Remember the threads¹² about #LetsEncrypt removing a crucial key usage from certificates issued by them in predictive obedience to their premium sponsor Google?

We were at first concerned about #SMTP. While I had lived through this problem with #StartSSL by #StartCom back in 2011, I only had a vague recollection of Jabber but recalled in detail that it broke server-to-server SMTP verification (whether the receiving server acted on it or just documented it).

Well, turns out someone now reported that it indeed breaks #XMPP entirely: community.letsencrypt.org/t/do…

This means that it will soon no longer be possible at all to operate Jabber (XMPP) servers because the servers use the operating system’s CA certificate bundle for verification, which generally follows the major browsers’ root stores, which has requirements from the CA/Browser forum who apparently don’t care about anything else than the webbrowser, and so no CA whose root certificate is in that store will be allowed to issue certificates suitable for Jabber/XMPP server-to-server communication while these CAs are the only ones trusted by those servers.

So, yes, Google’s requirement change is after all breaking Jabber entirely. Ein Schelm, wer Böses dabei denkt.

Update: it also breaks the connections between domain registrars and registries, with most being unaware that there even is a problem at this time, let alone the crazily short timeframe. See the thread linked to in a self-reply, which also confirms that the CA/Browser forum is supporting Google in this (possibly by means of Google paying, my interpretation).

While nerdcert.eu/ by @jwildeboer would in theory help, it’s not existent yet, and there’s not just the question of when it will be included in operating systems’ root CA stores but whether it will be included in them at all.

Google’s policy has no listed contact point, and the CA/B forum isn’t something mere mortals can complain to, so I’d appreciate if someone who can, and who has significant skills to argument this in English and is willing to, to bring it to them.

① mine: toot.mirbsd.org/@mirabilos/sta…
② jwildeboer’s: social.wildeboer.net/@jwildebo…


Dear #Letsencrypt, you helped secure millions and millions of servers, not just web servers. But your announcement at letsencrypt.org/2025/05/14/end… about ending Ending TLS Client Authentication Certificate Support in 2026 because Google changes their requirements would result in your certificates becoming a possible risk for ensuring SMTP traffic. Please think again. Please.

1/5


This entry was edited (6 months ago)

Dnes bylo celej den hnusne, takze vyjmecne stravena nedela doma misto v lese 🌳 ... toz proc to nevyuzit a nedat si nakej oblibenej cajik.

Zacal sem sheng pu cihlickou z 2004, je silne presovana a priprava vzdy peklicko, krasne vyzrala chut to vse prebiji.

Odpo sem presel na Liu an, pripomina mi vzdy vuni jehlici po desti 🌲 :) typicky se louhuje i s kouskem bambusu z kosicku.

Jinak kdybyste nekdo meli matrix a chteli si pokecat o caji pridte do #caj:mxchat.cz / #caj:matrix.org #caj #tea

#tea #caj
This entry was edited (6 months ago)

In der Oranienbaumer Heide kann man laut #reddit Wiedehopfe (Upupa epops, 🇬🇧 Hoopoe, 🇵🇱 dudek) sehen. Das ist nicht weit von mir. Ich habe den Ort in Google Maps auf gut Glück markiert und auf geht's. Als ich dort ankam, hörte ich diesen unverwechselbaren Gesang. Wegen der Entfernung und der Lichtverhältnisse sind die Fotos nicht grandios, aber ich bin trotzdem unglaublich glücklich!

#birds #birdphotography #birdsofmastodon #birdwatching #nature #naturephotography #vogelflausch #ptaki

Inside AXS Labs’ Mission to make the Real world a more accessible place to All disabled People curbcuts.co/blog/2025-5-28-how…

The Document Foundation announces LibreOffice 25.2.4 blog.documentfoundation.org/bl…

WEBINAR – SuperBrain Telehaptic Device enviter.eu/webinar-superbrain-…

A Saturday full of NVDA goodness!
Jamies’s latest try build fixed all the Start menu issues in Windows 11 24H2, including the NVDA freeze. @jcsteh awesome job!
Then Joseph’s 25.6 build of Win App Essentials add-on fixed NVDA not providing feedback when using Windows+Arrow keys to minimize, maximize, restore, or snap windows.
It also fixed NVDA’s silence when typing numbers in the “Go to line” dialog in modern Notepad, plus some improvements for the Voice Access app.
Let’s call it an NVDA avalanche then!
@NVAccess
github.com/nvaccess/nvda/issue…
github.com/josephsl/wintenApps…
This entry was edited (6 months ago)

New AI tool for people with learning disabilities converts information into easy read formats attoday.co.uk/new-ai-tool-for-…

Free guide provides a comprehensive framework for understanding and improving the assistive tech market attoday.co.uk/free-guide-provi…

Free guide provides a comprehensive framework for understanding and improving the assistive tech market attoday.co.uk/free-guide-provi…

Court allows Trump administration to proceed with efforts to destroy Institute of Museum and Library Services as case continues ala.org/news/2025/06/court-all…

I prompted Eleven Labs to create a sound effect with the following: “A joyful jingle that combines the sound of mirrors, crystal glasses, water drops, brushes and aspen trees.”
Among a few choices I got, this one really caught my attention! #AudioMo
This entry was edited (6 months ago)

Peter Vágner reshared this.

Introducing Eleven V3 (Alpha): elevenlabs.io/blog/eleven-v3
Wow, listen to the sample of that sports commentator. Amazing!
Also, love the idea of audio tags. Make it easy! :)

Configured auto-mounting of USB storage devices on FreeBSD courtesy of `sysutils/automount` and instructions by @vermaden ... tested with my Kobo ereader and it works good!

vermaden.wordpress.com/2018/10…

#FreeBSD #RunBSD