Re: xmpp.net ICA and jabber.org SSL cert issues
Florian Jensen <[email protected]> Thu, 1 Jan 2009 20:59:55 +0100
| Newsgroups | gmane.network.jabber.admin |
|---|---|
| Message-ID | <[email protected]> |
Forwarded to the XSF Sys Admins. Greets, Florian On 01 Jan 2009, at 20:46, Leonid Evdokimov wrote: > Happy new year to everyone! > > After reading recent news about hacking MD5 signed SSL certs (http://phreedom.org/research/rogue-ca/ > , http://www.win.tue.nl/hashclash/rogue-ca/) I decided to check if > SSL certs at xmpp.net are vulnerable. > > And as soon as I point my browser to https://xmpp.net and https://www.jabber.org > I see invalid and expired self-signed certs... Moreover https://xmpp.net > uses certificate that is only valid for www.jabber.org. > > Why do https://www.jabber.org and https://xmpp.org/ca use expired > and self-signed certs? Am I under man-in-the-middle attack? :-) > > -- > WBRBW, Leonid Evdokimov > > _______________________________________________ > JAdmin mailing list > FAQ: http://www.jabber.org/discussion-lists/jadmin-faq > Forum: http://www.jabberforum.org/forumdisplay.php?f=19 > Info: http://mail.jabber.org/mailman/listinfo/jadmin > Unsubscribe: [email protected] > _______________________________________________ _______________________________________________ JAdmin mailing list FAQ: http://www.jabber.org/discussion-lists/jadmin-faq Forum: http://www.jabberforum.org/forumdisplay.php?f=19 Info: http://mail.jabber.org/mailman/listinfo/jadmin Unsubscribe: [email protected] _______________________________________________