X-Git-Url: https://git.enpas.org/?a=blobdiff_plain;f=plugins%2Fmod_tls.lua;h=c79227e1748bb673a278cb09d6a736afc6fafcab;hb=6a529b2e925a4bd641d5139af95d7cd36783b832;hp=8b96aa157922c7bf1f63613a0e000e3baf72851f;hpb=416b600dd4475c7862070514895eb9314789d5e2;p=prosody.git diff --git a/plugins/mod_tls.lua b/plugins/mod_tls.lua index 8b96aa15..c79227e1 100644 --- a/plugins/mod_tls.lua +++ b/plugins/mod_tls.lua @@ -6,6 +6,8 @@ -- COPYING file in the source package for more information. -- +local config = require "core.configmanager"; +local create_context = require "core.certmanager".create_context; local st = require "util.stanza"; local secure_auth_only = module:get_option("c2s_require_encryption") or module:get_option("require_encryption"); @@ -83,7 +85,23 @@ module:hook_stanza(xmlns_starttls, "proceed", function (session, stanza) module:log("debug", "Proceeding with TLS on s2sout..."); session:reset_stream(); local ssl_ctx = session.from_host and hosts[session.from_host].ssl_ctx or global_ssl_ctx; - session.conn:starttls(ssl_ctx, true); + session.conn:starttls(ssl_ctx); session.secure = false; return true; end); + +function module.load() + local global_ssl_config = config.get("*", "core", "ssl"); + local ssl_config = config.get(module.host, "core", "ssl"); + local base_host = module.host:match("%.(.*)"); + if ssl_config == global_ssl_config and hosts[base_host] then + ssl_config = config.get(base_host, "core", "ssl"); + end + host.ssl_ctx = create_context(host.host, "client", ssl_config); -- for outgoing connections + host.ssl_ctx_in = create_context(host.host, "server", ssl_config); -- for incoming connections +end + +function module.unload() + host.ssl_ctx = nil; + host.ssl_ctx_in = nil; +end