bbs.archlinux.org is now switched to https only!

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]



I just performed the switch to https only on bbs! I also adjusted some
internal URLs, so all files will be properly fetched via https directly.
http is redirected automatically. Note that the navbar links on Archweb
and all other sites still point to http, but that is redirected
automatically.

There is a catch:
1) Apache configures SSL per-vhost. That means that even though we have
a wildcard certificate, the browser must support SNI for name-based
vhosts to work. All clients that are not SNI-capable will be redirected
to www instead.
2) wget doesn't like wildcard certificates. That means you need to use
--no-check-certificate with wget.
3) Our certificate is from CACert. AFAIK, this is not included in many
browsers by default. If you use Arch Linux, at least everything that
uses the OpenSSL certificate store and all Mozilla browsers are
CACert-enabled - on other operating systems, our certificate might show
up as untrusted.

Let me know if any of the above (especially 1) cause any problems.

Attachment: signature.asc
Description: OpenPGP digital signature


[Index of Archives]     [Linux Wireless]     [Linux Kernel]     [ATH6KL]     [Linux Bluetooth]     [Linux Netdev]     [Kernel Newbies]     [Share Photos]     [IDE]     [Security]     [Git]     [Netfilter]     [Bugtraq]     [Yosemite News]     [MIPS Linux]     [ARM Linux]     [Linux Security]     [Linux RAID]     [Linux ATA RAID]     [Samba]     [Device Mapper]
  Powered by Linux