27/10/2005
jabberd2 starttls client problems
I’ve recently setup another jabberd2 installation. This time I had
Filed by kargig at 02:09 under Encryption,General,Privacy
2 Comments | 4,677 views
Considering that only Gaim has this thing implemented, my best guess is that it is that hard. An alternative is that this feature does not worth it.
it’s in the rfc…it should be implemented. And security is always needed and worth the extra effort/(cpu|mind) cycles.
http://www.xmpp.org/specs/rfc3920.html#tls
quoting the rfc:
That “SHOULD” word for clients makes the difference, and is what I am talking about.
It’s about whether you want to authenticate over an encrypted “channel” or not…authentication and encryption should start “hanging out as best friends” as soon as possible for programmers. STARTTLS offers to the client the ability to encrypt his session over the current connection without having prior knoledge for a different “SSL enabled” port.
It’s usefull…at least to me, and it is in use with IMAP servers for years, so it’s feasible-doable-not that hard to do.