Manuel Kasper
f0436490b0
Enable SNI with OpenSSL 0.9.8f as well
2019-12-24 09:07:51 +01:00
Manuel Kasper
243664926f
Enable TLS SNI
2019-12-23 14:34:19 +01:00
Dmitry Podgorny
284e8f4421
tls/openssl: check return code
...
Check return code of SSL_CTX_set_default_verify_paths() and fail TLS on
an error. However, ignore the error when XMPP_CONN_FLAG_TRUST_TLS is
set.
2019-11-10 15:57:23 +02:00
Dmitry Podgorny
296df2fca9
tls/openssl: don't use deprecated function in 1.1.0+
...
SSLv23_client_method() was deprecated in OpenSSL 1.1.0. It is left as
macro to TLS_client_method.
2019-11-25 13:45:51 +00:00
François Revol
234bef4025
Haiku: C89
2019-11-17 14:28:26 +01:00
Dmitry Podgorny
18b67d6eaf
tls/openssl: add LibreSSL support
...
OpenSSL and LibreSSL versions are incompatible. Moreover, LibreSSL
always define OPENSSL_VERSION_NUMBER as 0x20000000L. Instead of checking
for LibreSSL everywhere explicitly, redefine OPENSSL_VERSION_NUMBER.
See similar issues with nginx project: https://trac.nginx.org/nginx/ticket/1605
2019-10-11 01:59:34 +03:00
Hoenig Mark (TT/EIS3-Lol)
5ee06776ee
tls/openssl: don't call SSL_shutdown() after a fatal error
...
According to SSL_shutdown(3), the function must not be called
if previous fatal error occurred.
2019-07-03 15:14:01 +02:00
Dmitry Podgorny
9cc9ea86bb
tls/openssl: log some info about certificate
...
Log subject name and issuer name from certificate after TLS connection
is established or fails to connect.
2018-11-06 10:53:46 +02:00
Dmitry Podgorny
7ede9c6d03
tls/openssl: suppress error in special case in tls_stop()
...
When peer closes connection instead of proper shutdown SSL_shutdown()
fails in bidirectional mode. Handle this case and suppress the error.
2018-02-18 12:03:11 +02:00
Dmitry Podgorny
d0644c5e95
tls/openssl: print errno on unrecoverable error
2017-08-23 09:23:51 +03:00
Dmitry Podgorny
8d2d59e914
tls/openssl: add OpenSSL-1.1.0 support ( #109 )
...
OpenSSL-1.1.0 marks cleanup functions as deprecated and changes
initialization function. It implements implicit de-initialization.
Reported by @zygmund2000.
2017-07-12 02:07:14 +03:00
Dmitry Podgorny
9269d6b0d5
conn: add flag XMPP_CONN_FLAG_TRUST_TLS
...
TLS modules accept invalid server's certificates when the flag is set.
2017-07-04 17:20:33 +03:00
Dmitry Podgorny
cc53012cfa
tls/openssl: enable cert verification for openssl older then 1.0.2
...
TODO: add flag to trust certificate even if verification fails.
2017-07-01 15:51:49 +03:00
Steffen Jaeckel
f226891520
fix openssl memory leaks
2017-06-29 16:54:41 +02:00
Alexander Krotov
92d006a41b
Disable hostname verification for pre-1.0.2 OpenSSL
2017-06-23 13:45:24 +03:00
Alexander Krotov
0741820711
Verify certificate hostname when using OpenSSL ( fixes #100 )
2017-06-23 03:00:26 +03:00
Alexander Krotov
c9ddc2b7ef
Make tls_new accept xmpp_conn_t
2017-06-23 02:59:05 +03:00
Alexander Krotov
f776b34d8c
Fix tls_openssl.c indentation
2017-06-22 19:44:41 +03:00
Alexander Krotov
f47609c1f0
Disable insecure SSL/TLS versions
2017-06-20 22:44:39 +03:00
Dmitry Podgorny
0c60e8d384
tls_openssl: coding style
2016-09-02 00:49:32 +03:00
Dmitry Podgorny
ab80d72518
tls/openssl: handle SSL_shutdown() properly
...
Handle SSL_ERROR_WANT_READ/WRITE and return value 0.
2016-04-19 19:57:52 +00:00
Dmitry Podgorny
ba7422c893
tls/openssl: be more verbose
...
Log non-recoverable errors. The openssl error queue can contain useful
information.
2016-04-19 18:21:27 +00:00
Dmitry Podgorny
4b444ea699
tls/openssl: fixed indentation
2016-04-19 16:33:47 +00:00
Dmitry Podgorny
b04c40d3ea
tls: don't hang with openssl implementation
...
* Exit from tls_start() on fatal errors. If SSL_connect() fails and
returns -1 this leads to endless loop in case of fatal error.
* Don't set writefds on SSL_ERROR_WANT_READ. Otherwise, this makes
select(2) exit immediately what leads to CPU usage.
2015-10-13 02:43:23 +03:00
Dariusz Dwornikowski
71f75b2e2e
Closes #31
2014-10-23 08:44:52 +02:00
Dmitry Podgorny
65d2535302
tls_openssl: removed unused openssl/rand.h
2014-09-06 22:31:53 +03:00
Jack Moffitt
ee8afdb64e
Memory leak fixes from @elisamanfrin.
...
Fixes issue #4 .
2012-02-07 22:46:38 -07:00
Vlad-Mihai Sima
511606835d
Bug fix: when using tls, if a stanza is bigger than the buffer of 4096 in event.c, the stanza will not be read as select will return 0 on the ssl socket and the data will be in ssl buffers. Partial fix, only for Linux for now
2012-01-01 20:09:18 +01:00
Jack Moffitt
370a371800
Dual licensed libstrophe under MIT and GPLv3.
...
Updated copyright headers.
2009-06-15 15:26:10 -06:00
Jack Moffitt
4f608fd957
First pass at fixing up OpenSSL support. It now seems to work.
2008-12-10 09:25:22 -07:00
Jack Moffitt
1c0bbb1f5d
Reverting r513. I mistakenly committed my entire tree.
2008-08-26 04:46:41 +00:00
Jack Moffitt
ade38ae188
Small patch to handler_fire_stanza() from Matthew Wild <mwild1@gmail.com>. prev was not advanced along with item.
2008-08-26 04:44:19 +00:00
Jack Moffitt
65a174ee7e
Most public API points are now documented.
2008-06-24 14:43:54 +00:00
Jack Moffitt
b6027cfd7f
Updated copyright years and fixed LLC typo.
2008-06-19 22:33:13 +00:00
James Canete
f45380bb23
Added OpenSSL support.
...
Added win32-specific srv lookup support.
Extend session timeout to 15 seconds.
2007-09-05 20:01:24 +00:00