summaryrefslogtreecommitdiff
path: root/data
diff options
context:
space:
mode:
authorAdam <adam@sigterm.info>2014-02-17 22:21:08 -0500
committerAdam <adam@sigterm.info>2014-02-17 22:21:08 -0500
commit0db81ca46ad3a9faeacd9b138ba4c1634cd1faab (patch)
treef3c7d3da8a0f8ae30d6c8b867bbf8f594793b256 /data
parent7f7144de1fe96b42e3845690b77738e7b93bbe46 (diff)
parent1c39d25ccaabeab2a8b1f317bf5394f007db14f8 (diff)
Merge pull request #52 from attilamolnar/2.0+gnutls
Add support for SSL connections powered by GnuTLS
Diffstat (limited to 'data')
-rw-r--r--data/example.conf2
-rw-r--r--data/modules.example.conf86
-rw-r--r--data/stats.standalone.example.conf2
3 files changed, 66 insertions, 24 deletions
diff --git a/data/example.conf b/data/example.conf
index fbb7e310e..4d4ba6b17 100644
--- a/data/example.conf
+++ b/data/example.conf
@@ -168,7 +168,7 @@ uplink
/*
* Enable if Services should connect using SSL.
- * You must have m_ssl loaded for this to work.
+ * You must have an SSL module loaded for this to work.
*/
ssl = no
diff --git a/data/modules.example.conf b/data/modules.example.conf
index e58ebea88..8fe9ca4db 100644
--- a/data/modules.example.conf
+++ b/data/modules.example.conf
@@ -201,7 +201,7 @@ module { name = "help" }
/* Time before connections to this server are timed out. */
timeout = 30
- /* Listen using SSL. Requires m_ssl. */
+ /* Listen using SSL. Requires an SSL module. */
#ssl = yes
/* If you are using a reverse proxy that sends one of the
@@ -469,6 +469,69 @@ module { name = "help" }
#module { name = "m_sasl_dh-blowfish" }
/*
+ * m_ssl_gnutls [EXTRA]
+ *
+ * This module provides SSL services to Anope using GnuTLS, for example to
+ * connect to the uplink server(s) via SSL.
+ *
+ * You may only load either m_ssl_gnutls or m_ssl_openssl, bot not both.
+ */
+#module
+{
+ name = "m_ssl_gnutls"
+
+ /*
+ * An optional certificate and key for m_gnutls to give to the uplink.
+ *
+ * You can generate your own certificate and key pair by using:
+ *
+ * certtool --generate-privkey --bits 2048 --outfile anope.key
+ * certtool --generate-self-signed --load-privkey anope.key --outfile anope.crt
+ *
+ */
+ cert = "data/anope.crt"
+ key = "data/anope.key"
+
+ /*
+ * Diffie-Hellman parameters to use when acting as a server. This is only
+ * required for TLS servers that want to use ephemeral DH cipher suites.
+ *
+ * This is NOT required for Anope to connect to the uplink server(s) via SSL.
+ *
+ * You can generate DH parameters by using:
+ *
+ * certtool --generate-dh-params --bits 2048 --outfile dhparams.pem
+ *
+ */
+# dhparams = "data/dhparams.pem"
+}
+
+/*
+ * m_ssl_openssl [EXTRA]
+ *
+ * This module provides SSL services to Anope using OpenSSL, for example to
+ * connect to the uplink server(s) via SSL.
+ *
+ * You may only load either m_ssl_openssl or m_ssl_gnutls, bot not both.
+ *
+ */
+#module
+{
+ name = "m_ssl_openssl"
+
+ /*
+ * An optional certificate and key for m_openssl to give to the uplink.
+ *
+ * You can generate your own certificate and key pair by using:
+ *
+ * openssl genrsa -out anope.key 2048
+ * openssl req -new -x509 -key anope.key -out anope.crt -days 1095
+ */
+ cert = "data/anope.crt"
+ key = "data/anope.key"
+}
+
+/*
* m_sql_authentication [EXTRA]
*
* This module allows authenticating users against an external SQL database using a custom
@@ -663,27 +726,6 @@ module { name = "help" }
}
/*
- * m_ssl [EXTRA]
- *
- * This module uses SSL to connect to the uplink server(s).
- */
-#module
-{
- name = "m_ssl"
-
- /*
- * An optional certificate and key for m_ssl to give to the uplink.
- *
- * You can generate your own certificate and key pair by using:
- *
- * openssl genrsa -out anope.key 2048
- * openssl req -new -x509 -key anope.key -out anope.crt -days 1095
- */
- cert = "data/anope.crt"
- key = "data/anope.key"
-}
-
-/*
* m_xmlrpc
*
* Allows remote applications (websites) to execute queries in real time to retrieve data from Anope.
diff --git a/data/stats.standalone.example.conf b/data/stats.standalone.example.conf
index 7ba985e19..8db7c9999 100644
--- a/data/stats.standalone.example.conf
+++ b/data/stats.standalone.example.conf
@@ -168,7 +168,7 @@ uplink
/*
* Enable if Services should connect using SSL.
- * You must have m_ssl loaded for this to work.
+ * You must have an SSL module loaded for this to work.
*/
ssl = no