loading

The perfect choice of one-stop service for diversification of architecture.

CA Certificate Shows As Unkown Certificate

Meaning if I specify certfiles here I do not have to specify per each module? like for c2S module, do I have to specify the path for cert file?Looking at the documentation, it clearly says that the option certfiles is global, so ejabberd uses it whenever it has to get certificates in any of its modules:Global Options There are some additional global options that can be specified in the ejabberd configuration file (outside listen):acme: Automated SSL certificate management. See section ACME.certfiles: List of paths: The option accepts a list of file paths (optionally with wildcards) containing either PEM certificates or PEM private keys. At startup, ejabberd sorts the certificates, finds matching private keys and rebuilds full certificates chains. Use this option when enabling options like starttls or tls in listeners ejabberd_c2s, ejabberd_s2s or ejabberd_http. there are a few example configurations that use certfiles global option to define certificates that later are used by specific modules: I am trying to configure a certificate for usage with my ejabberd server. This is not a self-signed cert but one from PossitiveSSL from Comodo valid for 1 year. Cert is not expired.

I have the private key in PEM format, the certificate in .crt and the chain in .ca-bundle

In the /opt/ejabberd/conf/ejabberd.yml there is a line that says:

certfiles: - /opt/ejabberd/conf/server.example.com.crt - /opt/ejabberd/conf/server.example.com.ca-bundle - /opt/ejabberd/conf/privkey.pem

for the privkey.pem I had to remove passphrase as ejabberd services could not start. It failed to read the private key.

My question is: Do I have to have a single PEM file where I will cat privkeycertchain?

I tried both options and it works the same for Gajim client required to do TLS on connection. In may case is easier to leave three lines in config each pointing to proper container.

Anyway, I have a gajim windows XMPP client that connects fine with TLS required to the server and no errors and it's using TLS

When I try to connect another JID via an Android device I get this: Accept Unkonwn Certificate? The server certificate is not signed by a known Certificate AUthority.

Why would I get this? While in Android I have the option to "Always accept" which I do not want to do anyway, since I'm using a signed certificate from Authority, the apple devices don't even give the option to accept anything and TLS connection breaks.

I have tried multiple things but I still get this pop up in android.

Is this entry:

certfiles: - /opt/ejabberd/conf/server.example.com.crt - /opt/ejabberd/conf/server.example.com.ca-bundle - /opt/ejabberd/conf/privkey.pem

Global? Meaning if I specify certfiles here I do not have to specify per each module? like for c2S module, do I have to specify the path for cert file?

listen: - port: 5222 module: ejabberd_c2s ## ## If TLS is compiled in and you installed a SSL ## certificate, specify the full path to the ## file and uncomment these lines: ## ## certfile: "/path/to/ssl.pem" ## starttls: true

Thanks in advance.

·OTHER ANSWER:

I am trying to configure a certificate for usage with my ejabberd server. This is not a self-signed cert but one from PossitiveSSL from Comodo valid for 1 year. Cert is not expired.

I have the private key in PEM format, the certificate in .crt and the chain in .ca-bundle

In the /opt/ejabberd/conf/ejabberd.yml there is a line that says:

certfiles: - /opt/ejabberd/conf/server.example.com.crt - /opt/ejabberd/conf/server.example.com.ca-bundle - /opt/ejabberd/conf/privkey.pem

for the privkey.pem I had to remove passphrase as ejabberd services could not start. It failed to read the private key.

My question is: Do I have to have a single PEM file where I will cat privkeycertchain?

I tried both options and it works the same for Gajim client required to do TLS on connection. In may case is easier to leave three lines in config each pointing to proper container.

Anyway, I have a gajim windows XMPP client that connects fine with TLS required to the server and no errors and it's using TLS

When I try to connect another JID via an Android device I get this: Accept Unkonwn Certificate? The server certificate is not signed by a known Certificate AUthority.

Why would I get this? While in Android I have the option to "Always accept" which I do not want to do anyway, since I'm using a signed certificate from Authority, the apple devices don't even give the option to accept anything and TLS connection breaks.

I have tried multiple things but I still get this pop up in android.

Is this entry:

certfiles: - /opt/ejabberd/conf/server.example.com.crt - /opt/ejabberd/conf/server.example.com.ca-bundle - /opt/ejabberd/conf/privkey.pem

Global? Meaning if I specify certfiles here I do not have to specify per each module? like for c2S module, do I have to specify the path for cert file?

listen: - port: 5222 module: ejabberd_c2s ## ## If TLS is compiled in and you installed a SSL ## certificate, specify the full path to the ## file and uncomment these lines: ## ## certfile: "/path/to/ssl.pem" ## starttls: true

Thanks in advance.

CA Certificate Shows As Unkown Certificate 1

GET IN TOUCH WITH Us
recommended articles
Related Blogs blog
Might I suggest going over to Amazon S3 for image hosting? Depending on your bandwidth, the storage and hosting is cheap and I would think much more reliable and cos...
I've been searching for a solution to this, but the closest thing I came up with to what I want is adding a new item to the context menu which calls a script that ma...
(like FOO, T, ; unlike FOO.BAR, ETE (where that is written as E followed by a U0301 combining acute accent))With ksh or zsh -o kshglob -o nobareglobqual or bash -O e...
In first case :access right prevent shell(*) expansion of /var/solr/data/new_core/_default/* when your are centos.command expand then as /var/solr/data/new_core/_def...
In the windows folder for both the target image and winPE image, you will need to create cmd files that have something like set /p new_variable"type the SSID of the ...
I had the same problem once, I think you should choose more carefully the options of rsync. The option -a equals to -rlptgoD, so rsync tries to preserve permissions,...
Although GPR has been widely used in hydrology, engineering, environment and other fields, many basic theoretical and technical problems have not been fundamentally ...
So I am thinking of a possible answer to my own question:Build my own journal note entry app linked to a wiki.Zim Wiki uses a file based system for wiki. Maybe I cou...
About 8 I think1. where can i get ncaa football 10 rosters with names?For the last two years I got mine from "Pastapadre". From what i can tell they are really prett...
The Haunting I vaguely remember some kind of eye injury in the movie.• Other Related Knowledge ofa cocktail glass— â€&...
no data
Customer service
detect