Mercurial > prosody-hg
view util/random.lua @ 14216:2ec517d8d43e
net.unbound: Enable DNSSEC by default with option for turning off
You know what they say about opt-in security.
Enabling DNSSEC in libunbound without a way to turn it off would likely
be a problem for those whose DNS resolvers do not support, or outright
block DNSSEC. The merge algorithm already in place here doesn't have a
way to unset something, so instead a simpler boolean setting is
introduced, similar to some existing ones like use_ipv6/4 and use_dane.
| author | Kim Alvefur <zash@zash.se> |
|---|---|
| date | Sun, 07 Jun 2026 20:32:55 +0200 |
| parents | d10957394a3c |
| children |
line wrap: on
line source
-- Prosody IM -- Copyright (C) 2008-2014 Matthew Wild -- Copyright (C) 2008-2014 Waqas Hussain -- -- This project is MIT/X11 licensed. Please see the -- COPYING file in the source package for more information. -- local ok, crand = pcall(require, "prosody.util.crand"); if ok and pcall(crand.bytes, 1) then return crand; end local urandom, urandom_err = io.open("/dev/urandom", "r"); local function bytes(n) local data, err = urandom:read(n); if not data then if err then error("Unable to retrieve data from secure random number generator (/dev/urandom): "..tostring(err)); else error("Secure random number generator (/dev/urandom) returned an end-of-file condition"); end end return data; end if not urandom then function bytes() error("Unable to obtain a secure random number generator, please see https://prosody.im/doc/random ("..urandom_err..")"); end end return { bytes = bytes; _source = "/dev/urandom"; };
