[Date Prev][Date Next] [Thread Prev][Thread Next] [Date Index] [Thread Index]

Re: Possibly moving Debian services to a CDN

]] Craig Small 

> On Thu, Jan 30, 2014 at 01:53:55PM +0100, Tollef Fog Heen wrote:
> > I thought it's time for a small update about this.  As of about an hour
> > ago, planet and metadata.ftp-master are now served from the Fastly CDN,
> > and it all seems to be working quite smoothly.

> https://planet.debian.org/ gives a big scary certificate warning.

Well, yes.  We didn't have HTTPS before and we don't have it now
either.  One reason to not have it is that you'd have a ton of «insecure
third party resource» warnings.  Ganneff said he'd take a look at having
Planet download those resources locally when he has some free time.
Until then, planet is HTTP-only as before.  (We want to do this anyway
to avoid leaking information about people who read planet to those
running the hosting for various blogs.)

> Interesting way they've stapled all the names together on the
> certificate too.
> I didn't know you could do that, but, you might like to tell them to
> fix that certificate.

There's not really anything to be fixed, since you shouldn't be using
HTTPS for that host yet.

Tollef Fog Heen
UNIX is user friendly, it's just picky about who its friends are

Reply to: