XMPP Service Operators - 2023-04-05


  1. Roi

    sslh is running on 5223 here at Hot-Chilli now. Transparent and dual stack. What a pain in the *ss... ;-)

  2. Roi

    ...to set it up. But it runs smooth now. ;-)

  3. Ty3r0X

    On a slightly unrelated note, regarding ssl, I believe xmpp clients should trust certificates received via dnssec + dane (I consider this to be the future of chain of trust)

  4. Menel

    It is the utopian chain of trust at least...

  5. msavoritias

    they dont trust these certificates atm? they should then yeah

  6. moparisthebest

    > sslh is running on 5223 here at Hot-Chilli now. Transparent and dual stack. What a pain in the *ss... ;-) Haha yes indeed, but great work Roi ! :)

  7. moparisthebest

    Ty3r0X: they should, but it's tricky and only some do, not many, but yes we should fix it

  8. Menel

    Is there some automatic process available to generate Dane TLSA records, or does one need to manually copy their cert in some online generator program and then enter that as record.... Some offline script/helper/program?

  9. jonas’

    yes

  10. jonas’

    let me check

  11. jonas’

    Menel, tlsa(1), from the hash-slinger debian package

  12. Menel

    I see, thanks... All the talk about DANE, led me to maybe try that out

  13. Roi

    > > sslh is running on 5223 here at Hot-Chilli now. Transparent and dual stack. What a pain in the *ss... ;-) > Haha yes indeed, but great work Roi ! :) Thank you! :-) And it really seems to work. That is fancy stuff. ;-)