view mod_s2s_auth_samecert/README.md @ 6534:5aeefc2251d4

mod_firewall: Load a script completely or not at all Previously it was possible that some chains would load, but others would not. This can be surprising (that a "half-loaded" state is possible) and hard to debug. This change makes it so that if some chains don't compile, the whole script will be treated as not loaded.
author Matthew Wild <mwild1@gmail.com>
date Wed, 06 May 2026 16:15:38 +0100
parents 7bca4f5935d6
children
line wrap: on
line source

This module implements the [Same Certificate shortcut] described in [XEP-0344].
Meaning it authenticates server-to-server connections by looking for an already established connection that uses the exact same certificate, reusing
the earlier validation results and letting Prosody skip performing slower validation methods such as [POSH][mod_s2s_auth_posh] twice.

[Same Certificate shortcut]: https://xmpp.org/extensions/xep-0344.html#samecert