diff options
author | 2015-02-07 10:45:19 +0000 | |
---|---|---|
committer | 2015-02-07 10:45:19 +0000 | |
commit | a2913c44cb7f5c198ff8f2f723e9cc379cd5785c (patch) | |
tree | f5342197b5df1ba2e4396c42e0d92f66e2059ab6 /lib/libcrypto/stack/stack.c | |
parent | Add support for interface-mtu (option 26). (diff) | |
download | wireguard-openbsd-a2913c44cb7f5c198ff8f2f723e9cc379cd5785c.tar.xz wireguard-openbsd-a2913c44cb7f5c198ff8f2f723e9cc379cd5785c.zip |
add STARTTLS support, using the shiny libtls.
Rationale: when you publish DANE records for certificate pinning, you MUST
offer TLS on the indicated service. Not offering TLS is verboten since
that would re-open the door for a MitM. This is obviously fundamentally
incompatible with having spamd in front of your mailservers - spamd kinda
is a MitM here, but intentional and utterly valid.
DANE is desirable because it allows one to not have to trust the broken
SSL CA model, and, depending on the mode chosen, even show the SSL cert
mafia the middle finger by not needing them at all.
ok reyk jsing bob
Diffstat (limited to 'lib/libcrypto/stack/stack.c')
0 files changed, 0 insertions, 0 deletions