Mercurial > prosody-modules
view mod_disable_tls/mod_disable_tls.lua @ 4433:0e3f5f70a51d
mod_auth_ccert/README: Add certificate purpose conifg to example
Thanks debacle
By default Prosody validates all client certificates as if they were
server certificates, for historical reasons, from a time when you
couldn't get certificates with the client purpose.
| author | Kim Alvefur <zash@zash.se> |
|---|---|
| date | Sat, 06 Feb 2021 22:15:08 +0100 |
| parents | 25be5fde250f |
| children |
line wrap: on
line source
local disable_tls_ports = module:get_option_set("disable_tls_ports", {}); module:hook("stream-features", function (event) if disable_tls_ports:contains(event.origin.conn:serverport()) then module:log("error", "Disabling TLS for client on port %d", event.origin.conn:serverport()); event.origin.conn.starttls = false; end end, 1000);
