[Date Prev][Date Next] [Thread Prev][Thread Next] [Date Index] [Thread Index]

Re: Possibly moving Debian services to a CDN



]] Craig Small 

> On Thu, Jan 30, 2014 at 01:53:55PM +0100, Tollef Fog Heen wrote:
> > I thought it's time for a small update about this.  As of about an hour
> > ago, planet and metadata.ftp-master are now served from the Fastly CDN,
> > and it all seems to be working quite smoothly.

> https://planet.debian.org/ gives a big scary certificate warning.

Well, yes.  We didn't have HTTPS before and we don't have it now
either.  One reason to not have it is that you'd have a ton of «insecure
third party resource» warnings.  Ganneff said he'd take a look at having
Planet download those resources locally when he has some free time.
Until then, planet is HTTP-only as before.  (We want to do this anyway
to avoid leaking information about people who read planet to those
running the hosting for various blogs.)

> Interesting way they've stapled all the names together on the
> certificate too.
> 
> I didn't know you could do that, but, you might like to tell them to
> fix that certificate.

There's not really anything to be fixed, since you shouldn't be using
HTTPS for that host yet.

-- 
Tollef Fog Heen
UNIX is user friendly, it's just picky about who its friends are


Reply to: