jabber.org certificate is expired if anyone knows how to ping admins
lumihas left
marc_has left
Zash
They know
moparisthebest
Cool
peterhas joined
kokonoehas left
kokonoehas joined
mr.fisterhas left
peterhas left
peterhas joined
UsLhas left
moparisthebesthas left
moparisthebesthas joined
zachhas left
zachhas joined
zachhas left
zachhas joined
Neustradamushas joined
Lancehas joined
waqashas joined
waqashas left
alacerhas left
alacerhas joined
Lancehas left
Wojtekhas left
waqashas joined
waqashas left
peterhas left
peterhas joined
peterhas left
Neustradamus
moparisthebest: there are tickets on github :)
https://github.com/stpeter/jabberdotorg/issues
Jeanhas left
waqashas joined
waqashas left
Archas left
igoosehas left
goffihas joined
novnovhas joined
jjrhhas left
jjrhhas joined
jjrhhas left
jjrhhas joined
karoshihas joined
igoosehas joined
UsLhas joined
Nekithas joined
blablahas joined
wurstsalathas joined
blablahas left
alacerhas left
alacerhas joined
jjrhhas left
jjrhhas joined
novnovhas left
kokonoehas left
kokonoehas joined
Archas joined
Ge0rG
Are they new or from previous periods? 🤔
yvohas joined
rtq3has joined
rtq3has left
Steve Killehas left
Steve Killehas joined
larmahas joined
mikaelahas joined
debaclehas joined
alacerhas left
alacerhas joined
rtq3has joined
blablahas joined
rtq3has left
yvohas left
Yagizahas joined
jjrhhas left
jjrhhas joined
jjrhhas left
jjrhhas joined
Syndacehas left
jjrhhas left
jjrhhas joined
Wiktorhas left
Wiktorhas joined
sezuanhas joined
blablahas left
blablahas joined
lskdjfhas joined
Syndacehas joined
lumihas joined
novnovhas joined
kokonoehas left
Yagizahas left
Yagizahas joined
marc_has joined
kokonoehas joined
debaclehas left
marc_has left
novnovhas left
debaclehas joined
debaclehas left
jjrhhas left
jjrhhas joined
Kev
jonas’: One of my team just noticed the new XEP rendering and commented how neat it looks. JFYI.
kokonoehas left
jjrhhas left
jjrhhas joined
frainzhas left
frainzhas joined
yvohas joined
blablahas left
Vaulorhas left
Vaulorhas joined
igoosehas left
Dele Olajidehas joined
igoosehas joined
alacerhas left
alacerhas joined
ThibGhas left
ThibGhas joined
Andrew Nenakhovhas left
Andrew Nenakhovhas joined
vanitasvitaehas left
valohas left
vanitasvitaehas joined
valohas joined
rtq3has joined
ThibGhas left
ThibGhas joined
jjrhhas left
jjrhhas joined
jjrhhas left
jjrhhas joined
Archas left
jjrhhas left
jjrhhas joined
neshtaxmpphas joined
blablahas joined
APachhas left
igoosehas left
APachhas joined
mimi89999has left
mimi89999has joined
rtq3has left
APachhas left
rtq3has joined
APachhas joined
alacerhas left
alacerhas joined
Dele Olajidehas left
alacerhas left
APachhas left
blablahas left
igoosehas joined
alacerhas joined
APachhas joined
ThibGhas left
ThibGhas joined
marc_has joined
yvohas left
rtq3has left
rtq3has joined
lovetoxhas joined
Lancehas joined
jjrhhas left
jjrhhas joined
404.cityhas joined
Lancehas left
rtq3has left
jjrhhas left
jjrhhas joined
rtq3has joined
peterhas joined
peterhas left
rtq3has left
Dele Olajidehas joined
Dele Olajidehas left
Dele Olajidehas joined
404.cityhas left
moparisthebest
Ge0rG, looks like both! needs more cron
Lancehas joined
moparisthebest
or, systemd timers, whatever the latest hotness in scheduled jobs is
Lancehas left
UsLhas left
rtq3has joined
Ge0rG
you can't cron everything.
Ge0rG
Also privilege separation. I don't want certbot to have enough privileges to restart/reload my xmpp server.
Ge0rG
but devops today just install a docker that hooks into your other docker and then everything sinks and...
moparisthebest
I mean you can give it *just* enough priveleges to tell it to reload the certificate
Zash
Sounded like there weren't any way to only reload the cert.
debxwoodyhas left
moparisthebest
then 'just enough' is restarting the server ¯\_(ツ)_/¯
Dele Olajidehas left
moparisthebest
is it better to have an admin remember to renew manually and restart the server manually? because you know where that gets you
kokonoehas joined
Ge0rG
Zash: did I mention yet that the documented way of reloading certs in prosody doesn't work? Except when I do it twice.
Zash
Ge0rG: Not that I remember. Is there an issue for that?
Ge0rG
Zash: no. Maybe a pastebin on the prosody@ MUC. I've got a "complicated" setup, and I never had enough evidence to feel that pulling a number would be actually useful
Zash
I might have seen it to, or at least wondered why it only works when directly observed.
nycohas joined
alacerhas left
UsLhas joined
Ge0rG
Zash: https://issues.prosody.im/1346
Zash
Thanks
Andrew Nenakhovhas left
Andrew Nenakhovhas joined
Dele Olajidehas joined
Dele Olajidehas left
Dele Olajidehas joined
Wiktorhas left
Wiktorhas joined
rtq3has left
peterhas joined
debxwoodyhas joined
sezuanhas left
Wojtekhas joined
debaclehas joined
UsLhas left
Wojtekhas left
marc_has left
winfriedhas left
winfriedhas joined
rtq3has joined
marc_has joined
marc_has left
Steve Killehas left
alacerhas joined
goffihas left
Steve Killehas joined
alacerhas left
marc_has joined
yvohas joined
neshtaxmpphas left
blablahas joined
lumihas left
jubalhhas joined
goffihas joined
igoosehas left
blablahas left
blablahas joined
lumihas joined
Yagizahas left
jubalhhas left
jubalhhas joined
marc_has left
marc_has joined
mucshas joined
blablahas left
jubalhhas left
igoosehas joined
rtq3has left
rtq3has joined
Wojtekhas joined
Wojtekhas left
Dele Olajidehas left
Dele Olajidehas joined
Archas joined
peterhas left
neshtaxmpphas joined
archas joined
marc_has left
peterhas joined
mucshas left
mucshas joined
UsLhas joined
larmahas left
Nekithas left
larmahas joined
waqashas joined
mr.fisterhas joined
lovetoxhas left
lovetoxhas joined
mucshas left
mucshas joined
mr.fisterhas left
mr.fisterhas joined
mr.fisterhas left
mr.fisterhas joined
APachhas left
mr.fisterhas left
mr.fisterhas joined
mr.fisterhas left
mr.fisterhas joined
mucshas left
mucshas joined
alacerhas joined
mr.fisterhas left
mr.fisterhas joined
mr.fisterhas left
mr.fisterhas joined
moparisthebest
> MASQUE (Multiplexed Application Substrate over QUIC Encryption) is a mechanism that allows co-locating and obfuscating networking applications behind an HTTPS web server.
mucshas left
mucshas joined
moparisthebest
new IETF mailing list set up for it, expect a XEP soon >:)
moparisthebest
new ALPN I guess?
Zash
Saw the mail. I cried.
mucshas left
mucshas joined
Nekithas joined
debaclehas left
peterhas left
peterhas joined
moparisthebestpats Zash , it'll be ok
moparisthebest
hey you didn't want everything going over TLS on 443 right?
moparisthebest
now it'll just all go over UDP instead
Zash
Is that even going to work?
peterhas left
moparisthebest
only because all browsers and CDNs will add support at the same time yes
moparisthebest
ie, the same reason TLS on 443 worked
Zash
TLS on 443 works because nobody dare block it ... yet.
moparisthebest
can't have anything nice, unless you are 1 of the 2ish major browser vendors, and then you can have whatever you want
Zash
Browser vendors being the driving force behind anything, and everything becoming browser based is what depresses me.
neshtaxmpphas left
neshtaxmpphas joined
rtq3has left
rtq3has joined
mr.fisterhas left
mr.fisterhas joined
Ge0rG
Browser vendors being the driving force behind MTA-STS...