HTTPS incoming as the new STH standard

Notice: Page may contain affiliate links for which we may earn a small commission through services like Amazon Affiliates or Skimlinks.

Patrick

Administrator
Staff member
Dec 21, 2010
12,513
5,805
113
I just wanted to drop a quick note and let folks know that SSL encryption testing is happening. That means that practically HTTPS will become the new standard for both the forums and the main site in the next month or so.
 

Patrick

Administrator
Staff member
Dec 21, 2010
12,513
5,805
113
Varnish + nginx + SSL is a bit more complex than I expected. I also want to enable SPYDY when I do this.
 

nitrobass24

Moderator
Dec 26, 2010
1,087
131
63
TX
Have you considered using a reverse proxy to handle the SSL and then keep the actual webservers and cache on an internal segment?
 

Patrick

Administrator
Staff member
Dec 21, 2010
12,513
5,805
113
Have you considered using a reverse proxy to handle the SSL and then keep the actual webservers and cache on an internal segment?
That is what it basically is going to end up happening. The big issue is keeping sessions straight.

BTW if you are in Dallas Monday/ Tuesday let me know. Should be here next Monday too.
 

nitrobass24

Moderator
Dec 26, 2010
1,087
131
63
TX
Getting on a plane to Chicago right now then headed to NY for a long weekend. Will be in Sf at some point next week. Haven't booked yet though.
 

Patrick

Administrator
Staff member
Dec 21, 2010
12,513
5,805
113
I should be around next Monday evening. Next week is Dallas then Maine. The following is Dallas, Seattle then Washington DC.
 

Patrick

Administrator
Staff member
Dec 21, 2010
12,513
5,805
113
Pat, you can use Citrix Netscaler to do SSL sessions.
I will look into that. The big issue right now is just I need it to be easily maintained and I need to be able to get folks to admin it with minimal complexity if I cannot get to an urgent issue.
 

Patrick

Administrator
Staff member
Dec 21, 2010
12,513
5,805
113
Hopefully folks can see this message.

I changed the forums over to HTTPS. It seems to have worked on my first try after my previous 10 practice runs.

Please let me know if you have any issues... of course if there are issues... nobody will be able to read this.
 

Jeggs101

Well-Known Member
Dec 29, 2010
1,529
241
63
nice work. Your pingdom went to *@)#! but it loads fast on my machine.
 

rnavarro

Active Member
Feb 14, 2013
197
40
28
Not to derail the discussion, but have improvements been made for backups?

I like new tech as much as anyone on this forum but the data loss we had a while back was pretty catastrophic. Many a good post were lost :(

Just wondering if that was still a high priority.
 

Patrick

Administrator
Staff member
Dec 21, 2010
12,513
5,805
113
Not to derail the discussion, but have improvements been made for backups?

I like new tech as much as anyone on this forum but the data loss we had a while back was pretty catastrophic. Many a good post were lost :(

Just wondering if that was still a high priority.
Right now both sites are copied across a total of six different physical disks. Replication is setup (actually have an article on that one) and there is also a backup to AWS that happens on a fairly regular basis.

The full second colo/ DR site is not up just yet though, but it is penciled in for late September.

For the time being I am just going with the idea that disks are cheap so we are copying across different ones, different brands, spindle, SSD and cloud.
 

rnavarro

Active Member
Feb 14, 2013
197
40
28
Right now both sites are copied across a total of six different physical disks. Replication is setup (actually have an article on that one) and there is also a backup to AWS that happens on a fairly regular basis.

The full second colo/ DR site is not up just yet though, but it is penciled in for late September.

For the time being I am just going with the idea that disks are cheap so we are copying across different ones, different brands, spindle, SSD and cloud.
Sweeeet glad to hear it! Thanks for all the hard work Patrick!
 

Patrick

Administrator
Staff member
Dec 21, 2010
12,513
5,805
113
I saw your post earlier. Just a big sigh since now I have to figure that out.
 

eva2000

Active Member
Apr 15, 2013
244
49
28
Brisbane, Australia
centminmod.com
Should be as simple as contacting SSL provider to get SSL certificate reissued with SHA256 signatures and reinstalling your SSL certificate with the new key and csr :)

You'll need to do this as your SSL expires in 2019 so runs past the 2017 deadline for SHA-1
 
  • Like
Reactions: rnavarro