summaryrefslogtreecommitdiff
path: root/doc/source/misc
diff options
context:
space:
mode:
authormathieui <mathieui@mathieui.net>2013-04-10 01:37:23 +0200
committermathieui <mathieui@mathieui.net>2013-04-10 01:37:23 +0200
commitbf8e2a942c884a4a35e297734ce6c098849ac086 (patch)
treeca1744be21ba7f0532c8850f3cf9fc4a445c87d2 /doc/source/misc
parent1ec613b95ce33d9768f61ab1eff58a0522907cbf (diff)
downloadpoezio-bf8e2a942c884a4a35e297734ce6c098849ac086.tar.gz
poezio-bf8e2a942c884a4a35e297734ce6c098849ac086.tar.bz2
poezio-bf8e2a942c884a4a35e297734ce6c098849ac086.tar.xz
poezio-bf8e2a942c884a4a35e297734ce6c098849ac086.zip
Move images, and add SSL page
Diffstat (limited to 'doc/source/misc')
-rw-r--r--doc/source/misc/index.rst22
-rw-r--r--doc/source/misc/ssl.rst60
2 files changed, 82 insertions, 0 deletions
diff --git a/doc/source/misc/index.rst b/doc/source/misc/index.rst
new file mode 100644
index 00000000..bf8fcb90
--- /dev/null
+++ b/doc/source/misc/index.rst
@@ -0,0 +1,22 @@
+Miscellaneous topics
+====================
+
+Contents:
+
+.. toctree::
+ :maxdepth: 2
+
+ ssl
+
+
+..
+ configure
+ ssl
+ usage
+ themes
+ keys
+ plugins
+ misc
+ xep
+ dev
+
diff --git a/doc/source/misc/ssl.rst b/doc/source/misc/ssl.rst
new file mode 100644
index 00000000..a012ebed
--- /dev/null
+++ b/doc/source/misc/ssl.rst
@@ -0,0 +1,60 @@
+SSL Management
+==============
+
+Starting from version 0.7.5, poezio offers some options to check the validity
+of a X.509 certificate.
+
+TOFU
+----
+
+The default handling method is the `TOFU/TUFU`_
+method. At your first connection, poezio will save the hash of the certificate
+received, and will compare the received one and the first one for the next
+connections.
+
+
+If you are paranoid (or run poezio for the first time in an unsafe
+environment), you can set the _certificate_ value of your config file yourself
+(the hash, not colon-separated).
+
+
+If the certificate is not the same, poezio will show an error message and wait
+for confirmation:
+
+.. figure:: ../images/ssl_warning.png
+ :alt: Warning message
+
+If you press y, the change is validated an poezio will match the next certs
+with the accepted one.
+
+If you press n, you will get the confirmation that the change has been
+refused, and you will be disconnected.
+
+CA-Based
+--------
+
+If you are connecting to a large server that has several front-facing
+endpoints, you might be bothered by having to validate the change each time,
+and you may want to check only if it the same authority delivered the
+certificate.
+
+You can then set the *ca_cert_path* option to the path of a file containing
+the validation chain in `PEM format`_ ; those certificates are usually in
+/usr/share/ca-certificates/ but it may vary depending of your distribution.
+
+
+If the authority does not match when connecting, you should be disconnected.
+
+None
+----
+
+If you do not want to bother with certificate validation at all (which can be
+the case when you run poezio on the same computer as your jabber server), you
+can set the *ignore_certificate* value to true, and let the *ca_cert_path*
+option empty (or even remove it).
+
+.. warning:: Only do this if you know what you are doing, or you will be open
+ to Man in The Middle attacks!
+
+.. _TOFU/TUFU: https://en.wikipedia.org/wiki/User:Dotdotike/Trust_Upon_First_Use
+.. _PEM format: https://tools.ietf.org/html/rfc1422.html