We have openfire running with SSL being enforced for clients. The openfire server comes with a self signed ssl cert, but I do not recall any of the spark clients I've used asking to validate the certificate, although the cert is definately not trusted by the client. Is spark even checking the validity of the cert?