Essentially, because your Openfire-network setup is wrong. Old Spark versions allowed that to slide, but new versions are more strict about security.
You should use proper domain name to login, proper SSL certificates for that domain name. If this is an internal server and it is not possible to get a proper SSL certificate for it, then you would still have to check “Accept all certificates” option as it would be a silf-signed certificate and it is considered less safe.