-
mirux
Establishing a secure connection to conference.siacs.eu failed. Certificate hash: 28f112735c956c229a4050c49a38f2c9da13ced3. Error with certificate 1: certificate has expired. Error with certificate 2: certificate has expired. Establishing a secure connection to conference.conversations.im failed. Certificate hash: 19ea0e3a6548a8a73c670cc64e36709851d1dcf7. Error with certificate 1: certificate has expired. Error with certificate 2: certificate has expired.
-
Licaon_Kter
At least is not mitm?!✎ -
Licaon_Kter
At least it is not mitm?! ✏
-
☭Mike Yellow
What happens on conversations.im?
-
Licaon_Kter
See above...expired cert...now we wait...
-
dsp3
Same with jabber.at
-
Licaon_Kter
Maybe they updated CAA records last week but not tested?
-
dsp3
jabber.at is back. yesterday they had cert problem
-
dsp3
Probably everyone running to mitigate MITM issues
-
Licaon_Kter
dsp3: this happens in cycles, as certs expire, something is not working in that automated way you've setup it ¯\_(ツ)_/¯
-
dsp3
Yeah. Understood. Interesting coincidence it happened to conversations as well
-
Menel
Interestingly I get another error: Establishing a secure connection to conference.siacs.eu failed. Certificate hash: d926745ca77c1290bf9ccb27738621e2fb8d2e00e56272e8cd0760ffe9835568. Error with certificate 1: unable to get local issuer certificate.
-
Licaon_Kter
I see the same ^^^
-
Menel
It's another hash, maybe direct tls port. Vs starttls port
-
Menel
I don't think it's a simple expiry, because it's expired 2021 what we see
-
Menel
More like a fallback cert that's somewhere ein the sever✎ -
Menel
More like a fallback cert that's somewhere on the the sever ✏
-
audamar
it isn't necessarily a different hash, just a different hash type, note the length
-
dsp3
On conference.siacs.eu, testtls.com reports "certificate does not match supplied URI (same w/o SNI)"
-
Licaon_Kter
Them people are looking into it...
-
Menel
Now I got it the cert is fine, but the intermediate cert is old for some reason. Needed the newest version of testssl.sh... Intermediate cert validity #1: expired! (2021-09-29 19:21). R3 <-- DST Root CA X3
-
Menel
dsp3: you must use it like this: ./testssl.sh -S -t xmpp-server --xmpphost conference.siacs.eu xmpp-hosting.conversations.im:5269 No SNI problem... "Only" the chain is broken
-
mimi89999
Establishing a secure connection from lebihan.pl to conference.siacs.eu failed. Certificate hash: d926745ca77c1290bf9ccb27738621e2fb8d2e00e56272e8cd0760ffe9835568. Error with certificate 1: unable to get local issuer certificate. Establishing a secure connection from lebihan.pl to conference.conversations.im failed. Certificate hash: 44c4dafeb451bb81491e9f37df51e33680190443a8103ba4e94b565e74cef39e. Error with certificate 1: unable to get local issuer certificate.
-
mimi89999
Got that 3h ago
-
Menel
We all did
-
dsp3
> dsp3: you must use it like this: > ./testssl.sh -S -t xmpp-server --xmpphost conference.siacs.eu xmpp-hosting.conversations.im:5269 > No SNI problem... "Only" the chain is broken Yeah, I was just testing on 443 as I presumed same cert used by all services to see if there was a general problem ↺
-
mirux
I have a question for https://certwatch.xmpp.net/, I did upgrade to bookworm, and afterwards did a cert renewal via for - when I now try to access certwatch I am getting gateway time-out (might be independant from the upgrade) .... Is this known?✎ -
mirux
I have a question for https://certwatch.xmpp.net/, I did upgrade to bookworm, and afterwards did a cert renewal via certbot for my server - when I now try to access certwatch I am getting gateway time-out (might be independant from the upgrade) .... Is this known? ✏
-
MattJ
You can't load the certwatch website?
-
audamar
what is the **** website?
-
mirux
504 Gateway Time-out nginx/1.18.0
-
mirux
getting that
-
mirux
https://certwatch.xmpp.net/servers
-
mirux
after entering my servername
-
TheCoffeMaker
mirux: certwatch is made with which language? maybe u are reverse proxying to the wrong socket (after a version upgrade, your nginx setup can be pointing to the old version number, this is common on php-fpm environments)
-
mirux
no proxy on my side
-
TheCoffeMaker
go
-
mirux
no clue where/what to check ....
-
root
It is working just fine for me.
-
mirux
any module I need to check on my side?
-
audamar
mirux, are you blocking tor?
-
mirux
nope, it went ok yesterday, my server is/was registered, only change is bookwork upgrade
-
Menel
That service had some hiccups, just try later
-
mirux
ok, the pubsub subscription stats I am registered
-
TheCoffeMaker
> It is working just fine for me. for me too ↺
-
mirux
error message is socks connect tcp localhost:9050->[MYIPV6]:5222: unknown error general SOCKS server failure
-
mirux
or
-
mirux
504 Gateway Time-out nginx/1.18.0