Hi
One of our security guys looked at Kopete a long time ago and realised it
doesn't consistently verify SSL certs, warn the user if they are invalid, or
allow a user to set an acceptance policy. This counts as a security hole.
I quickly grepped through Kopete trunk and saw it is using QTcpSocket and
QSslSocket. Would there be any resistance to porting protocols to KTcpSocket?
Having one socket class throughout would allow us to use a shared common set
of CA certs and certificate policy.
Will
_______________________________________________
kopete-devel mailing list
kopete-devel@...
https://mail.kde.org/mailman/listinfo/kopete-devel