Mercurial > prosody-modules
view mod_watchuntrusted/README.md @ 6519:01d8bfbfc435
mod_pubsub_serverinfo: Fix check for local domain
The module was checking whether a host exists, but this may be misleading if
our host is loaded before the host that is being checked.
This change makes it check the config. This will provide a false positive in
the rare case that the host is defined but not activated/enabled. But we don't
have an API currently for "is this host configured and enabled?"
| author | Matthew Wild <mwild1@gmail.com> |
|---|---|
| date | Tue, 21 Apr 2026 19:54:19 +0100 |
| parents | 996c038dfca3 |
| children |
line wrap: on
line source
--- labels: - 'Stage-Beta' summary: | Warn admins about outgoing s2s connections that are refused due to invalid or untrusted certificates ... Introduction ============ Similar to mod\_watchregistrations, this module warns admins when an s2s connection fails due for encryption or trust reasons. The certificate shows the SHA1 hash, so it can easily be used together with mod\_s2s\_auth\_fingerprint. Configuration ============= modules_enabled = { -- other modules -- "watchuntrusted", } untrusted_fail_watchers = { "admin@example.lit" } untrusted_fail_notification = "Establishing a secure connection from $from_host to $to_host failed. Certificate hash: $sha1. $errors" Option Default Description ------------------------------- --------------------------------------------------------------------------------------------------------------- -------------------------------------------------------------------------------------- untrusted\_fail\_watchers All admins The users to send the message to untrusted\_fail\_notification "Establishing a secure connection from \$from\_host to \$to\_host failed. Certificate hash: \$sha1. \$errors" The message to send, \$from\_host, \$to\_host, \$sha1 and \$errors are replaced untrusted\_message\_type `"chat"` Which kind of message to send. `"normal"` or `"headline"` are other sensible options untrusted\_ignore\_domains Empty The domains that this module should not warn about Compatibility ============= -------- ------- \>= 0.12 Works -------- -------
