Re: [Operators] ECDSA certs score F

2014-08-18 Thread Solomon Peachy
On Mon, Aug 18, 2014 at 06:06:21PM +1000, shm...@riseup.net wrote: > i also wonder if mqas.net is the only photographer in the world to have > a dnssec signed zone...not sure how to research that one though Not the only one. :) - Solomon -- Solomon Peachy pizza at shaft

Re: [Operators] ECDSA certs score F

2014-08-18 Thread Thijs Alkemade
On 18 aug. 2014, at 10:06, shm...@riseup.net wrote: > . > . > . > . > . > > s2s and c2s tests reporting ok now > > the new badges are a nice addition > > whatever changed in your report is working for ec certs > > interestingly, this is the only server ever reported to have an ec cert > at xm

Re: [Operators] ECDSA certs score F

2014-08-18 Thread shm...@riseup.net
. . . . . s2s and c2s tests reporting ok now the new badges are a nice addition whatever changed in your report is working for ec certs interestingly, this is the only server ever reported to have an ec cert at xmpp.net i also wonder if mqas.net is the only photographer in the world to have a

Re: [Operators] ECDSA certs score F

2014-08-14 Thread shm...@riseup.net
additionally using this server to chat to many others was tested and working is it because of the cert that the s2s test fails completely ? shm...@riseup.net wrote: > hi Thijs, > > Thijs Alkemade wrote: >> >> On 26 jul. 2014, at 05:18, shm...@riseup.net wrote: > >>> i dont know what's up with t

Re: [Operators] ECDSA certs score F

2014-08-07 Thread shm...@riseup.net
hi Thijs, Thijs Alkemade wrote: > > On 26 jul. 2014, at 05:18, shm...@riseup.net wrote: >> i dont know what's up with the s2s though >> >> > > It’s still unimplemented because I didn’t have any server to test against > when I set it up. i tried mqas.net again s2s but froze again completing on

Re: [Operators] ECDSA certs score F

2014-08-06 Thread Kim Alvefur
On 2014-08-06 10:14, Dave Cridland wrote: > Without an RSA cert at all, can a remote server with only RSA negotiate TLS? Sure they can. But here the only non-ECDSA-ciphers offered are DHE ones, so for another server to support incoming connections from mqas.net they need to have DH parameters set

Re: [Operators] ECDSA certs score F

2014-08-06 Thread Thijs Alkemade
On 26 jul. 2014, at 05:18, shm...@riseup.net wrote: > > hi, > > i was testing an xmpp server and i believe its wrong to reduce the > score because of the cert which is reported < 1024 bits > > i think the testing backend only assumes an RSA cert, is that right ? > > the server i tested is usi

Re: [Operators] ECDSA certs score F

2014-08-06 Thread Dave Cridland
Without an RSA cert at all, can a remote server with only RSA negotiate TLS? On 5 August 2014 19:30, shm...@riseup.net wrote: > ? > > shm...@riseup.net wrote: > > > > hi, > > > > i was testing an xmpp server and i believe its wrong to reduce the > > score because of the cert which is reported <

Re: [Operators] ECDSA certs score F

2014-08-05 Thread shm...@riseup.net
? shm...@riseup.net wrote: > > hi, > > i was testing an xmpp server and i believe its wrong to reduce the > score because of the cert which is reported < 1024 bits > > i think the testing backend only assumes an RSA cert, is that right ? > > the server i tested is using a cert in a pure ECC ch

[Operators] ECDSA certs score F

2014-07-25 Thread shm...@riseup.net
hi, i was testing an xmpp server and i believe its wrong to reduce the score because of the cert which is reported < 1024 bits i think the testing backend only assumes an RSA cert, is that right ? the server i tested is using a cert in a pure ECC chain with ECDSA 384 and not a standard RSA cert