xmpp.net ICA and jabber.org SSL cert issues
Leonid Evdokimov <[email protected]> Fri, 02 Jan 2009 01:46:12 +0600
| Newsgroups | gmane.network.jabber.admin |
|---|---|
| Message-ID | <[email protected]> |
Happy new year to everyone! After reading recent news about hacking MD5 signed SSL certs (http://phreedom.org/research/rogue-ca/, http://www.win.tue.nl/hashclash/rogue-ca/) I decided to check if SSL certs at xmpp.net are vulnerable. And as soon as I point my browser to https://xmpp.net and https://www.jabber.org I see invalid and expired self-signed certs... Moreover https://xmpp.net uses certificate that is only valid for www.jabber.org. Why do https://www.jabber.org and https://xmpp.org/ca use expired and self-signed certs? Am I under man-in-the-middle attack? :-) -- WBRBW, Leonid Evdokimov _______________________________________________ JAdmin mailing list FAQ: http://www.jabber.org/discussion-lists/jadmin-faq Forum: http://www.jabberforum.org/forumdisplay.php?f=19 Info: http://mail.jabber.org/mailman/listinfo/jadmin Unsubscribe: [email protected] _______________________________________________
signature.asc
(application/pgp-signature, 260 B)
-----BEGIN PGP SIGNATURE----- Version: GnuPG v2.0.9 (GNU/Linux) Comment: Using GnuPG with Mozilla - http://enigmail.mozdev.org iEYEARECAAYFAkldHYQACgkQbNKln9z6vVyMzQCgh3oPlCKhVHZa1TfSHX5iOitO XEUAn0Ewo9ZClzXcjHIoKF9FoedIF1b5 =j999 -----END PGP SIGNATURE-----