You cannot select more than 25 topics Topics must start with a letter or number, can include dashes ('-') and can be up to 35 characters long.
tailscale/net
Brad Fitzpatrick 7cf8ec8108 net/tlsdial: bake in LetsEncrypt's ISRG Root X1 root
We still try the host's x509 roots first, but if that fails (like if
the host is old), we fall back to using LetsEncrypt's root and
retrying with that.

tlsdial was used in the three main places: logs, control, DERP. But it
was missing in dnsfallback. So added it there too, so we can run fine
now on a machine with no DNS config and no root CAs configured.

Also, move SSLKEYLOGFILE support out of DERP. tlsdial is the logical place
for that support.

Fixes #1609

Signed-off-by: Brad Fitzpatrick <bradfitz@tailscale.com>
4 years ago
..
dns net/dns/resolver: add unsecured Quad9 resolvers 4 years ago
dnscache net/{dnscache,interfaces}: use netaddr.IP.IsPrivate, delete copied code 5 years ago
dnsfallback net/tlsdial: bake in LetsEncrypt's ISRG Root X1 root 4 years ago
flowtrack fix: typo spelling grammar 4 years ago
interfaces net/interfaces: remove stray C header file 4 years ago
netcheck fix: typo spelling grammar 4 years ago
netknob all: disable TCP keep-alives on iOS/Android 4 years ago
netns all: disable TCP keep-alives on iOS/Android 4 years ago
netstat all: gofmt with Go 1.17 4 years ago
nettest net/nettest: make nettest.NewConn pass x/net/nettest.TestConn. 5 years ago
packet net/packet: use netaddr AppendTo methods 5 years ago
portmapper all: update tests to use tstest.MemLogger 4 years ago
socks5 net/socks5/tssocks: add a SOCKS5 dialer type, method-ifying code 5 years ago
speedtest Implemented Commandline Download Speedtest (#2064) 5 years ago
stun all: gofmt with Go 1.17 4 years ago
tlsdial net/tlsdial: bake in LetsEncrypt's ISRG Root X1 root 4 years ago
tsaddr ipn/ipnlocal: add MagicDNS records for IPv6-only nodes 4 years ago
tshttpproxy all: gofmt with Go 1.17 4 years ago
tstun net/tstun: block looped disco traffic, take 17 4 years ago