Logo by Pauldelbrot - Contribute your own Logo!

END OF AN ERA, FRACTALFORUMS.COM IS CONTINUED ON FRACTALFORUMS.ORG

it was a great time but no longer maintainable by c.Kleinhuis contact him for any data retrieval,
thanks and see you perhaps in 10 years again

this forum will stay online for reference
News: Visit us on facebook
 
*
Welcome, Guest. Please login or register. April 26, 2024, 02:58:19 PM


Login with username, password and session length


The All New FractalForums is now in Public Beta Testing! Visit FractalForums.org and check it out!


Pages: [1]   Go Down
  Print  
Share this topic on DiggShare this topic on FacebookShare this topic on GoogleShare this topic on RedditShare this topic on StumbleUponShare this topic on Twitter
Author Topic: https / SSL for fractalforums.com  (Read 1368 times)
Description: port 443 is open but not for https
0 Members and 1 Guest are viewing this topic.
claude
Fractal Bachius
*
Posts: 563



WWW
« on: January 12, 2015, 06:26:30 PM »

Would be nice to be able to use https://www.fractalforums.com/ as well as http://www.fractalforums.com

I tried but Iceweasel (Firefox in disguise) freaked out, so I investigated with wget:

Code:
$ wget https://www.fractalforums.com/
--2015-01-12 17:15:53--  https://www.fractalforums.com/
Resolving www.fractalforums.com (www.fractalforums.com)... 82.165.59.163
Connecting to www.fractalforums.com (www.fractalforums.com)|82.165.59.163|:443..
GnuTLS: An unexpected TLS packet was received.
Unable to establish SSL connection.

Turns out port 443 (usually https, with SSL) is serving regular http instead of https, which is quite unusual...

Code:
$ wget http://www.fractalforums.com:443/
--2015-01-12 17:19:32--  http://www.fractalforums.com:443/
Resolving www.fractalforums.com (www.fractalforums.com)... 82.165.59.163
Connecting to www.fractalforums.com (www.fractalforums.com)|82.165.59.163|:443... connected.
HTTP request sent, awaiting response... 200 OK
Length: unspecified [text/html]
Saving to: `index.html'

    [ <=> ] 108,040      565K/s   in 0.2s   

2015-01-12 17:19:33 (565 KB/s) - `index.html' saved [108040]

Is this intentional?

I know that getting an SSL certificate that browsers won't scream about can be a pain, though - some DNS registrar offer a certificate as part of the bundle, possibly hosting companies too - a self-signed certificate would be better than nothing though, even though you have to click about 6 buttons in scary-looking dialogs to accept them these days..
Logged
cKleinhuis
Administrator
Fractal Senior
*******
Posts: 7044


formerly known as 'Trifox'


WWW
« Reply #1 on: January 12, 2015, 07:57:02 PM »

the thing is that my provider just does it with a special sub domain or something, not just replacing the http with https, i try to make some time to look into it and confgure it
there is just only security breach that might occur, that is, when logging  in the password can be grabbed by man in the middle attacks or just plain sniffing
Logged

---

divide and conquer - iterate and rule - chaos is No random!
3dickulus
Global Moderator
Fractal Senior
******
Posts: 1558



WWW
« Reply #2 on: January 13, 2015, 03:27:24 AM »

if the login page is served via https it should be relatively impervious to sniffing and such as the connection is SSL before a password is sent ? (cmiiw)

I have nothing against self signed certs as long as the information about the owner is correct and verifiable wink and what's a few clicks between friends? once it's accepted users won't have to keep clickety clicking

regular http can serve the masses (bots) while https can serve members
Logged

Resistance is fertile...
You will be illuminated!

                            #B^] https://en.wikibooks.org/wiki/Fractals/fragmentarium
cKleinhuis
Administrator
Fractal Senior
*******
Posts: 7044


formerly known as 'Trifox'


WWW
« Reply #3 on: January 13, 2015, 07:39:15 AM »

yay, i will look into it, throughout the week!
Logged

---

divide and conquer - iterate and rule - chaos is No random!
claude
Fractal Bachius
*
Posts: 563



WWW
« Reply #4 on: January 16, 2015, 11:33:16 PM »

actually, it might be worth waiting a few months for this to be live: https://letsencrypt.org/
Logged
3dickulus
Global Moderator
Fractal Senior
******
Posts: 1558



WWW
« Reply #5 on: January 16, 2015, 11:51:46 PM »

 Repeating Zooming Self-Silimilar Thumb Up, by Craig
Logged

Resistance is fertile...
You will be illuminated!

                            #B^] https://en.wikibooks.org/wiki/Fractals/fragmentarium
cKleinhuis
Administrator
Fractal Senior
*******
Posts: 7044


formerly known as 'Trifox'


WWW
« Reply #6 on: January 17, 2015, 01:00:46 AM »

i checked, an ssl certificate has to be ordered by my provider, i ordered one, it is going to cost 5€ bucks a year, so it is bearable
as soon as i got the certificate i will instruct the webserver to use it, it is going to be available via a subdomain, i will see what we can
do about it just mirroring the content to there in the most easy to use way
Logged

---

divide and conquer - iterate and rule - chaos is No random!
Pages: [1]   Go Down
  Print  
 
Jump to:  

Related Topics
Subject Started by Replies Views Last post
Welcome to the New Fractalforums Discuss Fractal Forums cKleinhuis 14 5562 Last post April 16, 2008, 11:36:59 PM
by ramblerette
Fractalforums.com Membergroups Discuss Fractal Forums « 1 2 » cKleinhuis 24 7355 Last post August 12, 2008, 07:27:26 AM
by JackOfTraDeZ
fractalforums.com FractalForums.com Banner Logos JodyVL 0 3272 Last post June 22, 2011, 05:17:49 PM
by JodyVL
Hello to FractalForums Meet & Greet TroyPuzz 1 2194 Last post December 22, 2011, 03:48:01 AM
by TroyPuzz
embedding of https youtube videos enabled Fractal Forums News cKleinhuis 1 1225 Last post September 05, 2014, 12:19:35 PM
by kram1032

Powered by MySQL Powered by PHP Powered by SMF 1.1.21 | SMF © 2015, Simple Machines

Valid XHTML 1.0! Valid CSS! Dilber MC Theme by HarzeM
Page created in 0.151 seconds with 25 queries. (Pretty URLs adds 0.01s, 2q)