Open Neustradamus opened 5 years ago
Short version:
jabber.org uses 1024 bit DH parameters.
Recent OpenSSL (1.1.1 possibly) enforces a limit on (I think) 2048 bit minimum.
Hilarity ensues. ^W^W
Nothing works.
I think this implies that the jabber.org contigent have detached from the rest of federated XMPP space (or is at least becoming more so, as openssl 1.1.1 is spreading). It's a loss!
Same here with trashserver.net :( Too bad the problem still exists.
To allow connections to ancient, poorly secured servers you need to do the following:
in /etc/ssl/default.cnf go to section [system_default_sect] and set CipherString = DEFAULT@SECLEVEL=1
However, this will weaken overall encryption security of your system, so you must know what you're doing...
This problem is now more aggressive. Connections e.g. Jabber.de no longer work properly.
@stpeter: Any news about the migration?
@stpeter: Any news about the end of the migration after several months?
@stpeter: https://weakdh.org/
When we contact a Jabber.org JID:
When we go on a Jabber.org Muc Room: