summaryrefslogtreecommitdiff
path: root/doc
AgeCommit message (Collapse)Author
2023-11-16 Add -J and -j to the TLS tools to check for peer close_notify.Laurent Bercot
Also, and more importantly, significantly rewrite stls_run() for better full-duplex support. This implementation isn't fully tested yet. Signed-off-by: Laurent Bercot <ska@appnovation.com>
2023-11-11 New and fixed version of sbearssl_runLaurent Bercot
Signed-off-by: Laurent Bercot <ska@appnovation.com>
2023-11-10 Prepare for 2.7.0.0. Better s6-tlsc-io interface.Laurent Bercot
Signed-off-by: Laurent Bercot <ska@appnovation.com>
2023-10-01 Doc typo fixLaurent Bercot
Signed-off-by: Laurent Bercot <ska@appnovation.com>
2023-09-30 s6-tlsserver bugfix, doc updatesLaurent Bercot
Signed-off-by: Laurent Bercot <ska@appnovation.com>
2023-09-30 Great Tcpserver Unification. Prepare for 2.6.0.0.Laurent Bercot
Signed-off-by: Laurent Bercot <ska@appnovation.com>
2023-09-25 Doc typo fixLaurent Bercot
Signed-off-by: Laurent Bercot <ska@appnovation.com>
2023-09-20 Document itLaurent Bercot
Signed-off-by: Laurent Bercot <ska@appnovation.com>
2023-09-20 Remove extra warning when s6-tcpserver-access has no rulesetLaurent Bercot
Signed-off-by: Laurent Bercot <ska@appnovation.com>
2023-09-12 Update depsLaurent Bercot
Signed-off-by: Laurent Bercot <ska@appnovation.com>
2023-09-11 Update depsLaurent Bercot
Signed-off-by: Laurent Bercot <ska@appnovation.com>
2023-09-09 Update depsLaurent Bercot
Signed-off-by: Laurent Bercot <ska@appnovation.com>
2023-08-08 Prepare for 2.5.1.4; fix s6-tlsserver -Y|-yLaurent Bercot
Signed-off-by: Laurent Bercot <ska@appnovation.com>
2023-02-09 Prepare for 2.5.1.3Laurent Bercot
Signed-off-by: Laurent Bercot <ska@appnovation.com>
2023-01-02 Update dependenciesLaurent Bercot
Signed-off-by: Laurent Bercot <ska@appnovation.com>
2022-11-29 Prepare for 2.5.1.2Laurent Bercot
Signed-off-by: Laurent Bercot <ska@appnovation.com>
2022-11-20 Doc typo fixLaurent Bercot
Signed-off-by: Laurent Bercot <ska@appnovation.com>
2022-11-01 Doc fixLaurent Bercot
Signed-off-by: Laurent Bercot <ska@appnovation.com>
2022-10-31 Doc typo fixesLaurent Bercot
Signed-off-by: Laurent Bercot <ska@appnovation.com>
2022-10-14 Prepare for 2.5.1.2Laurent Bercot
Signed-off-by: Laurent Bercot <ska@appnovation.com>
2022-10-14 Bring libsbearssl doc up to date.Laurent Bercot
Also fix a typo in sbearssl.h Signed-off-by: Laurent Bercot <ska@appnovation.com>
2022-10-13 More doc fixesLaurent Bercot
Signed-off-by: Laurent Bercot <ska@appnovation.com>
2022-10-13 Doc fixesLaurent Bercot
Signed-off-by: Laurent Bercot <ska@appnovation.com>
2022-10-10 Doc typo fixLaurent Bercot
Signed-off-by: Laurent Bercot <ska@appnovation.com>
2022-08-23 ... and fix typosLaurent Bercot
Signed-off-by: Laurent Bercot <ska@appnovation.com>
2022-08-23 Do not require optional certificates XDLaurent Bercot
Signed-off-by: Laurent Bercot <ska@appnovation.com>
2022-04-09 Prepare for 2.5.1.1; adapt to skalibs-2.12.0.0Laurent Bercot
Signed-off-by: Laurent Bercot <ska@appnovation.com>
2021-12-19 Update depsLaurent Bercot
Signed-off-by: Laurent Bercot <ska@appnovation.com>
2021-12-05 Prepare for 2.5.1.0Laurent Bercot
Signed-off-by: Laurent Bercot <ska@appnovation.com>
2021-11-18 Allow SNI wildcarding for *.example.comLaurent Bercot
Signed-off-by: Laurent Bercot <ska@appnovation.com>
2021-09-26 Update LibreSSL/LibreTLS dependenciesLaurent Bercot
Signed-off-by: Laurent Bercot <ska@appnovation.com>
2021-09-24 Log client decision on s6-ucspitls[cd] -v2Laurent Bercot
Signed-off-by: Laurent Bercot <ska@appnovation.com>
2021-08-10 Update dependencies2.5.0.0Laurent Bercot
Signed-off-by: Laurent Bercot <ska@appnovation.com>
2021-07-23 Prepare for 2.5.0.0; remove minidentdLaurent Bercot
Signed-off-by: Laurent Bercot <ska@appnovation.com>
2021-05-28 Server-side SNI, libtls versionLaurent Bercot
Implementation for bearssl coming soon.
2021-05-25 More debug commandsLaurent Bercot
2021-05-18 Prepare for 2.4.2.0; implement client certificates with bearsslLaurent Bercot
Also send a bit more environment with libtls
2021-04-15 version: 2.4.1.1v2.4.1.1Laurent Bercot
2021-04-13 Prepare for 2.4.1.1Laurent Bercot
2021-02-16 More doc fixesLaurent Bercot
2021-02-15 version: 2.4.1.0v2.4.1.0Laurent Bercot
2021-02-07 Add link to s6-networking man pagesLaurent Bercot
2021-02-04 More doc fixesLaurent Bercot
2021-02-04 Doc fixes, thanks flexibeastLaurent Bercot
2021-01-28 Remove SSL_TLS_SNI_SERVERNAME (instead of defined but empty) if no SNILaurent Bercot
2021-01-28 Prepare for 2.4.1.0; add SSL_TLS_SNI_SERVERNAMELaurent Bercot
2021-01-18 Tiny code and doc fixesLaurent Bercot
2021-01-13 Implement handshake timeout for libtls backendLaurent Bercot
2021-01-03 Document optional execlineLaurent Bercot
2020-12-07 Change -K semantics: timeout *during handshake*, not afterwardsLaurent Bercot
- the TLS tunnel itself should be transparent so it has no business shutting down the connection no matter how long the app takes - there's still an undetectable situation on some kernels where EOF doesn't get transmitted from the network, and the engine is in the handshake, and it can't do anything but wait forever. A timeout is useful here: dawg, your peer is never going to send any more data, you should just give up. - if the situation happens after the handshake, the *app* should have a timeout and die. The tunnel will follow suit. - libtls has a blocking tls_handshake() blackbox, we cannot give it a timeout. Too bad, use bearssl.