Pārlūkot izejas kodu

Increase depth to accomodate intermediate certificates

Bob Mottram 8 gadus atpakaļ
vecāks
revīzija
8c71dd25f0
1 mainītis faili ar 4 papildinājumiem un 4 dzēšanām
  1. 4
    4
      src/freedombone-app-xmpp

+ 4
- 4
src/freedombone-app-xmpp Parādīt failu

687
         echo "    certificate = \"/etc/ssl/certs/${DEFAULT_DOMAIN_NAME}.crt\";" >> /etc/prosody/prosody.cfg.lua
687
         echo "    certificate = \"/etc/ssl/certs/${DEFAULT_DOMAIN_NAME}.crt\";" >> /etc/prosody/prosody.cfg.lua
688
     fi
688
     fi
689
     echo "    curve = $XMPP_ECC_CURVE;" >> /etc/prosody/prosody.cfg.lua
689
     echo "    curve = $XMPP_ECC_CURVE;" >> /etc/prosody/prosody.cfg.lua
690
-    echo '    depth = "1";' >> /etc/prosody/prosody.cfg.lua
690
+    echo '    depth = "2";' >> /etc/prosody/prosody.cfg.lua
691
     echo "    ciphers = $XMPP_CIPHERS;" >> /etc/prosody/prosody.cfg.lua
691
     echo "    ciphers = $XMPP_CIPHERS;" >> /etc/prosody/prosody.cfg.lua
692
     echo '    options = { "tlsv1+" };' >> /etc/prosody/prosody.cfg.lua
692
     echo '    options = { "tlsv1+" };' >> /etc/prosody/prosody.cfg.lua
693
     echo "    dhparam = \"/etc/ssl/certs/${DEFAULT_DOMAIN_NAME}.dhparam\";" >> /etc/prosody/prosody.cfg.lua
693
     echo "    dhparam = \"/etc/ssl/certs/${DEFAULT_DOMAIN_NAME}.dhparam\";" >> /etc/prosody/prosody.cfg.lua
722
         echo "        certificate = \"/etc/prosody/certs/${DEFAULT_DOMAIN_NAME}.crt\";" >> /etc/prosody/prosody.cfg.lua
722
         echo "        certificate = \"/etc/prosody/certs/${DEFAULT_DOMAIN_NAME}.crt\";" >> /etc/prosody/prosody.cfg.lua
723
     fi
723
     fi
724
     echo "        curve = $XMPP_ECC_CURVE;" >> /etc/prosody/prosody.cfg.lua
724
     echo "        curve = $XMPP_ECC_CURVE;" >> /etc/prosody/prosody.cfg.lua
725
-    echo '        depth = "1";' >> /etc/prosody/prosody.cfg.lua
725
+    echo '        depth = "2";' >> /etc/prosody/prosody.cfg.lua
726
     echo "        ciphers = $XMPP_CIPHERS;" >> /etc/prosody/prosody.cfg.lua
726
     echo "        ciphers = $XMPP_CIPHERS;" >> /etc/prosody/prosody.cfg.lua
727
     echo '        options = { "tlsv1+" };' >> /etc/prosody/prosody.cfg.lua
727
     echo '        options = { "tlsv1+" };' >> /etc/prosody/prosody.cfg.lua
728
     echo "        dhparam = \"/etc/prosody/certs/${DEFAULT_DOMAIN_NAME}.dhparam\";" >> /etc/prosody/prosody.cfg.lua
728
     echo "        dhparam = \"/etc/prosody/certs/${DEFAULT_DOMAIN_NAME}.dhparam\";" >> /etc/prosody/prosody.cfg.lua
896
     if ! grep -q 'ciphers =' /etc/prosody/conf.avail/xmpp.cfg.lua; then
896
     if ! grep -q 'ciphers =' /etc/prosody/conf.avail/xmpp.cfg.lua; then
897
         sed -i "/certificate =/a\        ciphers = $XMPP_CIPHERS;" /etc/prosody/conf.avail/xmpp.cfg.lua
897
         sed -i "/certificate =/a\        ciphers = $XMPP_CIPHERS;" /etc/prosody/conf.avail/xmpp.cfg.lua
898
     fi
898
     fi
899
-    if ! grep -q 'depth = "1";' /etc/prosody/conf.avail/xmpp.cfg.lua; then
900
-        sed -i '/certificate =/a\        depth = "1";' /etc/prosody/conf.avail/xmpp.cfg.lua
899
+    if ! grep -q 'depth = "2";' /etc/prosody/conf.avail/xmpp.cfg.lua; then
900
+        sed -i '/certificate =/a\        depth = "2";' /etc/prosody/conf.avail/xmpp.cfg.lua
901
     fi
901
     fi
902
     if ! grep -q 'curve =' /etc/prosody/conf.avail/xmpp.cfg.lua; then
902
     if ! grep -q 'curve =' /etc/prosody/conf.avail/xmpp.cfg.lua; then
903
         sed -i "/certificate =/a\        curve = $XMPP_ECC_CURVE;" /etc/prosody/conf.avail/xmpp.cfg.lua
903
         sed -i "/certificate =/a\        curve = $XMPP_ECC_CURVE;" /etc/prosody/conf.avail/xmpp.cfg.lua