tailscale/net
Brad Fitzpatrick 7cf8ec8108 net/tlsdial: bake in LetsEncrypt's ISRG Root X1 root
We still try the host's x509 roots first, but if that fails (like if
the host is old), we fall back to using LetsEncrypt's root and
retrying with that.

tlsdial was used in the three main places: logs, control, DERP. But it
was missing in dnsfallback. So added it there too, so we can run fine
now on a machine with no DNS config and no root CAs configured.

Also, move SSLKEYLOGFILE support out of DERP. tlsdial is the logical place
for that support.

Fixes #1609

Signed-off-by: Brad Fitzpatrick <bradfitz@tailscale.com>
2021-10-01 08:30:07 -07:00
..
dns net/dns/resolver: add unsecured Quad9 resolvers 2021-09-30 18:08:19 -07:00
dnscache net/{dnscache,interfaces}: use netaddr.IP.IsPrivate, delete copied code 2021-07-26 20:30:28 -07:00
dnsfallback net/tlsdial: bake in LetsEncrypt's ISRG Root X1 root 2021-10-01 08:30:07 -07:00
flowtrack fix: typo spelling grammar 2021-08-24 07:55:04 -07:00
interfaces net/interfaces: remove stray C header file 2021-09-08 12:01:35 -07:00
netcheck fix: typo spelling grammar 2021-08-24 07:55:04 -07:00
netknob all: disable TCP keep-alives on iOS/Android 2021-09-28 12:03:18 -07:00
netns all: disable TCP keep-alives on iOS/Android 2021-09-28 12:03:18 -07:00
netstat all: gofmt with Go 1.17 2021-08-05 15:54:00 -07:00
nettest net/nettest: make nettest.NewConn pass x/net/nettest.TestConn. 2021-04-06 15:34:29 -07:00
packet net/packet: use netaddr AppendTo methods 2021-05-20 20:42:18 -07:00
portmapper all: update tests to use tstest.MemLogger 2021-09-07 20:06:15 -07:00
socks5 net/socks5/tssocks: add a SOCKS5 dialer type, method-ifying code 2021-06-28 13:12:42 -07:00
speedtest Implemented Commandline Download Speedtest (#2064) 2021-07-15 14:43:13 -04:00
stun all: gofmt with Go 1.17 2021-08-05 15:54:00 -07:00
tlsdial net/tlsdial: bake in LetsEncrypt's ISRG Root X1 root 2021-10-01 08:30:07 -07:00
tsaddr ipn/ipnlocal: add MagicDNS records for IPv6-only nodes 2021-09-07 15:56:13 -07:00
tshttpproxy all: gofmt with Go 1.17 2021-08-05 15:54:00 -07:00
tstun net/tstun: block looped disco traffic, take 17 2021-09-29 14:17:40 -07:00