certificate

New server version is running

A new version of the Tigase XMPP Server has been just deployed. Those of you who have accounts in own, custom domains could have notice that a new, self-signed certificates have been automatically generated.

SSL Ceriticates regeneration

This is an early notice that in a few days, SSL certificates for all domains will be automatically regenerated. Your XMPP clients may complain about changed SSL certificate.
Right now, for all domains, there is a single, self-sgined certificate generated for the tigase.im domain. This is neither good or convenient or even secure. It may also cause problems with XMPP clients and s2s communication.

SHA1 for self-signed certificate?

I tried to connect my IM client (Pidgin) to a tigase.im account, but received a warning that the certificate was self-signed and could not be verified. The SHA1 was listed as 96:48:69:5f:64:0c:bc:3a:fa:ef:27:fb:27:08:71:aa:7b:8d:fe:43 -- can you verify this, post it in an FAQ, or use a CA-signed cert?

Edit: I suppose that alternate domains pose a problem here -- a CA-signed cert would work with at most one domain.

Syndicate content