1. 26 6月, 2015 1 次提交
    • Travis Cross's avatar
      FS-7708: Fix docs on enabling cert CN/SAN validation · 979c94de
      Travis Cross 提交于
      The correct incantations to enable certification common name / subject
      alternative name verification, per our code, are `subjects_all`,
      `subjects_in`, and `subjects_out` in a Sofia profile's
      `tls-verify-policy`.  What we've had in our examples and documentation
      for years are `all_subjects`, `in_subjects`, and `out_subjects`.
      
      The result of this is that we've almost certainly confused people into
      using the incorrect forms.  Those poor people will believe that they
      are verifying the CN/SAN of the received host certificate against the
      list in `tls-verify-in-subjects` when in fact they are not.
      
      One clear issue in this case was that the incorrect forms failed to
      have any effect without providing any warning or error.  This issue
      could not have persisted if we had made more noise about incorrect
      input.
      
      Given how long this has been broken, it's tempting to alias the
      incorrect forms to the correct ones.  However this would certainly
      break many existing installations that have, because of this error,
      never actually tested their setup with CN/SAN validation enabled.
      
      In this commit, we fix the examples and documentation, and add an
      error-level log output when unknown values are passed to
      `tls-verify-policy`.
      
      Thanks-to: Andrew Patrikalakis <anrp+freeswitch@anrp.net>
      979c94de
  2. 24 6月, 2015 3 次提交
  3. 19 6月, 2015 3 次提交
  4. 18 6月, 2015 1 次提交
  5. 17 6月, 2015 2 次提交
  6. 15 6月, 2015 2 次提交
  7. 13 6月, 2015 1 次提交
  8. 11 6月, 2015 5 次提交
  9. 10 6月, 2015 1 次提交
  10. 09 6月, 2015 2 次提交
  11. 08 6月, 2015 1 次提交
  12. 05 6月, 2015 5 次提交
  13. 03 6月, 2015 1 次提交
  14. 02 6月, 2015 4 次提交
  15. 01 6月, 2015 3 次提交
  16. 27 5月, 2015 5 次提交