view mod_s2s_never_encrypt_blacklist/README.markdown @ 2968:569b98d6fca1

mod_http_logging: Be robust against missing connection object
author Kim Alvefur <>
date Fri, 30 Mar 2018 13:37:39 +0200
parents 4d73a1a6ba68
line wrap: on
line source

- 'Stage-Beta'
summary: |
    Stops prosody from including starttls into available features for
    specified remote servers.


Let's you stop Prosody from sending \<starttls
xmlns='urn:ietf:params:xml:ns:xmpp-tls'\> feature to choppy/buggy
servers which therefore would fail to re-negotiate and use a secure
stream. (e.g. [OpenFire


Copy the plugin into your prosody's modules directory.

And add it between your enabled modules into the global section

Then list each host as follow:

    tls_s2s_blacklist = { "host1.tld", "host2.tld", "host3.tld" }

In the unfortunate case of OpenFire... you can add the Server's ip
address directly as it may not send proper rfc6121 requests.

    tls_s2s_blacklist_ip = { "a.a.a.a", "b.b.b.b", "c.c.c.c" }


It's supposed to work with 0.7-0.8.x