#Certificate authorities have decided to stop setting the “TLS client” #EKU on the #TLS server certificates they issue.
This immediately created a problem for server-to-server protocols like #SMTP and #XMPP.
Now it looks like XMPP servers have begun to simply ignore their clients' certificates' EKU. https://monal-im.org/post/00016-upgrade-ejabberd-on-debian/
I thought restricting the EKU like this was a bad idea. Looks like I was right. The #CA decision is backfiring.
Chances might be that you are running a Debian based ejabberd server. Unfortunately push for all your Monal users on that server will break in less than 2 month. And chances are that some of your S2S connections are already failing today. Some background The Web-PKI is moving away from certificates having bot, the TLS Web Server Authentication and the TLS Web Client Authentication extended key usage enabled. Most CAs already stopped issuing certificates with the TLS Web Client Authentication EKU set or will stop doing so in a few month.
"#Easter is an important day for many and sharing a meal is a traditional part of this celebration. People like "Bonita" who harvests carrots in #CA’s #CentralCoast, make these sacred meals possible. #WeFeedYou"
#CityAttorneyLosAngeles #MarissaRoy #CandidateCorner
#LosAngeles #LA #California #CA

