> wurstsalat: i feel like it'll snowball and i'll end up spending way more time and effort than i intend. That's normally how nontrivial PRs go for me and it's kinda put me off them...
https://xmpp.org/contact/ which actually is on the website
jonas’
I think at least that info@ is read by board
ti_gj06has joined
Steve Killehas left
Steve Killehas joined
Steve Killehas left
Steve Killehas joined
franckhas left
wgreenhousehas joined
chronosx88has left
wgreenhousehas left
adiaholichas left
chronosx88has joined
wgreenhousehas joined
restive_monkhas joined
Mikaelahas joined
Wojtekhas joined
wgreenhousehas left
restive_monkhas left
franckhas joined
Yagizahas left
harry837374884has left
harry837374884has joined
Tobiashas left
Tobiashas joined
emus
jonas’: but I was looking for this where is it linked?
bunghas left
emus
ah at the very bottom
emus
hmmm, I wonder if we should place that better
restive_monkhas joined
mjkhas left
mjkhas joined
ti_gj06has left
franckhas left
djorzhas joined
dwd
rion, Also RFC 6125 goes into all of that DNS/DNSSEC/X.509/etc stuff in more detail, but with fewer fairies and wizards and stuff.
adiaholichas joined
wgreenhousehas joined
ti_gj06has joined
wgreenhousehas left
rion
I'm still trying to figure out. Assuming xmpp is somehow balanced via srv records. Each host behind srv has a host name and all of them are covered by wildcard certificate.
Does it mean I need two certificates?
Like wildcard + for base domain.
Or its better to not use certs for particular hosts at all. Like to use just base certificate for every host and check just it. In other words ignore the fact the returned certificate doesn't match particular host name but rather matches only to xmpp domain.
jonas’
rion, you need a certificate only for the domain behind the @ in XMPP adresses
jonas’
the host names inside the SRV records do not matter at all
rion
Ok. Thsnks
dwd
rion, All clients (and servers) will validate the XMPP domain name is in the certificate, so this is the best option. Some will also validate the hostname, but only if the SRV record was DNSSEC-signed. Some might also validate the IP Address, but again only if the A/AAAA record was signed.
dwd
rion, We want DNSSEC and hostname verification supported in clients (and servers) because it makes mass-hosting of many domains much much simpler, and results in less sharing of cryptographic material across administrative domain boundaries.
ti_gj06has left
Wojtekhas left
franckhas joined
wgreenhousehas joined
rion
dwd: thanks. Though could you elaborate about "much simpler"?
wgreenhousehas left
kurisuhas joined
dwd
If you have one (clustered) server hosting, say, 1000 domains, and you add one, currently (for interop) you need to replace the certificate on the service to include the new domain (or add a new certificate). The certificate then allows the XMPP provider to spoof the customer's website, which is "not ideal". But if the new domain has a DNSSEC SRV record, and the certificate has the hostname(s), then you don't need to do anything.
Wojtekhas joined
Yagizahas joined
kurisuhas left
Yagizahas left
Yagizahas joined
wgreenhousehas joined
ti_gj06has joined
daagshas left
wgreenhousehas left
debaclehas joined
mjkhas left
daagshas joined
mjkhas joined
neshtaxmpphas left
neshtaxmpphas joined
stphas left
millesimushas joined
lovetoxhas left
archas left
archas joined
stphas joined
lovetoxhas joined
wgreenhousehas joined
restive_monkhas left
wgreenhousehas left
BASSGODhas left
djorzhas left
BASSGODhas joined
restive_monkhas joined
kyemxdenhas left
kyemxdenhas joined
xnamedhas joined
wgreenhousehas joined
djorzhas joined
raghavgururajanhas left
wgreenhousehas left
wladmishas joined
restive_monkhas left
jonathanhas joined
L29Ahhas joined
restive_monkhas joined
wgreenhousehas joined
wladmishas left
pasdesushihas joined
wgreenhousehas left
ti_gj06has left
nycohas joined
xnamedhas left
mjkhas left
mjkhas joined
jgarthas left
wgreenhousehas joined
wgreenhousehas left
nycohas left
TheCoffeMakerhas left
TheCoffeMakerhas joined
harry837374884has left
harry837374884has joined
neshtaxmpphas left
neshtaxmpphas joined
wgreenhousehas joined
intosihas left
intosihas joined
adiaholichas left
wgreenhousehas left
adiaholichas joined
adiaholichas left
wladmishas joined
tykaynhas joined
sabryhas joined
wgreenhousehas joined
archas left
archas joined
bunghas joined
archas left
archas joined
wgreenhousehas left
intosihas left
sabryhas left
BASSGODhas left
sabryhas joined
intosihas joined
BASSGODhas joined
wgreenhousehas joined
wladmishas left
wgreenhousehas left
intosihas left
Wojtekhas left
Wojtekhas joined
papatutuwawahas joined
lovetoxhas left
sabryhas left
intosihas joined
wgreenhousehas joined
Calvinhas joined
djorzhas left
marc0shas left
marc0shas joined
wgreenhousehas left
Calvinhas left
raghavgururajanhas joined
wgreenhousehas joined
millesimushas left
ti_gj06has joined
djorzhas joined
karoshihas left
karoshihas joined
lovetoxhas joined
tykaynhas left
ti_gj06has left
adiaholichas joined
lovetoxhas left
adiaholichas left
rafasaurushas left
rafasaurushas joined
lovetoxhas joined
Wojtekhas left
Wojtekhas joined
ti_gj06has joined
Tobiashas left
ti_gj06has left
marc0shas left
marc0shas joined
adiaholichas joined
adiaholichas left
Tobiashas joined
ti_gj06has joined
xeckshas left
adiaholichas joined
millesimushas joined
msavoritiashas left
msavoritiashas joined
xeckshas joined
wladmishas joined
archas left
archas joined
eevvoorhas left
archas left
uhoreghas left
Rixon 👁🗨has left
homebeachhas left
Matthewhas left
Half-Shothas left
Half-Shothas joined
Matthewhas joined
Rixon 👁🗨has joined
uhoreghas joined
homebeachhas joined
archas joined
eevvoorhas joined
ti_gj06has left
lovetoxhas left
ti_gj06has joined
lovetoxhas joined
wladmishas left
restive_monkhas left
tykaynhas joined
neshtaxmpphas left
neshtaxmpphas joined
marc0shas left
marc0shas joined
marc0shas left
marc0shas joined
sonnyhas joined
Titihas left
millesimushas left
Vidakhas left
Vidakhas joined
millesimushas joined
Alexhas left
Alexhas joined
florettahas left
restive_monkhas joined
rafasaurushas left
raghavgururajanhas left
raghavgururajanhas joined
reimarhas joined
qwestionhas joined
atomicwatchhas left
chronosx88has left
chronosx88has joined
florettahas joined
rafasaurushas joined
rafasaurushas left
rafasaurushas joined
adiaholichas left
ti_gj06has left
atomicwatchhas joined
me9has joined
wladmishas joined
Wojtekhas left
Wojtekhas joined
guus.der.kinderenhas left
guus.der.kinderenhas joined
restive_monkhas left
mjkhas left
karoshihas left
mjkhas joined
wladmishas left
karoshihas joined
restive_monkhas joined
florettahas left
restive_monkhas left
neshtaxmpphas left
neshtaxmpphas joined
neshtaxmpphas left
neshtaxmpphas joined
homebeachhas left
Matthewhas left
Half-Shothas left
Rixon 👁🗨has left
uhoreghas left
Half-Shothas joined
Matthewhas joined
Rixon 👁🗨has joined
uhoreghas joined
homebeachhas joined
adiaholichas joined
ti_gj06has joined
ti_gj06has left
adiaholichas left
qrpnxzhas left
qrpnxzhas joined
neshtaxmpphas left
COM8has joined
neshtaxmpphas joined
karoshihas left
adiaholichas joined
karoshihas joined
florettahas joined
COM8has left
COM8has joined
COM8has left
COM8has joined
Wojtekhas left
Wojtekhas joined
rafasaurushas left
kyemxdenhas left
rafasaurushas joined
COM8has left
COM8has joined
COM8has left
kyemxdenhas joined
COM8has joined
millesimushas left
COM8has left
Titihas joined
florettahas left
nicolahas joined
millesimushas joined
millesimushas left
nicolahas left
Nekithas left
ti_gj06has joined
Steve Killehas left
BASSGODhas left
BASSGODhas joined
intosihas left
intosihas joined
Steve Killehas joined
florettahas joined
me9has left
restive_monkhas joined
intosihas left
intosihas joined
jgarthas joined
karoshihas left
ti_gj06has left
BASSGODhas left
florettahas left
restive_monkhas left
karoshihas joined
intosihas left
intosihas joined
BASSGODhas joined
intosihas left
intosihas joined
Nekithas joined
marc0shas left
marc0shas joined
adiaholichas left
adiaholichas joined
beanhas joined
kyemxdenhas left
kyemxdenhas joined
kyemxdenhas left
kyemxdenhas joined
rafasaurushas left
wladmishas joined
kyemxdenhas left
kyemxdenhas joined
Wojtekhas left
Wojtekhas joined
intosihas left
intosihas joined
florettahas joined
adiaholichas left
BASSGODhas left
kyemxdenhas left
kyemxdenhas joined
adiaholichas joined
wladmishas left
wladmishas joined
adiaholichas left
kyemxdenhas left
kyemxdenhas joined
marc0shas left
marc0shas joined
intosihas left
intosihas joined
qwestionhas left
me9has joined
franckhas left
franckhas joined
Wojtekhas left
karoshihas left
franckhas left
franckhas joined
Yagizahas left
wladmishas left
flow
allright, which one here owns xmpp.sexy? :)
edhelas
flow depends, what do you want to do with it 😏 ?
karoshihas joined
flow
same as rms.sexy, just with current council members maybe? :)