summaryrefslogtreecommitdiffstats
path: root/lib/libcrypto/stack/stack.c
diff options
context:
space:
mode:
authorhenning <henning@openbsd.org>2015-02-07 10:45:19 +0000
committerhenning <henning@openbsd.org>2015-02-07 10:45:19 +0000
commita2913c44cb7f5c198ff8f2f723e9cc379cd5785c (patch)
treef5342197b5df1ba2e4396c42e0d92f66e2059ab6 /lib/libcrypto/stack/stack.c
parentAdd support for interface-mtu (option 26). (diff)
downloadwireguard-openbsd-a2913c44cb7f5c198ff8f2f723e9cc379cd5785c.tar.xz
wireguard-openbsd-a2913c44cb7f5c198ff8f2f723e9cc379cd5785c.zip
add STARTTLS support, using the shiny libtls.
Rationale: when you publish DANE records for certificate pinning, you MUST offer TLS on the indicated service. Not offering TLS is verboten since that would re-open the door for a MitM. This is obviously fundamentally incompatible with having spamd in front of your mailservers - spamd kinda is a MitM here, but intentional and utterly valid. DANE is desirable because it allows one to not have to trust the broken SSL CA model, and, depending on the mode chosen, even show the SSL cert mafia the middle finger by not needing them at all. ok reyk jsing bob
Diffstat (limited to 'lib/libcrypto/stack/stack.c')
0 files changed, 0 insertions, 0 deletions