traceback when replying to incoming connection to a host we ↵ | Kim Alvefur | 2013-03-26 | 1 | -1/+1 |
| | | | | don't serve | ||||
* | mod_s2s: Reset secure flag on new connection attempt | Kim Alvefur | 2013-03-25 | 1 | -0/+4 |
| | |||||
* | mod_s2s: session.from_host does not allways exist on incoming connections, ↵ | Kim Alvefur | 2013-03-25 | 1 | -1/+1 |
| | | | | true and nil or "our hostname" does not evaluate to what we want here | ||||
* | mod_s2s: Keep the dns answer object around a while so plugins can look at it | Kim Alvefur | 2013-03-23 | 1 | -1/+1 |
| | |||||
* | mod_s2s: Fix variable usage in check_auth_policy (thanks Florob) | Matthew Wild | 2013-03-22 | 1 | -6/+7 |
| | |||||
* | mod_s2s: Remove unused variable | Matthew Wild | 2013-03-22 | 1 | -1/+0 |
| | |||||
* | mod_s2s: Add controls for certificate validation via the s2s_secure_auth ↵ | Matthew Wild | 2013-03-22 | 1 | -3/+32 |
| | | | | option. Plugins can now return false from handling s2s-check-certificate to prevent connection establishment (s2sin+s2sout) | ||||
* | s2smanager, mod_s2s, mod_dialback, mod_saslauth: Move ↵ | Matthew Wild | 2013-03-22 | 1 | -2/+74 |
| | | | | s2smanager.make_authenticated() to mod_s2s, and plugins now signal authentication via the s2s-authenticated event | ||||
* | mod_s2s, mod_saslauth, mod_compression: Refactor to have common code for ↵ | Kim Alvefur | 2013-03-16 | 2 | -13/+26 |
| | | | | opening streams | ||||
* | mod_s2s: Do not include xmlns:db declaration in stream header if ↵ | Matthew Wild | 2013-03-12 | 1 | -1/+2 |
| | | | | mod_dialback is not loaded | ||||
* | mod_s2s: Make sure host variable is reachable | Kim Alvefur | 2013-03-11 | 1 | -2/+1 |
| | |||||
* | mod_s2s: Fire s2s-check-certificate event after validating a certificate, to ↵ | Matthew Wild | 2013-03-10 | 1 | -0/+1 |
| | | | | allow plugins to override standard procedure | ||||
* | mod_s2s, mod_dialback: Rename s2s-authenticate-legacy event to ↵ | Matthew Wild | 2013-03-10 | 1 | -1/+1 |
| | | | | s2sout-authenticate-legacy for clarity. Also, hello! | ||||
* | mod_s2s: Don't try to close sessions that were destroyed before timeout | Kim Alvefur | 2013-01-24 | 1 | -0/+2 |
| | |||||
* | prosody, mod_c2s, mod_s2s: Move closing of c2s and s2s sessions to ↵ | Kim Alvefur | 2012-12-28 | 1 | -0/+9 |
| | | | | respective plugins | ||||
* | mod_s2s: Remove connection from sessions table as soon as we learn it is ↵ | Matthew Wild | 2012-12-28 | 1 | -1/+1 |
| | | | | disconnected. Fixes a connection/session leak. | ||||
* | mod_s2s: Detect TLS compression | Kim Alvefur | 2012-10-24 | 1 | -0/+8 |
| | |||||
* | mod_{admin_telnet,c2s,component,http,net_multiplex,s2s}: Use ↵ | Waqas Hussain | 2012-09-12 | 1 | -1/+1 |
| | | | | module:provides() instead of module:add_item(). | ||||
* | mod_s2s: Check that an SRV reply isn't empty. | Kim Alvefur | 2012-09-03 | 1 | -1/+1 |
| | |||||
* | mod_admin_adhoc, mod_admin_telnet, mod_bosh, mod_c2s, mod_component, ↵ | Kim Alvefur | 2012-07-26 | 1 | -1/+1 |
| | | | | mod_pep, mod_presence, mod_roster, mod_s2s: Import core_post_stanza from the global prosody table. |