jdev - 2023-12-24

  moparisthebest

    > moparisthebest, does your implementation also support authenticating the initiating entity via certificates? flow: *only* via certificates, what brought this up is xmpp-dns shows DirectTLS s2s as failed because I see s2s and no certificate so just close the socket

  Martin

    It checks for the stream closing. Without this it sometimes showed directTLS as passed but it only did tls to sslh/nginx and the xmppd behind was not listening.

  Martin

    Actually this works with prosody, ejabberd, tigase, metronome and openfire. xmpp-proxy seems to be the only implementation which closes the connection without sending an error.

  moparisthebest

    Martin: do you know if the ones you checked had dialback enabled or not?

  Martin

    No idea