prosody.git
9 years agonet.dns: Avoid duplicate cache entries
Florian Zeitz [Sun, 5 Oct 2014 12:28:40 +0000 (14:28 +0200)]
net.dns: Avoid duplicate cache entries

9 years agomod_admin_adhoc: Add required to field in user deletion form too
Kim Alvefur [Mon, 29 Sep 2014 09:18:04 +0000 (11:18 +0200)]
mod_admin_adhoc: Add required to field in user deletion form too

9 years agomod_admin_adhoc: Mark 'accountjids' field as required in 'end user sessions' command...
Kim Alvefur [Mon, 29 Sep 2014 09:02:06 +0000 (11:02 +0200)]
mod_admin_adhoc: Mark 'accountjids' field as required in 'end user sessions' command (thanks Lloyd)

9 years agocore.stanza_router: Stricter validation of stanzas
Kim Alvefur [Tue, 9 Sep 2014 12:42:10 +0000 (14:42 +0200)]
core.stanza_router: Stricter validation of stanzas

9 years agonet.http.parser: Support status code 101 and allow handling of the received data...
Matthew Wild [Wed, 3 Sep 2014 17:49:41 +0000 (18:49 +0100)]
net.http.parser: Support status code 101 and allow handling of the received data by someone else

9 years agonet.server_select: 'listener'->'listeners' (fixes undefined global access)
Matthew Wild [Tue, 2 Sep 2014 16:23:44 +0000 (17:23 +0100)]
net.server_select: 'listener'->'listeners' (fixes undefined global access)

9 years agonet.http, net.http.server, mod_c2s, mod_s2s, mod_component, mod_admin_telnet, mod_net...
Matthew Wild [Fri, 29 Aug 2014 10:54:34 +0000 (11:54 +0100)]
net.http, net.http.server, mod_c2s, mod_s2s, mod_component, mod_admin_telnet, mod_net_multiplex: Add ondetach to release connection from 'sessions' table (or equivalent)

9 years agonet.server_{select,event}: Add 'ondetach' callback for listener objects, to notify...
Matthew Wild [Fri, 29 Aug 2014 10:39:56 +0000 (11:39 +0100)]
net.server_{select,event}: Add 'ondetach' callback for listener objects, to notify them when another listener is being assigned to a connection

9 years agomod_s2s: Close offending s2s streams missing an 'id' attribute with a stream error...
Kim Alvefur [Tue, 2 Sep 2014 15:24:25 +0000 (17:24 +0200)]
mod_s2s: Close offending s2s streams missing an 'id' attribute with a stream error instead of throwing an unhandled error

9 years agoTagging 0.9.5
Matthew Wild [Thu, 28 Aug 2014 11:22:39 +0000 (12:22 +0100)]
Tagging 0.9.5

9 years agoutil.filters: Ignore filters being added twice (fixes issues on removal)
Matthew Wild [Thu, 28 Aug 2014 08:20:33 +0000 (09:20 +0100)]
util.filters: Ignore filters being added twice (fixes issues on removal)

9 years agomod_privacy: Fix to correctly sort privacy list rules by order (thanks Flow)
Matthew Wild [Thu, 28 Aug 2014 08:17:07 +0000 (09:17 +0100)]
mod_privacy: Fix to correctly sort privacy list rules by order (thanks Flow)

9 years agomod_c2s, mod_s2s: Log received invalid stream headers
Matthew Wild [Sat, 23 Aug 2014 08:29:17 +0000 (09:29 +0100)]
mod_c2s, mod_s2s: Log received invalid stream headers

9 years agoutil.xmppstream: When error is 'no-stream', pass the received tagname to the error...
Matthew Wild [Sat, 23 Aug 2014 08:22:05 +0000 (09:22 +0100)]
util.xmppstream: When error is 'no-stream', pass the received tagname to the error handler

9 years agomod_s2s: Reset stream ID when resetting stream [compliance]
Kim Alvefur [Wed, 27 Aug 2014 11:20:08 +0000 (13:20 +0200)]
mod_s2s: Reset stream ID when resetting stream [compliance]

9 years agomodulemanager: Reduce warning to debug level message about modules already being...
Kim Alvefur [Wed, 27 Aug 2014 08:46:22 +0000 (10:46 +0200)]
modulemanager: Reduce warning to debug level message about modules already being loaded, it's probably just module:depends()

9 years agonet.http.server: Comment out a log message
Kim Alvefur [Wed, 27 Aug 2014 08:44:45 +0000 (10:44 +0200)]
net.http.server: Comment out a log message

9 years agomod_s2s: Mark stream as opened earlier for outgoing connections, fixes double stream...
Kim Alvefur [Tue, 26 Aug 2014 19:50:08 +0000 (21:50 +0200)]
mod_s2s: Mark stream as opened earlier for outgoing connections, fixes double stream headers on policy failures

9 years agomod_compression: Handle compression setup errors by logging a warning about it (fixes...
Kim Alvefur [Tue, 26 Aug 2014 10:19:27 +0000 (12:19 +0200)]
mod_compression: Handle compression setup errors by logging a warning about it (fixes #408)

9 years agomod_posix: Make sure that 'pidfile' is a string
Kim Alvefur [Tue, 26 Aug 2014 10:02:41 +0000 (12:02 +0200)]
mod_posix: Make sure that 'pidfile' is a string

9 years agoprosodyctl: Verify that 'pidfile' is a string, show friendly error otherwise
Kim Alvefur [Tue, 26 Aug 2014 10:00:51 +0000 (12:00 +0200)]
prosodyctl: Verify that 'pidfile' is a string, show friendly error otherwise

9 years agoprosodyctl: Remove nonsensical warning
Matthew Wild [Thu, 31 Jul 2014 05:59:12 +0000 (06:59 +0100)]
prosodyctl: Remove nonsensical warning

9 years agoprosodyctl: Improve JID splitting and normalization for adduser/passwd/deluser
Matthew Wild [Thu, 31 Jul 2014 05:58:15 +0000 (06:58 +0100)]
prosodyctl: Improve JID splitting and normalization for adduser/passwd/deluser

9 years agoconfigmanager: nameprep VirtualHost and Component names
Matthew Wild [Thu, 31 Jul 2014 05:56:21 +0000 (06:56 +0100)]
configmanager: nameprep VirtualHost and Component names

9 years agonet.server_select/event: Switch sender mode to *a when reading, to make sure we get...
Matthew Wild [Fri, 25 Jul 2014 12:53:39 +0000 (13:53 +0100)]
net.server_select/event: Switch sender mode to *a when reading, to make sure we get all available data

9 years agomod_admin_telnet: Fix dns:(add,set)nameservers()
Kim Alvefur [Fri, 25 Jul 2014 11:59:17 +0000 (13:59 +0200)]
mod_admin_telnet: Fix dns:(add,set)nameservers()

9 years agonet.dns: Remove unused obsolete code
Matthew Wild [Fri, 25 Jul 2014 11:54:31 +0000 (12:54 +0100)]
net.dns: Remove unused obsolete code

9 years agonet.dns: Ensure all pending requests get notified of a timeout when looking up a...
Matthew Wild [Fri, 25 Jul 2014 11:08:07 +0000 (12:08 +0100)]
net.dns: Ensure all pending requests get notified of a timeout when looking up a record (fix for d122420542fb)

9 years agomod_register: get_child_text! (thanks Lloyd)
Kim Alvefur [Thu, 3 Jul 2014 15:53:24 +0000 (17:53 +0200)]
mod_register: get_child_text! (thanks Lloyd)

9 years agonet.dns: Fix duplicated cache insertions by limiting outstanding queries per name...
Kim Alvefur [Mon, 30 Jun 2014 10:45:53 +0000 (12:45 +0200)]
net.dns: Fix duplicated cache insertions by limiting outstanding queries per name to one

9 years agonet.adns: Add missing local declaration
Kim Alvefur [Wed, 25 Jun 2014 13:33:49 +0000 (15:33 +0200)]
net.adns: Add missing local declaration

9 years agotools/ejabberd2prosody.lua: Fix JID building, node-less jids became @hostname in...
Kim Alvefur [Tue, 17 Jun 2014 09:01:51 +0000 (11:01 +0200)]
tools/ejabberd2prosody.lua: Fix JID building, node-less jids became @hostname in some cases

10 years agomod_c2s: Fix traceback if c2s stream sent to component
Kim Alvefur [Sat, 10 May 2014 00:12:51 +0000 (02:12 +0200)]
mod_c2s: Fix traceback if c2s stream sent to component

10 years agoconfigmanager: Delay importing LuaFileSystem until needed by an Include line
Kim Alvefur [Fri, 9 May 2014 17:59:49 +0000 (19:59 +0200)]
configmanager: Delay importing LuaFileSystem until needed by an Include line

10 years agoutil.pposix: Fix error reporting from really old Linux fallocate() that did not use...
Kim Alvefur [Fri, 25 Apr 2014 00:41:55 +0000 (02:41 +0200)]
util.pposix: Fix error reporting from really old Linux fallocate() that did not use errno for some reason (thanks pro)

10 years agoutil.pposix: Fix error reporting from posix_fallocate, it doesn't use errno (thanks...
Kim Alvefur [Thu, 24 Apr 2014 22:36:01 +0000 (00:36 +0200)]
util.pposix: Fix error reporting from posix_fallocate, it doesn't use errno (thanks pro)

10 years agoutil.dataforms: Add support for XEP-0221: Data Forms Media Element
Kim Alvefur [Tue, 22 Apr 2014 21:36:26 +0000 (23:36 +0200)]
util.dataforms: Add support for XEP-0221: Data Forms Media Element

10 years agotools/jabberd14sql2prosody: Fix package.path (thanks daurnimator)
Kim Alvefur [Tue, 22 Apr 2014 21:14:53 +0000 (23:14 +0200)]
tools/jabberd14sql2prosody: Fix package.path (thanks daurnimator)

10 years agoprosody: Check dependencies later in the startup sequence
Kim Alvefur [Wed, 9 Apr 2014 18:46:39 +0000 (20:46 +0200)]
prosody: Check dependencies later in the startup sequence

10 years agoutil.dependencies: Check for Lua 5.1. We don't currently support any other versions...
Waqas Hussain [Wed, 9 Apr 2014 18:01:02 +0000 (14:01 -0400)]
util.dependencies: Check for Lua 5.1. We don't currently support any other versions. LuaJIT identifies as 5.1.

10 years agomod_admin_telnet: muc:*: Fix nil index error when a room JID is passed with a non...
Matthew Wild [Sat, 5 Apr 2014 14:05:40 +0000 (15:05 +0100)]
mod_admin_telnet: muc:*: Fix nil index error when a room JID is passed with a non-existent host

10 years agoutil.xmppstream: Also disable CharacterData merging after stream restarts
Matthew Wild [Wed, 2 Apr 2014 13:31:19 +0000 (14:31 +0100)]
util.xmppstream: Also disable CharacterData merging after stream restarts

10 years agoutil.xmppstream: Disable LuaExpat's buffering (if possible)
Matthew Wild [Wed, 2 Apr 2014 10:05:41 +0000 (11:05 +0100)]
util.xmppstream: Disable LuaExpat's buffering (if possible)

10 years agoTagging 0.9.4
Matthew Wild [Tue, 1 Apr 2014 15:50:15 +0000 (16:50 +0100)]
Tagging 0.9.4

10 years agoMerge
Matthew Wild [Tue, 1 Apr 2014 15:03:21 +0000 (16:03 +0100)]
Merge

10 years agoMUC: Fixed traceback when a JID not in a room requested a role change for an occupant.
Waqas Hussain [Tue, 1 Apr 2014 14:02:58 +0000 (10:02 -0400)]
MUC: Fixed traceback when a JID not in a room requested a role change for an occupant.

10 years agoMerge
Matthew Wild [Tue, 1 Apr 2014 14:02:36 +0000 (15:02 +0100)]
Merge

10 years agonet.server_{select,event}: Add compat code for supporting the same client port API...
Kim Alvefur [Tue, 1 Apr 2014 13:26:40 +0000 (15:26 +0200)]
net.server_{select,event}: Add compat code for supporting the same client port API on connections

10 years agoBacked out changeset a5b5bce71a11
Kim Alvefur [Mon, 31 Mar 2014 17:38:06 +0000 (19:38 +0200)]
Backed out changeset a5b5bce71a11

10 years agoMakefile: Change sed regex to be compatible with FreeBSD's odd sed, and change /...
Matthew Wild [Sun, 30 Mar 2014 08:16:27 +0000 (09:16 +0100)]
Makefile: Change sed regex to be compatible with FreeBSD's odd sed, and change / to | to allow paths to be used in RUNWITH (thanks Ben)

10 years agoutil.dependencies: Log error when LuaExpat is not capable of enforcing stanza size...
Matthew Wild [Sun, 30 Mar 2014 08:15:28 +0000 (09:15 +0100)]
util.dependencies: Log error when LuaExpat is not capable of enforcing stanza size limits

10 years agoutil.xmppstream: Implement stanza size limiting, default limit 10MB
Matthew Wild [Sun, 30 Mar 2014 08:14:39 +0000 (09:14 +0100)]
util.xmppstream: Implement stanza size limiting, default limit 10MB

10 years agoportmanager: Make maximum read size configurable, and default to 4KB
Matthew Wild [Sun, 30 Mar 2014 07:44:55 +0000 (08:44 +0100)]
portmanager: Make maximum read size configurable, and default to 4KB

10 years agonet.server_event: Rename conn:port() -> conn:clientport() to match server_select
Kim Alvefur [Thu, 27 Mar 2014 22:02:52 +0000 (23:02 +0100)]
net.server_event: Rename conn:port() -> conn:clientport() to match server_select

10 years agoprosodyctl: Show real error if certificate config file can't be opened
Kim Alvefur [Sat, 22 Mar 2014 11:02:11 +0000 (12:02 +0100)]
prosodyctl: Show real error if certificate config file can't be opened

10 years agomodulemanager: Load mod_saslauth on components by default
Kim Alvefur [Sat, 22 Mar 2014 11:42:01 +0000 (12:42 +0100)]
modulemanager: Load mod_saslauth on components by default

10 years agomod_saslauth: Only do c2s SASL on normal VirtualHosts
Kim Alvefur [Sat, 22 Mar 2014 11:41:38 +0000 (12:41 +0100)]
mod_saslauth: Only do c2s SASL on normal VirtualHosts

10 years agomod_http_files: Strip path separator from end of paths, was broken on Windows (thanks...
Kim Alvefur [Sun, 9 Mar 2014 21:16:44 +0000 (22:16 +0100)]
mod_http_files: Strip path separator from end of paths, was broken on Windows (thanks Junne)

10 years agoutil.pluginloader: Always use path separator from package.config (thanks Junne)
Kim Alvefur [Sun, 9 Mar 2014 21:15:40 +0000 (22:15 +0100)]
util.pluginloader: Always use path separator from package.config (thanks Junne)

10 years agomod_http: Fix http_external_url setting without an explicit port
Kim Alvefur [Wed, 26 Feb 2014 21:19:58 +0000 (22:19 +0100)]
mod_http: Fix http_external_url setting without an explicit port

10 years agomod_http: Use hostname from the correct context (thanks gryffus)
Kim Alvefur [Thu, 20 Feb 2014 18:08:55 +0000 (19:08 +0100)]
mod_http: Use hostname from the correct context (thanks gryffus)

10 years agotools/ejabberd2prosody: Don't throw an error if XML CDATA is null ([] in Erlang,...
Waqas Hussain [Tue, 18 Feb 2014 21:03:13 +0000 (16:03 -0500)]
tools/ejabberd2prosody: Don't throw an error if XML CDATA is null ([] in Erlang, instead of a string or being missing).

10 years agomod_compression: Only allow compression on authenticated streams
Kim Alvefur [Tue, 18 Feb 2014 19:03:12 +0000 (20:03 +0100)]
mod_compression: Only allow compression on authenticated streams

10 years agomod_auth_anonymous: Fixed a traceback in listing all users (issue#396).
Waqas Hussain [Mon, 17 Feb 2014 21:00:41 +0000 (16:00 -0500)]
mod_auth_anonymous: Fixed a traceback in listing all users (issue#396).

10 years agomod_admin_telnet: Prep jids for user:create() etc.
Kim Alvefur [Sun, 9 Feb 2014 14:17:01 +0000 (15:17 +0100)]
mod_admin_telnet: Prep jids for user:create() etc.

10 years agomod_s2s: Log a warning if no local addresses are found, as this breaks s2sout
Kim Alvefur [Sun, 9 Feb 2014 14:13:46 +0000 (15:13 +0100)]
mod_s2s: Log a warning if no local addresses are found, as this breaks s2sout

10 years agomod_motd: Strip indentation only, leave multiple newlines
Kim Alvefur [Thu, 6 Feb 2014 09:44:21 +0000 (10:44 +0100)]
mod_motd: Strip indentation only, leave multiple newlines

10 years agotools/ejabberd2prosody: Handle new room member format.
Kim Alvefur [Mon, 27 Jan 2014 15:47:54 +0000 (16:47 +0100)]
tools/ejabberd2prosody: Handle new room member format.

10 years agotools/ejabberd2prosody: Disable generating a config, as the format it generates is...
Waqas Hussain [Sat, 18 Jan 2014 22:26:02 +0000 (17:26 -0500)]
tools/ejabberd2prosody: Disable generating a config, as the format it generates is completely out of date.

10 years agotools/ejabberd2prosody: ?xmlelement? can be ?xmlel? in newer ejabberd (thanks cr).
Waqas Hussain [Sat, 18 Jan 2014 22:24:10 +0000 (17:24 -0500)]
tools/ejabberd2prosody: ?xmlelement? can be ?xmlel? in newer ejabberd (thanks cr).

10 years agoMUC: Fire muc-room-destroyed event when the last participant leaves a non-persistent...
Kim Alvefur [Sat, 18 Jan 2014 19:14:05 +0000 (20:14 +0100)]
MUC: Fire muc-room-destroyed event when the last participant leaves a non-persistent room

10 years agotools/ejabberd2prosody: Add support for importing MUC rooms.
Waqas Hussain [Sat, 18 Jan 2014 15:37:12 +0000 (10:37 -0500)]
tools/ejabberd2prosody: Add support for importing MUC rooms.

10 years agotools/ejabberdsql2prosody: Skip invalid XML in data, and print out errors.
Waqas Hussain [Thu, 16 Jan 2014 19:03:27 +0000 (14:03 -0500)]
tools/ejabberdsql2prosody: Skip invalid XML in data, and print out errors.

10 years agoadditional fix for erlparse loading in ejabberd2prosody.lua
Vadim Misbakh-Soloviov [Fri, 14 Jun 2013 08:43:35 +0000 (15:43 +0700)]
additional fix for erlparse loading in ejabberd2prosody.lua

10 years agopackage{,c}path fixes for migration tools
Vadim Misbakh-Soloviov [Fri, 14 Jun 2013 08:15:05 +0000 (15:15 +0700)]
package{,c}path fixes for migration tools

10 years agomod_tls: Let s2s_secure_auth override s2s_require_encryption and warn if they differ
Kim Alvefur [Wed, 15 Jan 2014 21:47:50 +0000 (22:47 +0100)]
mod_tls: Let s2s_secure_auth override s2s_require_encryption and warn if they differ

10 years agomod_tls: Rename variables to be less confusing
Kim Alvefur [Wed, 15 Jan 2014 20:57:15 +0000 (21:57 +0100)]
mod_tls: Rename variables to be less confusing

10 years agoTagging 0.9.3
Matthew Wild [Sun, 12 Jan 2014 11:17:40 +0000 (06:17 -0500)]
Tagging 0.9.3

10 years agomod_tls: Log error when TLS initialization fails
Matthew Wild [Sun, 12 Jan 2014 11:16:49 +0000 (06:16 -0500)]
mod_tls: Log error when TLS initialization fails

10 years agomod_s2s: Include IP in log messages, if host is unavailable
Florian Zeitz [Sun, 5 Jan 2014 21:21:50 +0000 (22:21 +0100)]
mod_s2s: Include IP in log messages, if host is unavailable

10 years agotools/migration/migrator/prosody_files: Fix undefined global access of ?error?, print...
Waqas Hussain [Fri, 3 Jan 2014 20:52:52 +0000 (15:52 -0500)]
tools/migration/migrator/prosody_files: Fix undefined global access of ?error?, print the actual error message and correct file path in the error message when we fail to load a file, skip broken files instead of failing migration.

10 years agomod_component: Enable TCP keepalives on component streams
Kim Alvefur [Wed, 18 Dec 2013 17:35:35 +0000 (18:35 +0100)]
mod_component: Enable TCP keepalives on component streams

10 years agomod_component: Decrease priority of component auth hook
Kim Alvefur [Wed, 18 Dec 2013 17:34:22 +0000 (18:34 +0100)]
mod_component: Decrease priority of component auth hook

10 years agonet.server_select: Don't remove the socket from sendlist when we might have data...
Matthew Wild [Mon, 16 Dec 2013 23:31:43 +0000 (23:31 +0000)]
net.server_select: Don't remove the socket from sendlist when we might have data in the buffer (we'll now let sendbuffer() take care of that) (thanks daurnimator)

10 years agonet.http: assert() for socket creation success so it doesn't silently fail (thanks...
Matthew Wild [Mon, 16 Dec 2013 23:24:16 +0000 (23:24 +0000)]
net.http: assert() for socket creation success so it doesn't silently fail (thanks daurnimator)

10 years agoutil.jid: Strip trailing '.' when normalizing hostnames
Matthew Wild [Mon, 16 Dec 2013 02:03:35 +0000 (02:03 +0000)]
util.jid: Strip trailing '.' when normalizing hostnames

10 years agomod_muc: Remove extra parenthesis (thanks janhouse)
Kim Alvefur [Sat, 14 Dec 2013 16:25:17 +0000 (17:25 +0100)]
mod_muc: Remove extra parenthesis (thanks janhouse)

10 years agomod_muc: Allow admins to always bypass restrict_room_creation (thanks Chris B)
Matthew Wild [Fri, 13 Dec 2013 12:52:03 +0000 (12:52 +0000)]
mod_muc: Allow admins to always bypass restrict_room_creation (thanks Chris B)

10 years agoprosody: Store the config file name so the same file can be used when reloading
Kim Alvefur [Fri, 13 Dec 2013 09:25:40 +0000 (10:25 +0100)]
prosody: Store the config file name so the same file can be used when reloading

10 years agoTagging 0.9.2 (again)
Matthew Wild [Wed, 4 Dec 2013 15:06:48 +0000 (15:06 +0000)]
Tagging 0.9.2 (again)

10 years agoMakefile, configure: Add option for disabling generation of example certificates
Kim Alvefur [Sat, 30 Nov 2013 21:26:20 +0000 (22:26 +0100)]
Makefile, configure: Add option for disabling generation of example certificates

10 years agoTagging 0.9.2
Matthew Wild [Fri, 29 Nov 2013 20:10:13 +0000 (20:10 +0000)]
Tagging 0.9.2

10 years agoutil.pposix: Verify that file handle is open
Kim Alvefur [Thu, 28 Nov 2013 15:12:40 +0000 (16:12 +0100)]
util.pposix: Verify that file handle is open

10 years agoMakefile, certs: Generate example certificates on build, remove the old static one
Kim Alvefur [Fri, 22 Nov 2013 14:27:21 +0000 (15:27 +0100)]
Makefile, certs: Generate example certificates on build, remove the old static one

10 years agocertmanager: Further cipher string tweaking. Re-enable ciphers required for DSA and...
Matthew Wild [Thu, 21 Nov 2013 02:11:09 +0000 (02:11 +0000)]
certmanager: Further cipher string tweaking. Re-enable ciphers required for DSA and ECDH certs/keys.

10 years agoBack out 1b0ac7950129, as SSLv3 appears to still be in moderate use on the network...
Matthew Wild [Tue, 12 Nov 2013 02:13:01 +0000 (02:13 +0000)]
Back out 1b0ac7950129, as SSLv3 appears to still be in moderate use on the network. Also, although obsolete, SSLv3 isn't documented to have any weaknesses that TLS 1.0 (the most common version used today) doesn't also have. Get your act together clients!

10 years agocertmanager: Update default cipher string to prefer forward-secrecy over cipher stren...
Matthew Wild [Sun, 10 Nov 2013 18:46:48 +0000 (18:46 +0000)]
certmanager: Update default cipher string to prefer forward-secrecy over cipher strength and to disable triple-DES (weaker and much slower than AES)

10 years agoutil.set: Remove unused variable
Matthew Wild [Sun, 10 Nov 2013 16:43:10 +0000 (16:43 +0000)]
util.set: Remove unused variable

10 years agocertmanager: Fix order of options, so that the dynamic option is at the end of the...
Matthew Wild [Sat, 9 Nov 2013 17:54:21 +0000 (17:54 +0000)]
certmanager: Fix order of options, so that the dynamic option is at the end of the array

10 years agocertmanager: Default to using the server's cipher preference order by default, as...
Matthew Wild [Sat, 9 Nov 2013 17:50:19 +0000 (17:50 +0000)]
certmanager: Default to using the server's cipher preference order by default, as clients have been shown to commonly select weak and insecure ciphers even when they support stronger ones