Re: Should I enable STARTTLS for S2S in ejabberd

David Banes <[email protected]>
Newsgroups gmane.network.jabber.admin
Message-ID <[email protected]>
On 13/11/2008, at 4:56 AM, Damjan wrote:

>> No, but you can get a free CA-issued cert here:
>>
>> http://xmpp.org/ca/
>
> I have 2 questions,
>
> 1. will the xmpp clients trust this certificate by default?
>

Yes.

>
> 2. on the page http://xmpp.org/ca/installation.shtml it's suggested to
> download http://cert.startcom.org/sub.class1.xmpp.ca.crt and
> http://cert.startcom.org/ca.crt
> shouldn't those certificates be served over https?
>

No it doesn't matter really, if you're thinking about public key  
crypto then it's the private key that's always kept secure(private),  
public keys and certs are, well public.

>
>
> -- 
> damjan | дамјан
> This is my jabber ID -->         [email protected]
> -- not my mail address, it's a Jabber ID --^ :)
> _______________________________________________
> JAdmin mailing list
> FAQ: http://www.jabber.org/discussion-lists/jadmin-faq
> Forum: http://www.jabberforum.org/forumdisplay.php?f=19
> Info: http://mail.jabber.org/mailman/listinfo/jadmin
> Unsubscribe: [email protected]
> _______________________________________________

David Banes
Director & Secretary, Internet Industry Association
Director & Chairman, XMPP Standards Foundation
web: http://davidbanes.com/
work: http://www.cleartext.com/
email:  [email protected]
xmpp: [email protected]

--------------------------------------------------------------------------------------------------------
Email Filtering by Cleartext a Carbon Minimsed company - www.cleartext.com
--------------------------------------------------------------------------------------------------------
_______________________________________________
JAdmin mailing list
FAQ: http://www.jabber.org/discussion-lists/jadmin-faq
Forum: http://www.jabberforum.org/forumdisplay.php?f=19
Info: http://mail.jabber.org/mailman/listinfo/jadmin
Unsubscribe: [email protected]
_______________________________________________
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.