Files
2026-09-06 13:51:11 +00:00

20 lines
1.6 KiB
Markdown

# Testing STARTTLS on Prosody (c2s 5222 / s2s 5269) — tools that lie, and the python way
## Why naive tools fail
- `openssl s_client -connect host:5222` WITHOUT `-starttls` → "wrong version number". Expected: XMPP starts as plaintext XML, TLS upgrade comes after `<starttls/>`.
- `openssl s_client -starttls xmpp ...` → "no peer certificate available", Cipher NONE. FALSE NEGATIVE: OpenSSL 3.x's xmpp starttls mode does not complete Prosody's handshake. Do not chase this.
- Prosody 0.11 does NOT send the stream header first — it waits for the client's `<stream:stream>`. A bare probe that only reads times out; that is normal, not a hang.
- Raw python socket sending nothing → recv timeout. Normal.
## Correct probe: manual STARTTLS in python
1. send `<stream:stream to='nixg.ru' xmlns='jabber:client' xmlns:stream='http://etherx.jabber.org/streams' version='1.0'>` → recv features (starttls, SCRAM-SHA-1)
2. send `<starttls xmlns='urn:ietf:params:xml:ns:xmpp-tls'/>` → recv `<proceed/>`
3. `ssl.create_default_context().wrap_socket(s, server_hostname='nixg.ru')` → recv post-TLS stream header (from='nixg.ru')
4. `tls.getpeercert()` → subject/issuer/SAN. Issuer "Let's Encrypt" = trusted.
Run the ready-made probe: `python3 scripts/starttls_probe.py <host> <port> <domain> [--s2s]`
(s2s uses xmlns jabber:server and tests 5269-style handshakes).
## External testers
- xmpp.net (result.php) is dead/closed since ~2022. Current checker: inspect.xmpp.net.
- Testing the public IP from the SAME host trips the hairpin-NAT trap (traffic never leaves the box, DNAT never fires) — test from vps02 over WG, or from a phone / other VPS.