Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]
Groups > linux.debian.user > #180540 > unrolled thread
| Started by | Gene Heskett <gheskett@shentel.net> |
|---|---|
| First post | 2017-04-29 05:40 +0200 |
| Last post | 2017-05-02 23:50 +0200 |
| Articles | 20 on this page of 31 — 12 participants |
Back to article view | Back to linux.debian.user
converting my local site to be https only access Gene Heskett <gheskett@shentel.net> - 2017-04-29 05:40 +0200
Re: converting my local site to be https only access Felix Dietrich <felix.dietrich@sperrhaken.name> - 2017-04-29 10:30 +0200
Re: converting my local site to be https only access Gene Heskett <gheskett@shentel.net> - 2017-04-29 15:10 +0200
Re: converting my local site to be https only access Jochen Spieker <ml@well-adjusted.de> - 2017-04-29 20:30 +0200
Re: converting my local site to be https only access Gene Heskett <gheskett@shentel.net> - 2017-04-29 20:50 +0200
Re: converting my local site to be https only access Gene Heskett <gheskett@shentel.net> - 2017-04-30 23:10 +0200
Re: converting my local site to be https only access Dejan Jocic <jodejka@gmail.com> - 2017-04-30 23:50 +0200
Re: converting my local site to be https only access Eike Lantzsch <zp6cge@gmx.net> - 2017-05-01 00:00 +0200
Re: converting my local site to be https only access davidson@freevolt.org - 2017-05-01 02:20 +0200
Re: converting my local site to be https only access Lisi Reisz <lisi.reisz@gmail.com> - 2017-05-01 03:00 +0200
Re: converting my local site to be https only access Gene Heskett <gheskett@shentel.net> - 2017-05-01 03:40 +0200
Re: converting my local site to be https only access davidson@freevolt.org - 2017-05-01 21:50 +0200
Re: converting my local site to be https only access Gene Heskett <gheskett@shentel.net> - 2017-05-01 03:40 +0200
Re: converting my local site to be https only access Greg Wooledge <wooledg@eeg.ccf.org> - 2017-05-01 15:30 +0200
Re: converting my local site to be https only access Gene Heskett <gheskett@shentel.net> - 2017-05-01 16:10 +0200
Re: converting my local site to be https only access rhkramer@gmail.com - 2017-05-01 17:20 +0200
Re: converting my local site to be https only access Gene Heskett <gheskett@shentel.net> - 2017-05-01 19:00 +0200
Re: converting my local site to be https only access rhkramer@gmail.com - 2017-05-01 21:00 +0200
Re: converting my local site to be https only access rhkramer@gmail.com - 2017-05-01 21:00 +0200
Re: converting my local site to be https only access davidson@freevolt.org - 2017-05-02 01:40 +0200
Re: converting my local site to be https only access Ric Moore <wayward4now@gmail.com> - 2017-05-03 18:40 +0200
Re: converting my local site to be https only access Jonathan Dowland <jmtd@debian.org> - 2017-05-02 12:40 +0200
Re: converting my local site to be https only access <tomas@tuxteam.de> - 2017-05-02 13:30 +0200
Re: converting my local site to be https only access Jonathan Dowland <jmtd@debian.org> - 2017-05-02 23:20 +0200
Re: converting my local site to be https only access Gene Heskett <gheskett@shentel.net> - 2017-05-02 23:40 +0200
Re: converting my local site to be https only access <tomas@tuxteam.de> - 2017-05-03 11:30 +0200
Re: converting my local site to be https only access Gene Heskett <gheskett@shentel.net> - 2017-05-03 14:40 +0200
Re: converting my local site to be https only access <tomas@tuxteam.de> - 2017-05-03 15:30 +0200
Re: converting my local site to be https only access Gene Heskett <gheskett@shentel.net> - 2017-05-02 22:50 +0200
Re: converting my local site to be https only access Jonathan Dowland <jmtd@debian.org> - 2017-05-02 23:20 +0200
Re: converting my local site to be https only access Gene Heskett <gheskett@shentel.net> - 2017-05-02 23:50 +0200
Page 1 of 2 [1] 2 Next page →
| From | Gene Heskett <gheskett@shentel.net> |
|---|---|
| Date | 2017-04-29 05:40 +0200 |
| Subject | converting my local site to be https only access |
| Message-ID | <tBroJ-AM-1@gated-at.bofh.it> |
Greetings all; My web site (see the sig) is local, on this machine, in a pretty tight sandbox, but not running https. Where can I find a tut that is a complete instruction set to have it do an auto-redirect to itself, but using the "s" stuff regardless of the accessing client as long as the client can handle the https stuff this conversion will return to the client? I tried putting those 3 lines quoted numerous times at the bottom of the httpd/conf/httpd.conf, but that killed local access so I assume it also killed external access too. And its failure did not generate an error.log entry. Something was said about the AllowRedirect settings in httpd.conf, but it did not specify what to change it to. Currently several such entries are "none" I want to have it applied to the whole site. URL to the best tut please. Thank you. Cheers, Gene Heskett -- "There are four boxes to be used in defense of liberty: soap, ballot, jury, and ammo. Please use in that order." -Ed Howdershelt (Author) Genes Web page <http://geneslinuxbox.net:6309/gene>
[toc] | [next] | [standalone]
| From | Felix Dietrich <felix.dietrich@sperrhaken.name> |
|---|---|
| Date | 2017-04-29 10:30 +0200 |
| Message-ID | <tBvVo-3Tv-9@gated-at.bofh.it> |
| In reply to | #180540 |
Gene Heskett <gheskett@shentel.net> writes:
> Where can I find a tut that is a complete instruction set to have it do
> an auto-redirect to itself, but using the "s" stuff regardless of the
> accessing client as long as the client can handle the https stuff this
> conversion will return to the client?
For the apache webserver, which I am assuming you are using, I found
https://wiki.apache.org/httpd/RedirectSSL
which describes how to permanently redirect clients to an encrypted
connection. Clients without the capability to use SSL encryption will
not be able to see the contents of your site.
> I tried putting those 3 lines quoted numerous times at the bottom of the
> httpd/conf/httpd.conf, but that killed local access so I assume it also
> killed external access too. And its failure did not generate an
> error.log entry.
Which 3 lines are you referring to? I cannot see any lines that look
like they represent configuration file syntax in your message.
> Something was said about the AllowRedirect settings in httpd.conf, but it
> did not specify what to change it to.
Where was something said about AllowRedirect? What was stated exactly?
> URL to the best tut please.
As much as I enjoy a bit of social interaction: are you abusing us to do
your internet searches for you? Searching for "SSL redirect apache"
yields plenty of results. Part of the "joy" of the computer hobby is to
wheat out obsolete information, identify the wrong, and copy and paste
the slightly less wrong. I also won't judge anything to be "the best" –
unless it is my own of course. :-p
--
Felix Dietrich
[toc] | [prev] | [next] | [standalone]
| From | Gene Heskett <gheskett@shentel.net> |
|---|---|
| Date | 2017-04-29 15:10 +0200 |
| Message-ID | <tBAil-6Em-3@gated-at.bofh.it> |
| In reply to | #180541 |
On Saturday 29 April 2017 04:05:01 Felix Dietrich wrote: > Gene Heskett <gheskett@shentel.net> writes: > > Where can I find a tut that is a complete instruction set to have it > > do an auto-redirect to itself, but using the "s" stuff regardless of > > the accessing client as long as the client can handle the https > > stuff this conversion will return to the client? > > For the apache webserver, which I am assuming you are using, I found > > https://wiki.apache.org/httpd/RedirectSSL > > which describes how to permanently redirect clients to an encrypted > connection. Clients without the capability to use SSL encryption will > not be able to see the contents of your site. > > > I tried putting those 3 lines quoted numerous times at the bottom of > > the httpd/conf/httpd.conf, but that killed local access so I assume > > it also killed external access too. And its failure did not > > generate an error.log entry. > > Which 3 lines are you referring to? I cannot see any lines that look > like they represent configuration file syntax in your message. > > > Something was said about the AllowRedirect settings in httpd.conf, > > but it did not specify what to change it to. > > Where was something said about AllowRedirect? What was stated > exactly? > > > URL to the best tut please. > > As much as I enjoy a bit of social interaction: are you abusing us to > do your internet searches for you? Searching for "SSL redirect > apache" yields plenty of results. Part of the "joy" of the computer > hobby is to wheat out obsolete information, identify the wrong, and > copy and paste the slightly less wrong. I also won't judge anything > to be "the best" – unless it is my own of course. :-p > Chuckle, point taken, used your search string and got smarter hits for apache2. Since my domain registrar is namecheap, I'm reading this link: <https://www.namecheap.com/support/knowledgebase/article.aspx/9821/38/redirect-to-https-on-apache> The recommended commands, and responses: sudo a2enmod rewrite [sudo] password for gene: Enabling module rewrite. To activate the new configuration, you need to run: service apache2 restart gene@coyote:/etc/httpd/conf$ sudo a2enmod ssl Enabling module ssl. See /usr/share/doc/apache2.2-common/README.Debian.gz on how to configure SSL and create self-signed certificates. To activate the new configuration, you need to run: service apache2 restart On restarting apache2, I get this error report on screen but the error.log is not showing the attempted restart. Error shown: Syntax error on line 71 of /etc/apache2/mods-enabled/ssl.conf: Invalid command 'Header', perhaps misspelled or defined by a module not included in the server configuration Action 'start' failed. That files line 71: region 68:SSLCipherSuite AES128+EECDH:AES128+EDH 69:SSLHonorCipherOrder on # enable only secure protocols: SSLv3 and TLSv1, but not SSLv2 70:SSLProtocol -all +TLSv1 71:Header always set Strict-Transport-Security "max-age=63072000; include SubDomains" 72:Header alway set X-Frame-Options DENY Being big dummy, whats this tell me? So I read the file it recommends, which contains 2 more commands: a2ensite default-ssl a2enmod ssl which appear to have worked, but it still will not restart. The next recommended command is: If you install the ssl-cert package, a self-signed certificate will be automatically created using the hostname currently configured on your computer. You can recreate that certificate (e.g. after you have changed /etc/hosts or DNS to give the correct hostname) as user root with: make-ssl-cert generate-default-snakeoil --force-overwrite But this brings up a question: The hostname of this computer doesn't match the name in the sig, my whole home networks domain name is coyote.den, and this machine is coyote.coyote.den. Since its all behind a dd-wrt install, and its not even running on a normal port number, this to bypass the ususal port 80 blocking the ISP's do in order to force you to use their servers at X$ a month, and to honor one of the cpu industries most enforced secrets ever, which is the Hitachi HD63C09, a clone of the Moto 6809, but which we have discovered is many times smarter. Hence the port:6309 in the sig, and the only port forwarded to this machine. So in internal name and the one in the sig don't match? So which name will it use if I run the above cert generator command? Ah, reading further, thats addressed by: To create more certificates with different host names, you can use make-ssl-cert /usr/share/ssl-cert/ssleay.cnf /path/to/cert-file.crt This will ask you for the hostname and place both SSL key and certificate in the file /path/to/cert-file.crt . Use this file with the SSLCertificateFile directive in the Apache config (you don't need the SSLCertificateKeyFile in this case as it also contains the key). The file /path/to/cert-file.crt should only be readable by root. A good directory to use for the additional certificates/keys is /etc/ssl/private. So I run it this way: root@coyote:~# make-ssl-cert /usr/share/ssl-cert/ssleay.cnf /etc/ssl/private/ debconf: DbDriver "config": /var/cache/debconf/config.dat is locked by another process: Resource temporarily unavailable. synaptic was running in another workspace, waiting on input, and it wants to restart the gui among other things, canceled it. Now a 2nd attempt: Could not create certificate. Openssl output was: Error Loading extension section v3_req 4147165448:error:2207507C:X509 V3 routines:v2i_GENERAL_NAME_ex:missing value:v3_alt.c:531: 4147165448:error:22098080:X509 V3 routines:X509V3_EXT_nconf:error in extension:v3_conf.c:95:name=subjectAltName, value=coyote.coyote.den,IP:192,168.71.3 Aha! a comma in the wrong place. 3rd pass: root@coyote:~# make-ssl-cert /usr/share/ssl-cert/ssleay.cnf /etc/ssl/private Could not create certificate. Openssl output was: Error Loading extension section v3_req 4147910920:error:2207507C:X509 V3 routines:v2i_GENERAL_NAME_ex:missing value:v3_alt.c:531: 4147910920:error:22098080:X509 V3 routines:X509V3_EXT_nconf:error in extension:v3_conf.c:95:name=subjectAltName, value=coyote.coyote.den,IP:192.168.71.3 WTH is v3_req? Apparently refers to man 5 x509_config, and that is way above my pay grade. 4th pass, different arguments for the extras.Failed, same report. Looks like it did work when I used the snake-oil version: root@coyote:~# ls -l /etc/ssl/private/ total 4 -rw-r----- 1 root ssl-cert 1704 Apr 29 08:46 ssl-cert-snakeoil.key And the 2nd version about 6" up then appeared to fail as before. however, no httpd start And still no entry's from the restarts in /var/log/apache2/error.log. My site is offline. And I need to reboot after the last update. Thanks Felix. > -- > Felix Dietrich Cheers, Gene Heskett -- "There are four boxes to be used in defense of liberty: soap, ballot, jury, and ammo. Please use in that order." -Ed Howdershelt (Author) Genes Web page <http://geneslinuxbox.net:6309/gene>
[toc] | [prev] | [next] | [standalone]
| From | Jochen Spieker <ml@well-adjusted.de> |
|---|---|
| Date | 2017-04-29 20:30 +0200 |
| Message-ID | <tBFi2-1bq-5@gated-at.bofh.it> |
| In reply to | #180546 |
[Multipart message — attachments visible in raw view] — view raw
Gene Heskett:
> On Saturday 29 April 2017 04:05:01 Felix Dietrich wrote:
>> Gene Heskett <gheskett@shentel.net> writes:
>>
>>> Where can I find a tut that is a complete instruction set to have it
>>> do an auto-redirect to itself, but using the "s" stuff regardless of
>>> the accessing client as long as the client can handle the https
>>> stuff this conversion will return to the client?
What you want to do requires that you understand the basics of Apache's
configuration mechanism. You should really start with that.
http://httpd.apache.org/docs/2.4/en/getting-started.html
http://httpd.apache.org/docs/2.4/en/bind.html
http://httpd.apache.org/docs/2.4/en/configuring.html
http://httpd.apache.org/docs/2.4/en/urlmapping.html
http://httpd.apache.org/docs/2.4/en/vhosts/
That's really just the basics so you know where to put random things you
find on the internet. For your use case, these should also be helpful:
http://httpd.apache.org/docs/2.4/en/ssl/
http://httpd.apache.org/docs/2.4/en/rewrite/
What the upstream Apache documentation does not mention (or care about)
is that Debian has its own way of splitting up Apache configuration
files. If a random (not Debian- or Ubuntu-specific) tutorial tells you
to change your httpd.conf then this is most certainly not the way to do
it in Debian.
>>> I tried putting those 3 lines quoted numerous times at the bottom of
>>> the httpd/conf/httpd.conf, but that killed local access so I assume
>>> it also killed external access too. And its failure did not
>>> generate an error.log entry.
The bottom of your httpd.conf might be the wrong place to put it. It
really depends on your local configuration which we do not know. Do you
have a plain Debian installation that you did yourself or do you use an
image from a hoster or any other company? What changes have you done to
your configuration?
What Debian expects most admins to do is drop their own virtual host
definitions into /etc/apache2/sites-available/ and use a2ensite to
enable them. Global configuration directives can be placed in
conf-available/ (use a2enconf).
>>> Something was said about the AllowRedirect settings in httpd.conf,
>>> but it did not specify what to change it to.
Don't touch httpd.conf, it will probably not do what you want to
achieve. Instead, edit the virtual host you are using.
> Chuckle, point taken, used your search string and got smarter hits for
> apache2. Since my domain registrar is namecheap, I'm reading this link:
> <https://www.namecheap.com/support/knowledgebase/article.aspx/9821/38/redirect-to-https-on-apache>
Your domain registrar is irrelevant here. Look for
Debian/Ubuntu-specific tutorials after reading up on the basics.
> Syntax error on line 71 of /etc/apache2/mods-enabled/ssl.conf:
> Invalid command 'Header', perhaps misspelled or defined by a module not
> included in the server configuration
> Action 'start' failed.
Apparently the header module is not enabled in your configuration. You
can do so by running "a2enmod headers".
> If you install the ssl-cert package, a self-signed certificate will be
> automatically created using the hostname currently configured on your
> computer.
If your machine is publicly available, there is really no reason anymore
to use self-signed certificates -- except for testing, probably. If your
configuration works with your self-signed certificate, you should
consider using Let's Encrypt.
> So in internal name and the one in the sig don't match?
> So which name will it use if I run the above cert generator command?
Nowadays you can run more than one VirtualHosts even with only one IP
address. You just set up regular virtual hosts which use their own
certificates.
I cannot comment on the other errors you are getting, but (just in case
I didn't stress it enough :)) I think your life will become a lot easier
once you master the basics of Apache. The creation of SSL certificates
actually becomes a lot easier with Let's Encrypt.
J.
--
In this bunker there are women and children. There are no weapons.
[Agree] [Disagree]
<http://archive.slowlydownward.com/NODATA/data_enter2.html>
[toc] | [prev] | [next] | [standalone]
| From | Gene Heskett <gheskett@shentel.net> |
|---|---|
| Date | 2017-04-29 20:50 +0200 |
| Message-ID | <tBFBo-1jR-5@gated-at.bofh.it> |
| In reply to | #180550 |
On Saturday 29 April 2017 14:21:27 Jochen Spieker wrote: > Gene Heskett: > > On Saturday 29 April 2017 04:05:01 Felix Dietrich wrote: > >> Gene Heskett <gheskett@shentel.net> writes: > >>> Where can I find a tut that is a complete instruction set to have > >>> it do an auto-redirect to itself, but using the "s" stuff > >>> regardless of the accessing client as long as the client can > >>> handle the https stuff this conversion will return to the client? > > What you want to do requires that you understand the basics of > Apache's configuration mechanism. You should really start with that. > > http://httpd.apache.org/docs/2.4/en/getting-started.html > http://httpd.apache.org/docs/2.4/en/bind.html > http://httpd.apache.org/docs/2.4/en/configuring.html > http://httpd.apache.org/docs/2.4/en/urlmapping.html > http://httpd.apache.org/docs/2.4/en/vhosts/ > > That's really just the basics so you know where to put random things > you find on the internet. For your use case, these should also be > helpful: > > http://httpd.apache.org/docs/2.4/en/ssl/ > http://httpd.apache.org/docs/2.4/en/rewrite/ > > What the upstream Apache documentation does not mention (or care > about) is that Debian has its own way of splitting up Apache > configuration files. If a random (not Debian- or Ubuntu-specific) > tutorial tells you to change your httpd.conf then this is most > certainly not the way to do it in Debian. > > >>> I tried putting those 3 lines quoted numerous times at the bottom > >>> of the httpd/conf/httpd.conf, but that killed local access so I > >>> assume it also killed external access too. And its failure did > >>> not generate an error.log entry. > > The bottom of your httpd.conf might be the wrong place to put it. It > really depends on your local configuration which we do not know. Do > you have a plain Debian installation that you did yourself or do you > use an image from a hoster or any other company? What changes have you > done to your configuration? > > What Debian expects most admins to do is drop their own virtual host > definitions into /etc/apache2/sites-available/ and use a2ensite to > enable them. Global configuration directives can be placed in > conf-available/ (use a2enconf). > > >>> Something was said about the AllowRedirect settings in httpd.conf, > >>> but it did not specify what to change it to. > > Don't touch httpd.conf, it will probably not do what you want to > achieve. Instead, edit the virtual host you are using. > > > Chuckle, point taken, used your search string and got smarter hits > > for apache2. Since my domain registrar is namecheap, I'm reading > > this link: > > <https://www.namecheap.com/support/knowledgebase/article.aspx/9821/3 > >8/redirect-to-https-on-apache> > > Your domain registrar is irrelevant here. Look for > Debian/Ubuntu-specific tutorials after reading up on the basics. > > > Syntax error on line 71 of /etc/apache2/mods-enabled/ssl.conf: > > Invalid command 'Header', perhaps misspelled or defined by a module > > not included in the server configuration > > Action 'start' failed. > > Apparently the header module is not enabled in your configuration. You > can do so by running "a2enmod headers". > Not being fam with this a2enmod thing, I just used mc to make a softlink. That moved the error and changed it a wee bit, to line 72, which had the keyword always spelled alway. Fixed, start right up. I can only see it at localhost, so I've no clue if the link in my sig works or not. If it redirects to https and the front page pix loads, I'm good to go I think. > > If you install the ssl-cert package, a self-signed certificate will > > be automatically created using the hostname currently configured on > > your computer. Which is not the same as the dns servers returns. > > If your machine is publicly available, there is really no reason > anymore to use self-signed certificates -- except for testing, > probably. If your configuration works with your self-signed > certificate, you should consider using Let's Encrypt. > > > So in internal name and the one in the sig don't match? > > So which name will it use if I run the above cert generator command? > > Nowadays you can run more than one VirtualHosts even with only one IP > address. You just set up regular virtual hosts which use their own > certificates. > > I cannot comment on the other errors you are getting, but (just in > case I didn't stress it enough :)) I think your life will become a lot > easier once you master the basics of Apache. The creation of SSL > certificates actually becomes a lot easier with Let's Encrypt. Those are done I believe: root@coyote:/etc/httpd/conf# ls -l /etc/ssl/private/ total 8 lrwxrwxrwx 1 root root 18 Apr 29 10:27 fba0a812 -> ssl-cert-genes.key -rw------- 1 root root 2798 Apr 29 10:27 ssl-cert-genes.key -rw-r----- 1 root ssl-cert 1704 Apr 29 08:46 ssl-cert-snakeoil.key Unless thats not enough. > > J. Thanks, Jochen Spieker. Cheers, Gene Heskett -- "There are four boxes to be used in defense of liberty: soap, ballot, jury, and ammo. Please use in that order." -Ed Howdershelt (Author) Genes Web page <http://geneslinuxbox.net:6309/gene>
[toc] | [prev] | [next] | [standalone]
| From | Gene Heskett <gheskett@shentel.net> |
|---|---|
| Date | 2017-04-30 23:10 +0200 |
| Message-ID | <tC4gq-8jL-11@gated-at.bofh.it> |
| In reply to | #180551 |
On Saturday 29 April 2017 14:49:04 Gene Heskett wrote: > On Saturday 29 April 2017 14:21:27 Jochen Spieker wrote: > > Gene Heskett: > > > On Saturday 29 April 2017 04:05:01 Felix Dietrich wrote: > > >> Gene Heskett <gheskett@shentel.net> writes: > > >>> Where can I find a tut that is a complete instruction set to > > >>> have it do an auto-redirect to itself, but using the "s" stuff > > >>> regardless of the accessing client as long as the client can > > >>> handle the https stuff this conversion will return to the > > >>> client? > > > > What you want to do requires that you understand the basics of > > Apache's configuration mechanism. You should really start with that. > > > > http://httpd.apache.org/docs/2.4/en/getting-started.html > > http://httpd.apache.org/docs/2.4/en/bind.html > > http://httpd.apache.org/docs/2.4/en/configuring.html > > http://httpd.apache.org/docs/2.4/en/urlmapping.html > > http://httpd.apache.org/docs/2.4/en/vhosts/ > > I don't have 2.4, 2.2 here on wheezy. Looking in the docs/2.2/envvars reference and trying some of the commands I find I apparently must specify the port # somehow. apache2ctl cannot connect on port 80. It apparently uses /etc/alternatives/www-browser, which is a softlink to /usrt/bin/lynx, and guess what? lynx support at lynx.isc.org has been deleted. And it won't work without talking to isc.org first. Even after being re-installed. So A: file a bug against lynx, best to remove it as its apparently been EOL'd by isc.org And B: what can I change that softlink in /etc/alternatives to so apache2ctl will work against localhost:6309 ? And C: If I have to learn a new httpd server, is nginx any better than apache2? > > That's really just the basics so you know where to put random things > > you find on the internet. For your use case, these should also be > > helpful: > > > > http://httpd.apache.org/docs/2.4/en/ssl/ > > http://httpd.apache.org/docs/2.4/en/rewrite/ > > > > What the upstream Apache documentation does not mention (or care > > about) is that Debian has its own way of splitting up Apache > > configuration files. If a random (not Debian- or Ubuntu-specific) > > tutorial tells you to change your httpd.conf then this is most > > certainly not the way to do it in Debian. > > > > >>> I tried putting those 3 lines quoted numerous times at the > > >>> bottom of the httpd/conf/httpd.conf, but that killed local > > >>> access so I assume it also killed external access too. And its > > >>> failure did not generate an error.log entry. > > > > The bottom of your httpd.conf might be the wrong place to put it. It > > really depends on your local configuration which we do not know. Do > > you have a plain Debian installation that you did yourself or do you > > use an image from a hoster or any other company? What changes have > > you done to your configuration? > > > > What Debian expects most admins to do is drop their own virtual host > > definitions into /etc/apache2/sites-available/ and use a2ensite to > > enable them. Global configuration directives can be placed in > > conf-available/ (use a2enconf). > > > > >>> Something was said about the AllowRedirect settings in > > >>> httpd.conf, but it did not specify what to change it to. > > > > Don't touch httpd.conf, it will probably not do what you want to > > achieve. Instead, edit the virtual host you are using. > > > > > Chuckle, point taken, used your search string and got smarter hits > > > for apache2. Since my domain registrar is namecheap, I'm reading > > > this link: > > > <https://www.namecheap.com/support/knowledgebase/article.aspx/9821 > > >/3 8/redirect-to-https-on-apache> > > > > Your domain registrar is irrelevant here. Look for > > Debian/Ubuntu-specific tutorials after reading up on the basics. > > > > > Syntax error on line 71 of /etc/apache2/mods-enabled/ssl.conf: > > > Invalid command 'Header', perhaps misspelled or defined by a > > > module not included in the server configuration > > > Action 'start' failed. > > > > Apparently the header module is not enabled in your configuration. > > You can do so by running "a2enmod headers". > > Not being fam with this a2enmod thing, I just used mc to make a > softlink. That moved the error and changed it a wee bit, to line 72, > which had the keyword always spelled alway. Fixed, start right up. I > can only see it at localhost, so I've no clue if the link in my sig > works or not. > > If it redirects to https and the front page pix loads, I'm good to go > I think. > > > > If you install the ssl-cert package, a self-signed certificate > > > will be automatically created using the hostname currently > > > configured on your computer. > > Which is not the same as the dns servers returns. > > > If your machine is publicly available, there is really no reason > > anymore to use self-signed certificates -- except for testing, > > probably. If your configuration works with your self-signed > > certificate, you should consider using Let's Encrypt. > > > > > So in internal name and the one in the sig don't match? > > > So which name will it use if I run the above cert generator > > > command? > > > > Nowadays you can run more than one VirtualHosts even with only one > > IP address. You just set up regular virtual hosts which use their > > own certificates. > > > > I cannot comment on the other errors you are getting, but (just in > > case I didn't stress it enough :)) I think your life will become a > > lot easier once you master the basics of Apache. The creation of SSL > > certificates actually becomes a lot easier with Let's Encrypt. > > Those are done I believe: > root@coyote:/etc/httpd/conf# ls -l /etc/ssl/private/ > total 8 > lrwxrwxrwx 1 root root 18 Apr 29 10:27 fba0a812 -> > ssl-cert-genes.key > -rw------- 1 root root 2798 Apr 29 10:27 ssl-cert-genes.key > -rw-r----- 1 root ssl-cert 1704 Apr 29 08:46 ssl-cert-snakeoil.key > > Unless thats not enough. > > > J. > > Thanks, Jochen Spieker. > > Cheers, Gene Heskett Cheers, Gene Heskett -- "There are four boxes to be used in defense of liberty: soap, ballot, jury, and ammo. Please use in that order." -Ed Howdershelt (Author) Genes Web page <http://geneslinuxbox.net:6309/gene>
[toc] | [prev] | [next] | [standalone]
| From | Dejan Jocic <jodejka@gmail.com> |
|---|---|
| Date | 2017-04-30 23:50 +0200 |
| Message-ID | <tC4T7-5F-1@gated-at.bofh.it> |
| In reply to | #180557 |
On 30-04-17, Gene Heskett wrote: > On Saturday 29 April 2017 14:49:04 Gene Heskett wrote: > > > On Saturday 29 April 2017 14:21:27 Jochen Spieker wrote: > > > Gene Heskett: > > > > On Saturday 29 April 2017 04:05:01 Felix Dietrich wrote: > > > >> Gene Heskett <gheskett@shentel.net> writes: > > > >>> Where can I find a tut that is a complete instruction set to > > > >>> have it do an auto-redirect to itself, but using the "s" stuff > > > >>> regardless of the accessing client as long as the client can > > > >>> handle the https stuff this conversion will return to the > > > >>> client? > > > > > > What you want to do requires that you understand the basics of > > > Apache's configuration mechanism. You should really start with that. > > > > > > http://httpd.apache.org/docs/2.4/en/getting-started.html > > > http://httpd.apache.org/docs/2.4/en/bind.html > > > http://httpd.apache.org/docs/2.4/en/configuring.html > > > http://httpd.apache.org/docs/2.4/en/urlmapping.html > > > http://httpd.apache.org/docs/2.4/en/vhosts/ > > > > I don't have 2.4, 2.2 here on wheezy. > > Looking in the docs/2.2/envvars reference and trying some of the commands > I find I apparently must specify the port # somehow. apache2ctl cannot > connect on port 80. It apparently uses /etc/alternatives/www-browser, > which is a softlink to /usrt/bin/lynx, and guess what? > > lynx support at lynx.isc.org has been deleted. And it won't work without > talking to isc.org first. Even after being re-installed. > > So A: file a bug against lynx, best to remove it as its apparently been > EOL'd by isc.org > > And B: what can I change that softlink in /etc/alternatives to so > apache2ctl will work against localhost:6309 ? For changing those softlinks in /etc/alternatives best would be to use update-alternatives. As root, or with sudo, whatever you prefer. As to what would be best in your case, I do not know. Other terminal browsers you could use are Links and w3m.
[toc] | [prev] | [next] | [standalone]
| From | Eike Lantzsch <zp6cge@gmx.net> |
|---|---|
| Date | 2017-05-01 00:00 +0200 |
| Message-ID | <tC52N-9c-1@gated-at.bofh.it> |
| In reply to | #180557 |
On Sunday, 30 April 2017 17:07:47 -04 Gene Heskett wrote: [snip] > > I don't have 2.4, 2.2 here on wheezy. > > Looking in the docs/2.2/envvars reference and trying some of the commands > I find I apparently must specify the port # somehow. apache2ctl cannot > connect on port 80. It apparently uses /etc/alternatives/www-browser, > which is a softlink to /usrt/bin/lynx, and guess what? > > lynx support at lynx.isc.org has been deleted. And it won't work without > talking to isc.org first. Even after being re-installed. > > So A: file a bug against lynx, best to remove it as its apparently been > EOL'd by isc.org [snip] Gene, You might like to replace lynx with links. There is also links2 and elinks, but according to openbsd.org elinks is full of security holes and those guys I do believe. Sorry, can't comment on your main problem. Cheers Eike
[toc] | [prev] | [next] | [standalone]
| From | davidson@freevolt.org |
|---|---|
| Date | 2017-05-01 02:20 +0200 |
| Message-ID | <tC7eh-1FK-3@gated-at.bofh.it> |
| In reply to | #180557 |
On Sun, 30 Apr 2017, Gene Heskett wrote: > On Saturday 29 April 2017 14:49:04 Gene Heskett wrote: > >> On Saturday 29 April 2017 14:21:27 Jochen Spieker wrote: >>> Gene Heskett: >>>> On Saturday 29 April 2017 04:05:01 Felix Dietrich wrote: >>>>> Gene Heskett <gheskett@shentel.net> writes: >>>>>> Where can I find a tut that is a complete instruction set to >>>>>> have it do an auto-redirect to itself, but using the "s" stuff >>>>>> regardless of the accessing client as long as the client can >>>>>> handle the https stuff this conversion will return to the >>>>>> client? >>> >>> What you want to do requires that you understand the basics of >>> Apache's configuration mechanism. You should really start with that. >>> >>> http://httpd.apache.org/docs/2.4/en/getting-started.html >>> http://httpd.apache.org/docs/2.4/en/bind.html >>> http://httpd.apache.org/docs/2.4/en/configuring.html >>> http://httpd.apache.org/docs/2.4/en/urlmapping.html >>> http://httpd.apache.org/docs/2.4/en/vhosts/ >>> > I don't have 2.4, 2.2 here on wheezy. > > Looking in the docs/2.2/envvars reference and trying some of the commands > I find I apparently must specify the port # somehow. apache2ctl cannot > connect on port 80. It apparently uses /etc/alternatives/www-browser, > which is a softlink to /usrt/bin/lynx, and guess what? > > lynx support at lynx.isc.org has been deleted. And it won't work without > talking to isc.org first. Even after being re-installed. Lynx works just fine. I expect your configuration file simply has some references to obsolete remote locations. Does this work? $ WWW_HOME="https://en.wikipedia.org/wiki/PEBKAC" lynx or this? $ WWW_HOME="file://localhost/REPLACE-ME-WITH-A-PATH-TO-SOME-LOCAL-HTML-DOC.html" lynx And does this... $ grep '^STARTFILE:' /etc/lynx-cur/lynx.cfg ...confirm that you have something obsolete like STARTFILE:http://lynx.isc.org/ in your lynx.cfg ? Then fix that broken reference. Edit /etc/lynx-cur/lynx.cfg, replacing that STARTFILE url with whatever you like. FWIW, I think STARTFILE:file://localhost/~/ makes a sensible default. Or, if for some incomprehensible reason you think a remote website is an appropriate default startfile, you could use STARTFILE:http://lynx.invisible-island.net/ instead. While you're at it, you might want to cast your eye over any other lines returned by this... $ grep '^[A-Z_]*:[[:blank:]]*https\?://' /etc/lynx-cur/lynx.cfg ...and see if you wouldn't rather change them to something more up-to-date, more reliable, or more appropriate for your installation. > So A: file a bug against lynx, best to remove it as its apparently been > EOL'd by isc.org Huh? You would remove a program simply because isc.org removes a couple web pages? Development of lynx continues unabated: http://invisible-island.net/lynx/lynx-develop.html Good luck with your project.
[toc] | [prev] | [next] | [standalone]
| From | Lisi Reisz <lisi.reisz@gmail.com> |
|---|---|
| Date | 2017-05-01 03:00 +0200 |
| Message-ID | <tC7R0-1Tz-5@gated-at.bofh.it> |
| In reply to | #180561 |
On Monday 01 May 2017 01:19:21 davidson@freevolt.org wrote: > Development of lynx continues unabated: > > http://invisible-island.net/lynx/lynx-develop.html The most recent reference seems to be to 2015: "Finally (as of 2015).... " Lisi
[toc] | [prev] | [next] | [standalone]
| From | Gene Heskett <gheskett@shentel.net> |
|---|---|
| Date | 2017-05-01 03:40 +0200 |
| Message-ID | <tC8tH-2oO-1@gated-at.bofh.it> |
| In reply to | #180564 |
On Sunday 30 April 2017 20:51:54 Lisi Reisz wrote: > On Monday 01 May 2017 01:19:21 davidson@freevolt.org wrote: > > Development of lynx continues unabated: > > > > http://invisible-island.net/lynx/lynx-develop.html > > The most recent reference seems to be to 2015: > "Finally (as of 2015).... " > > Lisi Thanks Lisi, I hadn't had time to look yet. Cheers, Gene Heskett -- "There are four boxes to be used in defense of liberty: soap, ballot, jury, and ammo. Please use in that order." -Ed Howdershelt (Author) Genes Web page <http://geneslinuxbox.net:6309/gene>
[toc] | [prev] | [next] | [standalone]
| From | davidson@freevolt.org |
|---|---|
| Date | 2017-05-01 21:50 +0200 |
| Message-ID | <tCpux-4NU-13@gated-at.bofh.it> |
| In reply to | #180564 |
On Mon, 1 May 2017, Lisi Reisz wrote: > On Monday 01 May 2017 01:19:21 davidson@freevolt.org wrote: >> Development of lynx continues unabated: >> >> http://invisible-island.net/lynx/lynx-develop.html > > The most recent reference seems to be to 2015: > "Finally (as of 2015).... " I linked to that page because it contained discussion of the website's move away from isc.org to invisible-island.net . Lynx current development: http://lynx.invisible-island.net/current/index.html More generally: http://lynx.invisible-island.net/
[toc] | [prev] | [next] | [standalone]
| From | Gene Heskett <gheskett@shentel.net> |
|---|---|
| Date | 2017-05-01 03:40 +0200 |
| Message-ID | <tC8tH-2oO-5@gated-at.bofh.it> |
| In reply to | #180561 |
On Sunday 30 April 2017 20:19:21 davidson@freevolt.org wrote: > On Sun, 30 Apr 2017, Gene Heskett wrote: > > On Saturday 29 April 2017 14:49:04 Gene Heskett wrote: > >> On Saturday 29 April 2017 14:21:27 Jochen Spieker wrote: > >>> Gene Heskett: > >>>> On Saturday 29 April 2017 04:05:01 Felix Dietrich wrote: > >>>>> Gene Heskett <gheskett@shentel.net> writes: > >>>>>> Where can I find a tut that is a complete instruction set to > >>>>>> have it do an auto-redirect to itself, but using the "s" stuff > >>>>>> regardless of the accessing client as long as the client can > >>>>>> handle the https stuff this conversion will return to the > >>>>>> client? > >>> > >>> What you want to do requires that you understand the basics of > >>> Apache's configuration mechanism. You should really start with > >>> that. > >>> > >>> http://httpd.apache.org/docs/2.4/en/getting-started.html > >>> http://httpd.apache.org/docs/2.4/en/bind.html > >>> http://httpd.apache.org/docs/2.4/en/configuring.html > >>> http://httpd.apache.org/docs/2.4/en/urlmapping.html > >>> http://httpd.apache.org/docs/2.4/en/vhosts/ > > > > I don't have 2.4, 2.2 here on wheezy. > > > > Looking in the docs/2.2/envvars reference and trying some of the > > commands I find I apparently must specify the port # somehow. > > apache2ctl cannot connect on port 80. It apparently uses > > /etc/alternatives/www-browser, which is a softlink to > > /usrt/bin/lynx, and guess what? > > > > lynx support at lynx.isc.org has been deleted. And it won't work > > without talking to isc.org first. Even after being re-installed. > > Lynx works just fine. I expect your configuration file simply has some > references to obsolete remote locations. > > Does this work? > > $ WWW_HOME="https://en.wikipedia.org/wiki/PEBKAC" lynx > > or this? > > $ > WWW_HOME="file://localhost/REPLACE-ME-WITH-A-PATH-TO-SOME-LOCAL-HTML-D >OC.html" lynx > > And does this... > > $ grep '^STARTFILE:' /etc/lynx-cur/lynx.cfg > > ...confirm that you have something obsolete like > > STARTFILE:http://lynx.isc.org/ > > in your lynx.cfg ? > it was. > Then fix that broken reference. Edit /etc/lynx-cur/lynx.cfg, replacing > that STARTFILE url with whatever you like. > > FWIW, I think > > STARTFILE:file://localhost/~/ > > makes a sensible default. except I am then trapped in my home dir. > > Or, if for some incomprehensible reason you think a remote website is > an appropriate default startfile, you could use > > STARTFILE:http://lynx.invisible-island.net/ > > instead. > > While you're at it, you might want to cast your eye over any other > lines returned by this... > > $ grep '^[A-Z_]*:[[:blank:]]*https\?://' /etc/lynx-cur/lynx.cfg Which was a wisc.edu url. > > ...and see if you wouldn't rather change them to something more > up-to-date, more reliable, or more appropriate for your installation. > > > So A: file a bug against lynx, best to remove it as its apparently > > been EOL'd by isc.org > > Huh? You would remove a program simply because isc.org removes a > couple web pages? > > Development of lynx continues unabated: > > http://invisible-island.net/lynx/lynx-develop.html Sorta seems to me that ought to be kept uptodate in re that by the debian folks. > Good luck with your project. I have atm, the darnest collection of Murphy's work I've ever seen. So I am inclined to fire up amrecover, back it up a week, and recover the /etc/apache2, /etc/httpd, and /var/www/html trees. That sould put me back to a working, non ssl, web server. All this got started because the next firefox says it will not look at a plain http site, and I was trying to make robots.txt kick googlebot in the gonads and out of my site, its eating more #$%& bandwidth than my site traffic is. So once I've restored normal http operations, I'll come back and see if I can find some help converting it to https. Thank you davidson@freevolt.org. Cheers, Gene Heskett -- "There are four boxes to be used in defense of liberty: soap, ballot, jury, and ammo. Please use in that order." -Ed Howdershelt (Author) Genes Web page <http://geneslinuxbox.net:6309/gene>
[toc] | [prev] | [next] | [standalone]
| From | Greg Wooledge <wooledg@eeg.ccf.org> |
|---|---|
| Date | 2017-05-01 15:30 +0200 |
| Message-ID | <tCjyO-1f8-13@gated-at.bofh.it> |
| In reply to | #180567 |
On Sun, Apr 30, 2017 at 09:32:33PM -0400, Gene Heskett wrote: > > STARTFILE:file://localhost/~/ > > > > makes a sensible default. > > except I am then trapped in my home dir. *boggle* You can press 'g' and then paste (or type) whatever URL you want into the terminal. You are not "trapped" anywhere. Of course, the fact that you are in lynx means half the Web will not WORK, especially your new-fangled "Let's Encrypt" https site using a virtual domain, which is presumably what you are actually trying to use lynx to test. elinks has the same problem. It can't talk to sites like https://paste.debian.net/ I have been told that w3m might not have this problem, but I haven't had a chance to try it yet.
[toc] | [prev] | [next] | [standalone]
| From | Gene Heskett <gheskett@shentel.net> |
|---|---|
| Date | 2017-05-01 16:10 +0200 |
| Message-ID | <tCkbw-1IO-23@gated-at.bofh.it> |
| In reply to | #180573 |
On Monday 01 May 2017 09:28:10 Greg Wooledge wrote: > On Sun, Apr 30, 2017 at 09:32:33PM -0400, Gene Heskett wrote: > > > STARTFILE:file://localhost/~/ > > > > > > makes a sensible default. > > > > except I am then trapped in my home dir. > > *boggle* > > You can press 'g' and then paste (or type) whatever URL you want into > the terminal. You are not "trapped" anywhere. I was referring to the usual visitor who likely doesn't know that. > Of course, the fact that you are in lynx means half the Web will not > WORK, especially your new-fangled "Let's Encrypt" https site using a > virtual domain, which is presumably what you are actually trying to > use lynx to test. > > elinks has the same problem. It can't talk to sites like > https://paste.debian.net/ > > I have been told that w3m might not have this problem, but I haven't > had a chance to try it yet. Neither have I. I think I have it, but don't recall that it worked the last time. But does ok now. Thanks, its back among the living. but not for https. Cheers, Gene Heskett -- "There are four boxes to be used in defense of liberty: soap, ballot, jury, and ammo. Please use in that order." -Ed Howdershelt (Author) Genes Web page <http://geneslinuxbox.net:6309/gene>
[toc] | [prev] | [next] | [standalone]
| From | rhkramer@gmail.com |
|---|---|
| Date | 2017-05-01 17:20 +0200 |
| Message-ID | <tClhf-2mc-5@gated-at.bofh.it> |
| In reply to | #180567 |
On Sunday, April 30, 2017 09:32:33 PM Gene Heskett wrote:
> All this got started because
> the next firefox says it will not look at a plain http site, and I was
I hadn't heard anything about this, so I tried Googling. The only thing I've
found so far is reference to an optional add-on / plugin ("HTTPS Everywhere",
iiuc) that would allow the browser to look only at ssl (https) pages. Am I
missing something?
(Well, I didn't read what I found carefully or completely, I did see some
snippet of text that said that, in some respects, it would work (or use some
methodologies) of NoScript, which *might* mean that there might be a way to
override the plugin manually to view non-SSL pages.)
(Not to say that SSL everywhere wouldn't be a good idea, but, until "legacy"
websites are converted, we may be missing a lot of the web.)
[toc] | [prev] | [next] | [standalone]
| From | Gene Heskett <gheskett@shentel.net> |
|---|---|
| Date | 2017-05-01 19:00 +0200 |
| Message-ID | <tCmQ1-39r-5@gated-at.bofh.it> |
| In reply to | #180576 |
On Monday 01 May 2017 11:18:21 rhkramer@gmail.com wrote:
> On Sunday, April 30, 2017 09:32:33 PM Gene Heskett wrote:
> > All this got started because
> > the next firefox says it will not look at a plain http site, and I
> > was
>
> I hadn't heard anything about this, so I tried Googling. The only
> thing I've found so far is reference to an optional add-on / plugin
> ("HTTPS Everywhere", iiuc) that would allow the browser to look only
> at ssl (https) pages. Am I missing something?
>
That refers to ones browser, zip to do with a web server.
> (Well, I didn't read what I found carefully or completely, I did see
> some snippet of text that said that, in some respects, it would work
> (or use some methodologies) of NoScript, which *might* mean that there
> might be a way to override the plugin manually to view non-SSL pages.)
>
> (Not to say that SSL everywhere wouldn't be a good idea, but, until
> "legacy" websites are converted, we may be missing a lot of the web.)
Its converting my legacy web site that I am attempting to do.
Cheers, Gene Heskett
--
"There are four boxes to be used in defense of liberty:
soap, ballot, jury, and ammo. Please use in that order."
-Ed Howdershelt (Author)
Genes Web page <http://geneslinuxbox.net:6309/gene>
[toc] | [prev] | [next] | [standalone]
| From | rhkramer@gmail.com |
|---|---|
| Date | 2017-05-01 21:00 +0200 |
| Message-ID | <tCoI9-4h9-5@gated-at.bofh.it> |
| In reply to | #180581 |
On Monday, May 01, 2017 12:57:58 PM Gene Heskett wrote:
> On Monday 01 May 2017 11:18:21 rhkramer@gmail.com wrote:
> > I hadn't heard anything about this, so I tried Googling. The only
> > thing I've found so far is reference to an optional add-on / plugin
> > ("HTTPS Everywhere", iiuc) that would allow the browser to look only
> > at ssl (https) pages. Am I missing something?
>
> That refers to ones browser, zip to do with a web server.
Well, Firefox is a browser, I thought that was what was being talked about?
> Its converting my legacy web site that I am attempting to do.
Understood
[toc] | [prev] | [next] | [standalone]
| From | rhkramer@gmail.com |
|---|---|
| Date | 2017-05-01 21:00 +0200 |
| Message-ID | <tCoI9-4h9-13@gated-at.bofh.it> |
| In reply to | #180586 |
On Monday, May 01, 2017 02:54:05 PM rhkramer@gmail.com wrote:
> On Monday, May 01, 2017 12:57:58 PM Gene Heskett wrote:
> > On Monday 01 May 2017 11:18:21 rhkramer@gmail.com wrote:
> > > I hadn't heard anything about this, so I tried Googling. The only
> > > thing I've found so far is reference to an optional add-on / plugin
> > > ("HTTPS Everywhere", iiuc) that would allow the browser to look only
> > > at ssl (https) pages. Am I missing something?
> >
> > That refers to ones browser, zip to do with a web server.
>
> Well, Firefox is a browser, I thought that was what was being talked about?
Oh, maybe to be clearer, that plugin is for Firefox.
[toc] | [prev] | [next] | [standalone]
| From | davidson@freevolt.org |
|---|---|
| Date | 2017-05-02 01:40 +0200 |
| Message-ID | <tCt57-70S-1@gated-at.bofh.it> |
| In reply to | #180567 |
On Sun, 30 Apr 2017, Gene Heskett wrote:
> On Sunday 30 April 2017 20:19:21 davidson@freevolt.org wrote:
>
>> On Sun, 30 Apr 2017, Gene Heskett wrote:
[trimmed]
>>> lynx support at lynx.isc.org has been deleted. And it won't work
>>> without talking to isc.org first. Even after being re-installed.
>>
>> Lynx works just fine. I expect your configuration file simply has some
>> references to obsolete remote locations.
>>
>> Does this work?
>>
>> $ WWW_HOME="https://en.wikipedia.org/wiki/PEBKAC" lynx
>>
>> or this?
>>
>> $
>> WWW_HOME="file://localhost/REPLACE-ME-WITH-A-PATH-TO-SOME-LOCAL-HTML-D
>> OC.html" lynx
>>
>> And does this...
>>
>> $ grep '^STARTFILE:' /etc/lynx-cur/lynx.cfg
>>
>> ...confirm that you have something obsolete like
>>
>> STARTFILE:http://lynx.isc.org/
>>
>> in your lynx.cfg ?
>>
> it was.
>
>> Then fix that broken reference. Edit /etc/lynx-cur/lynx.cfg, replacing
>> that STARTFILE url with whatever you like.
>>
>> FWIW, I think
>>
>> STARTFILE:file://localhost/~/
>>
>> makes a sensible default.
>
> except I am then trapped in my home dir.
Well, as Greg W. pointed out, you aren't really restricted to whatever
links happen to be present in the startfile/"Main screen".
When running in "Novice" mode, the shortcut key for loading an
arbitrary url (G) is helpfully listed at the bottom of every screen:
Arrow keys: Up and Down to move. Right to follow a link; Left to go back.
H)elp O)ptions P)rint G)o M)ain screen Q)uit /=search [delete]=history list
But if you would like the default "Main screen" to be something more
web-access-centric, the choice is yours. Maybe
STARTFILE:https://duckduckgo.com/lite/
or
STARTFILE:https://www.google.com/
would fit the bill. Or something else entirely. Obviously you will
know better than I do what your users will find helpful.
Somebody upstream of us apparently thought that a site about lynx
would be a good initial default. Not a bad choice, if you ask me. Too
bad the site had to move.
>> Or, if for some incomprehensible reason you think a remote website is
>> an appropriate default startfile, you could use
>>
>> STARTFILE:http://lynx.invisible-island.net/
>>
>> instead.
>>
>> While you're at it, you might want to cast your eye over any other
>> lines returned by this...
>>
>> $ grep '^[A-Z_]*:[[:blank:]]*https\?://' /etc/lynx-cur/lynx.cfg
>
> Which was a wisc.edu url.
Thought so: http://scout.wisc.edu/
Which was presumably the value of DEFAULT_INDEX_FILE .
Whatever scout.wisc.edu may have had there in the past, the content
currently shown on that page is pretty much worthless as a general web
index.
So you'll probably change it to something better.
>> ...and see if you wouldn't rather change them to something more
>> up-to-date, more reliable, or more appropriate for your installation.
>>
>>> So A: file a bug against lynx, best to remove it as its apparently
>>> been EOL'd by isc.org
>>
>> Huh? You would remove a program simply because isc.org removes a
>> couple web pages?
>>
>> Development of lynx continues unabated:
>>
>> http://invisible-island.net/lynx/lynx-develop.html
>
> Sorta seems to me that ought to be kept uptodate in re that by the
> debian folks.
Sounds reasonable to me.
On the other hand, it is the site administrator, rather than Thomas
Dickey or the debian maintainer for lynx-cur, who is in the better
position to determine helpful values for both STARTFILE and
DEFAULT_INDEX_FILE in a given lynx install. I imagine (or hope) they
are frequently customised.
Anyways, maintenance of Wheezy is now in the hands of the Debian LTS
team:
https://wiki.debian.org/LTS/FAQ#Where_can_bugs_be_reported.3F
Where can bugs be reported?
Please report bugs that you found in the packages to the
debian-lts[1] mailing list. The bar for severity will be raised
(minor issues will no longer be fixed).
1. https://wiki.debian.org/LTS/Contact#debian-lts
>> Good luck with your project.
>
> I have atm, the darnest collection of Murphy's work I've ever seen. So I
> am inclined to fire up amrecover, back it up a week, and recover
> the /etc/apache2, /etc/httpd, and /var/www/html trees. That sould put
> me back to a working, non ssl, web server. All this got started because
> the next firefox says it will not look at a plain http site, and I was
> trying to make robots.txt kick googlebot in the gonads and out of my
> site, its eating more #$%& bandwidth than my site traffic is. So once
> I've restored normal http operations, I'll come back and see if I can
> find some help converting it to https.
It'll be interesting to follow along.
[toc] | [prev] | [next] | [standalone]
Page 1 of 2 [1] 2 Next page →
Back to top | Article view | linux.debian.user
csiph-web