fosstodon.org is one of the many independent Mastodon servers you can use to participate in the fediverse.
Fosstodon is an invite only Mastodon instance that is open to those who are interested in technology; particularly free & open source software. If you wish to join, contact us for an invite.

Administered by:

Server stats:

10K
active users

XSF: XMPP Standards Foundation

Announcement

Recently there was an incident via a so called attack happened to an .

To reduce the risk of such attacks in the future an early stage service called CertWatch has been published by our Community: certwatch.xmpp.net/

Many thanks to Stephen P. Weber (@singpolyma)!

Read two related blog posts:
blog.jmp.chat/b/certwatch/cert

snikket.org/blog/on-the-jabber

@xmpp @singpolyma seems it does not follow cname? or it does not tell if domain is ok already?

@ruff
It should work, could you tell me what name you are trying to check for debugging? (as DM of you wish)
@xmpp @singpolyma

@Menel @xmpp @singpolyma ok perhaps it's caching more agressively than SOA TTL, I just set tlsa and checked - it was saying i should set tlsa, waited for ttl time, rechecked - still said I need to set tlsa. But today it's ok, shows green.

@xmpp @singpolyma An alternative form of MitM is Manipulator-in-the-middle.

I prefer it as it is (1) more accurate and (2) less focused on a gender („man“ being ambiguous in English here).

@xmpp

#XMPP #CertWatch said that »[My] settings are correct and no MITM was detected.« That's great.

It then continued with some #PubSub stuff and finally said »If you do not have a pubsub-capable client you can subscribe for text notifications by opening a chat with certwatch.xmpp.net and sending the message “subscribe <my xmpp server>”«.

My question is now: How do I open a chat with a hostname and not a JID?

My clients are #Gajim resp. #Conversations / #BlabberIM.

Anyone?
certwatch.xmpp.netCertWatch: XMPP MITM Monitoring

@kas
With my clients (#profanity and #conversations) I just open the chat the same way I would do it with a user@example.org JID. I just have to confirm that I really want to do this in conv.
@xmpp

@mdosch Thank you Martin, that made the trick: While Gajim seems to refuse a domain name, Conversations will indeed let me do it if I choose the “Do it anyway” button (I would have tried Profanity if Conversations hadn't worked out, I forgot I also use that client). 🙏
@mdosch @xmpp The certwatch.xmpp.net is rather picky with the format: If I accidentally end “subscribe <my server name>” with a linefeed, it will claim that “That node does not exist”.
certwatch.xmpp.netCertWatch: XMPP MITM Monitoring

@xmpp @singpolyma It throws a 504 error if your c2s ports aren’t open to all IP addresses. But once I relaxed my server’s firewall, it was fine.