Chat no longer works for Pidgin - nothing in detail logs
Problem reported by Merle Wait - 7/28/2026 at 7:10 PM
Submitted
We have been using Pidgin for years with SM.
We are on the current release of SM.
During past couple of weeks have had complaints, and have verified, that SM no longer allows connections to Pidgin.  There is nothing in the detailed logs either.  Any help or troubleshooting advice is welcome.
Chris Hurst Replied
We recently upgraded Smartermail this week from a very old 15.7 version to the newest release from July 16th.  We also used Pidgin before and after the upgrade and saw no change in functionality after the upgrade.
Merle Wait Replied
@Christopher Hurst  - thank you for the feedback.  Appreciate it.
IF you get time, would check your detailed logs to see if you see Pidgin logging in.. in your logs?
Thanks
Chris Hurst Replied
Ours quit working today.  Not sure if it happened when I updated my certificates since SM was telling me my Private Key was not installed.  I updated the certs with my .pfx version and fixed the SM notifications but now getting Exception negotiating SSL: Cannot determine the frame size or a corrupted frame was received.in the XMPP log.  None of our previously working Pidgin clients are working now.  I'm in the process of trying some alternate clients now.
Chris Hurst Replied
Turning off encryption on the XMPP port in SM and setting Pidgin from Require Encryption to Use Encryption if Available allows the 2 to work now.  Not ideal but will work for now.
Kyle Kerst Replied
Employee Post
I completed some testing on this in-house against some of our Windows and Linux based SmarterMail hosts but was unfortunately not able to replicate connectivity or certificate errors in my testing. That being said, I suspect the problems you're facing are likely SSL/TLS related so I wanted to ask if you can both outline your XMPP port binding settings so I can compare to our own? 

The primary test servers we use for XMPP testing utilize port 5222 with StartTLS, specifying a specific PFX certificate as the fallback cert, whereas XMPP port 5223 selects SSL/TLS. These defaults can also introduce some trouble as SSL/TLS is explicitly disabled on modern Windows and Linux hosts and so its possible this is introducing a layer of complexity to the troubleshooting as well. 

Let me know what you guys find in Settings>Bindings>Ports for those entries and we can go from there. We'll get you going in the right direction!
Kyle Kerst
Lead Internal Network/System Administrator
SmarterTools Inc.
Merle Wait Replied
For XMPP  (we do have this firewall open) .. .
Port 6222
Encrypt: SSL/TLS
'---------
and then the *pfx cert

Kyle Kerst Replied
Employee Post
Thanks @Merle Wait! One of the issues I spot right away is the SSL/TLS option being used. SSL v2/v3 have both been deprecated as insecure for some time now and most mobile clients and fully updated installations of Windows/MacOS will refuse to use it. Because SSL is integral to the SSL/TLS options on an operating system level, this leaves them failing to connect in some cases. My recommendation is adjusting that port to use StartTLS which should support the vast majority of clients. A good way to test this temporarily might be just adding an additional XMPP port that uses the new options and existing certificate.

One additional step you can take server-side to confirm you're as secure as possible is running something like IIS Crypto (Nartac Software) to set the best practices for StartTLS versions (1.2+) so that your server isn't vulnerable to any of the DoS and other attack types identified in the older versions. 

Let me know what you find out there :)
Kyle Kerst
Lead Internal Network/System Administrator
SmarterTools Inc.
Chris Hurst Replied
changing the port port bindings to use StartTLS seems to have fixed the encryption problem for us.  Pidgin clients are working again.

Thanks Kyle
Andrew Barker Replied
Employee Post
@Merle Wait - I'm not sure if it's a typo in your post, but using ports other than 5222 and 5223 for XMPP may cause problems. I don't recall which client it was, but I do remember testing one that would only connect to one of those ports.

Andrew Barker
Lead Software Developer
SmarterTools Inc.
www.smartertools.com 

Reply to Thread

Enter the verification text