Re: xmpp.net ICA and jabber.org SSL cert issues

Peter Saint-Andre <[email protected]> Thu, 1 Jan 2009 19:50:01 -0700
Newsgroups gmane.network.jabber.admin
Message-ID <[email protected]>
The XMPP ICA is located here:

http://xmpp.org/ca/

Instructions there will direct you to the CA interface itself. The site
is no longer located at xmpp.net. None of the jabber.org, xmpp.org,
xmpp.net, or xmpp.com sites are currently served using SSL, so when
you visit those sites via https you are receiving some kind of default
certificate for lighttpd. We need to fix that.

On Fri, Jan 02, 2009 at 01:46:12AM +0600, Leonid Evdokimov wrote:
> Happy new year to everyone!
>
> After reading recent news about hacking MD5 signed SSL certs  
> (http://phreedom.org/research/rogue-ca/,  
> http://www.win.tue.nl/hashclash/rogue-ca/) I decided to check if SSL  
> certs at xmpp.net are vulnerable.
>
> And as soon as I point my browser to https://xmpp.net and  
> https://www.jabber.org I see invalid and expired self-signed certs...  
> Moreover https://xmpp.net uses certificate that is only valid for  
> www.jabber.org.
>
> Why do https://www.jabber.org and https://xmpp.org/ca use expired and  
> self-signed certs? Am I under man-in-the-middle attack? :-)
>
> -- 
> WBRBW, Leonid Evdokimov
>
_______________________________________________
JAdmin mailing list
FAQ: http://www.jabber.org/discussion-lists/jadmin-faq
Forum: http://www.jabberforum.org/forumdisplay.php?f=19
Info: http://mail.jabber.org/mailman/listinfo/jadmin
Unsubscribe: [email protected]
_______________________________________________