On Fri, 2009-10-16 at 15:34 -0400, Robert Joly wrote:

I agree with your suggested values, except possibly for these:

> Setting #5- Clients can only connect to the server using secured
> connections.
> openfire-provided default: optional
> new suggested default value: required
> Justification: Privacy concern 
> 
> Setting #6- Connections between servers always use secured
> connections.
> openfire-provided default: optional
> new suggested default value: required
> Justification: : Privacy concern

Requiring secured connections may get you into a whole bunch of
certificate management issues.  The xmpp server cert will need to be
constructed differently than the self-signed cert we have now, and
probably should use a public CA if anyone outside the local domain is
going to attach to it.  

Granted that's imperfect, but most people don't encrypt IM today, and it
seems to have caught on pretty well.


_______________________________________________
sipx-dev mailing list [email protected]
List Archive: http://list.sipfoundry.org/archive/sipx-dev
Unsubscribe: http://list.sipfoundry.org/mailman/listinfo/sipx-dev
sipXecs IP PBX -- http://www.sipfoundry.org/

Reply via email to