logoalt Hacker News

benjojo12yesterday at 10:42 PM1 replyview on HN

For those wondering if ejabberd Debian systems will be impacted, it seems like for now there no fix, the issue is being tracked here: https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1127369


Replies

Avamanderyesterday at 11:16 PM

Code can just ignore the EKU. Especially if the ecosystem consists of things that are already using certificates in odd ways, as it shouldn't be making outgoing connections without it in the first place.