-
edhelas
Licaon_Kter https://xmpp.net/result.php?domain=convorb.im&type=client
-
Licaon_Kter
edhelas: do explain why that like that✎ -
Licaon_Kter
edhelas: do explain why that's like that ✏
-
edhelas
https://blog.windfluechter.net/2021/09/29/letsencrypt-ca-chain-issues-with-ejabberd/
-
Licaon_Kter
The cert is valid, there's an issue with xmpp.net, right?
-
edhelas
you have to change your certificate keychain, the one you're using is not trusted by some clients/servers
-
MattJ
Yes, don't rely on xmpp.net for cert validation
-
Licaon_Kter
Except that line I see no issue being mentioned in the report edhelas
-
Licaon_Kter
edhelas: not my fault those old systems can't cope.
-
Licaon_Kter
¯\_(ツ)_/¯
-
MattJ
edhelas, is your server running Ubuntu? Is the ca-certificates package up to date?
-
Licaon_Kter
Maybe thu cert ecosystem moved already? :))✎ -
edhelas
> 2021-11-15 10:57:40.899 [warning] <0.16550.121>@ejabberd_s2s_in:handle_auth_failure:200 (tls|<0.16550.121>) Failed inbound s2s EXTERNAL authentication convorb.im -> movim.eu (::ffff:85.186.135.101): certificate has expired
-
Licaon_Kter
Maybe the cert ecosystem moved already? :)) ✏
-
Licaon_Kter
edhelas: my ISRG inturmediate has not expired, so that's FUD :)✎ -
neox
Licaon_Kter, lol
-
Licaon_Kter
edhelas: my ISRG X1 intermediate cert has not expired, so that's FUD :) ✏
-
edhelas
I'vz manually removed DST Root CA X3 from the chain to fix it on my side
-
Licaon_Kter
That dii not help...afaics✎ -
Licaon_Kter
That did not help...afaics ✏
-
edhelas
https://xmpp.net/result.php?domain=movim.eu&type=client
-
edhelas
I moved from T to A (and users were able to login again on some clients)
-
edhelas
to me that was the fix, but I might be wrong
-
Licaon_Kter
edhelas: which OS? I think I've asked this before multiple times, maybe I've missed the answer✎ -
Licaon_Kter
edhelas: which OS&version? I think I've asked this before multiple times, maybe I've missed the answer ✏
-
Licaon_Kter
edhelas: compare the two reports, so your's is *great* with DST in thu chain but mine is *bad* without DST? Logic?✎ -
Licaon_Kter
edhelas: compare the two reports, so yours is *great* with DST in thu chain but mine is *bad* without DST? Logic? ✏
-
Licaon_Kter
edhelas: compare the two reports, so yours is *great* with DST in the chain but mine is *bad* without DST? Logic? ✏
-
Julian
Removing DST Root CA X3 from the chain will break compatibility with clients that dont trust ISRG X1. Especially Android 6 and below. Just saying. 😅
-
MattJ
The issue is not related to movim.eu's cert anyway
-
Licaon_Kter
Julian: DST is expired so not trusted, there on 6/7 they need to import the cert
-
Julian
It is expired, but still served as part of the default chain. LE will by default give you the chain "leaf > ISRG > DST". Thats intendet because some clients ignore the validity date of root certs (e.g. old androids).
-
Licaon_Kter
Oh fuuuu
-
jonas’
Licaon_Kter, and it should also not be a problem, unless with certain broken validators which stop at the first chain they find
-
Licaon_Kter
edhelas: yes, I do get your messages, 'test', bun I can't reply :) Will nuke Movim Android asap too✎ -
Licaon_Kter
edhelas: yes, I do get your messages, 'test', but I can't reply :) Will nuke Movim Android asap too ✏