All of lore.kernel.org
 help / color / mirror / Atom feed
From: Mike Frysinger <vapier@gentoo.org>
To: buildroot@busybox.net
Subject: [Buildroot] [psa] various server software upgrades
Date: Sun, 6 Dec 2015 20:55:25 -0500	[thread overview]
Message-ID: <20151207015525.GH23754@vapier.lan> (raw)
In-Reply-To: <87610bs0dv.fsf@dell.be.48ers.dk>

On 06 Dec 2015 23:00, Peter Korsgaard wrote:
> >>>>> "Yann" == Yann E MORIN <yann.morin.1998@free.fr> writes:
> 
>  > Hello Mike,
>  > On 2015-12-02 02:35 -0500, Mike Frysinger spake thusly:
>  >> the busybox.net software has been languishing for quite a long time,
>  >> so i gave it a strong kick today.  just about every piece of software
>  >> has been upgraded on the box including bugzilla.  my various testing
>  >> looks like it still works, but if you guys notice anything weird, feel
>  >> free to let me know.
> 
>  > Yes, I've noticed that buildroot.org has switched to https with:
>  >     Strict-Transport-Security: max-age=63072000; includeSubDomains
> 
>  > Unfortunately, we do have subdomains that are not https-enabled, and are
>  > on another machine:
>  >     http://autobuild.buildroot.org/
> 
> sources.buildroot.{org,net} is another example (even though that it
> normally only accessed from wget, so less critical).

there's really no reason you can't generate a cert for those domains using
let's encrypt.  let's encrypt doesn't require you to own the root domain,
just be in control of the web server the domain resolves to.

> We have the same problem for lists.{buildroot,busybox,uclibc}.*, as that
> ends up serving an osuosl certificate.

those aren't a new issue ... they've always used osuosl certs.  those are
out of my control.

> We also have nightly.buildroot.{org,net} for the nightly generated
> manual.

you should also gen certs for those

> And finally we have patchwork.buildroot.{org,net} which redirects to the
> ozlabs patchwork.

gen certs for them.  if you can't, assign the IP to the main buildroot.org
box and i can take care of it.

>  > Which means anyone that has visited buildroot.org will be blocked from
>  > the sub-domains for the next two years (unles sthey switch to https
>  > too).
> 
> :/
> 
>  > What can we do about this?
> 
> Step 1 should imho be to disable HTST as soon as possible.

i've turned of HTST for subdomains for buildroot.org/buildroot.net.  i'm
leaving it on for the domains served directly off the box, and for all
uclibc.org and busybox.net domains.

> Then we might
> consider if we could HTTPS enable some of these subdomains, but they are
> on different hosts, which complicates stuff (E.G. we presumably need to
> distribute the buildroot.org private keys and update everywhere every 90
> days).

there is no need to distribute the same keys here.  just generate ones
for the domains in question using let's encrypt.
-mike
-------------- next part --------------
A non-text attachment was scrubbed...
Name: signature.asc
Type: application/pgp-signature
Size: 819 bytes
Desc: Digital signature
URL: <http://lists.busybox.net/pipermail/buildroot/attachments/20151206/7cc00c66/attachment.asc>

  reply	other threads:[~2015-12-07  1:55 UTC|newest]

Thread overview: 33+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2015-12-02  7:35 [Buildroot] [psa] various server software upgrades Mike Frysinger
2015-12-02  7:58 ` Lionel Orry
2015-12-02  8:43   ` Peter Korsgaard
2015-12-02  9:25 ` Nikolay Dimitrov
2015-12-02  9:28   ` Nikolay Dimitrov
2015-12-02 17:31   ` Mike Frysinger
2015-12-02 18:38     ` Nikolay Dimitrov
2015-12-06 21:42 ` Yann E. MORIN
2015-12-06 22:00   ` Peter Korsgaard
2015-12-07  1:55     ` Mike Frysinger [this message]
2015-12-07  6:34       ` Peter Korsgaard
2015-12-07 18:51         ` Mike Frysinger
2015-12-07 20:37           ` Peter Korsgaard
2015-12-07 21:55             ` Mike Frysinger
2015-12-07 22:16               ` Peter Korsgaard
2015-12-07 22:54                 ` Mike Frysinger
2015-12-07 23:02                   ` Yann E. MORIN
2015-12-07 23:22                     ` Mike Frysinger
2015-12-08  7:52                       ` Peter Korsgaard
2015-12-08 16:40                         ` Mike Frysinger
2015-12-08 16:43                           ` Peter Korsgaard
2015-12-08 17:27                             ` Mike Frysinger
2015-12-08  7:50                   ` Peter Korsgaard
2015-12-08  0:17                 ` Mike Frysinger
2015-12-08  7:55                   ` Peter Korsgaard
2015-12-08 16:38                     ` Mike Frysinger
2015-12-07  8:00       ` Peter Korsgaard
2015-12-07  8:23         ` Peter Korsgaard
2015-12-07 18:52         ` Mike Frysinger
2015-12-07 19:57           ` Mike Frysinger
2015-12-07 19:59             ` Yann E. MORIN
2015-12-07 23:52               ` Mike Frysinger
2015-12-07 20:42           ` Peter Korsgaard

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=20151207015525.GH23754@vapier.lan \
    --to=vapier@gentoo.org \
    --cc=buildroot@busybox.net \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.