mirror of
https://gitverse.ru/kpa39l/xmpp-server-prosody.git
synced 2026-09-29 22:05:03 +00:00
20 lines
1.6 KiB
Markdown
20 lines
1.6 KiB
Markdown
# Testing STARTTLS on Prosody (c2s 5222 / s2s 5269) — tools that lie, and the python way
|
|
|
|
## Why naive tools fail
|
|
- `openssl s_client -connect host:5222` WITHOUT `-starttls` → "wrong version number". Expected: XMPP starts as plaintext XML, TLS upgrade comes after `<starttls/>`.
|
|
- `openssl s_client -starttls xmpp ...` → "no peer certificate available", Cipher NONE. FALSE NEGATIVE: OpenSSL 3.x's xmpp starttls mode does not complete Prosody's handshake. Do not chase this.
|
|
- Prosody 0.11 does NOT send the stream header first — it waits for the client's `<stream:stream>`. A bare probe that only reads times out; that is normal, not a hang.
|
|
- Raw python socket sending nothing → recv timeout. Normal.
|
|
|
|
## Correct probe: manual STARTTLS in python
|
|
1. send `<stream:stream to='nixg.ru' xmlns='jabber:client' xmlns:stream='http://etherx.jabber.org/streams' version='1.0'>` → recv features (starttls, SCRAM-SHA-1)
|
|
2. send `<starttls xmlns='urn:ietf:params:xml:ns:xmpp-tls'/>` → recv `<proceed/>`
|
|
3. `ssl.create_default_context().wrap_socket(s, server_hostname='nixg.ru')` → recv post-TLS stream header (from='nixg.ru')
|
|
4. `tls.getpeercert()` → subject/issuer/SAN. Issuer "Let's Encrypt" = trusted.
|
|
|
|
Run the ready-made probe: `python3 scripts/starttls_probe.py <host> <port> <domain> [--s2s]`
|
|
(s2s uses xmlns jabber:server and tests 5269-style handshakes).
|
|
|
|
## External testers
|
|
- xmpp.net (result.php) is dead/closed since ~2022. Current checker: inspect.xmpp.net.
|
|
- Testing the public IP from the SAME host trips the hairpin-NAT trap (traffic never leaves the box, DNAT never fires) — test from vps02 over WG, or from a phone / other VPS. |