tls = false,
tls_enabled = false,
tls_options = [],
+ server,
authenticated = false,
auth_domain,
connections = ?DICT:new(),
s2s_stream_features,
Server,
[], [Server])}),
- {next_state, wait_for_feature_request, StateData};
+ {next_state, wait_for_feature_request, StateData#state{server = Server}};
{"jabber:server", _, Server, true} when
StateData#state.authenticated ->
send_text(StateData, ?STREAM_HEADER(" version='1.0'")),
SockMod == gen_tcp ->
?DEBUG("starttls", []),
Socket = StateData#state.socket,
- TLSOpts = StateData#state.tls_options,
+ TLSOpts = case ejabberd_config:get_local_option(
+ {domain_certfile,
+ StateData#state.server}) of
+ undefined ->
+ StateData#state.tls_options;
+ CertFile ->
+ [{certfile, CertFile} |
+ lists:keydelete(
+ certfile, 1,
+ StateData#state.tls_options)]
+ end,
TLSSocket = (StateData#state.sockmod):starttls(
Socket, TLSOpts,
xml:element_to_binary(
{next_state, wait_for_stream,
StateData#state{socket = TLSSocket,
streamid = new_id(),
- tls_enabled = true
+ tls_enabled = true,
+ tls_options = TLSOpts
}};
{?NS_SASL, "auth"} when TLSEnabled ->
Mech = xml:get_attr_s("mechanism", Attrs),
tls = false,
tls_required = false,
tls_enabled = false,
- tls_options = [],
+ tls_options = [connect],
authenticated = false,
db_enabled = true,
try_auth = true,
UseV10 = TLS,
TLSOpts = case ejabberd_config:get_local_option(s2s_certfile) of
undefined ->
- [];
+ [connect];
CertFile ->
[{certfile, CertFile}, connect]
end,
Socket = StateData#state.socket,
TLSOpts = case ejabberd_config:get_local_option(
{domain_certfile,
- StateData#state.server}) of
+ StateData#state.myname}) of
undefined ->
StateData#state.tls_options;
CertFile ->
TLSSocket = ejabberd_socket:starttls(Socket, TLSOpts),
NewStateData = StateData#state{socket = TLSSocket,
streamid = new_id(),
- tls_enabled = true
+ tls_enabled = true,
+ tls_options = TLSOpts
},
send_text(NewStateData,
io_lib:format(?STREAM_HEADER,