<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
  <channel>
	<title>Liberated Embedded Systems</title>
	<link>https://liberatedsystems.co.uk/</link>
	<description>Recent content on Liberated Embedded Systems</description>
	<generator>Hugo -- gohugo.io</generator>
	<language>en-gb</language>
	<lastBuildDate>Tue, 23 May 2023 12:59:44 +0100</lastBuildDate>
    
        <atom:link href="https://liberatedsystems.co.uk/index.xml" rel="self" type="application/rss+xml" />
    
        
	<item>
		<title>OFF-GRID COMMS - OPENCOM XL</title>
		<link>https://liberatedsystems.co.uk/blog/off-grid-comms-opencom-xl/</link>
		<pubDate>Thu, 22 Jun 2023 18:04:58 +0100</pubDate>
		<guid>https://liberatedsystems.co.uk/blog/off-grid-comms-opencom-xl/</guid>
		<description>&lt;h2 id=&#34;introduction&#34;&gt;Introduction&lt;/h2&gt;
&lt;p&gt;When you Google around about off-grid communications, a common theme emerges. Most options presented to you &lt;strong&gt;aren&amp;rsquo;t really off-grid&lt;/strong&gt;. 4G internet connections, satellite communications, etc. Yes sure, they do work, but they are still operated by the Government or a private company. Where&amp;rsquo;s the fun (or utility) in that?&lt;/p&gt;
&lt;p&gt;Imagine someone who, after you ask them how to get water off-grid, tells you that you should order bottled water online and get it delivered. It&amp;rsquo;s simply a different way of getting the exact same thing you had before, and it doesn&amp;rsquo;t make you any more off-grid or free from outside influences.&lt;/p&gt;
&lt;p&gt;In the case of water, you build your own well. There is also a way to install &amp;amp; operate off-grid communications yourself, without relying on the Government or other companies outside of your control.&lt;/p&gt;
&lt;p&gt;The &lt;a href=&#34;https://store.liberatedsystems.co.uk/product/opencom-xl/&#34;&gt;openCom XL&lt;/a&gt; is a handheld digital radio which can be used for general purpose communication. Combined with &lt;a href=&#34;https://git.liberatedsystems.co.uk/jacob.eva/openCom-Companion&#34;&gt;openCom Companion&lt;/a&gt; (or Sideband for desktop), you can:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;send texts&lt;/li&gt;
&lt;li&gt;send voice messages&lt;/li&gt;
&lt;li&gt;send images&lt;/li&gt;
&lt;li&gt;share your location&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;You can also perform audio calls and browse websites with &lt;a href=&#34;https://meshchat.app&#34;&gt;Reticulum Meshchat&lt;/a&gt;.&lt;/p&gt;
&lt;p&gt;All you need to be able to communicate is an openCom XL (or another RNode) on either side and a decent line of sight between the two points. Below, I give an example of a field test over two headlands I conducted with a friend.&lt;/p&gt;
&lt;h2 id=&#34;demonstration&#34;&gt;Demonstration&lt;/h2&gt;
&lt;p&gt;Our test area in Cornwall was along the south coastline. I set up at Dodman&amp;rsquo;s
point (green on the map), and I dropped my friend off at Killigerran Head (red
on the map) on the way. The total distance between the two points was around
&lt;strong&gt;9.2 miles&lt;/strong&gt; (14.8 km), a decent distance!&lt;/p&gt;
&lt;p&gt;&lt;img src=&#34;map.webp&#34; alt=&#34;A map of the coastline&#34;&gt;&lt;/p&gt;
&lt;p&gt;I was set up next to the huge cross at Dodman&amp;rsquo;s point.&lt;/p&gt;
&lt;p&gt;&lt;img src=&#34;dodman.webp&#34; alt=&#34;A cross with my laptop and radio at the bottom&#34;&gt;&lt;/p&gt;
&lt;p&gt;And my friend was ready at Killigerran Head. You can see Dodman&amp;rsquo;s point in this
image, it&amp;rsquo;s the furthest headland, in the center of the horizon.&lt;/p&gt;
&lt;p&gt;&lt;img src=&#34;killigerran.webp&#34; alt=&#34;A laptop and radio sat on a bench&#34;&gt;&lt;/p&gt;
&lt;p&gt;We fired up the radios then set the same channel and the spreading factor to 7
on each side (&lt;strong&gt;similar to the &amp;ldquo;medium range&amp;rdquo; preset on openCom companion&lt;/strong&gt;).
This gave us a link speed of &lt;strong&gt;5.47 kbps&lt;/strong&gt; between the two radios on the long
range modem. We did not utilise the high data rate modem in the radios as the
distance was too far for it to work reliably with our setup. Most likely the
difference in height between the two points also did not help.&lt;/p&gt;
&lt;p&gt;The data transfer speed is slow by modern standards, but it is perfectly adequate for
sending texts, transferring small files and even having push to talk audio calls. All
of which we tested of course. The audio call was somewhat difficult at times
due to the high winds blowing in the microphones, but we could hear each other!&lt;/p&gt;
&lt;p&gt;My friend also sent me a 240kb file, which took a couple of minutes to transfer but
arrived without any issues thanks to the reliable software backing the radios.&lt;/p&gt;
&lt;p&gt;At a signal strength of &lt;strong&gt;-107dBm&lt;/strong&gt;, the radio could most likely have gone even
further had we moved a short distance away from each other, and should have provided a
similar data rate to what we recorded here.&lt;/p&gt;
&lt;p&gt;All in all, our test was a massive success, and it serves as a great demonstration of the power of the openCom XL. You can &lt;a href=&#34;https://store.liberatedsystems.co.uk/product/opencom-xl/&#34;&gt;buy one in my store here&lt;/a&gt;.&lt;/p&gt;
&lt;p&gt;Join me, and experience truly free and off-grid communications.
&lt;strong&gt;TECHNOLOGY FOR FREEDOM.&lt;/strong&gt;&lt;/p&gt;
</description>
	</item>
	
	<item>
		<title>XMPP SETUP TUTORIAL: FED HUNTER EDITION</title>
		<link>https://liberatedsystems.co.uk/blog/xmpp-setup-tutorial/</link>
		<pubDate>Wed, 21 Jun 2023 18:30:13 +0100</pubDate>
		<guid>https://liberatedsystems.co.uk/blog/xmpp-setup-tutorial/</guid>
		<description>&lt;p&gt;&lt;b&gt;Are you tired of the government spying on you all the time, with proprietary
messaging applications like Telegram and Whatsapp?&lt;/b&gt;&lt;/p&gt;
&lt;p&gt;Fear no more, this tutorial will explain how to setup an ejabberd XMPP server
with a basic configuration, along with enabling federation, in order to allow
you to stay in touch with others online without any &lt;b&gt;glowies&lt;/b&gt; looking over
your shoulder.&lt;/p&gt;
&lt;p&gt;This tutorial is also in video format, which you can find
&lt;a href=&#34;https://videos.liberatedsystems.co.uk/w/jdUfUq5YPW8eRG5QjXJRem&#34;&gt;here&lt;/a&gt;.&lt;/p&gt;
&lt;h3&gt;Table Of Contents&lt;/h3&gt;
&lt;nav id=&#34;TableOfContents&#34;&gt;
  &lt;ul&gt;
    &lt;li&gt;&lt;a href=&#34;#dns-setup&#34;&gt;DNS setup&lt;/a&gt;&lt;/li&gt;
    &lt;li&gt;&lt;a href=&#34;#prerequisite-packages&#34;&gt;Prerequisite packages&lt;/a&gt;&lt;/li&gt;
    &lt;li&gt;&lt;a href=&#34;#installing-ejabberd&#34;&gt;Installing ejabberd&lt;/a&gt;&lt;/li&gt;
    &lt;li&gt;&lt;a href=&#34;#creating-nginx-domains&#34;&gt;Creating nginx domains&lt;/a&gt;
      &lt;ul&gt;
        &lt;li&gt;&lt;a href=&#34;#main-domain&#34;&gt;Main domain&lt;/a&gt;&lt;/li&gt;
        &lt;li&gt;&lt;a href=&#34;#subdomains&#34;&gt;Subdomains&lt;/a&gt;&lt;/li&gt;
        &lt;li&gt;&lt;a href=&#34;#creating-symlinks&#34;&gt;Creating symlinks&lt;/a&gt;&lt;/li&gt;
      &lt;/ul&gt;
    &lt;/li&gt;
    &lt;li&gt;&lt;a href=&#34;#restart-nginx&#34;&gt;Restart nginx&lt;/a&gt;&lt;/li&gt;
    &lt;li&gt;&lt;a href=&#34;#editing-certbot-renewservice&#34;&gt;Editing certbot-renew.service&lt;/a&gt;&lt;/li&gt;
    &lt;li&gt;&lt;a href=&#34;#running-certbot&#34;&gt;Running certbot&lt;/a&gt;&lt;/li&gt;
    &lt;li&gt;&lt;a href=&#34;#configuring-ejabberd&#34;&gt;Configuring ejabberd&lt;/a&gt;
      &lt;ul&gt;
        &lt;li&gt;&lt;a href=&#34;#hosts&#34;&gt;Hosts&lt;/a&gt;&lt;/li&gt;
        &lt;li&gt;&lt;a href=&#34;#certificates&#34;&gt;Certificates&lt;/a&gt;&lt;/li&gt;
        &lt;li&gt;&lt;a href=&#34;#sql-database&#34;&gt;SQL database&lt;/a&gt;&lt;/li&gt;
        &lt;li&gt;&lt;a href=&#34;#client-to-server-tls-config&#34;&gt;Client to server TLS config&lt;/a&gt;&lt;/li&gt;
        &lt;li&gt;&lt;a href=&#34;#server-to-server-tls-config&#34;&gt;Server to server TLS config&lt;/a&gt;&lt;/li&gt;
      &lt;/ul&gt;
    &lt;/li&gt;
    &lt;li&gt;&lt;a href=&#34;#generate-dhfile&#34;&gt;Generate dhfile&lt;/a&gt;&lt;/li&gt;
    &lt;li&gt;&lt;a href=&#34;#verify-config&#34;&gt;Verify config&lt;/a&gt;&lt;/li&gt;
    &lt;li&gt;&lt;a href=&#34;#register-admin-user&#34;&gt;Register admin user&lt;/a&gt;&lt;/li&gt;
    &lt;li&gt;&lt;a href=&#34;#connecting&#34;&gt;Connecting&lt;/a&gt;&lt;/li&gt;
    &lt;li&gt;&lt;a href=&#34;#federation&#34;&gt;Federation&lt;/a&gt;
      &lt;ul&gt;
        &lt;li&gt;&lt;a href=&#34;#testing-optional&#34;&gt;Testing (optional)&lt;/a&gt;&lt;/li&gt;
      &lt;/ul&gt;
    &lt;/li&gt;
    &lt;li&gt;&lt;a href=&#34;#closing&#34;&gt;Closing&lt;/a&gt;&lt;/li&gt;
  &lt;/ul&gt;
&lt;/nav&gt;

&lt;h2 id=&#34;dns-setup&#34;&gt;DNS setup&lt;/h2&gt;
&lt;p&gt;To start, ensure you have the following DNS entries present on your domain registrar&amp;rsquo;s management interface:&lt;/p&gt;
&lt;pre tabindex=&#34;0&#34;&gt;&lt;code&gt;liberatedsystems.co.uk A x.x.x.x
conference.liberatedsystems.co.uk A x.x.x.x
upload.liberatedsystems.co.uk A x.x.x.x
proxy.liberatedsystems.co.uk A x.x.x.x
pubsub.liberatedsystems.co.uk A x.x.x.x
&lt;/code&gt;&lt;/pre&gt;&lt;p&gt;Of course, ensure you replace liberatedsystems.co.uk with your own domain, and x.x.x.x with your server&amp;rsquo;s IP address.&lt;/p&gt;
&lt;h2 id=&#34;prerequisite-packages&#34;&gt;Prerequisite packages&lt;/h2&gt;
&lt;p&gt;I am assuming that you are performing this install on an Arch-based server, and
are therefore using the packages from the official repositories.&lt;/p&gt;
&lt;p&gt;You should ensure you have the following packages installed:&lt;/p&gt;
&lt;pre tabindex=&#34;0&#34;&gt;&lt;code&gt;Certbot
MariaDB (and running)
nginx (and running)
&lt;/code&gt;&lt;/pre&gt;&lt;h2 id=&#34;installing-ejabberd&#34;&gt;Installing ejabberd&lt;/h2&gt;
&lt;p&gt;Pretty damn easy to be honest, just run the below command to install ejabberd.&lt;/p&gt;
&lt;pre tabindex=&#34;0&#34;&gt;&lt;code&gt;doas/sudo pacman -S ejabberd
&lt;/code&gt;&lt;/pre&gt;&lt;p&gt;Of course choosing sudo &lt;b&gt;or&lt;/b&gt; doas depending on which you have installed.&lt;/p&gt;
&lt;h2 id=&#34;creating-nginx-domains&#34;&gt;Creating nginx domains&lt;/h2&gt;
&lt;p&gt;Next, we must add the various domains you created DNS entries for to nginx, so
that certbot can request and automatically renew certificates for these
domains.&lt;/p&gt;
&lt;h3 id=&#34;main-domain&#34;&gt;Main domain&lt;/h3&gt;
&lt;p&gt;If you have not yet done so, install the below nginx configuration file for
your main domain in &lt;code&gt;/etc/nginx/sites-available/liberatedsystems.co.uk&lt;/code&gt;:&lt;/p&gt;
&lt;pre tabindex=&#34;0&#34;&gt;&lt;code&gt;server {
    server_name liberatedsystems.co.uk;

    listen 80;
    
    return 404;
}
&lt;/code&gt;&lt;/pre&gt;&lt;p&gt;Again, substitute liberatedsystems.co.uk for your domain. All this config file
does is listen for requests and return 404 if any are received. You may wish to
edit this later if you&amp;rsquo;d like to host a main site.&lt;/p&gt;
&lt;h3 id=&#34;subdomains&#34;&gt;Subdomains&lt;/h3&gt;
&lt;p&gt;Next, you should also install the above config file in the following locations:&lt;/p&gt;
&lt;pre tabindex=&#34;0&#34;&gt;&lt;code&gt;/etc/nginx/sites-available/conference.liberatedsystems.co.uk
/etc/nginx/sites-available/upload.liberatedsystems.co.uk
/etc/nginx/sites-available/proxy.liberatedsystems.co.uk
/etc/nginx/sites-available/pubsub.liberatedsystems.co.uk
&lt;/code&gt;&lt;/pre&gt;&lt;p&gt;Ensure that besides substituting the domain for your own, you also add the
subdomain to the server_name variable for each config.&lt;/p&gt;
&lt;h3 id=&#34;creating-symlinks&#34;&gt;Creating symlinks&lt;/h3&gt;
&lt;p&gt;Now, ensure that you create symlinks in the &lt;code&gt;sites-enabled&lt;/code&gt; folder pointing to
the config files in the &lt;code&gt;sites-available&lt;/code&gt; folder, for example:&lt;/p&gt;
&lt;pre tabindex=&#34;0&#34;&gt;&lt;code&gt;doas/sudo ln -s /etc/nginx/sites-available/liberatedsystems.co.uk /etc/nginx/sites-enabled/liberatedsystems.co.uk
&lt;/code&gt;&lt;/pre&gt;&lt;p&gt;Once more, ensure you do this for each config file in the directory,
substituting &lt;code&gt;liberatedsystems.co.uk&lt;/code&gt; with the relevant domain. If you don&amp;rsquo;t,
you might end up having as bad of a time as &lt;a href=&#34;https://topgear.fandom.com/wiki/H982_FKL&#34;&gt;Top Gear in
Argentina&lt;/a&gt;.&lt;/p&gt;
&lt;h2 id=&#34;restart-nginx&#34;&gt;Restart nginx&lt;/h2&gt;
&lt;p&gt;After all that, just run the following to restart nginx and get it to load the config files:&lt;/p&gt;
&lt;pre tabindex=&#34;0&#34;&gt;&lt;code&gt;doas/sudo systemctl restart nginx
&lt;/code&gt;&lt;/pre&gt;&lt;h2 id=&#34;editing-certbot-renewservice&#34;&gt;Editing certbot-renew.service&lt;/h2&gt;
&lt;p&gt;Now we must edit the &lt;code&gt;certbot-renew.service&lt;/code&gt; file from the certbot package, as
by default the TLS certificates are stored separately and are owned by &lt;code&gt;root&lt;/code&gt;,
which is not what &lt;code&gt;ejabberd&lt;/code&gt; needs.&lt;/p&gt;
&lt;p&gt;Therefore, we will run the following:&lt;/p&gt;
&lt;pre tabindex=&#34;0&#34;&gt;&lt;code&gt;doas/sudo systemctl edit certbot-renew.service
&lt;/code&gt;&lt;/pre&gt;&lt;p&gt;Once you have entered your text editor, paste the following above the &amp;ldquo;edits
below will be discarded&amp;rdquo; line:&lt;/p&gt;
&lt;pre tabindex=&#34;0&#34;&gt;&lt;code&gt;[Unit]
Description=Renew certificates acquired via Certbot
Documentation=https://eff-certbot.readthedocs.io/en/stable/

[Service]
Type=oneshot
ExecStart=/usr/bin/certbot -q renew
ExecStop=/bin/bash -c &amp;#39;/bin/cat /etc/letsencrypt/live/liberatedsystems.co.uk/privkey.pem /etc/letsencrypt/live/liberatedsystems.co.uk/fullchain.pem &amp;gt; /var/lib/ejabberd/liberatedsystems.co.uk.pem &amp;amp;&amp;amp; /bin/chown jabber:jabber /var/lib/ejabberd/liberatedsystems.co.uk.pem&amp;#39;
PrivateTmp=true
&lt;/code&gt;&lt;/pre&gt;&lt;p&gt;Remember to replace the domain with your own. This ensures that each time the
service runs, the certificates are combined into one file, which is owned by
&lt;code&gt;jabber&lt;/code&gt;, the user which &lt;code&gt;ejabberd&lt;/code&gt; runs as.&lt;/p&gt;
&lt;p&gt;After writing to the file and saving it, run the following to reparse the
service file:&lt;/p&gt;
&lt;pre tabindex=&#34;0&#34;&gt;&lt;code&gt;doas/sudo systemctl daemon-reload
&lt;/code&gt;&lt;/pre&gt;&lt;h2 id=&#34;running-certbot&#34;&gt;Running certbot&lt;/h2&gt;
&lt;p&gt;Now run certbot to retrieve your TLS certificates:&lt;/p&gt;
&lt;pre tabindex=&#34;0&#34;&gt;&lt;code&gt;doas/sudo certbot
&lt;/code&gt;&lt;/pre&gt;&lt;p&gt;When prompted, press enter to request certs for all domains, and after a short
wait you should be done! Ensure you run the following to generate the
certificate for &lt;code&gt;ejabberd&lt;/code&gt; and enable auto-renewal:&lt;/p&gt;
&lt;pre tabindex=&#34;0&#34;&gt;&lt;code&gt;doas/sudo systemctl start certbot-renew
doas/sudo systemctl start certbot-renew.timer
doas/sudo systemctl enable certbot-renew.timer
&lt;/code&gt;&lt;/pre&gt;&lt;p&gt;Now if you run &lt;code&gt;ls /var/lib/ejabberd&lt;/code&gt;, you should see a file called
&lt;code&gt;yourdomain.co.uk.pem&lt;/code&gt;. If you do, you&amp;rsquo;ve successfully generated your
certificate!&lt;/p&gt;
&lt;h2 id=&#34;configuring-ejabberd&#34;&gt;Configuring ejabberd&lt;/h2&gt;
&lt;p&gt;We will now begin to configure ejabberd, so open the configuration file at
&lt;code&gt;/etc/ejabberd/ejabberd.yml&lt;/code&gt; in your text editor.&lt;/p&gt;
&lt;h3 id=&#34;hosts&#34;&gt;Hosts&lt;/h3&gt;
&lt;p&gt;Within the hosts section, replace &lt;code&gt;localhost&lt;/code&gt; with your domain.&lt;/p&gt;
&lt;h3 id=&#34;certificates&#34;&gt;Certificates&lt;/h3&gt;
&lt;p&gt;Add the following to your config file, beneath the commented &lt;code&gt;certfiles&lt;/code&gt;
section:&lt;/p&gt;
&lt;pre tabindex=&#34;0&#34;&gt;&lt;code&gt;acme:
    auto: false
certfiles:
 - /var/lib/ejabberd/liberatedsystems.co.uk.pem
&lt;/code&gt;&lt;/pre&gt;&lt;p&gt;Remember to replace the domain with yours. This snippet disables ejabberd&amp;rsquo;s
built-in certificate renewal, and tells it to instead use the one we requested
using certbot earlier.&lt;/p&gt;
&lt;h3 id=&#34;sql-database&#34;&gt;SQL database&lt;/h3&gt;
&lt;p&gt;Create an ejabberd user and database in your SQL console:&lt;/p&gt;
&lt;pre tabindex=&#34;0&#34;&gt;&lt;code&gt;doas/sudo mysql
create user ejabberd@localhost identified by &amp;#34;password&amp;#34;;
create database ejabberd;
grant all privileges on ejabberd.* to ejabberd@localhost;
flush privileges;
\q
&lt;/code&gt;&lt;/pre&gt;&lt;p&gt;Consider choosing a different password than &amp;ldquo;password&amp;rdquo; for the user.&lt;/p&gt;
&lt;p&gt;Add this section to your &lt;code&gt;/etc/ejabberd/ejabberd.yml&lt;/code&gt; config file:&lt;/p&gt;
&lt;pre tabindex=&#34;0&#34;&gt;&lt;code&gt;sql_type: mysql
sql_server: &amp;#34;localhost&amp;#34;
sql_database: &amp;#34;ejabberd&amp;#34;
sql_username: &amp;#34;ejabberd&amp;#34;
sql_password: &amp;#34;password&amp;#34;
&lt;/code&gt;&lt;/pre&gt;&lt;p&gt;Also ensure that you uncomment the &lt;code&gt;db_type: sql&lt;/code&gt; line in the &lt;code&gt;mod_mam&lt;/code&gt;
section. If you chose a different password than &amp;ldquo;password&amp;rdquo;, ensure you change it
here too. Both of these changes ensure that ejabberd uses your SQL server for
storage, since the default database is restricted to 2GB in size, which
depending on your deployment may be too small, particularly if you&amp;rsquo;re sharing
many images of the &lt;a href=&#34;https://www.cato.org/commentary/fanning-flames-waco&#34;&gt;Waco
Siege&lt;/a&gt;.&lt;/p&gt;
&lt;h3 id=&#34;client-to-server-tls-config&#34;&gt;Client to server TLS config&lt;/h3&gt;
&lt;p&gt;We will now alter ejabberd&amp;rsquo;s TLS parameters to processone&amp;rsquo;s recommendations for
security to minimise the risk of compromise, as your server&amp;rsquo;s traffic will
likely pass through government harvesting facilities at some point.&lt;/p&gt;
&lt;p&gt;Within the &lt;code&gt;listen&lt;/code&gt; block, in the section with the &lt;code&gt;port: 5222&lt;/code&gt; configuration,
insert the following:&lt;/p&gt;
&lt;pre tabindex=&#34;0&#34;&gt;&lt;code&gt;    protocol_options:
      - no_sslv2
      - no_sslv3
      - no_tlsv1
      - no_tlsv1_1
    ciphers: &amp;#34;ECDHE-ECDSA-AES256-GCM-SHA384:ECDHE-RSA-AES256-GCM-SHA384:ECDHE-ECDSA-CHACHA20-POLY1305:ECDHE-RSA-CHACHA20-POLY1305:ECDHE-ECDSA-AES128-GCM-SHA256:ECDHE-RSA-AES128-GCM-SHA256:ECDHE-ECDSA-AES256-SHA384:ECDHE-RSA-AES256-SHA384:ECDHE-ECDSA-AES128-SHA256:ECDHE-RSA-AES128-SHA256&amp;#34;
    starttls: true
    tls_compression: false
    dhfile: /etc/ssl/dh2048.pem
&lt;/code&gt;&lt;/pre&gt;&lt;p&gt;This disables old SSL and TLS versions for client to server communication,
along with insecure ciphers, and uses a dhfile for increased security.&lt;/p&gt;
&lt;p&gt;Within the &lt;code&gt;listen&lt;/code&gt; block, in the section with the &lt;code&gt;port: 5223&lt;/code&gt; configuration,
insert the following:&lt;/p&gt;
&lt;pre tabindex=&#34;0&#34;&gt;&lt;code&gt;    protocol_options:
      - no_sslv2
      - no_sslv3
      - no_tlsv1
      - no_tlsv1_1
    ciphers: &amp;#34;ECDHE-ECDSA-AES256-GCM-SHA384:ECDHE-RSA-AES256-GCM-SHA384:ECDHE-ECDSA-CHACHA20-POLY1305:ECDHE-RSA-CHACHA20-POLY1305:ECDHE-ECDSA-AES128-GCM-SHA256:ECDHE-RSA-AES128-GCM-SHA256:ECDHE-ECDSA-AES256-SHA384:ECDHE-RSA-AES256-SHA384:ECDHE-ECDSA-AES128-SHA256:ECDHE-RSA-AES128-SHA256&amp;#34;
    tls_compression: false
    dhfile: /etc/ssl/dh2048.pem
&lt;/code&gt;&lt;/pre&gt;&lt;p&gt;This does much the same, but for the encrypted port for client to server
communication.&lt;/p&gt;
&lt;h3 id=&#34;server-to-server-tls-config&#34;&gt;Server to server TLS config&lt;/h3&gt;
&lt;p&gt;Locate the &lt;code&gt;s2s_use_starttls: optional&lt;/code&gt; line in your config file and delete it.
After, paste the following:&lt;/p&gt;
&lt;pre tabindex=&#34;0&#34;&gt;&lt;code&gt;s2s_use_starttls: required
s2s_dhfile: /etc/ssl/dh2048.pem
s2s_ciphers: &amp;#34;ECDHE-ECDSA-AES256-GCM-SHA384:ECDHE-RSA-AES256-GCM-SHA384:ECDHE-ECDSA-CHACHA20-POLY1305:ECDHE-RSA-CHACHA20-POLY1305:ECDHE-ECDSA-AES128-GCM-SHA256:ECDHE-RSA-AES128-GCM-SHA256:ECDHE-ECDSA-AES256-SHA384:ECDHE-RSA-AES256-SHA384:ECDHE-ECDSA-AES128-SHA256:ECDHE-RSA-AES128-SHA256&amp;#34;
&lt;/code&gt;&lt;/pre&gt;&lt;p&gt;This configures the server to force STARTTLS in federation, along with a dhfile
and disables insecure ciphers.&lt;/p&gt;
&lt;p&gt;Within the &lt;code&gt;listen&lt;/code&gt; block, in the section with the &lt;code&gt;port: 5269&lt;/code&gt; configuration, insert the following:&lt;/p&gt;
&lt;pre tabindex=&#34;0&#34;&gt;&lt;code&gt;    protocol_options:
      - no_sslv2
      - no_sslv3
      - no_tlsv1
      - no_tlsv1_1
&lt;/code&gt;&lt;/pre&gt;&lt;p&gt;This disables older SSL and TLS versions when communicating in federation.&lt;/p&gt;
&lt;h2 id=&#34;generate-dhfile&#34;&gt;Generate dhfile&lt;/h2&gt;
&lt;p&gt;To generate a dhfile for secure TLS communication, run the following:&lt;/p&gt;
&lt;pre tabindex=&#34;0&#34;&gt;&lt;code&gt;doas/sudo openssl dhparam -out /etc/ssl/dh2048.pem 2048 
&lt;/code&gt;&lt;/pre&gt;&lt;p&gt;This operation may take some time.&lt;/p&gt;
&lt;h2 id=&#34;verify-config&#34;&gt;Verify config&lt;/h2&gt;
&lt;p&gt;Run the following to start ejabberd (and enable it on boot) to check if your config works:&lt;/p&gt;
&lt;pre tabindex=&#34;0&#34;&gt;&lt;code&gt;doas/sudo systemctl start ejabberd
doas/sudo systemctl enable ejabberd
&lt;/code&gt;&lt;/pre&gt;&lt;p&gt;If this was successful, congratulations! Allow us to move on.&lt;/p&gt;
&lt;h2 id=&#34;register-admin-user&#34;&gt;Register admin user&lt;/h2&gt;
&lt;p&gt;Let&amp;rsquo;s now register our first user:&lt;/p&gt;
&lt;pre tabindex=&#34;0&#34;&gt;&lt;code&gt;set +o history
doas/sudo -u jabber ejabberdctl register jacob.eva liberatedsystems.co.uk password
set -o history
&lt;/code&gt;&lt;/pre&gt;&lt;p&gt;The set commands are to turn off your command history, so that the password
isn&amp;rsquo;t stored on your server in plaintext. Ensure to change &amp;ldquo;jacob.eva&amp;rdquo; for your
desired username, the domain for yours, and pick a better password than
&amp;ldquo;password&amp;rdquo; (please lol).&lt;/p&gt;
&lt;p&gt;Next, just add the following to your config file at &lt;code&gt;/etc/ejabberd/ejabberd.yml&lt;/code&gt;:&lt;/p&gt;
&lt;pre tabindex=&#34;0&#34;&gt;&lt;code&gt;acl:
  admin:
    user: jacob.eva@liberatedsystems.co.uk
&lt;/code&gt;&lt;/pre&gt;&lt;p&gt;Once again, replace &amp;ldquo;jacob.eva&amp;rdquo; with your username, and the domain with your own.&lt;/p&gt;
&lt;p&gt;Finally, restart ejabberd:&lt;/p&gt;
&lt;pre tabindex=&#34;0&#34;&gt;&lt;code&gt;doas/sudo systemctl restart ejabberdctl
&lt;/code&gt;&lt;/pre&gt;&lt;h2 id=&#34;connecting&#34;&gt;Connecting&lt;/h2&gt;
&lt;p&gt;Fire up your favourite &lt;a href=&#34;https://xmpp.org/software/&#34;&gt;XMPP client&lt;/a&gt; and connect to
your server using your JID (&lt;a href=&#34;mailto:username@domain.com&#34;&gt;username@domain.com&lt;/a&gt;) and the password you set!&lt;/p&gt;
&lt;p&gt;If you&amp;rsquo;re able to login, excellent, your server works! If not, review your
configuration.&lt;/p&gt;
&lt;p&gt;Create a MUC (multi user chat) room and test sending messages. Ensure it is set
to public, so you can join it on another account later on to test federation.&lt;/p&gt;
&lt;h2 id=&#34;federation&#34;&gt;Federation&lt;/h2&gt;
&lt;p&gt;In order to enable federation, add the following DNS SRV records to your domain
via your domain registrar:&lt;/p&gt;
&lt;pre tabindex=&#34;0&#34;&gt;&lt;code&gt;_xmpp-client._tcp.liberatedsystems.co.uk SRV 5 0 5222 liberatedsystems.co.uk
_xmpps-client._tcp.liberatedsystems.co.uk SRV 5 0 5223 liberatedsystems.co.uk
_xmpp-server._tcp.liberatedsystems.co.uk SRV 5 0 5269 liberatedsystems.co.uk
_xmpps-server._tcp.liberatedsystems.co.uk SRV 5 0 5270 liberatedsystems.co.uk
&lt;/code&gt;&lt;/pre&gt;&lt;p&gt;But of course, substitute our domain for yours.&lt;/p&gt;
&lt;h3 id=&#34;testing-optional&#34;&gt;Testing (optional)&lt;/h3&gt;
&lt;p&gt;If you have an account on another XMPP server, use that to join the MUC, or
just create another on &lt;a href=&#34;https://providers.xmpp.net/&#34;&gt;another server&lt;/a&gt;.&lt;/p&gt;
&lt;p&gt;If you are able to send and receive messages in the same MUC across the
different accounts, congratulations, federation works!&lt;/p&gt;
&lt;h2 id=&#34;closing&#34;&gt;Closing&lt;/h2&gt;
&lt;p&gt;We will be making more XMPP tutorials in the future goy, so keep your eye out.
&lt;strong&gt;TECHNOLOGY FOR FREEDOM.&lt;/strong&gt;&lt;/p&gt;
</description>
	</item>
	
	</channel>
</rss>
