Verify SMTP STARTTLS certificate chains
Some checks are pending
Quality / full-local-gates (push) Waiting to run
Some checks are pending
Quality / full-local-gates (push) Waiting to run
This commit is contained in:
parent
8c281cc756
commit
9938fd60cd
|
|
@ -446,6 +446,7 @@ if config_env() == :prod do
|
|||
|
||||
smtp_username = System.get_env("SMTP_USERNAME")
|
||||
smtp_password = System.get_env("SMTP_PASSWORD")
|
||||
smtp_relay = System.get_env("SMTP_RELAY", "mailpit")
|
||||
smtp_username_set? = is_binary(smtp_username) and smtp_username != ""
|
||||
smtp_password_set? = is_binary(smtp_password) and smtp_password != ""
|
||||
|
||||
|
|
@ -461,13 +462,30 @@ if config_env() == :prod do
|
|||
raise "SMTP_TLS must be never when SMTP_SSL enables an implicit TLS connection."
|
||||
end
|
||||
|
||||
smtp_tls_options =
|
||||
if smtp_tls == :never do
|
||||
[]
|
||||
else
|
||||
[
|
||||
versions: [:"tlsv1.3", :"tlsv1.2"],
|
||||
verify: :verify_peer,
|
||||
cacerts: :public_key.cacerts_get(),
|
||||
depth: 10,
|
||||
server_name_indication: String.to_charlist(smtp_relay),
|
||||
customize_hostname_check: [
|
||||
match_fun: :public_key.pkix_verify_hostname_match_fun(:https)
|
||||
]
|
||||
]
|
||||
end
|
||||
|
||||
[
|
||||
adapter: Swoosh.Adapters.SMTP,
|
||||
relay: System.get_env("SMTP_RELAY", "mailpit"),
|
||||
relay: smtp_relay,
|
||||
port: String.to_integer(System.get_env("SMTP_PORT", "1025")),
|
||||
auth: smtp_auth,
|
||||
tls: smtp_tls,
|
||||
ssl: smtp_ssl
|
||||
ssl: smtp_ssl,
|
||||
tls_options: smtp_tls_options
|
||||
]
|
||||
|> then(fn config ->
|
||||
case smtp_username do
|
||||
|
|
|
|||
Loading…
Reference in New Issue
Block a user