1
0
mirror of https://github.com/osmarks/ngircd.git synced 2025-12-18 11:58:06 +00:00

Compare commits

..

1 Commits

Author SHA1 Message Date
osmarks
164da7d063 Update documentation on CAFile
ngIRCd 27 now checks server certificates, and without `CAFile` set will reject all server/server connections with a confusing error.
Update documentation to say that `CAFile` is needed to accept incoming server connections.
2024-08-04 16:22:36 +01:00

View File

@@ -26,7 +26,7 @@ SSL-encrypted connections and plain-text connects can't run on the same network
port (which is a limitation of the IRC protocol); therefore you have to define
separate port(s) in your `[SSL]` block in the configuration file.
A minimal configuration for *accepting* SSL-encrypted client & server
A minimal configuration for *accepting* SSL-encrypted client
connections looks like this:
``` ini
@@ -36,11 +36,12 @@ KeyFile = /etc/ssl/certs/my-privkey.pem
Ports = 6697, 6698
```
In this case, the server only deals with *incoming* connections and never has to
validate SSL certificates itself, and therefore no "Certificate Authorities" are
needed.
In this case, the server only deals with unauthenticated incoming
connections and never has to validate SSL certificates itself, and therefore
no "Certificate Authorities" are needed.
If you want to use *outgoing* SSL-connections to other servers, you need to add:
If you want to use *outgoing* SSL-connections to other servers or accept
incoming *server* connections, you need to add:
``` ini
[SSL]