HTTPS

Discussion in 'Shelter Releases' started by Order2Chaos, Mar 24, 2017.

Thread Status:
Not open for further replies.
  1. Order2Chaos

    Order2Chaos Ultimate... Immortal Administrator

    Joined:
    Apr 2, 2004
    Messages:
    25,195
    Location:
    here there be dragons
    Ratings:
    +21,413
    We don't have it. We should, and probably require it via redirect.

    Likely this will be a few $ for a certificate from a reputable Certificate Authority. I don't remember if Let's Encrypt has finally solved their issues, but if they have, that's probably the easiest way to get one and get it set up.
  2. Lanzman

    Lanzman Vast, Cool and Unsympathetic Formerly Important

    Joined:
    Mar 27, 2004
    Messages:
    35,163
    Location:
    Someplace high and cold
    Ratings:
    +36,643
  3. Order2Chaos

    Order2Chaos Ultimate... Immortal Administrator

    Joined:
    Apr 2, 2004
    Messages:
    25,195
    Location:
    here there be dragons
    Ratings:
    +21,413
    Let's Encrypt still has issues, but the really bad ones have been fixed, so I'm going to go ahead and install it since it's free. Shouldn't be any downtime.
    • Thank You! Thank You! x 2
  4. Order2Chaos

    Order2Chaos Ultimate... Immortal Administrator

    Joined:
    Apr 2, 2004
    Messages:
    25,195
    Location:
    here there be dragons
    Ratings:
    +21,413
    So I'm an idiot and managed to lock myself out of the board at my hotel and at home over VPN while trying to pull a backup. Can someone log in over SSH as root and run

    Code:
    iptables -f DENYIN
    ? Thanks.
  5. Order2Chaos

    Order2Chaos Ultimate... Immortal Administrator

    Joined:
    Apr 2, 2004
    Messages:
    25,195
    Location:
    here there be dragons
    Ratings:
    +21,413
    Thanks whoever did that.
  6. Order2Chaos

    Order2Chaos Ultimate... Immortal Administrator

    Joined:
    Apr 2, 2004
    Messages:
    25,195
    Location:
    here there be dragons
    Ratings:
    +21,413
    Actually there will be a bit of downtime. Let's Encrypt doesn't work with our current WHM/cPanel, but the latest WHM/cPanel requires an OS update of some magnitude which will undoubtedly require at least a few minutes of downtime, possibly, but hopefully not, longer.
  7. Order2Chaos

    Order2Chaos Ultimate... Immortal Administrator

    Joined:
    Apr 2, 2004
    Messages:
    25,195
    Location:
    here there be dragons
    Ratings:
    +21,413
    So we have a 32-bit server, but can't get newer WHM/cPanel versions without a 64-bit OS. Investigating an upgrade path.
    • Agree Agree x 2
  8. Lanzman

    Lanzman Vast, Cool and Unsympathetic Formerly Important

    Joined:
    Mar 27, 2004
    Messages:
    35,163
    Location:
    Someplace high and cold
    Ratings:
    +36,643
    I almost hate to ask, but is anyone other than me even paying attention here? O2C is lining up some pretty major upgrades, yanno.
    • Agree Agree x 1
  9. Shirogayne

    Shirogayne Gay™ Formerly Important

    Joined:
    May 17, 2005
    Messages:
    42,358
    Location:
    San Diego
    Ratings:
    +56,071
    I don't think many folks understand what it is he's doing :unsure:

    I trust him, though :shrug:
    • Agree Agree x 1
    • Winner Winner x 1
  10. Quincunx

    Quincunx anti-anti-establishment Staff Member Administrator

    Joined:
    Mar 31, 2004
    Messages:
    20,211
    Location:
    Chicago, U.S.A.
    Ratings:
    +24,062
    He might as well have announced his intention to run a level 3 diagnostic on the main deflector array. :technobabble:
    • Funny Funny x 4
    • Agree Agree x 2
  11. Tuckerfan

    Tuckerfan BMF

    Joined:
    Oct 13, 2007
    Messages:
    77,150
    Location:
    Can't tell you, 'cause I'm undercover!
    Ratings:
    +155,436
    I get it, but don't have time to comment, ATM.
  12. shootER

    shootER Insubordinate...and churlish Administrator

    Joined:
    Mar 27, 2004
    Messages:
    49,321
    Location:
    The Steam Pipe Trunk Distribution Venue
    Ratings:
    +50,597
    Do whatever is necessary. If you know when and how long it'll take either pin an announcement to the top of the Red Room or let us know so someone else can do it.
    • Agree Agree x 3
  13. Ancalagon

    Ancalagon Scalawag Administrator Formerly Important

    Joined:
    Mar 29, 2004
    Messages:
    51,469
    Location:
    Downtown
    Ratings:
    +57,856
    I have no idea how to do any of that so I took a screen shot of your ask and hit up John. He temporarily stepped back into his Tech Admin role to free you. :D
  14. Ancalagon

    Ancalagon Scalawag Administrator Formerly Important

    Joined:
    Mar 29, 2004
    Messages:
    51,469
    Location:
    Downtown
    Ratings:
    +57,856
    Have you tried reversing the polarity?
    • Agree Agree x 2
  15. Dr. Krieg

    Dr. Krieg Stay at Home Astronaut. Administrator Overlord

    Joined:
    Oct 15, 2008
    Messages:
    10,371
    Location:
    The Hell, where youth and laughter go.
    Ratings:
    +13,469
    I have no idea what any of that means, but you have my support. :lol:
    • Funny Funny x 1
  16. Tuckerfan

    Tuckerfan BMF

    Joined:
    Oct 13, 2007
    Messages:
    77,150
    Location:
    Can't tell you, 'cause I'm undercover!
    Ratings:
    +155,436
    Okay, I'll weigh in now. First of all, let me say that I have a good (though non-technical) understanding of what O2C's talking about. For those of you wondering, essentially, it means that any time you log on to WF, your connection would be "encrypted," meaning that nobody but you, and the board's software could snoop in on your connection. The EFF, and others, have started pushing for all websites to do this in the wake of all the Snowden revelations about how much the government is spying on people. Google bumps sites that use HTTPS higher in search rankings, so WF would move up a notch or two in search results by doing this.

    The problem with all of this, however, is that while it's great for somebody living in a place like Saudi Arabia (or other despotic shithole), outside of those countries, it really doesn't make much difference. (I'm sure that when O2C or John reads this, they'll have kittens, because I'm simplifying things tremendously, but, IMHO, it's close enough.) The thing that I have found, when dealing with Mom-N-Pop sites like WF (ie, those operated by non-professionals for fun, rather than profit) is that sooner, rather than later, something goes wrong with either how the site's configured, or the cert lapses, and when you try to access it, instead of getting a notice that, "Hey, the security setting's are bonkers, so don't do anything stupid like entering your credit card number," your web browser goes:

    Mind you, it doesn't even have to be anything that we, or the cert issuer has does done to trigger that. It could simply be the setting of the hotel wifi that are bonkers which are causing the problem (because the clerk is too dumb to reboot the router when he's supposed to).

    I appreciate those kinds of warnings and being blocked when I'm attempting to go to an "important" site (ie one where I could be expected to have put damaging information up, or credit card information), but not when I'm trying to get to a place as mundane as this one. I'm not objecting to adopting HTTPS, I'm just pointing out that there's "hazards" to using it. Eventually, every site is probably going to have to adopt it, so we might as well accept the inevitable and deal with it.
    • Agree Agree x 1
    • Thank You! Thank You! x 1
    • Funny Funny x 1
  17. Lanzman

    Lanzman Vast, Cool and Unsympathetic Formerly Important

    Joined:
    Mar 27, 2004
    Messages:
    35,163
    Location:
    Someplace high and cold
    Ratings:
    +36,643
    Certificate expiration is the only real concern, and it's not that big of a deal.
  18. Tuckerfan

    Tuckerfan BMF

    Joined:
    Oct 13, 2007
    Messages:
    77,150
    Location:
    Can't tell you, 'cause I'm undercover!
    Ratings:
    +155,436
    17553821_598929226973704_7956773981064099424_n.jpg
    • Funny Funny x 2
  19. Order2Chaos

    Order2Chaos Ultimate... Immortal Administrator

    Joined:
    Apr 2, 2004
    Messages:
    25,195
    Location:
    here there be dragons
    Ratings:
    +21,413
    Tuckerfan is mostly right, although there are other benefits, like your ISP or anyone snooping on your connection can't alter the content that comes down. Plus, what with major ISPs aiming to start selling browsing data to advertisers, better that they can only tell what site you visit, rather than also what pages within that site. That one is my primary motivation here.

    Re: big updates, I'm currently looking at a workaround, rather than an OS upgrade. That looks to be a rather larger project than I want to take on, including moving the board to a new VM.
    • Thank You! Thank You! x 2
Thread Status:
Not open for further replies.