Elektrine
Log in Register
Paige Chat Timeline Gallery Friends Email Drive DNS Private DNS Domains VPN Kairo Nerve
Remote

Holger Weiß

@holger@metalhead.club
mastodon 4.7.3
  • Open on metalhead.club

#ejabberd developer. Interested in #xmpp, functional programming, protocol design and implementation of Internet services. And #communism. And #soccer.

214 Followers
171 Following
5 Posts
Joined May 21, 2020
GitHub:
https://github.com/weiss
Web:
https://holger.weiss-berlin.de
Instagram:
https://instagram.com/jeremy.holger
Twitter:
https://twitter.com/JeremyHolger
Open post
Holger Weiß @holger@metalhead.club
· 6mo ago

In case you're using the official ejabberd packages on Debian stable: They're affected by a recent CA policy change (e.g., Let's Encrypt), causing ejabberd to reject newly issued certificates and thereby breaking federation with some remote servers. Deploy this update to fix the issue:

https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1128568#23

You may also want to consider enabling mod_s2s_dialback to deal with remote servers that haven't been updated yet.

#ejabberd #XMPP #Jabber #Debian #LetsEncrypt

bugs.debian.org

#1128568 - ejabberd: Federation with some servers is broken (TLS issue: unsupported certificate purpose) - Debian Bug report logs

19
4
19
0
Open post
Holger Weiß @holger@metalhead.club
· 5mo ago
Replying to
@bjoern@social.sengotta.net @kuketzblog@social.tchncs.de Signal mag nochmal stressfreier als Quicksy, Monal oder Conversations sein. Die Frage ist nur, warum man überhaupt wechseln möchte. Wer blöd findet, dass WhatsApp nur Kommunikation mit den eigenen Kunden erlaubt, hat mit Signal halt nichts gewonnen. Für mich vereint es die Nachteile von WhatsApp (geschlossenes Silo) und XMPP (leeres Adressbuch).
4
4
0
0
Open post
Holger Weiß @holger@metalhead.club
· 5mo ago
Replying to
@ber@osna.social @kuketzblog@social.tchncs.de Vielleicht ist Threema das tollste Silo, vielleicht gibt's aber auch noch tollere, heute oder morgen. Unsere Strategie ist, sich auf das weltbeste zu einigen, die Welt dorthin zu migrieren, und dann kontrolliert dieser Anbieter die Weltkommunikation?
2
3
0
0
Open post
Holger Weiß @holger@metalhead.club
· 6mo ago
Replying to

@Monal@fosstodon.org Yes.

I think the main scenario that certificate authentication protects against but Dialback does not looks like this:

  • Alice exchanges messages with a remote contact, Bob.
  • Those messages aren't E2E-encrypted/-verified.
  • The attacker cannot MitM Alice's c2s connection.
  • The attacker cannot MitM Bob's c2s connection.
  • The attacker has no access to the remote server's certificate/key.
  • DNSSEC is not deployed for the relevant domain(s).
  • The attacker cannot MitM the (multi-perspective) DNS traffic used for issuing a new certificate.
  • But the attacker can MitM the DNS traffic used for Dialback.
2
0
0
0
Open post
Holger Weiß @holger@metalhead.club
· 6mo ago
Replying to
@thomas@metalhead.club ejabberd 25.07 and newer contain that fix, so no, your instance is not affected.
1
0
0
0
Back
313k7r1n3
Elektrine

Tor hidden service

elekhj7afj4qnrr4yd3bkzslsyo5jgfxw3orgjkhlcxifueodybyiiad.onion

I2P eepsite

j6b6cyk6gjmepjih7jjadxgxvvf3lzzujljuu2v4biemzpg3naya.b32.i2p

Platform

  • Email
  • Chat
  • Timeline
  • VPN
  • DNS

Company

  • About
  • Contact
  • FAQ
  • Lite (no JS)

Legal

  • Terms of Service
  • Privacy Policy
  • Transparency Report
  • Report Abuse
  • Warrant Canary
  • VPN Policy

Support

  • support@elektrine.com
  • Report Security Issue
Mail client setup IMAP mail.elektrine.com:993 POP3 mail.elektrine.com:995 SMTP mail.elektrine.com:465
© 2026 Elektrine. All rights reserved. Server: 03:06:16 UTC