Re: xmpp.net ICA and jabber.org SSL cert issues
Peter Saint-Andre <[email protected]> Thu, 1 Jan 2009 19:50:01 -0700
| Newsgroups | gmane.network.jabber.admin |
|---|---|
| Message-ID | <[email protected]> |
The XMPP ICA is located here: http://xmpp.org/ca/ Instructions there will direct you to the CA interface itself. The site is no longer located at xmpp.net. None of the jabber.org, xmpp.org, xmpp.net, or xmpp.com sites are currently served using SSL, so when you visit those sites via https you are receiving some kind of default certificate for lighttpd. We need to fix that. On Fri, Jan 02, 2009 at 01:46:12AM +0600, Leonid Evdokimov wrote: > Happy new year to everyone! > > After reading recent news about hacking MD5 signed SSL certs > (http://phreedom.org/research/rogue-ca/, > http://www.win.tue.nl/hashclash/rogue-ca/) I decided to check if SSL > certs at xmpp.net are vulnerable. > > And as soon as I point my browser to https://xmpp.net and > https://www.jabber.org I see invalid and expired self-signed certs... > Moreover https://xmpp.net uses certificate that is only valid for > www.jabber.org. > > Why do https://www.jabber.org and https://xmpp.org/ca use expired and > self-signed certs? Am I under man-in-the-middle attack? :-) > > -- > WBRBW, Leonid Evdokimov > _______________________________________________ JAdmin mailing list FAQ: http://www.jabber.org/discussion-lists/jadmin-faq Forum: http://www.jabberforum.org/forumdisplay.php?f=19 Info: http://mail.jabber.org/mailman/listinfo/jadmin Unsubscribe: [email protected] _______________________________________________