AIM Secure Login

Zachary West zacw at adium.im
Wed Jan 13 17:29:18 UTC 2010


On Wed, Jan 13, 2010 at 02:08, Ryan Govostes <rgovostes at gmail.com> wrote:

> I noticed today that I can't connect to AOL's secure login server
> (slogin.oscar.aol.com) but the unsecured server (login.oscar.aol.com)
> works fine.
>
> I get:
>
> Received unexpected response from
> http://api.oscar.aol.com/aim/startOSCARSession
>
> It looks like the response the server is sending is:
>
> <?xml version="1.0" encoding="UTF-8"?>
> <response
> xmlns="http://developer.aim.com/xsd/aim.xsd
> "><statusCode>400</statusCode><statusText>useTLS=1
> is not allowed for non secure
>
> requests.</statusText><data><ts>1263366228</ts><upgradeData></upgradeData><betaData></betaData></data></response>
>
> I interpret this as a complaint that we're asking for a secure
> connection but using HTTP rather than HTTPS.
>
> I figure this is handled in libpurple so I'll report this there
> tomorrow. Either way we'll need to update something on our end.
>
> -- Ryan
>
>
The only version of Adium with clientLogin enabled is the nightly. The
libpurple devs are very much aware of the issue, since their release product
ships with it enabled.

-- 
Zachary West
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://adium.im/pipermail/devel_adium.im/attachments/20100113/5a4db613/attachment-0002.html>


More information about the devel mailing list