]> arthur.barton.de Git - ngircd-alex.git/blobdiff - src/ngircd/conf.c
Move "ClientHost" and "ClientUserNick" to end of [Global] section
[ngircd-alex.git] / src / ngircd / conf.c
index fde37b00948cc1d048273496239c0515f7b5c112..12893ad8f86446abaa1574280abefb14be6889a8 100644 (file)
@@ -1,25 +1,29 @@
 /*
  * ngIRCd -- The Next Generation IRC Daemon
- * Copyright (c)2001,2002 Alexander Barton (alex@barton.de)
+ * Copyright (c)2001-2010 Alexander Barton (alex@barton.de)
  *
  * This program is free software; you can redistribute it and/or modify
  * it under the terms of the GNU General Public License as published by
  * the Free Software Foundation; either version 2 of the License, or
  * (at your option) any later version.
  * Please read the file COPYING, README and AUTHORS for more information.
- *
- * Configuration management (reading, parsing & validation)
  */
 
-
 #include "portab.h"
 
-static char UNUSED id[] = "$Id: conf.c,v 1.63 2004/01/17 03:17:00 alex Exp $";
+/**
+ * @file
+ * Configuration management (reading, parsing & validation)
+ */
 
 #include "imp.h"
 #include <assert.h>
 #include <errno.h>
-#include <stdarg.h>
+#ifdef PROTOTYPES
+#      include <stdarg.h>
+#else
+#      include <varargs.h>
+#endif
 #include <stdio.h>
 #include <stdlib.h>
 #include <string.h>
@@ -34,155 +38,371 @@ static char UNUSED id[] = "$Id: conf.c,v 1.63 2004/01/17 03:17:00 alex Exp $";
 # include <ctype.h>
 #endif
 
+#include "array.h"
 #include "ngircd.h"
 #include "conn.h"
-#include "client.h"
+#include "channel.h"
 #include "defines.h"
 #include "log.h"
-#include "resolve.h"
+#include "match.h"
 #include "tool.h"
 
 #include "exp.h"
 #include "conf.h"
 
 
-LOCAL BOOLEAN Use_Log = TRUE;
-LOCAL CONF_SERVER New_Server;
-LOCAL INT New_Server_Idx;
+static bool Use_Log = true, Using_MotdFile = true;
+static CONF_SERVER New_Server;
+static int New_Server_Idx;
+
+static size_t Conf_Oper_Count;
+static size_t Conf_Channel_Count;
+static char Conf_MotdFile[FNAME_LEN];
+
+static void Set_Defaults PARAMS(( bool InitServers ));
+static bool Read_Config PARAMS(( bool ngircd_starting ));
+static bool Validate_Config PARAMS(( bool TestOnly, bool Rehash ));
+
+static void Handle_GLOBAL PARAMS(( int Line, char *Var, char *Arg ));
+static void Handle_FEATURES PARAMS(( int Line, char *Var, char *Arg ));
+static void Handle_OPERATOR PARAMS(( int Line, char *Var, char *Arg ));
+static void Handle_SERVER PARAMS(( int Line, char *Var, char *Arg ));
+static void Handle_CHANNEL PARAMS(( int Line, char *Var, char *Arg ));
+
+static void Config_Error PARAMS(( const int Level, const char *Format, ... ));
+
+static void Config_Error_NaN PARAMS(( const int LINE, const char *Value ));
+static void Config_Error_TooLong PARAMS(( const int LINE, const char *Value ));
+
+static void Init_Server_Struct PARAMS(( CONF_SERVER *Server ));
+
+#ifdef WANT_IPV6
+#define DEFAULT_LISTEN_ADDRSTR "::,0.0.0.0"
+#else
+#define DEFAULT_LISTEN_ADDRSTR "0.0.0.0"
+#endif
+
+#ifdef SSL_SUPPORT
+struct SSLOptions Conf_SSLOptions;
+
+static void
+ConfSSL_Init(void)
+{
+       free(Conf_SSLOptions.KeyFile);
+       Conf_SSLOptions.KeyFile = NULL;
+
+       free(Conf_SSLOptions.CertFile);
+       Conf_SSLOptions.CertFile = NULL;
+
+       free(Conf_SSLOptions.DHFile);
+       Conf_SSLOptions.DHFile = NULL;
+       array_free_wipe(&Conf_SSLOptions.KeyFilePassword);
+}
 
+static bool
+ssl_print_configvar(const char *name, const char *file)
+{
+       FILE *fp;
+
+       if (!file) {
+               printf("  %s =\n", name);
+               return true;
+       }
+
+       fp = fopen(file, "r");
+       if (fp)
+               fclose(fp);
+       else
+               fprintf(stderr, "ERROR: %s \"%s\": %s\n",
+                       name, file, strerror(errno));
+
+       printf("  %s = %s\n", name, file);
+       return fp != NULL;
+}
+
+static bool
+ConfSSL_Puts(void)
+{
+       bool ret;
+
+       ret = ssl_print_configvar("SSLKeyFile", Conf_SSLOptions.KeyFile);
+
+       if (!ssl_print_configvar("SSLCertFile", Conf_SSLOptions.CertFile))
+               ret = false;
+
+       if (!ssl_print_configvar("SSLDHFile", Conf_SSLOptions.DHFile))
+               ret = false;
+
+       if (array_bytes(&Conf_SSLOptions.KeyFilePassword))
+               puts("  SSLKeyFilePassword = <secret>");
 
-LOCAL VOID Set_Defaults PARAMS(( BOOLEAN InitServers ));
-LOCAL VOID Read_Config PARAMS(( VOID ));
-LOCAL VOID Validate_Config PARAMS(( BOOLEAN TestOnly ));
+       array_free_wipe(&Conf_SSLOptions.KeyFilePassword);
 
-LOCAL VOID Handle_GLOBAL PARAMS(( INT Line, CHAR *Var, CHAR *Arg ));
-LOCAL VOID Handle_OPERATOR PARAMS(( INT Line, CHAR *Var, CHAR *Arg ));
-LOCAL VOID Handle_SERVER PARAMS(( INT Line, CHAR *Var, CHAR *Arg ));
-LOCAL VOID Handle_CHANNEL PARAMS(( INT Line, CHAR *Var, CHAR *Arg ));
+       return ret;
+}
+#endif
+
+static char *
+strdup_warn(const char *str)
+{
+       char *ptr = strdup(str);
+       if (!ptr)
+               Config_Error(LOG_ERR, "Could not allocate mem for string: %s", str);
+       return ptr;
+}
 
-LOCAL VOID Config_Error PARAMS(( CONST INT Level, CONST CHAR *Format, ... ));
 
-LOCAL VOID Init_Server_Struct PARAMS(( CONF_SERVER *Server ));
+static void
+ports_puts(array *a)
+{
+       size_t len;
+       UINT16 *ports;
+       len = array_length(a, sizeof(UINT16));
+       if (len--) {
+               ports = (UINT16*) array_start(a);
+               printf("%u", (unsigned int) *ports);
+               while (len--) {
+                       ports++;
+                       printf(", %u", (unsigned int) *ports);
+               }
+       }
+       putc('\n', stdout);
+}
+
+
+static void
+ports_parse(array *a, int Line, char *Arg)
+{
+       char *ptr;
+       int port;
+       UINT16 port16;
+
+       array_trunc(a);
+
+       /* Ports on that the server should listen. More port numbers
+        * must be separated by "," */
+       ptr = strtok( Arg, "," );
+       while (ptr) {
+               ngt_TrimStr(ptr);
+               port = atoi(ptr);
+               if (port > 0 && port < 0xFFFF) {
+                       port16 = (UINT16) port;
+                       if (!array_catb(a, (char*)&port16, sizeof port16))
+                               Config_Error(LOG_ERR, "%s, line %d Could not add port number %ld: %s",
+                                                       NGIRCd_ConfFile, Line, port, strerror(errno));
+               } else {
+                       Config_Error( LOG_ERR, "%s, line %d (section \"Global\"): Illegal port number %ld!",
+                                                                       NGIRCd_ConfFile, Line, port );
+               }
+
+               ptr = strtok( NULL, "," );
+       }
+}
 
 
-GLOBAL VOID
-Conf_Init( VOID )
+GLOBAL void
+Conf_Init( void )
 {
-       Set_Defaults( TRUE );
-       Read_Config( );
-       Validate_Config( FALSE );
+       Read_Config( true );
+       Validate_Config(false, false);
 } /* Config_Init */
 
 
-GLOBAL VOID
-Conf_Rehash( VOID )
+GLOBAL bool
+Conf_Rehash( void )
 {
-       Set_Defaults( FALSE );
-       Read_Config( );
-       Validate_Config( FALSE );
+       if (!Read_Config(false))
+               return false;
+       Validate_Config(false, true);
+
+       /* Update CLIENT structure of local server */
+       Client_SetInfo(Client_ThisServer(), Conf_ServerInfo);
+       return true;
 } /* Config_Rehash */
 
 
-GLOBAL INT
-Conf_Test( VOID )
+static const char*
+yesno_to_str(int boolean_value)
+{
+       if (boolean_value)
+               return "yes";
+       return "no";
+}
+
+
+static void
+opers_free(void)
+{
+       struct Conf_Oper *op;
+       size_t len;
+
+       len = array_length(&Conf_Opers, sizeof(*op));
+       op = array_start(&Conf_Opers);
+       while (len--) {
+               free(op->mask);
+               op++;
+       }
+       array_free(&Conf_Opers);
+}
+
+static void
+opers_puts(void)
+{
+       struct Conf_Oper *op;
+       size_t len;
+
+       len = array_length(&Conf_Opers, sizeof(*op));
+       op = array_start(&Conf_Opers);
+       while (len--) {
+               assert(op->name[0]);
+
+               puts("[OPERATOR]");
+               printf("  Name = %s\n", op->name);
+               printf("  Password = %s\n", op->pwd);
+               printf("  Mask = %s\n\n", op->mask ? op->mask : "");
+               op++;
+       }
+}
+
+
+GLOBAL int
+Conf_Test( void )
 {
        /* Read configuration, validate and output it. */
 
        struct passwd *pwd;
        struct group *grp;
-       INT i;
+       unsigned int i;
+       bool config_valid;
+       size_t predef_channel_count;
+       struct Conf_Channel *predef_chan;
 
-       Use_Log = FALSE;
-       Set_Defaults( TRUE );
+       Use_Log = false;
 
-       Read_Config( );
-       Validate_Config( TRUE );
+       if (! Read_Config(true))
+               return 1;
 
-       /* If stdin is a valid tty wait for a key: */
-       if( isatty( fileno( stdout )))
-       {
+       config_valid = Validate_Config(true, false);
+
+       /* If stdin and stdout ("you can read our nice message and we can
+        * read in your keypress") are valid tty's, wait for a key: */
+       if( isatty( fileno( stdin )) && isatty( fileno( stdout ))) {
                puts( "OK, press enter to see a dump of your service configuration ..." );
                getchar( );
+       } else {
+               puts( "Ok, dump of your server configuration follows:\n" );
        }
-       else puts( "Ok, dump of your server configuration follows:\n" );
 
        puts( "[GLOBAL]" );
-       printf( "  ServerName = %s\n", Conf_ServerName );
-       printf( "  ServerInfo = %s\n", Conf_ServerInfo );
-       printf( "  Password = %s\n", Conf_ServerPwd );
-       printf( "  AdminInfo1 = %s\n", Conf_ServerAdmin1 );
-       printf( "  AdminInfo2 = %s\n", Conf_ServerAdmin2 );
-       printf( "  AdminEMail = %s\n", Conf_ServerAdminMail );
-       printf( "  MotdFile = %s\n", Conf_MotdFile );
-       printf( "  Ports = " );
-       for( i = 0; i < Conf_ListenPorts_Count; i++ )
-       {
-               if( i != 0 ) printf( ", " );
-               printf( "%u", Conf_ListenPorts[i] );
-       }
-       puts( "" );
-       printf( "  Listen = %s\n", Conf_ListenAddress );
-       pwd = getpwuid( Conf_UID );
-       if( pwd ) printf( "  ServerUID = %s\n", pwd->pw_name );
-       else printf( "  ServerUID = %ld\n", (LONG)Conf_UID );
-       grp = getgrgid( Conf_GID );
-       if( grp ) printf( "  ServerGID = %s\n", grp->gr_name );
-       else printf( "  ServerGID = %ld\n", (LONG)Conf_GID );
-       printf( "  PingTimeout = %d\n", Conf_PingTimeout );
-       printf( "  PongTimeout = %d\n", Conf_PongTimeout );
-       printf( "  ConnectRetry = %d\n", Conf_ConnectRetry );
-       printf( "  OperCanUseMode = %s\n", Conf_OperCanMode == TRUE ? "yes" : "no" );
-       if( Conf_MaxConnections > 0 ) printf( "  MaxConnections = %ld\n", Conf_MaxConnections );
-       else printf( "  MaxConnections = -1\n" );
-       if( Conf_MaxConnectionsIP > 0 ) printf( "  MaxConnectionsIP = %d\n", Conf_MaxConnectionsIP );
-       else printf( "  MaxConnectionsIP = -1\n" );
-       if( Conf_MaxJoins > 0 ) printf( "  MaxJoins = %d\n", Conf_MaxJoins );
-       else printf( "  MaxJoins = -1\n" );
-       puts( "" );
-
-       for( i = 0; i < Conf_Oper_Count; i++ )
-       {
-               if( ! Conf_Oper[i].name[0] ) continue;
-               
-               /* Valid "Operator" section */
-               puts( "[OPERATOR]" );
-               printf( "  Name = %s\n", Conf_Oper[i].name );
-               printf( "  Password = %s\n", Conf_Oper[i].pwd );
-               puts( "" );
+       printf("  Name = %s\n", Conf_ServerName);
+       printf("  Info = %s\n", Conf_ServerInfo);
+#ifndef PAM
+       printf("  Password = %s\n", Conf_ServerPwd);
+#endif
+       printf("  WebircPassword = %s\n", Conf_WebircPwd);
+       printf("  AdminInfo1 = %s\n", Conf_ServerAdmin1);
+       printf("  AdminInfo2 = %s\n", Conf_ServerAdmin2);
+       printf("  AdminEMail = %s\n", Conf_ServerAdminMail);
+       if (Using_MotdFile) {
+               printf("  MotdFile = %s\n", Conf_MotdFile);
+               printf("  MotdPhrase =\n");
+       } else {
+               printf("  MotdFile = \n");
+               printf("  MotdPhrase = %s\n", array_bytes(&Conf_Motd)
+                      ? (const char*) array_start(&Conf_Motd) : "");
        }
+       printf("  ChrootDir = %s\n", Conf_Chroot);
+       printf("  PidFile = %s\n", Conf_PidFile);
+       printf("  Listen = %s\n", Conf_ListenAddress);
+       fputs("  Ports = ", stdout);
+       ports_puts(&Conf_ListenPorts);
+#ifdef SSL_SUPPORT
+       fputs("  SSLPorts = ", stdout);
+       ports_puts(&Conf_SSLOptions.ListenPorts);
+       if (!ConfSSL_Puts())
+               config_valid = false;
+#endif
 
-       for( i = 0; i < MAX_SERVERS; i++ )
-       {
+       pwd = getpwuid(Conf_UID);
+       if (pwd)
+               printf("  ServerUID = %s\n", pwd->pw_name);
+       else
+               printf("  ServerUID = %ld\n", (long)Conf_UID);
+       grp = getgrgid(Conf_GID);
+       if (grp)
+               printf("  ServerGID = %s\n", grp->gr_name);
+       else
+               printf("  ServerGID = %ld\n", (long)Conf_GID);
+#ifdef SYSLOG
+       printf("  SyslogFacility = %s\n",
+              ngt_SyslogFacilityName(Conf_SyslogFacility));
+#endif
+       printf("  PingTimeout = %d\n", Conf_PingTimeout);
+       printf("  PongTimeout = %d\n", Conf_PongTimeout);
+       printf("  ConnectRetry = %d\n", Conf_ConnectRetry);
+       printf("  OperCanUseMode = %s\n", yesno_to_str(Conf_OperCanMode));
+       printf("  OperServerMode = %s\n", yesno_to_str(Conf_OperServerMode));
+       printf("  AllowRemoteOper = %s\n", yesno_to_str(Conf_AllowRemoteOper));
+       printf("  PredefChannelsOnly = %s\n", yesno_to_str(Conf_PredefChannelsOnly));
+#ifdef WANT_IPV6
+       printf("  ConnectIPv4 = %s\n", yesno_to_str(Conf_ConnectIPv6));
+       printf("  ConnectIPv6 = %s\n", yesno_to_str(Conf_ConnectIPv4));
+#endif
+       printf("  MaxConnections = %ld\n", Conf_MaxConnections);
+       printf("  MaxConnectionsIP = %d\n", Conf_MaxConnectionsIP);
+       printf("  MaxJoins = %d\n", Conf_MaxJoins > 0 ? Conf_MaxJoins : -1);
+       printf("  MaxNickLength = %u\n", Conf_MaxNickLength - 1);
+       printf("  ClientHost = %s\n", Conf_ClientHost);
+       printf("  ClientUserNick = %s\n\n", yesno_to_str(Conf_ClientUserNick));
+
+       puts("[FEATURES]");
+       printf("  DNS = %s\n", yesno_to_str(Conf_DNS));
+       printf("  Ident = %s\n", yesno_to_str(Conf_Ident));
+       printf("  PAM = %s\n", yesno_to_str(Conf_PAM));
+       puts("");
+
+       opers_puts();
+
+       for( i = 0; i < MAX_SERVERS; i++ ) {
                if( ! Conf_Server[i].name[0] ) continue;
-               
+
                /* Valid "Server" section */
                puts( "[SERVER]" );
                printf( "  Name = %s\n", Conf_Server[i].name );
                printf( "  Host = %s\n", Conf_Server[i].host );
-               printf( "  Port = %d\n", Conf_Server[i].port );
+               printf( "  Port = %u\n", (unsigned int)Conf_Server[i].port );
+#ifdef SSL_SUPPORT
+               printf( "  SSLConnect = %s\n", Conf_Server[i].SSLConnect?"yes":"no");
+#endif
                printf( "  MyPassword = %s\n", Conf_Server[i].pwd_in );
                printf( "  PeerPassword = %s\n", Conf_Server[i].pwd_out );
+               printf( "  ServiceMask = %s\n", Conf_Server[i].svs_mask);
                printf( "  Group = %d\n", Conf_Server[i].group );
-               puts( "" );
+               printf( "  Passive = %s\n\n", Conf_Server[i].flags & CONF_SFLAG_DISABLED ? "yes" : "no");
        }
 
-       for( i = 0; i < Conf_Channel_Count; i++ )
-       {
-               if( ! Conf_Channel[i].name[0] ) continue;
-               
+       predef_channel_count = array_length(&Conf_Channels, sizeof(*predef_chan));
+       predef_chan = array_start(&Conf_Channels);
+
+       for (i = 0; i < predef_channel_count; i++, predef_chan++) {
+               if (!predef_chan->name[0])
+                       continue;
+
                /* Valid "Channel" section */
                puts( "[CHANNEL]" );
-               printf( "  Name = %s\n", Conf_Channel[i].name );
-               printf( "  Modes = %s\n", Conf_Channel[i].modes );
-               printf( "  Topic = %s\n", Conf_Channel[i].topic );
-               puts( "" );
+               printf("  Name = %s\n", predef_chan->name);
+               printf("  Modes = %s\n", predef_chan->modes);
+               printf("  Key = %s\n", predef_chan->key);
+               printf("  MaxUsers = %lu\n", predef_chan->maxusers);
+               printf("  Topic = %s\n", predef_chan->topic);
+               printf("  KeyFile = %s\n\n", predef_chan->keyfile);
        }
-       
-       return 0;
+
+       return (config_valid ? 0 : 1);
 } /* Conf_Test */
 
 
-GLOBAL VOID
+GLOBAL void
 Conf_UnsetServer( CONN_ID Idx )
 {
        /* Set next time for next connection attempt, if this is a server
@@ -190,36 +410,36 @@ Conf_UnsetServer( CONN_ID Idx )
         * "once", delete it from our configuration.
         * Non-Server-Connections will be silently ignored. */
 
-       INT i;
+       int i;
+       time_t t;
 
        /* Check all our configured servers */
-       for( i = 0; i < MAX_SERVERS; i++ )
-       {
+       for( i = 0; i < MAX_SERVERS; i++ ) {
                if( Conf_Server[i].conn_id != Idx ) continue;
 
                /* Gotcha! Mark server configuration as "unused": */
                Conf_Server[i].conn_id = NONE;
 
-               if( Conf_Server[i].flags & CONF_SFLAG_ONCE )
-               {
+               if( Conf_Server[i].flags & CONF_SFLAG_ONCE ) {
                        /* Delete configuration here */
                        Init_Server_Struct( &Conf_Server[i] );
-               }
-               else
-               {
+               } else {
                        /* Set time for next connect attempt */
-                       if( Conf_Server[i].lasttry <  time( NULL ) - Conf_ConnectRetry )
-                       {
-                               /* Okay, the connection was established "long enough": */
-                               Conf_Server[i].lasttry = time( NULL ) - Conf_ConnectRetry + RECONNECT_DELAY;
-                       }
+                       t = time(NULL);
+                       if (Conf_Server[i].lasttry < t - Conf_ConnectRetry) {
+                               /* The connection has been "long", so we don't
+                                * require the next attempt to be delayed. */
+                               Conf_Server[i].lasttry =
+                                       t - Conf_ConnectRetry + RECONNECT_DELAY;
+                       } else
+                               Conf_Server[i].lasttry = t;
                }
        }
 } /* Conf_UnsetServer */
 
 
-GLOBAL VOID
-Conf_SetServer( INT ConfServer, CONN_ID Idx )
+GLOBAL void
+Conf_SetServer( int ConfServer, CONN_ID Idx )
 {
        /* Set connection for specified configured server */
 
@@ -230,75 +450,88 @@ Conf_SetServer( INT ConfServer, CONN_ID Idx )
 } /* Conf_SetServer */
 
 
-GLOBAL INT
+GLOBAL int
 Conf_GetServer( CONN_ID Idx )
 {
        /* Get index of server in configuration structure */
-       
-       INT i = 0;
-       
+
+       int i = 0;
+
        assert( Idx > NONE );
 
-       for( i = 0; i < MAX_SERVERS; i++ )
-       {
+       for( i = 0; i < MAX_SERVERS; i++ ) {
                if( Conf_Server[i].conn_id == Idx ) return i;
        }
        return NONE;
 } /* Conf_GetServer */
 
 
-GLOBAL BOOLEAN
-Conf_EnableServer( CHAR *Name, INT Port )
+GLOBAL bool
+Conf_EnableServer( const char *Name, UINT16 Port )
 {
        /* Enable specified server and adjust port */
 
-       INT i;
+       int i;
 
        assert( Name != NULL );
 
-       for( i = 0; i < MAX_SERVERS; i++ )
-       {
-               if( strcasecmp( Conf_Server[i].name, Name ) == 0 )
-               {
+       for( i = 0; i < MAX_SERVERS; i++ ) {
+               if( strcasecmp( Conf_Server[i].name, Name ) == 0 ) {
                        /* Gotcha! Set port and enable server: */
                        Conf_Server[i].port = Port;
                        Conf_Server[i].flags &= ~CONF_SFLAG_DISABLED;
-                       return TRUE;
+                       return (Conf_Server[i].port && Conf_Server[i].host[0]);
                }
        }
-       return FALSE;
+       return false;
 } /* Conf_EnableServer */
 
 
-GLOBAL BOOLEAN
-Conf_DisableServer( CHAR *Name )
+GLOBAL bool
+Conf_EnablePassiveServer(const char *Name)
+{
+       /* Enable specified server */
+       int i;
+
+       assert( Name != NULL );
+       for (i = 0; i < MAX_SERVERS; i++) {
+               if ((strcasecmp( Conf_Server[i].name, Name ) == 0) && (Conf_Server[i].port > 0)) {
+                       /* BINGO! Enable server */
+                       Conf_Server[i].flags &= ~CONF_SFLAG_DISABLED;
+                       return true;
+               }
+       }
+       return false;
+} /* Conf_EnablePassiveServer */
+
+
+GLOBAL bool
+Conf_DisableServer( const char *Name )
 {
        /* Enable specified server and adjust port */
 
-       INT i;
+       int i;
 
        assert( Name != NULL );
 
-       for( i = 0; i < MAX_SERVERS; i++ )
-       {
-               if( strcasecmp( Conf_Server[i].name, Name ) == 0 )
-               {
+       for( i = 0; i < MAX_SERVERS; i++ ) {
+               if( strcasecmp( Conf_Server[i].name, Name ) == 0 ) {
                        /* Gotcha! Disable and disconnect server: */
                        Conf_Server[i].flags |= CONF_SFLAG_DISABLED;
-                       if( Conf_Server[i].conn_id > NONE ) Conn_Close( Conf_Server[i].conn_id, NULL, "Server link terminated on operator request", TRUE );
-                       return TRUE;
+                       if( Conf_Server[i].conn_id > NONE ) Conn_Close( Conf_Server[i].conn_id, NULL, "Server link terminated on operator request", true);
+                       return true;
                }
        }
-       return FALSE;
+       return false;
 } /* Conf_DisableServer */
 
 
-GLOBAL BOOLEAN
-Conf_AddServer( CHAR *Name, INT Port, CHAR *Host, CHAR *MyPwd, CHAR *PeerPwd )
+GLOBAL bool
+Conf_AddServer( const char *Name, UINT16 Port, const char *Host, const char *MyPwd, const char *PeerPwd )
 {
        /* Add new server to configuration */
 
-       INT i;
+       int i;
 
        assert( Name != NULL );
        assert( Host != NULL );
@@ -306,12 +539,11 @@ Conf_AddServer( CHAR *Name, INT Port, CHAR *Host, CHAR *MyPwd, CHAR *PeerPwd )
        assert( PeerPwd != NULL );
 
        /* Search unused item in server configuration structure */
-       for( i = 0; i < MAX_SERVERS; i++ )
-       {
+       for( i = 0; i < MAX_SERVERS; i++ ) {
                /* Is this item used? */
                if( ! Conf_Server[i].name[0] ) break;
        }
-       if( i >= MAX_SERVERS ) return FALSE;
+       if( i >= MAX_SERVERS ) return false;
 
        Init_Server_Struct( &Conf_Server[i] );
        strlcpy( Conf_Server[i].name, Name, sizeof( Conf_Server[i].name ));
@@ -320,72 +552,173 @@ Conf_AddServer( CHAR *Name, INT Port, CHAR *Host, CHAR *MyPwd, CHAR *PeerPwd )
        strlcpy( Conf_Server[i].pwd_in, PeerPwd, sizeof( Conf_Server[i].pwd_in ));
        Conf_Server[i].port = Port;
        Conf_Server[i].flags = CONF_SFLAG_ONCE;
-       
-       return TRUE;
+
+       return true;
 } /* Conf_AddServer */
 
 
-LOCAL VOID
-Set_Defaults( BOOLEAN InitServers )
+/**
+ * Check if the given nick name is an service
+ */
+GLOBAL bool
+Conf_IsService(int ConfServer, const char *Nick)
+{
+       return MatchCaseInsensitive(Conf_Server[ConfServer].svs_mask, Nick);
+} /* Conf_IsService */
+
+
+static void
+Set_Defaults_Optional(void)
 {
-       /* Initialize configuration variables with default values. */
+#ifdef IDENTAUTH
+       Conf_Ident = true;
+#else
+       Conf_Ident = false;
+#endif
+#ifdef PAM
+       Conf_PAM = true;
+#else
+       Conf_PAM = false;
+#endif
+}
 
-       INT i;
 
-       strcpy( Conf_ServerName, "" );
-       sprintf( Conf_ServerInfo, "%s %s", PACKAGE_NAME, PACKAGE_VERSION );
-       strcpy( Conf_ServerPwd, "" );
+/**
+ * Initialize configuration settings with their default values.
+ */
+static void
+Set_Defaults(bool InitServers)
+{
+       int i;
 
-       strcpy( Conf_ServerAdmin1, "" );
-       strcpy( Conf_ServerAdmin2, "" );
-       strcpy( Conf_ServerAdminMail, "" );
+       strcpy(Conf_ServerName, "");
+       strcpy(Conf_ClientHost, "");
+       Conf_ClientUserNick = false;
+       snprintf(Conf_ServerInfo, sizeof Conf_ServerInfo, "%s %s",
+                PACKAGE_NAME, PACKAGE_VERSION);
+       strcpy(Conf_ServerPwd, "");
 
-       strlcpy( Conf_MotdFile, SYSCONFDIR, sizeof( Conf_MotdFile ));
-       strlcat( Conf_MotdFile, MOTD_FILE, sizeof( Conf_MotdFile ));
+       strcpy(Conf_ServerAdmin1, "");
+       strcpy(Conf_ServerAdmin2, "");
+       strcpy(Conf_ServerAdminMail, "");
 
-       Conf_ListenPorts_Count = 0;
-       strcpy( Conf_ListenAddress, "" );
+       strlcpy(Conf_MotdFile, SYSCONFDIR, sizeof(Conf_MotdFile));
+       strlcat(Conf_MotdFile, MOTD_FILE, sizeof(Conf_MotdFile));
 
        Conf_UID = Conf_GID = 0;
-       
+       strlcpy(Conf_Chroot, CHROOT_DIR, sizeof(Conf_Chroot));
+       strlcpy(Conf_PidFile, PID_FILE, sizeof(Conf_PidFile));
+
+       free(Conf_ListenAddress);
+       Conf_ListenAddress = NULL;
+
        Conf_PingTimeout = 120;
        Conf_PongTimeout = 20;
-
        Conf_ConnectRetry = 60;
+       Conf_DNS = true;
 
        Conf_Oper_Count = 0;
        Conf_Channel_Count = 0;
 
-       Conf_OperCanMode = FALSE;
-       
-       Conf_MaxConnections = -1;
+       Conf_OperCanMode = false;
+       Conf_OperServerMode = false;
+       Conf_AllowRemoteOper = false;
+       Conf_PredefChannelsOnly = false;
+
+       Conf_ConnectIPv4 = true;
+       Conf_ConnectIPv6 = true;
+
+       Conf_MaxConnections = 0;
        Conf_MaxConnectionsIP = 5;
        Conf_MaxJoins = 10;
+       Conf_MaxNickLength = CLIENT_NICK_LEN_DEFAULT;
+
+#ifdef SYSLOG
+#ifdef LOG_LOCAL5
+       Conf_SyslogFacility = LOG_LOCAL5;
+#else
+       Conf_SyslogFacility = 0;
+#endif
+#endif
+       Set_Defaults_Optional();
 
        /* Initialize server configuration structures */
-       if( InitServers ) for( i = 0; i < MAX_SERVERS; Init_Server_Struct( &Conf_Server[i++] ));
+       if (InitServers) {
+               for (i = 0; i < MAX_SERVERS;
+                    Init_Server_Struct(&Conf_Server[i++]));
+       }
+
+       /* Free MOTD; this is important when reloading the configuration */
+       array_free(&Conf_Motd);
 } /* Set_Defaults */
 
 
-LOCAL VOID
-Read_Config( VOID )
+static bool
+no_listenports(void)
+{
+       size_t cnt = array_bytes(&Conf_ListenPorts);
+#ifdef SSL_SUPPORT
+       cnt += array_bytes(&Conf_SSLOptions.ListenPorts);
+#endif
+       return cnt == 0;
+}
+
+static void
+Read_Motd(const char *filename)
+{
+       char line[127];
+       FILE *fp;
+
+       if (*filename == '\0')
+               return;
+
+       fp = fopen(filename, "r");
+       if (!fp) {
+               Config_Error(LOG_WARNING, "Can't read MOTD file \"%s\": %s",
+                                       filename, strerror(errno));
+               return;
+       }
+
+       array_free(&Conf_Motd);
+       Using_MotdFile = true;
+
+       while (fgets(line, (int)sizeof line, fp)) {
+               ngt_TrimLastChr( line, '\n');
+
+               /* add text including \0 */
+               if (!array_catb(&Conf_Motd, line, strlen(line) + 1)) {
+                       Log(LOG_WARNING, "Cannot add MOTD text: %s", strerror(errno));
+                       break;
+               }
+       }
+       fclose(fp);
+}
+
+static bool
+Read_Config( bool ngircd_starting )
 {
        /* Read configuration file. */
 
-       CHAR section[LINE_LEN], str[LINE_LEN], *var, *arg, *ptr;
-       INT line, i, n;
+       char section[LINE_LEN], str[LINE_LEN], *var, *arg, *ptr;
+       const UINT16 defaultport = 6667;
+       int line, i, n;
        FILE *fd;
 
        /* Open configuration file */
        fd = fopen( NGIRCd_ConfFile, "r" );
-       if( ! fd )
-       {
+       if( ! fd ) {
                /* No configuration file found! */
-               Config_Error( LOG_ALERT, "Can't read configuration \"%s\": %s", NGIRCd_ConfFile, strerror( errno ));
+               Config_Error( LOG_ALERT, "Can't read configuration \"%s\": %s",
+                                       NGIRCd_ConfFile, strerror( errno ));
+               if (!ngircd_starting)
+                       return false;
                Config_Error( LOG_ALERT, "%s exiting due to fatal errors!", PACKAGE_NAME );
                exit( 1 );
        }
 
+       opers_free();
+       Set_Defaults( ngircd_starting );
+
        Config_Error( LOG_INFO, "Reading configuration from \"%s\" ...", NGIRCd_ConfFile );
 
        /* Clean up server configuration structure: mark all already
@@ -394,28 +727,24 @@ Read_Config( VOID )
         * And delete all servers which are "duplicates" of servers
         * that are already marked as "once" (such servers have been
         * created by the last rehash but are now useless). */
-       for( i = 0; i < MAX_SERVERS; i++ )
-       {
+       for( i = 0; i < MAX_SERVERS; i++ ) {
                if( Conf_Server[i].conn_id == NONE ) Init_Server_Struct( &Conf_Server[i] );
-               else
-               {
+               else {
                        /* This structure is in use ... */
-                       if( Conf_Server[i].flags & CONF_SFLAG_ONCE )
-                       {
+                       if( Conf_Server[i].flags & CONF_SFLAG_ONCE ) {
                                /* Check for duplicates */
-                               for( n = 0; n < MAX_SERVERS; n++ )
-                               {
+                               for( n = 0; n < MAX_SERVERS; n++ ) {
                                        if( n == i ) continue;
 
-                                       if( Conf_Server[i].conn_id == Conf_Server[n].conn_id )
-                                       {
+                                       if( Conf_Server[i].conn_id == Conf_Server[n].conn_id ) {
                                                Init_Server_Struct( &Conf_Server[n] );
-                                               Log( LOG_DEBUG, "Deleted unused duplicate server %d (kept %d).", n, i );
+#ifdef DEBUG
+                                               Log(LOG_DEBUG,"Deleted unused duplicate server %d (kept %d).",
+                                                                                               n, i );
+#endif
                                        }
                                }
-                       }
-                       else
-                       {
+                       } else {
                                /* Mark server as "once" */
                                Conf_Server[i].flags |= CONF_SFLAG_ONCE;
                                Log( LOG_DEBUG, "Marked server %d as \"once\"", i );
@@ -428,10 +757,11 @@ Read_Config( VOID )
        strcpy( section, "" );
        Init_Server_Struct( &New_Server );
        New_Server_Idx = NONE;
-
+#ifdef SSL_SUPPORT
+       ConfSSL_Init();
+#endif
        /* Read configuration file */
-       while( TRUE )
-       {
+       while( true ) {
                if( ! fgets( str, LINE_LEN, fd )) break;
                ngt_TrimStr( str );
                line++;
@@ -440,27 +770,15 @@ Read_Config( VOID )
                if( str[0] == ';' || str[0] == '#' || str[0] == '\0' ) continue;
 
                /* Is this the beginning of a new section? */
-               if(( str[0] == '[' ) && ( str[strlen( str ) - 1] == ']' ))
-               {
+               if(( str[0] == '[' ) && ( str[strlen( str ) - 1] == ']' )) {
                        strlcpy( section, str, sizeof( section ));
-                       if( strcasecmp( section, "[GLOBAL]" ) == 0 ) continue;
-                       if( strcasecmp( section, "[OPERATOR]" ) == 0 )
-                       {
-                               if( Conf_Oper_Count + 1 > MAX_OPERATORS ) Config_Error( LOG_ERR, "Too many operators configured." );
-                               else
-                               {
-                                       /* Initialize new operator structure */
-                                       strcpy( Conf_Oper[Conf_Oper_Count].name, "" );
-                                       strcpy( Conf_Oper[Conf_Oper_Count].pwd, "" );
-                                       Conf_Oper_Count++;
-                               }
+                       if (strcasecmp( section, "[GLOBAL]" ) == 0 ||
+                           strcasecmp( section, "[FEATURES]") == 0)
                                continue;
-                       }
-                       if( strcasecmp( section, "[SERVER]" ) == 0 )
-                       {
+
+                       if( strcasecmp( section, "[SERVER]" ) == 0 ) {
                                /* Check if there is already a server to add */
-                               if( New_Server.name[0] )
-                               {
+                               if( New_Server.name[0] ) {
                                        /* Copy data to "real" server structure */
                                        assert( New_Server_Idx > NONE );
                                        Conf_Server[New_Server_Idx] = New_Server;
@@ -470,13 +788,11 @@ Read_Config( VOID )
                                Init_Server_Struct( &New_Server );
 
                                /* Search unused item in server configuration structure */
-                               for( i = 0; i < MAX_SERVERS; i++ )
-                               {
+                               for( i = 0; i < MAX_SERVERS; i++ ) {
                                        /* Is this item used? */
                                        if( ! Conf_Server[i].name[0] ) break;
                                }
-                               if( i >= MAX_SERVERS )
-                               {
+                               if( i >= MAX_SERVERS ) {
                                        /* Oops, no free item found! */
                                        Config_Error( LOG_ERR, "Too many servers configured." );
                                        New_Server_Idx = NONE;
@@ -484,19 +800,15 @@ Read_Config( VOID )
                                else New_Server_Idx = i;
                                continue;
                        }
-                       if( strcasecmp( section, "[CHANNEL]" ) == 0 )
-                       {
-                               if( Conf_Channel_Count + 1 > MAX_DEFCHANNELS ) Config_Error( LOG_ERR, "Too many pre-defined channels configured." );
-                               else
-                               {
-                                       /* Initialize new channel structure */
-                                       strcpy( Conf_Channel[Conf_Channel_Count].name, "" );
-                                       strcpy( Conf_Channel[Conf_Channel_Count].modes, "" );
-                                       strcpy( Conf_Channel[Conf_Channel_Count].topic, "" );
-                                       Conf_Channel_Count++;
-                               }
+                       if (strcasecmp(section, "[CHANNEL]") == 0) {
+                               Conf_Channel_Count++;
+                               continue;
+                       }
+                       if (strcasecmp(section, "[OPERATOR]") == 0) {
+                               Conf_Oper_Count++;
                                continue;
                        }
+
                        Config_Error( LOG_ERR, "%s, line %d: Unknown section \"%s\"!", NGIRCd_ConfFile, line, section );
                        section[0] = 0x1;
                }
@@ -504,8 +816,7 @@ Read_Config( VOID )
 
                /* Split line into variable name and parameters */
                ptr = strchr( str, '=' );
-               if( ! ptr )
-               {
+               if( ! ptr ) {
                        Config_Error( LOG_ERR, "%s, line %d: Syntax error!", NGIRCd_ConfFile, line );
                        continue;
                }
@@ -514,6 +825,7 @@ Read_Config( VOID )
                arg = ptr + 1; ngt_TrimStr( arg );
 
                if( strcasecmp( section, "[GLOBAL]" ) == 0 ) Handle_GLOBAL( line, var, arg );
+               else if( strcasecmp( section, "[FEATURES]" ) == 0 ) Handle_FEATURES( line, var, arg );
                else if( strcasecmp( section, "[OPERATOR]" ) == 0 ) Handle_OPERATOR( line, var, arg );
                else if( strcasecmp( section, "[SERVER]" ) == 0 ) Handle_SERVER( line, var, arg );
                else if( strcasecmp( section, "[CHANNEL]" ) == 0 ) Handle_CHANNEL( line, var, arg );
@@ -524,240 +836,497 @@ Read_Config( VOID )
        fclose( fd );
 
        /* Check if there is still a server to add */
-       if( New_Server.name[0] )
-       {
+       if( New_Server.name[0] ) {
                /* Copy data to "real" server structure */
                assert( New_Server_Idx > NONE );
                Conf_Server[New_Server_Idx] = New_Server;
        }
-       
-       /* If there are no ports configured use the default: 6667 */
-       if( Conf_ListenPorts_Count < 1 )
+
+       /* not a single listening port? Add default. */
+       if (no_listenports() &&
+               !array_copyb(&Conf_ListenPorts, (char*) &defaultport, sizeof defaultport))
        {
-               Conf_ListenPorts_Count = 1;
-               Conf_ListenPorts[0] = 6667;
+               Config_Error(LOG_ALERT, "Could not add default listening Port %u: %s",
+                                       (unsigned int) defaultport, strerror(errno));
+
+               exit(1);
        }
+
+       if (!Conf_ListenAddress)
+               Conf_ListenAddress = strdup_warn(DEFAULT_LISTEN_ADDRSTR);
+
+       if (!Conf_ListenAddress) {
+               Config_Error(LOG_ALERT, "%s exiting due to fatal errors!", PACKAGE_NAME);
+               exit(1);
+       }
+
+       /* No MOTD phrase configured? (re)try motd file. */
+       if (array_bytes(&Conf_Motd) == 0)
+               Read_Motd(Conf_MotdFile);
+       return true;
 } /* Read_Config */
 
 
-LOCAL VOID
-Handle_GLOBAL( INT Line, CHAR *Var, CHAR *Arg )
+static bool
+Check_ArgIsTrue( const char *Arg )
+{
+       if( strcasecmp( Arg, "yes" ) == 0 ) return true;
+       if( strcasecmp( Arg, "true" ) == 0 ) return true;
+       if( atoi( Arg ) != 0 ) return true;
+
+       return false;
+} /* Check_ArgIsTrue */
+
+
+static unsigned int
+Handle_MaxNickLength(int Line, const char *Arg)
+{
+       unsigned new;
+
+       new = (unsigned) atoi(Arg) + 1;
+       if (new > CLIENT_NICK_LEN) {
+               Config_Error(LOG_WARNING,
+                            "%s, line %d: Value of \"MaxNickLength\" exceeds %u!",
+                            NGIRCd_ConfFile, Line, CLIENT_NICK_LEN - 1);
+               return CLIENT_NICK_LEN;
+       }
+       if (new < 2) {
+               Config_Error(LOG_WARNING,
+                            "%s, line %d: Value of \"MaxNickLength\" must be at least 1!",
+                            NGIRCd_ConfFile, Line);
+               return 2;
+       }
+       return new;
+} /* Handle_MaxNickLength */
+
+
+static void
+WarnIdent(int UNUSED Line)
+{
+#ifndef IDENTAUTH
+       if (Conf_Ident) {
+               /* user has enabled ident lookups explicitly, but ... */
+               Config_Error(LOG_WARNING,
+                       "%s: line %d: %s=True, but ngircd was built without support",
+                       NGIRCd_ConfFile, Line, "Ident");
+       }
+#endif
+}
+
+static void
+WarnPAM(int UNUSED Line)
+{
+#ifndef PAM
+       if (Conf_PAM) {
+               Config_Error(LOG_WARNING,
+                       "%s: line %d: %s=True, but ngircd was built without support",
+                       NGIRCd_ConfFile, Line, "PAM");
+       }
+#endif
+}
+
+static bool
+CheckLegacyNoOption(const char *Var, const char *Arg)
+{
+       if( strcasecmp( Var, "NoDNS" ) == 0 ) {
+               Conf_DNS = !Check_ArgIsTrue( Arg );
+               return true;
+       }
+       if (strcasecmp(Var, "NoIdent") == 0) {
+               Conf_Ident = !Check_ArgIsTrue(Arg);
+               return true;
+       }
+       if(strcasecmp(Var, "NoPAM") == 0) {
+               Conf_PAM = !Check_ArgIsTrue(Arg);
+               return true;
+       }
+       return false;
+}
+
+static const char *
+NoNo(const char *str)
+{
+       assert(strncasecmp("no", str, 2) == 0 && str[2]);
+       return str + 2;
+}
+
+static const char *
+InvertArg(const char *arg)
+{
+       return yesno_to_str(!Check_ArgIsTrue(arg));
+}
+
+static void
+Handle_GLOBAL( int Line, char *Var, char *Arg )
 {
        struct passwd *pwd;
        struct group *grp;
-       CHAR *ptr;
-       LONG port;
+       size_t len;
        
        assert( Line > 0 );
        assert( Var != NULL );
        assert( Arg != NULL );
        
-       if( strcasecmp( Var, "Name" ) == 0 )
-       {
+       if( strcasecmp( Var, "Name" ) == 0 ) {
                /* Server name */
-               if( strlcpy( Conf_ServerName, Arg, sizeof( Conf_ServerName )) >= sizeof( Conf_ServerName )) Config_Error( LOG_WARNING, "%s, line %d: Value of \"Name\" too long!", NGIRCd_ConfFile, Line );
+               len = strlcpy( Conf_ServerName, Arg, sizeof( Conf_ServerName ));
+               if (len >= sizeof( Conf_ServerName ))
+                       Config_Error_TooLong( Line, Var );
                return;
        }
-       if( strcasecmp( Var, "Info" ) == 0 )
-       {
+       if( strcasecmp( Var, "ClientHost" ) == 0 ) {
+               /* Client hostname */
+               len = strlcpy( Conf_ClientHost, Arg, sizeof( Conf_ClientHost ));
+               if (len >= sizeof( Conf_ClientHost ))
+                       Config_Error_TooLong( Line, Var );
+               return;
+       }
+       if( strcasecmp( Var, "ClientUserNick" ) == 0 ) {
+               /* Use client nick name as user name */
+               Conf_ClientUserNick = Check_ArgIsTrue( Arg );
+               return;
+       }
+       if( strcasecmp( Var, "Info" ) == 0 ) {
                /* Info text of server */
-               if( strlcpy( Conf_ServerInfo, Arg, sizeof( Conf_ServerInfo )) >= sizeof( Conf_ServerInfo )) Config_Error( LOG_WARNING, "%s, line %d: Value of \"Info\" too long!", NGIRCd_ConfFile, Line );
+               len = strlcpy( Conf_ServerInfo, Arg, sizeof( Conf_ServerInfo ));
+               if (len >= sizeof( Conf_ServerInfo ))
+                       Config_Error_TooLong ( Line, Var );
                return;
        }
-       if( strcasecmp( Var, "Password" ) == 0 )
-       {
+       if( strcasecmp( Var, "Password" ) == 0 ) {
                /* Global server password */
-               if( strlcpy( Conf_ServerPwd, Arg, sizeof( Conf_ServerPwd )) >= sizeof( Conf_ServerPwd )) Config_Error( LOG_WARNING, "%s, line %d: Value of \"Password\" too long!", NGIRCd_ConfFile, Line );
+               len = strlcpy( Conf_ServerPwd, Arg, sizeof( Conf_ServerPwd ));
+               if (len >= sizeof( Conf_ServerPwd ))
+                       Config_Error_TooLong( Line, Var );
                return;
        }
-       if( strcasecmp( Var, "AdminInfo1" ) == 0 )
-       {
+       if (strcasecmp(Var, "WebircPassword") == 0) {
+               /* Password required for WEBIRC command */
+               len = strlcpy(Conf_WebircPwd, Arg, sizeof(Conf_WebircPwd));
+               if (len >= sizeof(Conf_WebircPwd))
+                       Config_Error_TooLong(Line, Var);
+               return;
+       }
+       if( strcasecmp( Var, "AdminInfo1" ) == 0 ) {
                /* Administrative info #1 */
-               if( strlcpy( Conf_ServerAdmin1, Arg, sizeof( Conf_ServerAdmin1 )) >= sizeof( Conf_ServerAdmin1 )) Config_Error( LOG_WARNING, "%s, line %d: Value of \"AdminInfo1\" too long!", NGIRCd_ConfFile, Line );
+               len = strlcpy( Conf_ServerAdmin1, Arg, sizeof( Conf_ServerAdmin1 ));
+               if (len >= sizeof( Conf_ServerAdmin1 ))
+                       Config_Error_TooLong ( Line, Var );
                return;
        }
-       if( strcasecmp( Var, "AdminInfo2" ) == 0 )
-       {
+       if( strcasecmp( Var, "AdminInfo2" ) == 0 ) {
                /* Administrative info #2 */
-               if( strlcpy( Conf_ServerAdmin2, Arg, sizeof( Conf_ServerAdmin2 )) >= sizeof( Conf_ServerAdmin2 )) Config_Error( LOG_WARNING, "%s, line %d: Value of \"AdminInfo2\" too long!", NGIRCd_ConfFile, Line );
+               len = strlcpy( Conf_ServerAdmin2, Arg, sizeof( Conf_ServerAdmin2 ));
+               if (len >= sizeof( Conf_ServerAdmin2 ))
+                       Config_Error_TooLong ( Line, Var );
                return;
        }
-       if( strcasecmp( Var, "AdminEMail" ) == 0 )
-       {
+       if( strcasecmp( Var, "AdminEMail" ) == 0 ) {
                /* Administrative email contact */
-               if( strlcpy( Conf_ServerAdminMail, Arg, sizeof( Conf_ServerAdminMail )) >= sizeof( Conf_ServerAdminMail )) Config_Error( LOG_WARNING, "%s, line %d: Value of \"AdminEMail\" too long!", NGIRCd_ConfFile, Line );
+               len = strlcpy( Conf_ServerAdminMail, Arg, sizeof( Conf_ServerAdminMail ));
+               if (len >= sizeof( Conf_ServerAdminMail ))
+                       Config_Error_TooLong( Line, Var );
                return;
        }
-       if( strcasecmp( Var, "Ports" ) == 0 )
-       {
-               /* Ports on that the server should listen. More port numbers
-                * must be separated by "," */
-               ptr = strtok( Arg, "," );
-               while( ptr )
-               {
-                       ngt_TrimStr( ptr );
-                       port = atol( ptr );
-                       if( Conf_ListenPorts_Count + 1 > MAX_LISTEN_PORTS ) Config_Error( LOG_ERR, "Too many listen ports configured. Port %ld ignored.", port );
-                       else
-                       {
-                               if( port > 0 && port < 0xFFFF ) Conf_ListenPorts[Conf_ListenPorts_Count++] = (UINT)port;
-                               else Config_Error( LOG_ERR, "%s, line %d (section \"Global\"): Illegal port number %ld!", NGIRCd_ConfFile, Line, port );
-                       }
-                       ptr = strtok( NULL, "," );
+
+       if( strcasecmp( Var, "Ports" ) == 0 ) {
+               ports_parse(&Conf_ListenPorts, Line, Arg);
+               return;
+       }
+       if( strcasecmp( Var, "MotdFile" ) == 0 ) {
+               len = strlcpy( Conf_MotdFile, Arg, sizeof( Conf_MotdFile ));
+               if (len >= sizeof( Conf_MotdFile ))
+                       Config_Error_TooLong( Line, Var );
+               return;
+       }
+       if( strcasecmp( Var, "MotdPhrase" ) == 0 ) {
+               /* "Message of the day" phrase (instead of file) */
+               len = strlen(Arg);
+               if (len == 0)
+                       return;
+               if (len >= LINE_LEN) {
+                       Config_Error_TooLong( Line, Var );
+                       return;
                }
+               if (!array_copyb(&Conf_Motd, Arg, len + 1))
+                       Config_Error(LOG_WARNING, "%s, line %d: Could not append MotdPhrase: %s",
+                                                       NGIRCd_ConfFile, Line, strerror(errno));
+               Using_MotdFile = false;
                return;
        }
-       if( strcasecmp( Var, "MotdFile" ) == 0 )
-       {
-               /* "Message of the day" (MOTD) file */
-               if( strlcpy( Conf_MotdFile, Arg, sizeof( Conf_MotdFile )) >= sizeof( Conf_MotdFile )) Config_Error( LOG_WARNING, "%s, line %d: Value of \"MotdFile\" too long!", NGIRCd_ConfFile, Line );
+       if( strcasecmp( Var, "ChrootDir" ) == 0 ) {
+               /* directory for chroot() */
+               len = strlcpy( Conf_Chroot, Arg, sizeof( Conf_Chroot ));
+               if (len >= sizeof( Conf_Chroot ))
+                       Config_Error_TooLong( Line, Var );
                return;
        }
-       if( strcasecmp( Var, "ServerUID" ) == 0 )
-       {
+       if ( strcasecmp( Var, "PidFile" ) == 0 ) {
+               /* name of pidfile */
+               len = strlcpy( Conf_PidFile, Arg, sizeof( Conf_PidFile ));
+               if (len >= sizeof( Conf_PidFile ))
+                       Config_Error_TooLong( Line, Var );
+               return;
+       }
+       if( strcasecmp( Var, "ServerUID" ) == 0 ) {
                /* UID the daemon should switch to */
                pwd = getpwnam( Arg );
                if( pwd ) Conf_UID = pwd->pw_uid;
-               else
-               {
-#ifdef HAVE_ISDIGIT
-                       if( ! isdigit( (INT)*Arg )) Config_Error( LOG_WARNING, "%s, line %d: Value of \"ServerUID\" is not a number!", NGIRCd_ConfFile, Line );
-                       else
-#endif
-                       Conf_UID = (UINT)atoi( Arg );
+               else {
+                       Conf_UID = (unsigned int)atoi( Arg );
+                       if (!Conf_UID && strcmp(Arg, "0"))
+                               Config_Error_NaN(Line, Var);
                }
                return;
        }
-       if( strcasecmp( Var, "ServerGID" ) == 0 )
-       {
+       if( strcasecmp( Var, "ServerGID" ) == 0 ) {
                /* GID the daemon should use */
                grp = getgrnam( Arg );
                if( grp ) Conf_GID = grp->gr_gid;
-               else
-               {
-#ifdef HAVE_ISDIGIT
-                       if( ! isdigit( (INT)*Arg )) Config_Error( LOG_WARNING, "%s, line %d: Value of \"ServerGID\" is not a number!", NGIRCd_ConfFile, Line );
-                       else
-#endif
-                       Conf_GID = (UINT)atoi( Arg );
+               else {
+                       Conf_GID = (unsigned int)atoi(Arg);
+                       if (!Conf_GID && strcmp(Arg, "0"))
+                               Config_Error_NaN( Line, Var );
                }
                return;
        }
-       if( strcasecmp( Var, "PingTimeout" ) == 0 )
-       {
+       if( strcasecmp( Var, "PingTimeout" ) == 0 ) {
                /* PING timeout */
                Conf_PingTimeout = atoi( Arg );
-               if( Conf_PingTimeout < 5 )
-               {
-                       Config_Error( LOG_WARNING, "%s, line %d: Value of \"PingTimeout\" too low!", NGIRCd_ConfFile, Line );
+               if( Conf_PingTimeout < 5 ) {
+                       Config_Error( LOG_WARNING, "%s, line %d: Value of \"PingTimeout\" too low!",
+                                                                       NGIRCd_ConfFile, Line );
                        Conf_PingTimeout = 5;
                }
                return;
        }
-       if( strcasecmp( Var, "PongTimeout" ) == 0 )
-       {
+       if( strcasecmp( Var, "PongTimeout" ) == 0 ) {
                /* PONG timeout */
                Conf_PongTimeout = atoi( Arg );
-               if( Conf_PongTimeout < 5 )
-               {
-                       Config_Error( LOG_WARNING, "%s, line %d: Value of \"PongTimeout\" too low!", NGIRCd_ConfFile, Line );
+               if( Conf_PongTimeout < 5 ) {
+                       Config_Error( LOG_WARNING, "%s, line %d: Value of \"PongTimeout\" too low!",
+                                                                       NGIRCd_ConfFile, Line );
                        Conf_PongTimeout = 5;
                }
                return;
        }
-       if( strcasecmp( Var, "ConnectRetry" ) == 0 )
-       {
+       if( strcasecmp( Var, "ConnectRetry" ) == 0 ) {
                /* Seconds between connection attempts to other servers */
                Conf_ConnectRetry = atoi( Arg );
-               if( Conf_ConnectRetry < 5 )
-               {
-                       Config_Error( LOG_WARNING, "%s, line %d: Value of \"ConnectRetry\" too low!", NGIRCd_ConfFile, Line );
+               if( Conf_ConnectRetry < 5 ) {
+                       Config_Error( LOG_WARNING, "%s, line %d: Value of \"ConnectRetry\" too low!",
+                                                                       NGIRCd_ConfFile, Line );
                        Conf_ConnectRetry = 5;
                }
                return;
        }
-       if( strcasecmp( Var, "OperCanUseMode" ) == 0 )
-       {
-               /* Are IRC operators allowed to use MODE in channels they aren't Op in? */
-               if( strcasecmp( Arg, "yes" ) == 0 ) Conf_OperCanMode = TRUE;
-               else if( strcasecmp( Arg, "true" ) == 0 ) Conf_OperCanMode = TRUE;
-               else if( atoi( Arg ) != 0 ) Conf_OperCanMode = TRUE;
-               else Conf_OperCanMode = FALSE;
+       if( strcasecmp( Var, "PredefChannelsOnly" ) == 0 ) {
+               /* Should we only allow pre-defined-channels? (i.e. users cannot create their own channels) */
+               Conf_PredefChannelsOnly = Check_ArgIsTrue( Arg );
+               return;
+       }
+
+       if (CheckLegacyNoOption(Var, Arg)) {
+               Config_Error(LOG_WARNING, "%s, line %d: \"No\"-Prefix has been removed, use "
+                               "\"%s = %s\" in [FEATURES] section instead",
+                                       NGIRCd_ConfFile, Line, NoNo(Var), InvertArg(Arg));
+               if (strcasecmp(Var, "NoIdent") == 0)
+                       WarnIdent(Line);
+               else if (strcasecmp(Var, "NoPam") == 0)
+                       WarnPAM(Line);
+               return;
+       }
+#ifdef WANT_IPV6
+       /* the default setting for all the WANT_IPV6 special options is 'true' */
+       if( strcasecmp( Var, "ConnectIPv6" ) == 0 ) {
+               /* connect to other hosts using ipv6, if they have an AAAA record? */
+               Conf_ConnectIPv6 = Check_ArgIsTrue( Arg );
+               return;
+       }
+       if( strcasecmp( Var, "ConnectIPv4" ) == 0 ) {
+               /* connect to other hosts using ipv4.
+                * again, this can be used for ipv6-only setups */
+               Conf_ConnectIPv4 = Check_ArgIsTrue( Arg );
                return;
        }
-       if( strcasecmp( Var, "MaxConnections" ) == 0 )
-       {
-               /* Maximum number of connections. Values <= 0 are equal to "no limit". */
-#ifdef HAVE_ISDIGIT
-               if( ! isdigit( (INT)*Arg )) Config_Error( LOG_WARNING, "%s, line %d: Value of \"MaxConnections\" is not a number!", NGIRCd_ConfFile, Line );
-               else
 #endif
+       if( strcasecmp( Var, "OperCanUseMode" ) == 0 ) {
+               /* Are IRC operators allowed to use MODE in channels they aren't Op in? */
+               Conf_OperCanMode = Check_ArgIsTrue( Arg );
+               return;
+       }
+       if( strcasecmp( Var, "OperServerMode" ) == 0 ) {
+               /* Mask IRC operator as if coming from the server? (ircd-irc2 compat hack) */
+               Conf_OperServerMode = Check_ArgIsTrue( Arg );
+               return;
+       }
+       if(strcasecmp(Var, "AllowRemoteOper") == 0) {
+               /* Are remote IRC operators allowed to control this server? */
+               Conf_AllowRemoteOper = Check_ArgIsTrue(Arg);
+               return;
+       }
+       if( strcasecmp( Var, "MaxConnections" ) == 0 ) {
+               /* Maximum number of connections. 0 -> "no limit". */
                Conf_MaxConnections = atol( Arg );
+               if (!Conf_MaxConnections && strcmp(Arg, "0"))
+                       Config_Error_NaN(Line, Var);
                return;
        }
-       if( strcasecmp( Var, "MaxConnectionsIP" ) == 0 )
-       {
-               /* Maximum number of simoultanous connections from one IP. Values <= 0 are equal to "no limit". */
-#ifdef HAVE_ISDIGIT
-               if( ! isdigit( (INT)*Arg )) Config_Error( LOG_WARNING, "%s, line %d: Value of \"MaxConnectionsIP\" is not a number!", NGIRCd_ConfFile, Line );
-               else
-#endif
+       if( strcasecmp( Var, "MaxConnectionsIP" ) == 0 ) {
+               /* Maximum number of simultaneous connections from one IP. 0 -> "no limit" */
                Conf_MaxConnectionsIP = atoi( Arg );
+               if (!Conf_MaxConnectionsIP && strcmp(Arg, "0"))
+                       Config_Error_NaN(Line, Var);
                return;
        }
-       if( strcasecmp( Var, "MaxJoins" ) == 0 )
-       {
-               /* Maximum number of channels a user can join. Values <= 0 are equal to "no limit". */
-#ifdef HAVE_ISDIGIT
-               if( ! isdigit( (INT)*Arg )) Config_Error( LOG_WARNING, "%s, line %d: Value of \"MaxJoins\" is not a number!", NGIRCd_ConfFile, Line );
-               else
-#endif
+       if( strcasecmp( Var, "MaxJoins" ) == 0 ) {
+               /* Maximum number of channels a user can join. 0 -> "no limit". */
                Conf_MaxJoins = atoi( Arg );
+               if (!Conf_MaxJoins && strcmp(Arg, "0"))
+                       Config_Error_NaN(Line, Var);
                return;
        }
-       if( strcasecmp( Var, "Listen" ) == 0 )
-       {
+       if( strcasecmp( Var, "MaxNickLength" ) == 0 ) {
+               /* Maximum length of a nick name; must be same on all servers
+                * within the IRC network! */
+               Conf_MaxNickLength = Handle_MaxNickLength(Line, Arg);
+               return;
+       }
+
+       if( strcasecmp( Var, "Listen" ) == 0 ) {
                /* IP-Address to bind sockets */
-               if( strlcpy( Conf_ListenAddress, Arg, sizeof( Conf_ListenAddress )) >= sizeof( Conf_ListenAddress ))
-               {
-                       Config_Error( LOG_WARNING, "%s, line %d: Value of \"Listen\" too long!", NGIRCd_ConfFile, Line );
+               if (Conf_ListenAddress) {
+                       Config_Error(LOG_ERR, "Multiple Listen= options, ignoring: %s", Arg);
+                       return;
+               }
+               Conf_ListenAddress = strdup_warn(Arg);
+               /*
+                * if allocation fails, we're in trouble:
+                * we cannot ignore the error -- otherwise ngircd
+                * would listen on all interfaces.
+                */
+               if (!Conf_ListenAddress) {
+                       Config_Error(LOG_ALERT, "%s exiting due to fatal errors!", PACKAGE_NAME);
+                       exit(1);
                }
                return;
        }
 
-       Config_Error( LOG_ERR, "%s, line %d (section \"Global\"): Unknown variable \"%s\"!", NGIRCd_ConfFile, Line, Var );
+#ifdef SSL_SUPPORT
+       if( strcasecmp( Var, "SSLPorts" ) == 0 ) {
+               ports_parse(&Conf_SSLOptions.ListenPorts, Line, Arg);
+               return;
+       }
+
+       if( strcasecmp( Var, "SSLKeyFile" ) == 0 ) {
+               assert(Conf_SSLOptions.KeyFile == NULL );
+               Conf_SSLOptions.KeyFile = strdup_warn(Arg);
+               return;
+       }
+       if( strcasecmp( Var, "SSLCertFile" ) == 0 ) {
+               assert(Conf_SSLOptions.CertFile == NULL );
+               Conf_SSLOptions.CertFile = strdup_warn(Arg);
+               return;
+       }
+
+       if( strcasecmp( Var, "SSLKeyFilePassword" ) == 0 ) {
+               assert(array_bytes(&Conf_SSLOptions.KeyFilePassword) == 0);
+               if (!array_copys(&Conf_SSLOptions.KeyFilePassword, Arg))
+                       Config_Error( LOG_ERR, "%s, line %d (section \"Global\"): Could not copy %s: %s!",
+                                                               NGIRCd_ConfFile, Line, Var, strerror(errno));
+               return;
+       }
+       if( strcasecmp( Var, "SSLDHFile" ) == 0 ) {
+               assert(Conf_SSLOptions.DHFile == NULL);
+               Conf_SSLOptions.DHFile = strdup_warn( Arg );
+                return;
+        }
+#endif
+#ifdef SYSLOG
+       if (strcasecmp(Var, "SyslogFacility") == 0) {
+               Conf_SyslogFacility = ngt_SyslogFacilityID(Arg,
+                                                          Conf_SyslogFacility);
+               return;
+       }
+#endif
+       Config_Error(LOG_ERR, "%s, line %d (section \"Global\"): Unknown variable \"%s\"!",
+                                                               NGIRCd_ConfFile, Line, Var);
 } /* Handle_GLOBAL */
 
 
-LOCAL VOID
-Handle_OPERATOR( INT Line, CHAR *Var, CHAR *Arg )
+static void
+Handle_FEATURES(int Line, char *Var, char *Arg)
 {
+       assert( Line > 0 );
+       assert( Var != NULL );
+       assert( Arg != NULL );
+
+       if( strcasecmp( Var, "DNS" ) == 0 ) {
+               /* do reverse dns lookups when clients connect? */
+               Conf_DNS = Check_ArgIsTrue( Arg );
+               return;
+       }
+       if (strcasecmp(Var, "Ident") == 0) {
+               /* do IDENT lookups when clients connect? */
+               Conf_Ident = Check_ArgIsTrue(Arg);
+               WarnIdent(Line);
+               return;
+       }
+       if(strcasecmp(Var, "PAM") == 0) {
+               /* use PAM library to authenticate users */
+               Conf_PAM = Check_ArgIsTrue(Arg);
+               WarnPAM(Line);
+               return;
+       }
+}
+
+static void
+Handle_OPERATOR( int Line, char *Var, char *Arg )
+{
+       size_t len;
+       struct Conf_Oper *op;
+
        assert( Line > 0 );
        assert( Var != NULL );
        assert( Arg != NULL );
        assert( Conf_Oper_Count > 0 );
 
-       if( strcasecmp( Var, "Name" ) == 0 )
-       {
+       op = array_alloc(&Conf_Opers, sizeof(*op), Conf_Oper_Count - 1);
+       if (!op) {
+               Config_Error(LOG_ERR, "Could not allocate memory for operator (%d:%s = %s)", Line, Var, Arg);
+               return;
+       }
+
+       if (strcasecmp(Var, "Name") == 0) {
                /* Name of IRC operator */
-               if( strlcpy( Conf_Oper[Conf_Oper_Count - 1].name, Arg, sizeof( Conf_Oper[Conf_Oper_Count - 1].name )) >= sizeof( Conf_Oper[Conf_Oper_Count - 1].name )) Config_Error( LOG_WARNING, "%s, line %d: Value of \"Name\" too long!", NGIRCd_ConfFile, Line );
+               len = strlcpy(op->name, Arg, sizeof(op->name));
+               if (len >= sizeof(op->name))
+                               Config_Error_TooLong(Line, Var);
                return;
        }
-       if( strcasecmp( Var, "Password" ) == 0 )
-       {
+       if (strcasecmp(Var, "Password") == 0) {
                /* Password of IRC operator */
-               if( strlcpy( Conf_Oper[Conf_Oper_Count - 1].pwd, Arg, sizeof( Conf_Oper[Conf_Oper_Count - 1].pwd )) >= sizeof( Conf_Oper[Conf_Oper_Count - 1].pwd )) Config_Error( LOG_WARNING, "%s, line %d: Value of \"Password\" too long!", NGIRCd_ConfFile, Line );
+               len = strlcpy(op->pwd, Arg, sizeof(op->pwd));
+               if (len >= sizeof(op->pwd))
+                               Config_Error_TooLong(Line, Var);
                return;
        }
-       
-       Config_Error( LOG_ERR, "%s, line %d (section \"Operator\"): Unknown variable \"%s\"!", NGIRCd_ConfFile, Line, Var );
+       if (strcasecmp(Var, "Mask") == 0) {
+               if (op->mask)
+                       return; /* Hostname already configured */
+               op->mask = strdup_warn( Arg );
+               return;
+       }
+       Config_Error( LOG_ERR, "%s, line %d (section \"Operator\"): Unknown variable \"%s\"!",
+                                                               NGIRCd_ConfFile, Line, Var );
 } /* Handle_OPERATOR */
 
 
-LOCAL VOID
-Handle_SERVER( INT Line, CHAR *Var, CHAR *Arg )
+static void
+Handle_SERVER( int Line, char *Var, char *Arg )
 {
-       LONG port;
+       long port;
+       size_t len;
        
        assert( Line > 0 );
        assert( Var != NULL );
@@ -766,169 +1335,300 @@ Handle_SERVER( INT Line, CHAR *Var, CHAR *Arg )
        /* Ignore server block if no space is left in server configuration structure */
        if( New_Server_Idx <= NONE ) return;
 
-       if( strcasecmp( Var, "Host" ) == 0 )
-       {
+       if( strcasecmp( Var, "Host" ) == 0 ) {
                /* Hostname of the server */
-               if( strlcpy( New_Server.host, Arg, sizeof( New_Server.host )) >= sizeof( New_Server.host )) Config_Error( LOG_WARNING, "%s, line %d: Value of \"Host\" too long!", NGIRCd_ConfFile, Line );
+               len = strlcpy( New_Server.host, Arg, sizeof( New_Server.host ));
+               if (len >= sizeof( New_Server.host ))
+                       Config_Error_TooLong ( Line, Var );
                return;
        }
-       if( strcasecmp( Var, "Name" ) == 0 )
-       {
+       if( strcasecmp( Var, "Name" ) == 0 ) {
                /* Name of the server ("Nick"/"ID") */
-               if( strlcpy( New_Server.name, Arg, sizeof( New_Server.name )) >= sizeof( New_Server.name )) Config_Error( LOG_WARNING, "%s, line %d: Value of \"Name\" too long!", NGIRCd_ConfFile, Line );
+               len = strlcpy( New_Server.name, Arg, sizeof( New_Server.name ));
+               if (len >= sizeof( New_Server.name ))
+                       Config_Error_TooLong( Line, Var );
                return;
        }
-       if( strcasecmp( Var, "MyPassword" ) == 0 )
-       {
+       if (strcasecmp(Var, "Bind") == 0) {
+               if (ng_ipaddr_init(&New_Server.bind_addr, Arg, 0))
+                       return;
+
+               Config_Error(LOG_ERR, "%s, line %d (section \"Server\"): Can't parse IP address \"%s\"",
+                               NGIRCd_ConfFile, Line, Arg);
+               return;
+       }
+       if( strcasecmp( Var, "MyPassword" ) == 0 ) {
                /* Password of this server which is sent to the peer */
-               if( strlcpy( New_Server.pwd_in, Arg, sizeof( New_Server.pwd_in )) >= sizeof( New_Server.pwd_in )) Config_Error( LOG_WARNING, "%s, line %d: Value of \"MyPassword\" too long!", NGIRCd_ConfFile, Line );
+               if (*Arg == ':') {
+                       Config_Error(LOG_ERR,
+                               "%s, line %d (section \"Server\"): MyPassword must not start with ':'!",
+                                                                               NGIRCd_ConfFile, Line);
+               }
+               len = strlcpy( New_Server.pwd_in, Arg, sizeof( New_Server.pwd_in ));
+               if (len >= sizeof( New_Server.pwd_in ))
+                       Config_Error_TooLong( Line, Var );
                return;
        }
-       if( strcasecmp( Var, "PeerPassword" ) == 0 )
-       {
+       if( strcasecmp( Var, "PeerPassword" ) == 0 ) {
                /* Passwort of the peer which must be received */
-               if( strlcpy( New_Server.pwd_out, Arg, sizeof( New_Server.pwd_out )) >= sizeof( New_Server.pwd_out )) Config_Error( LOG_WARNING, "%s, line %d: Value of \"PeerPassword\" too long!", NGIRCd_ConfFile, Line );
+               len = strlcpy( New_Server.pwd_out, Arg, sizeof( New_Server.pwd_out ));
+               if (len >= sizeof( New_Server.pwd_out ))
+                       Config_Error_TooLong( Line, Var );
                return;
        }
-       if( strcasecmp( Var, "Port" ) == 0 )
-       {
+       if( strcasecmp( Var, "Port" ) == 0 ) {
                /* Port to which this server should connect */
                port = atol( Arg );
-               if( port > 0 && port < 0xFFFF ) New_Server.port = (INT)port;
-               else Config_Error( LOG_ERR, "%s, line %d (section \"Server\"): Illegal port number %ld!", NGIRCd_ConfFile, Line, port );
+               if (port >= 0 && port < 0xFFFF)
+                       New_Server.port = (UINT16)port;
+               else
+                       Config_Error(LOG_ERR,
+                               "%s, line %d (section \"Server\"): Illegal port number %ld!",
+                               NGIRCd_ConfFile, Line, port );
                return;
        }
-       if( strcasecmp( Var, "Group" ) == 0 )
-       {
-               /* Server group */
-#ifdef HAVE_ISDIGIT
-               if( ! isdigit( (INT)*Arg )) Config_Error( LOG_WARNING, "%s, line %d: Value of \"Group\" is not a number!", NGIRCd_ConfFile, Line );
-               else
+#ifdef SSL_SUPPORT
+       if( strcasecmp( Var, "SSLConnect" ) == 0 ) {
+               New_Server.SSLConnect = Check_ArgIsTrue(Arg);
+               return;
+        }
 #endif
+       if( strcasecmp( Var, "Group" ) == 0 ) {
+               /* Server group */
                New_Server.group = atoi( Arg );
+               if (!New_Server.group && strcmp(Arg, "0"))
+                       Config_Error_NaN(Line, Var);
                return;
        }
-       
-       Config_Error( LOG_ERR, "%s, line %d (section \"Server\"): Unknown variable \"%s\"!", NGIRCd_ConfFile, Line, Var );
+       if( strcasecmp( Var, "Passive" ) == 0 ) {
+               if (Check_ArgIsTrue(Arg))
+                       New_Server.flags |= CONF_SFLAG_DISABLED;
+               return;
+       }
+       if (strcasecmp(Var, "ServiceMask") == 0) {
+               len = strlcpy(New_Server.svs_mask, ngt_LowerStr(Arg),
+                             sizeof(New_Server.svs_mask));
+               if (len >= sizeof(New_Server.svs_mask))
+                       Config_Error_TooLong(Line, Var);
+               return;
+       }
+
+       Config_Error( LOG_ERR, "%s, line %d (section \"Server\"): Unknown variable \"%s\"!",
+                                                               NGIRCd_ConfFile, Line, Var );
 } /* Handle_SERVER */
 
 
-LOCAL VOID
-Handle_CHANNEL( INT Line, CHAR *Var, CHAR *Arg )
+static bool
+Handle_Channelname(struct Conf_Channel *new_chan, const char *name)
 {
+       size_t size = sizeof(new_chan->name);
+       char *dest = new_chan->name;
+
+       if (!Channel_IsValidName(name)) {
+               /*
+                * maybe user forgot to add a '#'.
+                * This is only here for user convenience.
+                */
+               *dest = '#';
+               --size;
+               ++dest;
+       }
+       return size > strlcpy(dest, name, size);
+}
+
+
+static void
+Handle_CHANNEL(int Line, char *Var, char *Arg)
+{
+       size_t len;
+       size_t chancount;
+       struct Conf_Channel *chan;
+
        assert( Line > 0 );
        assert( Var != NULL );
        assert( Arg != NULL );
+       assert(Conf_Channel_Count > 0);
 
-       if( strcasecmp( Var, "Name" ) == 0 )
-       {
-               /* Name of the channel */
-               if( strlcpy( Conf_Channel[Conf_Channel_Count - 1].name, Arg, sizeof( Conf_Channel[Conf_Channel_Count - 1].name )) >= sizeof( Conf_Channel[Conf_Channel_Count - 1].name )) Config_Error( LOG_WARNING, "%s, line %d: Value of \"Name\" too long!", NGIRCd_ConfFile, Line );
+       chancount = Conf_Channel_Count - 1;
+
+       chan = array_alloc(&Conf_Channels, sizeof(*chan), chancount);
+       if (!chan) {
+               Config_Error(LOG_ERR, "Could not allocate memory for predefined channel (%d:%s = %s)", Line, Var, Arg);
                return;
        }
-       if( strcasecmp( Var, "Modes" ) == 0 )
-       {
+       if (strcasecmp(Var, "Name") == 0) {
+               if (!Handle_Channelname(chan, Arg))
+                       Config_Error_TooLong(Line, Var);
+               return;
+       }
+       if (strcasecmp(Var, "Modes") == 0) {
                /* Initial modes */
-               if( strlcpy( Conf_Channel[Conf_Channel_Count - 1].modes, Arg, sizeof( Conf_Channel[Conf_Channel_Count - 1].modes )) >= sizeof( Conf_Channel[Conf_Channel_Count - 1].modes )) Config_Error( LOG_WARNING, "%s, line %d: Value of \"Modes\" too long!", NGIRCd_ConfFile, Line );
+               len = strlcpy(chan->modes, Arg, sizeof(chan->modes));
+               if (len >= sizeof(chan->modes))
+                       Config_Error_TooLong( Line, Var );
                return;
        }
-       if( strcasecmp( Var, "Topic" ) == 0 )
-       {
+       if( strcasecmp( Var, "Topic" ) == 0 ) {
                /* Initial topic */
-               if( strlcpy( Conf_Channel[Conf_Channel_Count - 1].topic, Arg, sizeof( Conf_Channel[Conf_Channel_Count - 1].topic )) >= sizeof( Conf_Channel[Conf_Channel_Count - 1].topic )) Config_Error( LOG_WARNING, "%s, line %d: Value of \"Topic\" too long!", NGIRCd_ConfFile, Line );
+               len = strlcpy(chan->topic, Arg, sizeof(chan->topic));
+               if (len >= sizeof(chan->topic))
+                       Config_Error_TooLong( Line, Var );
+               return;
+       }
+       if( strcasecmp( Var, "Key" ) == 0 ) {
+               /* Initial Channel Key (mode k) */
+               len = strlcpy(chan->key, Arg, sizeof(chan->key));
+               if (len >= sizeof(chan->key))
+                       Config_Error_TooLong(Line, Var);
+               return;
+       }
+       if( strcasecmp( Var, "MaxUsers" ) == 0 ) {
+               /* maximum user limit, mode l */
+               chan->maxusers = (unsigned long) atol(Arg);
+               if (!chan->maxusers && strcmp(Arg, "0"))
+                       Config_Error_NaN(Line, Var);
+               return;
+       }
+       if (strcasecmp(Var, "KeyFile") == 0) {
+               /* channel keys */
+               len = strlcpy(chan->keyfile, Arg, sizeof(chan->keyfile));
+               if (len >= sizeof(chan->keyfile))
+                       Config_Error_TooLong(Line, Var);
                return;
        }
 
-       Config_Error( LOG_ERR, "%s, line %d (section \"Channel\"): Unknown variable \"%s\"!", NGIRCd_ConfFile, Line, Var );
+       Config_Error( LOG_ERR, "%s, line %d (section \"Channel\"): Unknown variable \"%s\"!",
+                                                               NGIRCd_ConfFile, Line, Var );
 } /* Handle_CHANNEL */
 
 
-LOCAL VOID
-Validate_Config( BOOLEAN Configtest )
+static bool
+Validate_Config(bool Configtest, bool Rehash)
 {
        /* Validate configuration settings. */
 
 #ifdef DEBUG
-       INT i, servers, servers_once;
+       int i, servers, servers_once;
 #endif
+       bool config_valid = true;
+       char *ptr;
+
+       /* Validate configured server name, see RFC 2812 section 2.3.1 */
+       ptr = Conf_ServerName;
+       do {
+               if (*ptr >= 'a' && *ptr <= 'z') continue;
+               if (*ptr >= 'A' && *ptr <= 'Z') continue;
+               if (*ptr >= '0' && *ptr <= '9') continue;
+               if (ptr > Conf_ServerName) {
+                       if (*ptr == '.' || *ptr == '-')
+                               continue;
+               }
+               Conf_ServerName[0] = '\0';
+               break;
+       } while (*(++ptr));
 
-       if( ! Conf_ServerName[0] )
-       {
+       if (!Conf_ServerName[0]) {
                /* No server name configured! */
-               Config_Error( LOG_ALERT, "No server name configured in \"%s\" (section 'Global': 'Name')!", NGIRCd_ConfFile );
-               if( ! Configtest )
-               {
-                       Config_Error( LOG_ALERT, "%s exiting due to fatal errors!", PACKAGE_NAME );
-                       exit( 1 );
+               config_valid = false;
+               Config_Error(LOG_ALERT,
+                            "No (valid) server name configured in \"%s\" (section 'Global': 'Name')!",
+                            NGIRCd_ConfFile);
+               if (!Configtest && !Rehash) {
+                       Config_Error(LOG_ALERT,
+                                    "%s exiting due to fatal errors!",
+                                    PACKAGE_NAME);
+                       exit(1);
                }
        }
-       
-       if( Conf_ServerName[0] && ! strchr( Conf_ServerName, '.' ))
-       {
+
+       if (Conf_ServerName[0] && !strchr(Conf_ServerName, '.')) {
                /* No dot in server name! */
-               Config_Error( LOG_ALERT, "Invalid server name configured in \"%s\" (section 'Global': 'Name'): Dot missing!", NGIRCd_ConfFile );
-               if( ! Configtest )
-               {
-                       Config_Error( LOG_ALERT, "%s exiting due to fatal errors!", PACKAGE_NAME );
-                       exit( 1 );
+               config_valid = false;
+               Config_Error(LOG_ALERT,
+                            "Invalid server name configured in \"%s\" (section 'Global': 'Name'): Dot missing!",
+                            NGIRCd_ConfFile);
+               if (!Configtest) {
+                       Config_Error(LOG_ALERT,
+                                    "%s exiting due to fatal errors!",
+                                    PACKAGE_NAME);
+                       exit(1);
                }
        }
 
 #ifdef STRICT_RFC
-       if( ! Conf_ServerAdminMail[0] )
-       {
+       if (!Conf_ServerAdminMail[0]) {
                /* No administrative contact configured! */
-               Config_Error( LOG_ALERT, "No administrator email address configured in \"%s\" ('AdminEMail')!", NGIRCd_ConfFile );
-               if( ! Configtest )
-               {
-                       Config_Error( LOG_ALERT, "%s exiting due to fatal errors!", PACKAGE_NAME );
-                       exit( 1 );
+               config_valid = false;
+               Config_Error(LOG_ALERT,
+                            "No administrator email address configured in \"%s\" ('AdminEMail')!",
+                            NGIRCd_ConfFile);
+               if (!Configtest) {
+                       Config_Error(LOG_ALERT,
+                                    "%s exiting due to fatal errors!",
+                                    PACKAGE_NAME);
+                       exit(1);
                }
        }
 #endif
 
-       if( ! Conf_ServerAdmin1[0] && ! Conf_ServerAdmin2[0] && ! Conf_ServerAdminMail[0] )
-       {
+       if (!Conf_ServerAdmin1[0] && !Conf_ServerAdmin2[0]
+           && !Conf_ServerAdminMail[0]) {
                /* No administrative information configured! */
-               Config_Error( LOG_WARNING, "No administrative information configured but required by RFC!" );
-       }
-#ifdef FD_SETSIZE      
-       if(( Conf_MaxConnections > (LONG)FD_SETSIZE ) || ( Conf_MaxConnections < 1 ))
-       {
-               Conf_MaxConnections = (LONG)FD_SETSIZE;
-               Config_Error( LOG_ERR, "Setting MaxConnections to %ld, select() can't handle more file descriptors!", Conf_MaxConnections );
+               Config_Error(LOG_WARNING,
+                            "No administrative information configured but required by RFC!");
        }
-#else
-       Config_Error( LOG_WARN, "Don't know how many file descriptors select() can handle on this system, don't set MaxConnections too high!" );
+
+#ifdef PAM
+       if (Conf_ServerPwd[0])
+               Config_Error(LOG_ERR,
+                            "This server uses PAM, \"Password\" will be ignored!");
 #endif
 
 #ifdef DEBUG
        servers = servers_once = 0;
-       for( i = 0; i < MAX_SERVERS; i++ )
-       {
-               if( Conf_Server[i].name[0] )
-               {
+       for (i = 0; i < MAX_SERVERS; i++) {
+               if (Conf_Server[i].name[0]) {
                        servers++;
-                       if( Conf_Server[i].flags & CONF_SFLAG_ONCE ) servers_once++;
+                       if (Conf_Server[i].flags & CONF_SFLAG_ONCE)
+                               servers_once++;
                }
        }
-       Log( LOG_DEBUG, "Configuration: Operators=%d, Servers=%d[%d], Channels=%d", Conf_Oper_Count, servers, servers_once, Conf_Channel_Count );
+       Log(LOG_DEBUG,
+           "Configuration: Operators=%d, Servers=%d[%d], Channels=%d",
+           Conf_Oper_Count, servers, servers_once, Conf_Channel_Count);
 #endif
+
+       return config_valid;
 } /* Validate_Config */
 
 
+static void
+Config_Error_TooLong ( const int Line, const char *Item )
+{
+       Config_Error( LOG_WARNING, "%s, line %d: Value of \"%s\" too long!", NGIRCd_ConfFile, Line, Item );
+}
+
+
+static void
+Config_Error_NaN( const int Line, const char *Item )
+{
+       Config_Error( LOG_WARNING, "%s, line %d: Value of \"%s\" is not a number!",
+                                               NGIRCd_ConfFile, Line, Item );
+}
+
+
 #ifdef PROTOTYPES
-LOCAL VOID Config_Error( CONST INT Level, CONST CHAR *Format, ... )
+static void Config_Error( const int Level, const char *Format, ... )
 #else
-LOCAL VOID Config_Error( Level, Format, va_alist )
-CONST INT Level;
-CONST CHAR *Format;
+static void Config_Error( Level, Format, va_alist )
+const int Level;
+const char *Format;
 va_dcl
 #endif
 {
        /* Error! Write to console and/or logfile. */
 
-       CHAR msg[MAX_LOG_MSG_LEN];
+       char msg[MAX_LOG_MSG_LEN];
        va_list ap;
 
        assert( Format != NULL );
@@ -944,30 +1644,51 @@ va_dcl
        /* During "normal operations" the log functions of the daemon should
         * be used, but during testing of the configuration file, all messages
         * should go directly to the console: */
-       if( Use_Log ) Log( Level, "%s", msg );
+       if (Use_Log) Log( Level, "%s", msg );
        else puts( msg );
 } /* Config_Error */
 
 
-LOCAL VOID
+#ifdef DEBUG
+
+GLOBAL void
+Conf_DebugDump(void)
+{
+       int i;
+
+       Log(LOG_DEBUG, "Configured servers:");
+       for (i = 0; i < MAX_SERVERS; i++) {
+               if (! Conf_Server[i].name[0])
+                       continue;
+               Log(LOG_DEBUG,
+                   " - %s: %s:%d, last=%ld, group=%d, flags=%d, conn=%d",
+                   Conf_Server[i].name, Conf_Server[i].host,
+                   Conf_Server[i].port, Conf_Server[i].lasttry,
+                   Conf_Server[i].group, Conf_Server[i].flags,
+                   Conf_Server[i].conn_id);
+       }
+} /* Conf_DebugDump */
+
+#endif
+
+
+static void
 Init_Server_Struct( CONF_SERVER *Server )
 {
        /* Initialize server configuration structur to default values */
 
        assert( Server != NULL );
 
-       strcpy( Server->host, "" );
-       strcpy( Server->ip, "" );
-       strcpy( Server->name, "" );
-       strcpy( Server->pwd_in, "" );
-       strcpy( Server->pwd_out, "" );
-       Server->port = 0;
+       memset( Server, 0, sizeof (CONF_SERVER) );
+
        Server->group = NONE;
        Server->lasttry = time( NULL ) - Conf_ConnectRetry + STARTUP_DELAY;
-       Server->res_stat = NULL;
+
        if( NGIRCd_Passive ) Server->flags = CONF_SFLAG_DISABLED;
-       else Server->flags = 0;
+
+       Proc_InitStruct(&Server->res_stat);
        Server->conn_id = NONE;
+       memset(&Server->bind_addr, 0, sizeof(&Server->bind_addr));
 } /* Init_Server_Struct */