-
Wojtek
> Hello, are there any admins of the Tigase public xmpp server here? @emus 🙋♂️
-
emus
Wojtek: Im gonna text you later! ☺
-
Martin
Anyone knows sure.im? > Establishing a secure connection from diebesban.de to sure.im failed. Certificate hash: d6a22d3a9d5cf8d5d6c7962313024144359f71cfc1073c2165825e5b26f2d1b4. Error with certificate 0: certificate has expired.
-
ij
Martin, sure.im is a domain from Tigase, so Wojtek for example…
-
Licaon_Kter
Biggest enemy of xmpp, non-autoupdating server certs
-
Link Mauve
Wojtek, you might be interested in https://observe.jabber.network/ in order to get warned of such issues before they happen.
-
Харпер
Don't y'all get emailed when your cert is a few weeks from expiring?
-
Link Mauve
Харпер, most such services only monitor HTTPS, which is usually controlled by a different process than XMPP.
-
Харпер
I get emails from let's encrypt
-
Харпер
I guess if you had certbot update them but not copy them in place is the common issue?
- ij would like to have services being notified about ssl cert changes, checking validity and then automatically loading a new cert
-
Харпер
Doesn't ejabbers have native acme support?
-
Харпер
https://docs.ejabberd.im/admin/configuration/basic/#setting-up-acme
-
Holger
Not sure the Tigase people run ejabberd 🙂
-
Licaon_Kter
Holger, Харпер: they could start :))
-
Licaon_Kter
Харпер: yes, but it might not be viable https://github.com/processone/ejabberd/issues/3075 Eg. Even in my small instance's case I can't use it
-
Wojtek
erm, @all: * we do use certbot and the certs are updated automatically... there is some weird issue that cached cert is being loaded (sometimes during restart and I was doing just that right now) -- we are investigating it but it's kinda "haisenbug" and when we look it doesn't happen. * we are already on observer.jabber.network and I got single notification :-)
-
Харпер
Just reboot your servers daily
-
rozzin
I use certbot and run "ejabberdctl reload" after certbot updates.
-
rozzin
With what I hope are the obvious caveats....
-
Licaon_Kter
It takes 2-3 cycles in production to level out all the bugs of one cron line, we know :))✎ -
Licaon_Kter
It takes 2-3 cycles (aka 4-9 months) in production to level out all the bugs of one cron line, we know :)) ✏
-
WojtekIM
it wasn't cronjob line... but cronjob hook ;) it should be working from now on <fingers crossed>
-
Licaon_Kter
WojtekIM: that's what you've said last time ¯\_(ツ)_/¯
-
Wojtek
that's life
-
ernst.on.tour
Is it possible to disco a xmpp-server via curl and is somebody able to give an example how to do it ? This would mayne help some people to get the admin
-
MattJ
curl uses HTTP, disco is performed via XMPP
-
MattJ
If you have a Prosody server with mod_rest then you can use curl to disco though
-
ernst.on.tour
Okay, was just an idea. I monitor my certs via open_ssl, maybe curl or netcat could help.
-
jonas’
we could teach authbot to resolve contact info of XMPP servers which publish it
-
jonas’
but I’m not sure if that’s something which is desirable
-
rozzin
Mmm...
-
rozzin
jonas’: "contact info" meaning like e-mail address for the domain admin or something?
-
rob
Everyone should just do xmpp@domain.com
-
rob
Which I think is an xep recommendation? Maybe not
-
rob
I've got it for all my virtual hosts
-
rozzin
I feel like..., if people wanted to be found like that then they'd advertise their info via any of the standard means like: * WHOIS * links on web pages * standard aliases like "postmaster", "hostmaster", etc....
-
Харпер
https://datatracker.ietf.org/doc/html/rfc2142
-
Amolith
Is there a MUC for Gajim? I looked around on the site and didn't notice one
-
Licaon_Kter
Amolith: xmpp:gajim@conference.gajim.org?join
-
Amolith
Licaon_Kter, thank you!
-
freemo
Hello everyone, new user here, evaluating jabber to see if i want to run an instance.
-
Licaon_Kter
freemo: that's a good start
-
ernst.on.tour
rozzin, Харпер: Sometimes SMTP and XMPP isn't offered by the same company/person admin@xmpp.foo.bar can't be reached if xmpp is down, therefor maybe an additional admin@reserve.bar or an additional xmpp@mail.foo.bar is named in admin-disco.
-
rozzin
ernst.on.tour: granted. My thought was just that so many server operators seem to go out of their way to make their contact info altogether undiscoverable with things like obfuscated WHOIS etc., and the question of "_which_ specific contact info" seems pretty meaningless in those cases--basically because that question is made "unaskable".
-
rozzin
I actually had someone I'd met at a conference call me at the phone number in the WHOIS listing for the domain of a project we'd talked about. It was quite a nice experience actually--made me feel like I'd made the right decision keeping the info in there.
-
rob
I've always hidden mine in whois because it lists your home address
-
rob
If I could just put email and phone I'd probably do that
-
rob
Even just a VoIP number like jmp
-
rozzin
rob: well, it lists *an* address.... Plenty of people get PO boxes to decouple their home address from their public mailing address.
-
rozzin
PO boxes here are something like... $100/year?
-
Ellenor Malik
ah
-
Ellenor Malik
like $1000 in Canada
-
rozzin
That's not like $100 US anymore, is it?
-
rozzin
$100/*month* sounds incredibly expensive to me. Pretty sure there are USPS boxes available for rates like that here, but those would be the *really big* ones. Might cost more in bigger cities, maybe?
-
rob
A small one is $173 annually in Canada
-
rob
Sorry that's rural, $199 in cities
-
rob
Like the size for regular letters
-
argon3771
Small one in US is about 80 a year
-
rob
Ya not bad, but I try to avoid any extra cost with self hosting. And all the standard email inboxes work fine for me, with xmpp@ included
-
Ellenor Malik
rob: Are you a fox
-
rob
Indeed