Mercurial > prosody-modules
view mod_auth_ccert/README.markdown @ 5648:c217f4edfc4f
misc/mtail: Start of an mtail config
Stashing it here in case anyone wants to continue working on it.
Currently it's only counting log messages by level.
Due to the permissions set by systemd on Prosody logs, mtail never
managed to start correctly until permissions were manually relaxed.
author | Kim Alvefur <zash@zash.se> |
---|---|
date | Sun, 17 Sep 2023 13:36:30 +0200 |
parents | 0e3f5f70a51d |
children |
line wrap: on
line source
--- labels: - 'Stage-Alpha' - 'Type-Auth' summary: Client Certificate authentication module ... Introduction ============ This module implements PKI-style client certificate authentication. You will therefore need your own Certificate Authority. How to set that up is beyond the current scope of this document. Configuration ============= authentication = "ccert" certificate_match = "xmppaddr" -- or "email" c2s_ssl = { cafile = "/path/to/your/ca.pem"; capath = false; -- Disable capath inherited from built-in default verify = {"peer"; "client_once"}; -- Ask for client certificate verifyext = { -- Don't validate client certs as if they were server certs lsec_ignore_purpose = false } } Compatibility ============= ----------------- -------------- trunk Works 0.10 and later Works 0.9 and earlier Doesn't work ----------------- --------------