#780113 mcabber: should have more finegrained options for accepting 'invalid' certificates

Package:
mcabber
Source:
mcabber
Description:
small Jabber (XMPP) console client
Submitter:
Toni Mueller
Date:
2015-11-09 19:42:12 UTC
Severity:
wishlist
#780113#5
Date:
2015-03-09 12:35:13 UTC
From:
To:
Dear Maintainer,

after the recent certificate event at jabber.org (see
https://twitter.com/jabberdotorg/status/573882527280066561), the only
way I found around that problem was to add

    set ssl_verify = 0

to my mcabberrc. It would be great if there were advanced settings like
"ignore expiry date", or "accept this CA", eg.  if someone is using
their own CA, or "minimum key size", or "allow cert by fingerprint".

Just wishing... :/


Kind regards,
--Toni++

#780113#10
Date:
2015-11-09 19:39:22 UTC
From:
To:
Hi Tony,

Doesn't the 'ssl_fingerprint' option do what you want?

(mcabber >= 1.0.0, if used with Loudmouth 1.5.1, should let you set your
own certificate location, BTW.)

Regards,