xmpp.net ICA and jabber.org SSL cert issues

Leonid Evdokimov <[email protected]> Fri, 02 Jan 2009 01:46:12 +0600
Newsgroups gmane.network.jabber.admin
Message-ID <[email protected]>
Happy new year to everyone!

After reading recent news about hacking MD5 signed SSL certs 
(http://phreedom.org/research/rogue-ca/, 
http://www.win.tue.nl/hashclash/rogue-ca/) I decided to check if SSL 
certs at xmpp.net are vulnerable.

And as soon as I point my browser to https://xmpp.net and 
https://www.jabber.org I see invalid and expired self-signed certs... 
Moreover https://xmpp.net uses certificate that is only valid for 
www.jabber.org.

Why do https://www.jabber.org and https://xmpp.org/ca use expired and 
self-signed certs? Am I under man-in-the-middle attack? :-)

-- 
WBRBW, Leonid Evdokimov

_______________________________________________
JAdmin mailing list
FAQ: http://www.jabber.org/discussion-lists/jadmin-faq
Forum: http://www.jabberforum.org/forumdisplay.php?f=19
Info: http://mail.jabber.org/mailman/listinfo/jadmin
Unsubscribe: [email protected]
_______________________________________________
signature.asc (application/pgp-signature, 260 B)
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v2.0.9 (GNU/Linux)
Comment: Using GnuPG with Mozilla - http://enigmail.mozdev.org

iEYEARECAAYFAkldHYQACgkQbNKln9z6vVyMzQCgh3oPlCKhVHZa1TfSHX5iOitO
XEUAn0Ewo9ZClzXcjHIoKF9FoedIF1b5
=j999
-----END PGP SIGNATURE-----
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.