Enabling HTTPS?

User avatar
Muirium
µ

01 Jan 2016, 17:41

I might be confusing them for someone else. American, right?

My quote was from the old DT Club Meeting 2015 thread where Matteo managed to get someone to speak up in favour of dodgy certificate authorities. Criminy Pete…

User avatar
SL89

01 Jan 2016, 17:45

People clearly want https, and yet Mu keeps ribbing on 'zomg how do we pay for it' and 'no cert is better then a bad cert' despite not knowing the ins and outs himself. I'm sure the cert can be paid for, we have how many club members paying how much annually? And regarding the provider, I have to imagine that almost no effort has been spent on actually looking into it, while much ado has gone into decrying the desire for https.

User avatar
Muirium
µ

01 Jan 2016, 17:48

You underestimate the effort required to get a good rant out of me! It's very nearly zero. Implementing https across our highly customized and now unfortunately deprecated phpbb installation is worth about 7 lifetimes of my background grumblings combined, at a guess.

User avatar
SL89

01 Jan 2016, 17:50

Ok, well how about we talk about specifics of how much it would cost, how hard it would be to implement and which specific providers we can narrow it down. There was a vote in favor of it right?

edit: I know we have spoken of some specifics but we keep getting sidetracked by a plethora of what-ifs and other stuff instead of actual specifics.

User avatar
Muirium
µ

01 Jan 2016, 17:54

The trouble is we have just one guy who handles all of this stuff. You may have heard of him. And he's retiring this year. So far we have no idea who will replace him, and we haven't decided where to go now our phpbb branch is obsolete, or indeed who has the technical wherewithal to have an opinion that deserves consideration.

One of the reasons DT is so stable is because I don't monkey around with it. Top notch dev work is required. Aplenty. Quite besides https.

I agree that talk without action is pointless. I think Webwit needs to find his successor, tap him on the shoulder, and utter the appropriate incantation. Preferably somewhere imposing and creepy…

User avatar
SL89

01 Jan 2016, 18:02

That is a whole 'nother can of worms. I had no idea that Webwit was on his way out, can you link me to the relevant thread regarding that?

I appreciate that you don't monkey around with it, knowing limitations is more better then blundering forward and blowing things up.

If the hunt is on for a successor then all of this is a moot point until that happens. Are we looking internally, externally, hired gun? I mean, if we are that deprecated that https implementation is a herculean task then whoever gets tapped has quite the welcome party awaiting him.

User avatar
seebart
Offtopicthority Instigator

01 Jan 2016, 18:07

Muirium wrote: So far we have no idea who will replace him, and we haven't decided where to go now our phpbb branch is obsolete...
Someone with the necessary skills for one. :roll: I'm pretty sure we have DT users with those skills but it involves actual work and time.
Last edited by seebart on 01 Jan 2016, 18:30, edited 1 time in total.

User avatar
Muirium
µ

01 Jan 2016, 18:11

Here:

http://deskthority.net/club-discussions ... ml#p269257

Having just reread it, I see Webwit said he'd like to retire from DT's technical lead if there are strong candidates to replace him. Which indicates he won't retire if no one any good stands up! But he has less time these days, and the technical debt we've built up on this old phpbb branch is large and growing. So there's still a reckoning ahead. We really do need more than one duck on all this!

User avatar
ramnes
ПБТ НАВСЕГДА

01 Jan 2016, 19:05

Enabling HTTPS should be something like one or two lines to add in the web server configuration, I don't understand why we are talking about development work here.

User avatar
Madhias
BS TORPE

01 Jan 2016, 20:33

When I had my webpage running it was just copying the content from /httpdocs to /httpsdocs

User avatar
matt3o
-[°_°]-

18 Jan 2016, 15:30

I can technically do it as an emergency measure if webwit can't and we find no one else.

the problem that still stands is that 50% of the pages would still have mixed content (namely external images) that will cause the browser to whine.

User avatar
webwit
Wild Duck

18 Jan 2016, 16:21

Let's first install a cert and Apache rules to do the following: if on https, rewrite http://deskthority.net* requests to https. Then we'll tackle issues. After this is done, we redirect everything on http to https.

I think external images don't cause a problem. I just installed https on my own server and tested it on three browsers, and it just changes the green color and/or lock icon on the address bar. Please test yourself:

https://server1.webwit.nl/test.html (with insecure image)
https://server1.webwit.nl/test2.html (no insecure image)

I think this is only for images, so maybe our youtube script will fail, I'll test that as well.

User avatar
matt3o
-[°_°]-

18 Jan 2016, 16:41

that's good!

isn't youtube over https already? shouldn't be an issue at all (unless the script links to a not protected domain)

User avatar
webwit
Wild Duck

19 Jan 2016, 15:52

This was implemented earlier today.

User avatar
XMIT
[ XMIT ]

19 Jan 2016, 16:13

Looking good, thanks webwit for implementing https! My browser picked it up right away. :-)

User avatar
ohaimark
Kingpin

19 Jan 2016, 16:17

Good job, webwit! Many thanks for your work on DT.

User avatar
seebart
Offtopicthority Instigator

19 Jan 2016, 16:18

webwit wrote: This was implemented earlier today.
Cool, thanks! :P
Unbenannt.JPG
Unbenannt.JPG (12.29 KiB) Viewed 11513 times

User avatar
SL89

19 Jan 2016, 16:20

I saw it earlier but it didn't register at first.

Thank you webwit!

User avatar
matt3o
-[°_°]-

19 Jan 2016, 16:23

\o/

User avatar
scottc

19 Jan 2016, 17:08

Fantastic! Thank you, webwit.

andrewjoy

19 Jan 2016, 17:26

Nice one ! Thanks Webwit

User avatar
flabbergast

19 Jan 2016, 18:39

Very nice, thanks webwit!

User avatar
chzel

19 Jan 2016, 23:38

A nice change Mighty Duck!
I think Tapatalk broke though. Reports "Network error" when trying to log in.

User avatar
webwit
Wild Duck

20 Jan 2016, 00:05

I changed the url we've registered there to https but it still gives an error. Submitted a support ticket. I bet they'll tell me to update to the latest version.

User avatar
chzel

20 Jan 2016, 01:07

It seems to have resolved.
Thanks webwit!
Sent while half asleep from Tapatalk.

User avatar
Muirium
µ

20 Jan 2016, 04:54

Seems to work on everything I try. Nicely done!

I'd still like glass teletype access, but it's not a top priority…
Muirium wrote: It'll be a pity to lose Lynx.

Image
http://deskthority.net/photos-f62/volke ... t7744.html

User avatar
bhtooefr

20 Jan 2016, 11:51

Well, we haven't lost Lynx:

Image

(Just build your Lynx with SSL, which in FreeBSD's port, is default.)

User avatar
webwit
Wild Duck

20 Jan 2016, 12:10

Only problem is IE on Windows XP:
https://en.wikipedia.org/wiki/Server_Name_Indication
(In short, we have multiple domains on one IP, deskthority.net, deskthority.com and deskthority.org, and SNI makes this possible if you run https on one of them, but IE on XP doesn't support that, it expects a unique IP for https. This could cause some intruding warnings.).

However according to our visitor stats, almost no one (< 0.01%) uses IE and XP.

User avatar
Halvar

20 Jan 2016, 19:37

LoL, like this demographic gave a frigg about SSL... :P

User avatar
SL89

20 Jan 2016, 19:39

Yeah if they are on IE and XP they have bigger problems then SSL...

Post Reply

Return to “Deskthority talk”