Open Realtime
Ignite Realtime is the community site for the users and developers of open source Real Time Communications projects like Openfire, Smack, Spark, and Pàdé. Your involvement is helping to change the open RTC landscape.

The Ignite Realtime community is proud to announce that Smack 4.5.0 has been released.
This is a new major release after 4.4 nearly two years ago, with many bug fixes and improvements. Smack’s modular connection architecture is now deemed stable and users of the legacy XMPPTCPConnection should switch over to a modern architecture. The modular connection architecture abstracts the underlying connection mechanism, for example TCP, BOSH, and WebSockets, transporting the raw bytes of the XMPP stream, from the higher level XML layer. This allows, among other things, for a connection to transparently switch between TCP and WebSocket connections.
As always, this new Smack release is available on Maven Central.
On mobile (and worse), baseline XMPP is a little more painful than it should be. It has a lot of round-trips, where the client sends a request and waits - patiently - for the answer before it can continue.
Baseline XMPP actually has 9 of these before you can send and receive messages, and while Openfire has dropped some of these for a while (we’ve supported Direct TLS, for clients, for ever), others haven’t yet made it here. Silly, as I wrote SASL2 some time ago, which is a framework for amortising some of the start-up requests into the authentication.
Others are Bind2 - which pulls resource binding into SASL2 and also allows multiple other “connection setup” things to work - and FAST, which hands out tokens to allow reauthentication which is, well, FAST. This gets us down to 4 round-trips - halving connection time.
Thanks to a supporting grant from the NLNet Foundation, these are now all in our “main” branch, and undergoing their final testing before we make a release, so will be in our nightly builds from now on. I’ve been lucky enough to spend three weeks doing (sometimes literal!) field testing over slow links, so I’ve seen first hand that fortune really favours the bold with these extensions.
We’ve also improved security, with Channel Bindings and Downgrade Protection - also in the nightlies, and added new SCRAM variants like SCRAM-SHA-512-PLUS. Sorry Alexey, we’ve not done the SHA3 variant quite yet, but our FAST implementation does support the new HT2-* family, including the HT2-SHA3- variants.
We even found another round-trip to save, with Initial Authentication Pipelining.
There is also supporting work to make all this happen - like improvements to message archiving, and improvements to our sister project, the XMPP Interop Testing framework, so we can do live testing. This is based on Smack, so that, too now has SASL2, Bind2, and FAST support in its latest Alpha release, 4.6.0-alpha1.
We’d welcome people trying this code out - it’s a lot of exciting new features, and should be highly beneficial to most users of Openfire, and indeed client developers using Smack. It’s still nightlies, not releases, but we’re keen to move this forward as, erm, FAST as we can.
Yeah, I’m not even sorry.
For other release announcements and news follow us on Mastodon or X
We have made available a new version of the inVerse plugin for Openfire! This plugin allows you to easily deploy the third-party Converse client in Openfire. In this release, the version of the client that is bundled in the plugin is updated to 14.0.0.
The updated plugin should become available for download in your Openfire admin console in the course of the next few hours. Alternatively, you can download the plugin directly, from the plugin’s archive page.
For other release announcements and news follow us on Mastodon or X
The Ignite Realtime community is pleased to announce the release of Openfire 5.1.2, a maintenance update to our open-source XMPP real-time communication server!
This release primarily updates third-party libraries following reports of vulnerabilities in those dependencies. There’s no indication that Openfire itself was vulnerable to any of the reported issues, but as a precaution and to keep our dependencies up to date, we’ve included the updated libraries in this release.
The full changelog has all the details, with 12 items resolved in total.
You can obtain Openfire 5.1.2 for your platform from its download page. The SHA-256 checksums for the release artifacts are:
bbe0e3bd7837aeb6a78a1878b3e23a53a61e99d827ec966ddc40500db416eb86 openfire-5.1.2-1.noarch.rpm
354e14ebf80c03eee05649a43d52338a77797bb41529a4f1486c49e784119f9d openfire_5.1.2_all.deb
7da2582b4bc6c25640deecd9f22cdc1278c989cd39c0a8832fc15b3aeb208235 openfire_5_1_2.dmg
b32e33bc0e5305dcac308a82447f970b59a095f1edbb425d81ac93203db2f667 openfire_5_1_2.exe
0f45006e319fb36bf869ef9ca3a3bef930a1bd683a792883b0b0b4c9a3974680 openfire_5_1_2.tar.gz
5e52d57fb9e20235ed31a6809c3ecd139fb6583c0b24575cab3459ad4ff0b0a1 openfire_5_1_2_x64.exe
4f2bcdde684ed157f19df8a792db4f907a62864baa8a6c982c970dfaa43d0421 openfire_5_1_2.zip
We’d love to hear from you! Please join our community forum or group chat and let us know what you think!
For other release announcements and news follow us on Mastodon or X
The Ignite Realtime community is pleased to announce the release of Openfire 5.1.1, a maintenance update to our open-source XMPP real-time communication server!
Following last month’s 5.1.0 feature release, we’ve been gathering feedback and tracking down the issues that inevitably surface once a bigger release meets the real world. Openfire 5.1.1 is the result: a focused round of bug fixes and improvements, with a particular emphasis on PubSub correctness and connection handling.
A good chunk of this release tidies up PubSub behaviour. We fixed excessive memory consumption caused by a bloated ofPubsubSubscription table (OF-3306), alongside various smaller issues related to pub/sub functionality.
Connection handling gets some attention too. We resolved a nasty case where IQBindHandler could busy-wait up to 20 seconds on a resource conflict, causing thread starvation and misbehaving (OF-3319), fixed a NullPointerException in outbound S2S DirectTLS connections (OF-3332), and a number of other networking-related issues.
Certificate SANs now encode IP addresses correctly as iPAddress rather than dNSName (OF-3324), which should fix an issue that popped up under certain network configurations with recent versions of the Conversations client.
We also cleaned up a couple of migration-related issues carried over from 5.1.0’s database work, such as XML properties failing to save during PBKDF2 migration (OF-3305). This should guard against accidental loss of the encryption keys, preventing installations that become effectively unusable when migration happens while the file system is in a faulty state.
The full changelog has all the details, with 24 items resolved in total.
You can obtain Openfire 5.1.1 for your platform from its download page. The sha256sum values for the release artifacts are:
dc887032619b7ecf66cc8c17dc5cedc13c2479525cd93b41e5d999e4ec942adf openfire-5.1.1-1.noarch.rpm
4f6c5ccfe44fdd494760ae5a6f00f971ea000ec6c69e1481d3546bed994598e2 openfire_5.1.1_all.deb
17eafa2641a5cbe226328d54e115fd1780a90d6fedb6d63d8bcea048f91f23ab openfire_5_1_1.dmg
68b69309f22435e4996b18b21a451d8c3b98a543aa8680436694bf4a235b8299 openfire_5_1_1.exe
d930be11c93c995ee0a045118d0539629bd27d983ad99e6f174ded6453612a0d openfire_5_1_1.tar.gz
b55659388274deedde92813ed830e1060c89b48fc3d61e6227c153bd4d96b57e openfire_5_1_1_x64.exe
9faa8900c8aa56822deb83c82339842794b6e2e58be61ca08dbdf948ee931cd6 openfire_5_1_1.zip
Many of the issues fixed in this release were reported by our community members, and several of those were instrumental in finding and fixing bugs and applying improvements. We greatly appreciate everyone’s feedback! We’d love to hear from you! Please join our community forum or group chat and let us know what you think!
For other release announcements and news follow us on Mastodon or X