Two years and a couple of months ago Prosody’s hashed backend has been activated. Users that have logged in since automatically started using the security improvements it brought (hashed passwords on the server).
Users that haven’t logged in since still have their (old, unhashed) password file on the server and likely don’t use the service anymore. While I usually don’t see a reason to remove accounts at server level (users have the ability to delete their accounts themselves), I see one in this case as it removes the possibility for someone who gained unauthorized access to the server to gain possession of those unprotected password files.
If you haven’t logged in for more than two years and would like to keep your account, simply log in during the next ~30 days. Thank you.
I’m working on renewing the certificates. The new ones should be StartSSL™ Verified, which brings a couple of advantages (valid for two years, multiple domains in one cert etc.) and a slight disadvantage (they are not free anymore).
Update: The new certificate is in place. It’s valid for 2 years and has the following fingerprints:
Just a note to let you know the server has been restarted today because we hit a connection limit. Should be fine for the forseeable future now.
A certificate will be replaced this week since it has been expired.
This is a list of fingerprints in order to make sure you know it’s safe to accept the new one:
This post will be updated once the new certificate is in place. As always, please let us know if you encounter any kind of problems.
A couple of certificates will be replaced today since they have been expired.
This is a list of fingerprints in order to make sure you know it’s safe to accept the new ones:
thiessen.it and im.thiessen.it:
This post will be updated once the new certificates are in place. As always, please let us know if you encounter any kind of problems.
Update: The new certificates have been applied.
The provider hosting our machines recently informed us about planned maintenance work. We expect they won’t be reachable a couple of times during late night hours CET (UTC +1).
Tonight this will affect de2.xmpp.thiessen.org which is currently hosting:
- thiessen.im and its conference
On sunday, november 1st de1.xmpp.thiessen.org will be affected which is currently hosting:
- thiessen.it and its subdomains jabber.thiessen.it and im.thiessen.it
We are sorry for the inconvinience.
On Saturday, August 29 between 11:00 pm and 12:00 midnight (CEST) we will switch from ejabberd to Prosody.
We are also upgrading the host system from Debian Etch to Debian Lenny.
During this window, the domains thiessen.it, im.thiessen.it and jabber.thiessen.it won’t be available.
If you have any questions or encounter problems after the migration process
please join our support channel.
Please login using your username in lowercase. Fixed, thanks Tobias Markmann.
Short notice that we switched DNS-Servers today.
If you should encounter any problems (e.g. not being able to connect etc.) please use our webchat and notify us.
On Tuesday, June 2 between 8:00 am and 9:00 am (CEST) we will be performing maintenance work in our production environment.
During this window, the ‘thiessen.it’ domains won’t be available.
Update: The service is back up and running. From now on the ‘thiessen.it’ domains also listen on port 80 and 443. Please notify us if you encounter any problems.
Today we updated ejabberd to version 2.0.5 which has been released on april, 3rd. We didn’t encounter any problems during the process.
The main changes are:
- Fix two problems introduced in ejabberd 2.0.4: subscription request produced many authorization requests with some clients and transports; and subscription requests were not stored for later delivery when receiver was offline.
- Fix warning in expat_erl.c about implicit declaration of x_fix_buff
- HTTP-Bind (BOSH): Fix a missing stream:error in the returned remote-stream-error stanza