[jdev] Securing XMPP

2013-08-28 Thread Simon Tennant
I'm attempting to gather the details in one place on how to secure XMPP servers C2S and S2S traffic: http://wiki.xmpp.org/web/Securing_XMPP The DANE stuff is all pretty new and I'm struggling to find working examples of how we'd ensure that servers and DNS are setup to only use SSL. Is there

Re: [jdev] Securing XMPP

2013-08-28 Thread Matthew Wild
On 28 August 2013 17:14, Simon Tennant si...@buddycloud.com wrote: I'm attempting to gather the details in one place on how to secure XMPP servers C2S and S2S traffic: http://wiki.xmpp.org/web/Securing_XMPP Only feedback so far: you might want to clarify the single domain/multiple domain

Re: [jdev] Securing XMPP

2013-08-28 Thread Peter Saint-Andre
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 On 8/28/13 10:28 AM, Matthew Wild wrote: On 28 August 2013 17:14, Simon Tennant si...@buddycloud.com wrote: I'm attempting to gather the details in one place on how to secure XMPP servers C2S and S2S traffic:

Re: [jdev] Securing XMPP

2013-08-28 Thread Thijs Alkemade
On 28 aug. 2013, at 18:33, Peter Saint-Andre stpe...@stpeter.im wrote: On 8/28/13 10:28 AM, Matthew Wild wrote: On 28 August 2013 17:14, Simon Tennant si...@buddycloud.com wrote: I'm attempting to gather the details in one place on how to secure XMPP servers C2S and S2S traffic:

Re: [jdev] Securing XMPP

2013-08-28 Thread Olle E. Johansson
28 aug 2013 kl. 18:33 skrev Peter Saint-Andre stpe...@stpeter.im: DANE/DNSSEC is great for that, or will be when it is more generally available, but IMHO we might need to wait *years* for that to happen. Peter, If you keep repeating this statement it will become true... I don't think we're

Re: [jdev] Securing XMPP

2013-08-28 Thread Peter Saint-Andre
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 On 8/28/13 12:42 PM, Olle E. Johansson wrote: 28 aug 2013 kl. 18:33 skrev Peter Saint-Andre stpe...@stpeter.im: DANE/DNSSEC is great for that, or will be when it is more generally available, but IMHO we might need to wait *years* for that to