From 1e7ed15bcab06b4226d0eb4375f2b958b55937c9 Mon Sep 17 00:00:00 2001 From: godog <godog@autistici.org> Date: Mon, 21 Apr 2025 17:07:00 +0200 Subject: [PATCH] irc: fix ssl configuration --- roles/irc/templates/inspircd/inspircd.conf | 6 +++--- roles/irc/templates/inspircd/modules.conf | 1 + 2 files changed, 4 insertions(+), 3 deletions(-) diff --git a/roles/irc/templates/inspircd/inspircd.conf b/roles/irc/templates/inspircd/inspircd.conf index 0a1140d3..f15b48d1 100644 --- a/roles/irc/templates/inspircd/inspircd.conf +++ b/roles/irc/templates/inspircd/inspircd.conf @@ -18,13 +18,13 @@ email="irc@{{ domain_public[0] }}"> # note: for the TLS configuration check out modules.conf -<bind address="" port="16697" type="clients" profile="gnutls"> -<bind address="" port="19999" type="clients" profile="gnutls"> +<bind address="" port="16697" type="clients" sslprofile="gnutls"> +<bind address="" port="19999" type="clients" sslprofile="gnutls"> # note: if you change the server port remember to also update links.conf # services <bind address="127.0.0.1" port="7000" type="servers"> # linked irc servers -<bind address="" port="17029" type="servers" profile="gnutls"> +<bind address="" port="17029" type="servers" sslprofile="gnutls"> <sasl target="services.irc.{{ irc_network_name }}" requiressl="yes"> diff --git a/roles/irc/templates/inspircd/modules.conf b/roles/irc/templates/inspircd/modules.conf index c66e6431..97dee61c 100644 --- a/roles/irc/templates/inspircd/modules.conf +++ b/roles/irc/templates/inspircd/modules.conf @@ -62,6 +62,7 @@ <module name="m_ssl_gnutls.so"> <sslprofile name="gnutls" + provider="gnutls" certfile="/etc/credentials/public/irc.autistici.org/fullchain.pem" keyfile="/etc/credentials/public/irc.autistici.org/privkey.pem" priority="SECURE256:+SECURE128:-VERS-TLS-ALL:+VERS-TLS1.2:+VERS-TLS1.3:-RSA:-DHE-DSS" -- GitLab