Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]
Groups > linux.debian.user > #180540 > unrolled thread
| Started by | Gene Heskett <gheskett@shentel.net> |
|---|---|
| First post | 2017-04-29 05:40 +0200 |
| Last post | 2017-05-02 23:50 +0200 |
| Articles | 11 on this page of 31 — 12 participants |
Back to article view | Back to linux.debian.user
converting my local site to be https only access Gene Heskett <gheskett@shentel.net> - 2017-04-29 05:40 +0200
Re: converting my local site to be https only access Felix Dietrich <felix.dietrich@sperrhaken.name> - 2017-04-29 10:30 +0200
Re: converting my local site to be https only access Gene Heskett <gheskett@shentel.net> - 2017-04-29 15:10 +0200
Re: converting my local site to be https only access Jochen Spieker <ml@well-adjusted.de> - 2017-04-29 20:30 +0200
Re: converting my local site to be https only access Gene Heskett <gheskett@shentel.net> - 2017-04-29 20:50 +0200
Re: converting my local site to be https only access Gene Heskett <gheskett@shentel.net> - 2017-04-30 23:10 +0200
Re: converting my local site to be https only access Dejan Jocic <jodejka@gmail.com> - 2017-04-30 23:50 +0200
Re: converting my local site to be https only access Eike Lantzsch <zp6cge@gmx.net> - 2017-05-01 00:00 +0200
Re: converting my local site to be https only access davidson@freevolt.org - 2017-05-01 02:20 +0200
Re: converting my local site to be https only access Lisi Reisz <lisi.reisz@gmail.com> - 2017-05-01 03:00 +0200
Re: converting my local site to be https only access Gene Heskett <gheskett@shentel.net> - 2017-05-01 03:40 +0200
Re: converting my local site to be https only access davidson@freevolt.org - 2017-05-01 21:50 +0200
Re: converting my local site to be https only access Gene Heskett <gheskett@shentel.net> - 2017-05-01 03:40 +0200
Re: converting my local site to be https only access Greg Wooledge <wooledg@eeg.ccf.org> - 2017-05-01 15:30 +0200
Re: converting my local site to be https only access Gene Heskett <gheskett@shentel.net> - 2017-05-01 16:10 +0200
Re: converting my local site to be https only access rhkramer@gmail.com - 2017-05-01 17:20 +0200
Re: converting my local site to be https only access Gene Heskett <gheskett@shentel.net> - 2017-05-01 19:00 +0200
Re: converting my local site to be https only access rhkramer@gmail.com - 2017-05-01 21:00 +0200
Re: converting my local site to be https only access rhkramer@gmail.com - 2017-05-01 21:00 +0200
Re: converting my local site to be https only access davidson@freevolt.org - 2017-05-02 01:40 +0200
Re: converting my local site to be https only access Ric Moore <wayward4now@gmail.com> - 2017-05-03 18:40 +0200
Re: converting my local site to be https only access Jonathan Dowland <jmtd@debian.org> - 2017-05-02 12:40 +0200
Re: converting my local site to be https only access <tomas@tuxteam.de> - 2017-05-02 13:30 +0200
Re: converting my local site to be https only access Jonathan Dowland <jmtd@debian.org> - 2017-05-02 23:20 +0200
Re: converting my local site to be https only access Gene Heskett <gheskett@shentel.net> - 2017-05-02 23:40 +0200
Re: converting my local site to be https only access <tomas@tuxteam.de> - 2017-05-03 11:30 +0200
Re: converting my local site to be https only access Gene Heskett <gheskett@shentel.net> - 2017-05-03 14:40 +0200
Re: converting my local site to be https only access <tomas@tuxteam.de> - 2017-05-03 15:30 +0200
Re: converting my local site to be https only access Gene Heskett <gheskett@shentel.net> - 2017-05-02 22:50 +0200
Re: converting my local site to be https only access Jonathan Dowland <jmtd@debian.org> - 2017-05-02 23:20 +0200
Re: converting my local site to be https only access Gene Heskett <gheskett@shentel.net> - 2017-05-02 23:50 +0200
Page 2 of 2 — ← Prev page 1 [2]
| From | Ric Moore <wayward4now@gmail.com> |
|---|---|
| Date | 2017-05-03 18:40 +0200 |
| Message-ID | <tD5tN-7R3-17@gated-at.bofh.it> |
| In reply to | #180567 |
On 04/30/2017 09:32 PM, Gene Heskett wrote: than my site traffic is. So once > I've restored normal http operations, I'll come back and see if I can > find some help converting it to https. > > Thank you davidson@freevolt.org. If you were running wordpress, there are plugins to automate the conversion. BUT!! Since I have been down this path, all of your website references/links to http have to be converted to reflect https, since https will not willingly serve http content. Good luck. I finally went to a host that would do the complete conversion for me and serve our website.That, in the long run, was cheaper than another heart attack! :) Ric -- My father, Victor Moore (Vic) used to say: "There are two Great Sins in the world... ..the Sin of Ignorance, and the Sin of Stupidity. Only the former may be overcome." R.I.P. Dad. http://linuxcounter.net/user/44256.html
[toc] | [prev] | [next] | [standalone]
| From | Jonathan Dowland <jmtd@debian.org> |
|---|---|
| Date | 2017-05-02 12:40 +0200 |
| Message-ID | <tCDnP-5nt-7@gated-at.bofh.it> |
| In reply to | #180540 |
On Fri, Apr 28, 2017 at 11:35:06PM -0400, Gene Heskett wrote: > Greetings all; > > My web site (see the sig) is local, on this machine, in a pretty tight > sandbox, but not running https. > > Where can I find a tut that is a complete instruction set to have it do > an auto-redirect to itself, but using the "s" stuff regardless of the > accessing client as long as the client can handle the https stuff this > conversion will return to the client? Inferring that you are using apache2, a few notes from my observations of the thread as it currently stands. one of the instruction sets you were following was suggesting to use mod_rewrite. Personally, I think that's overkill. Achieving what you want is possible using a simple Redirect, which is provided by mod_rewrite, which is very likely already enabled (but if not, you can enable it in the same way, via symlink, which you can create via a2enmod, or by hand). We don't know how you have your site set up already, in particular whether or not you are using VirtualHosts. My advice would be to do so if you are not, so a "pre-step" would be migrating to them. Once using VirtualHosts, you can configure one to bind to port 80, and another to 443. From memory, it would look something like this <VirtualHost *:80> RedirectMatch permanent ^(.*)$ https://<YOUR SITE ADDRESS>$1 </VirtualHost> <VirtualHost *:443> # configuration for your website (now) lives here </VirtualHost> Substituting <YOUR SITE ADDRESS> appropriately. This is all from memory as I haven't used apache2 myself for many years (and looking back, having since used things like lighttpd and more recently nginx, the configuration language is much worse; stockholm syndrome whilst I was a user perhaps?) -- ⢀⣴⠾⠻⢶⣦⠀ ⣾⠁⢠⠒⠀⣿⡁ Jonathan Dowland ⢿⡄⠘⠷⠚⠋⠀ https://jmtd.net ⠈⠳⣄⠀⠀⠀⠀ Please do not CC me, I am subscribed to the list.
[toc] | [prev] | [next] | [standalone]
| From | <tomas@tuxteam.de> |
|---|---|
| Date | 2017-05-02 13:30 +0200 |
| Message-ID | <tCEae-64n-17@gated-at.bofh.it> |
| In reply to | #180592 |
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1
On Tue, May 02, 2017 at 11:35:19AM +0100, Jonathan Dowland wrote:
[...]
> one of the instruction sets you were following was suggesting to use
> mod_rewrite. Personally, I think that's overkill [...]
Good advice. Debugging Apache's mod_rewrite turns out to be a black
art in itself [1].
[elided, agree]
> This is all from memory as I haven't used apache2 myself for many years (and
> looking back, having since used things like lighttpd and more recently nginx,
> the configuration language is much worse; stockholm syndrome whilst I was a
> user perhaps?)
I don't understand that: do you find Apache's config worse, or
lighttpd's or nginx's?
Personally I *strongly* prefer lighttpd (I don't know nginx enough
to bother anyone with my opinion). Apache config's "looks-like-XML-
but-really-isn't" is downright ugly, but one can cope with that
(perhaps holding one's nose while editing. But the semantics ("looks-
like-declarative-but-really-isnt" -- see a pattern?) is horribly
error prone, and you've got to internalize that seven-phase model
and the hooks each module gets a stab at to understand the somewhat
counter-intuitive interaction of different configuration directives.
The result is that most end up cargo-culting some random snippets
off the Tubes, mixing them into their distro's default config and
beating on the resulting mess until it seems to work. Maintainability
and security... less good.
At work, Apache (they want it badly and it's not mine anyway). At
home, lighttpd (it's mine, after all).
Regards
[1] Written about an older mod_rewrite (Apache 1.3), but mod_rewrite has
*grown* since then:
``The great thing about mod_rewrite is it gives you all the
configurability and flexibility of Sendmail. The downside
to mod_rewrite is that it gives you all the configurability
and flexibility of Sendmail.''
-- Brian Behlendorf
Apache Group
`` Despite the tons of examples and docs, mod_rewrite is voodoo.
Damned cool voodoo, but still voodoo. ''
-- Brian Moore
bem@news.cmc.net
in http://mx.demos.su/manual/mod/mod_rewrite.html. I'd keep that
reference around anyway, since it helps a lot to wrap one's head
around Apache's "phases", without which config will stay a mystery
forever.
- -- tomás
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.12 (GNU/Linux)
iEYEARECAAYFAlkIbHoACgkQBcgs9XrR2kZsnQCfcsfSNnV+QLy3FB5NR7aTx+gp
188An05nuNZWwBDgR1ZgaQQ8jQ/II6JU
=YIX4
-----END PGP SIGNATURE-----
[toc] | [prev] | [next] | [standalone]
| From | Jonathan Dowland <jmtd@debian.org> |
|---|---|
| Date | 2017-05-02 23:20 +0200 |
| Message-ID | <tCNnc-3yM-11@gated-at.bofh.it> |
| In reply to | #180593 |
On Tue, May 02, 2017 at 01:24:42PM +0200, tomas@tuxteam.de wrote: > I don't understand that: do you find Apache's config worse, or > lighttpd's or nginx's? Sorry I was unclear: I meant I find Apache's config the worst. It was the first HTTPD I used, and I spent many years supporting it professionally. I only switched to lighttpd for personal stuff because it was much easier to get FastCGI working. But then the scales fell from my eyes; and I wondered why I hadn't considered alternatives sooner. The logic in professional web hosting circles was that Apache HTTPD was the only serious HTTPD to use for "real" web pages (at least back then); but the configuration language was always a nightmare, I just didn't know better. > At work, Apache (they want it badly and it's not mine anyway). At > home, lighttpd (it's mine, after all). I still use lighttpd for my main web server but I've been investigating nginx for my home NAS web server (which does much more proxying to web apps inside containers and suchlike, rather than serving content itself). I found some limitations with lighttpd's reverse-proxying and rewriting things. -- ⢀⣴⠾⠻⢶⣦⠀ ⣾⠁⢠⠒⠀⣿⡁ Jonathan Dowland ⢿⡄⠘⠷⠚⠋⠀ https://jmtd.net ⠈⠳⣄⠀⠀⠀⠀ Please do not CC me, I am subscribed to the list.
[toc] | [prev] | [next] | [standalone]
| From | Gene Heskett <gheskett@shentel.net> |
|---|---|
| Date | 2017-05-02 23:40 +0200 |
| Message-ID | <tCNGy-3EW-13@gated-at.bofh.it> |
| In reply to | #180620 |
On Tuesday 02 May 2017 17:13:44 Jonathan Dowland wrote: > On Tue, May 02, 2017 at 01:24:42PM +0200, tomas@tuxteam.de wrote: > > I don't understand that: do you find Apache's config worse, or > > lighttpd's or nginx's? > > Sorry I was unclear: I meant I find Apache's config the worst. It was > the first HTTPD I used, and I spent many years supporting it > professionally. I only switched to lighttpd for personal stuff because > it was much easier to get FastCGI working. But then the scales fell > from my eyes; and I wondered why I hadn't considered alternatives > sooner. The logic in professional web hosting circles was that Apache > HTTPD was the only serious HTTPD to use for "real" web pages (at least > back then); but the configuration language was always a nightmare, I > just didn't know better. > > > At work, Apache (they want it badly and it's not mine anyway). At > > home, lighttpd (it's mine, after all). > > I still use lighttpd for my main web server but I've been > investigating nginx for my home NAS web server (which does much more > proxying to web apps inside containers and suchlike, rather than > serving content itself). I found some limitations with lighttpd's > reverse-proxying and rewriting things. I've been looking at nginx myself, and wondering if it was any easier to setup. Apache2 can be a mutant bear with 6 sore paws. Cheers, Gene Heskett -- "There are four boxes to be used in defense of liberty: soap, ballot, jury, and ammo. Please use in that order." -Ed Howdershelt (Author) Genes Web page <http://geneslinuxbox.net:6309/gene>
[toc] | [prev] | [next] | [standalone]
| From | <tomas@tuxteam.de> |
|---|---|
| Date | 2017-05-03 11:30 +0200 |
| Message-ID | <tCYLE-3gi-27@gated-at.bofh.it> |
| In reply to | #180621 |
-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 On Tue, May 02, 2017 at 05:35:55PM -0400, Gene Heskett wrote: [...] > I've been looking at nginx myself, and wondering if it was any easier to > setup. Apache2 can be a mutant bear with 6 sore paws. This is a nice description ;-) Remember that in its very early infancy, "Apache" was a pun on "a patchy server", because it started its life as a set of patches on top of NCSA httpd. XML was all the rage at that time and supposed to reconciliate executive world (IBM's SGML) with the hippy early Internet (HTML). The result of such marriages tends to be an abominable monster (tell that to me, who at $DAYJOB have to watch "Agile Bureaucracy" unfurling in front of me... I'm too old for that shit). Combine that with the raging early success of Apache (which was, without doubt, very much deserved, for all the outstanding people working there. Remember the competition? Shudder!). That success brings on what I call the "no backtracking" curse: if you have so many users relying on you, you are not supposed to backtrack on any design decision, be it as shitty as it might. And you do take shitty design decisions when you're moving fast. cheers - -- tomás -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.12 (GNU/Linux) iEYEARECAAYFAlkJoPMACgkQBcgs9XrR2kZCfgCfUyP2tDzMCd/KIyS4KRPTMYvN CbMAn1uEP1m4AjNqlFIfRXlg0dRccLv4 =tDH5 -----END PGP SIGNATURE-----
[toc] | [prev] | [next] | [standalone]
| From | Gene Heskett <gheskett@shentel.net> |
|---|---|
| Date | 2017-05-03 14:40 +0200 |
| Message-ID | <tD1Jw-5or-15@gated-at.bofh.it> |
| In reply to | #180630 |
On Wednesday 03 May 2017 05:20:51 tomas@tuxteam.de wrote: > On Tue, May 02, 2017 at 05:35:55PM -0400, Gene Heskett wrote: > > [...] > > > I've been looking at nginx myself, and wondering if it was any > > easier to setup. Apache2 can be a mutant bear with 6 sore paws. > > This is a nice description ;-) > > Remember that in its very early infancy, "Apache" was a pun on "a > patchy server", because it started its life as a set of patches on top > of NCSA httpd. Interesting bit of history, that. > XML was all the rage at that time and supposed to reconciliate > executive world (IBM's SGML) with the hippy early Internet (HTML). The > result of such marriages tends to be an abominable monster (tell that > to me, who at $DAYJOB have to watch "Agile Bureaucracy" unfurling in > front of me... I'm too old for that shit). At 82 & long retired, so am I. But I'm still carving xml right now, prettying up the working face of linuxcnc. > Combine that with the raging early success of Apache (which was, > without doubt, very much deserved, for all the outstanding people > working there. Remember the competition? Shudder!). That success > brings on what I call the "no backtracking" curse: if you have so many > users relying on you, you are not supposed to backtrack on any design > decision, be it as shitty as it might. And you do take shitty design > decisions when you're moving fast. Absolutely. But generally, my audience was one tv station, so I had the agility to fix it once I saw that it wasn't working that well. But it wasn't drudgery to me, I was having immense fun proving it didn't take $20,000 to do THAT job, I was doing it with a far better user interface, and 4x faster than the 20 kilobuck kit from the Grass Valley Group folks. And sold it to the tv station as a trs-80 color computer 2, with 2 disk drives, for $250. Running a program I wrote in basic09. Gotta love it, Tomas. > cheers > -- tomás Cheers, Gene Heskett -- "There are four boxes to be used in defense of liberty: soap, ballot, jury, and ammo. Please use in that order." -Ed Howdershelt (Author) Genes Web page <http://geneslinuxbox.net:6309/gene>
[toc] | [prev] | [next] | [standalone]
| From | <tomas@tuxteam.de> |
|---|---|
| Date | 2017-05-03 15:30 +0200 |
| Message-ID | <tD2vT-5V7-1@gated-at.bofh.it> |
| In reply to | #180639 |
-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 On Wed, May 03, 2017 at 08:31:29AM -0400, Gene Heskett wrote: > On Wednesday 03 May 2017 05:20:51 tomas@tuxteam.de wrote: [...] > > I'm too old for that shit). > > At 82 & long retired, so am I. But I'm still carving xml right now, > prettying up the working face of linuxcnc. Yes. XML will stick for a while, just as COBOL. And due to the fundamental misunderstanding that just because it's a (somewhat usable) document description (meta-)language it makes for a good data description (meta-)language, it already oozed deep into systems (DBus service descriptions anyone? Yuck.) > [...] a trs-80 color computer 2, with > 2 disk drives, for $250. Running a program I wrote in basic09. Gotta > love it, Tomas. Sounds like you had some fun ;-D cheers - -- tomás -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.12 (GNU/Linux) iEYEARECAAYFAlkJ2xcACgkQBcgs9XrR2kbIIwCfeGsQqgSxCaL2tdPv8EhpmI77 JHYAn3fEKUExgyeg42h/m45f4qJdAGAu =v9oB -----END PGP SIGNATURE-----
[toc] | [prev] | [next] | [standalone]
| From | Gene Heskett <gheskett@shentel.net> |
|---|---|
| Date | 2017-05-02 22:50 +0200 |
| Message-ID | <tCMUa-3a8-19@gated-at.bofh.it> |
| In reply to | #180592 |
On Tuesday 02 May 2017 06:35:19 Jonathan Dowland wrote: > On Fri, Apr 28, 2017 at 11:35:06PM -0400, Gene Heskett wrote: > > Greetings all; > > > > My web site (see the sig) is local, on this machine, in a pretty > > tight sandbox, but not running https. > > > > Where can I find a tut that is a complete instruction set to have it > > do an auto-redirect to itself, but using the "s" stuff regardless of > > the accessing client as long as the client can handle the https > > stuff this conversion will return to the client? > > Inferring that you are using apache2, a few notes from my observations > of the thread as it currently stands. > > one of the instruction sets you were following was suggesting to use > mod_rewrite. Personally, I think that's overkill. Achieving what you > want is possible using a simple Redirect, which is provided by > mod_rewrite, which is very likely already enabled (but if not, you can > enable it in the same way, via symlink, which you can create via > a2enmod, or by hand). > > We don't know how you have your site set up already, in particular > whether or not you are using VirtualHosts. My advice would be to do so > if you are not, so a "pre-step" would be migrating to them. > > Once using VirtualHosts, you can configure one to bind to port 80, and > another to 443. From memory, it would look something like this > > <VirtualHost *:80> > RedirectMatch permanent ^(.*)$ https://<YOUR SITE ADDRESS>$1 > </VirtualHost> > <VirtualHost *:443> > # configuration for your website (now) lives here > </VirtualHost> > > Substituting <YOUR SITE ADDRESS> appropriately. > Humm, is this sounding like I should open up a fwd to port 443 on this machine in dd-wrt? As it is, I am only NATing port 6309 to it via the NAT menu. I have dd-wrt locked down pretty tightly. No one has come thru it in at least a decade except a friend, and I had to give him the username & pw, twice, once for the router and once to get on into this machine. Right? Thanks Jonathan. > This is all from memory as I haven't used apache2 myself for many > years (and looking back, having since used things like lighttpd and > more recently nginx, the configuration language is much worse; > stockholm syndrome whilst I was a user perhaps?) Cheers, Gene Heskett -- "There are four boxes to be used in defense of liberty: soap, ballot, jury, and ammo. Please use in that order." -Ed Howdershelt (Author) Genes Web page <http://geneslinuxbox.net:6309/gene>
[toc] | [prev] | [next] | [standalone]
| From | Jonathan Dowland <jmtd@debian.org> |
|---|---|
| Date | 2017-05-02 23:20 +0200 |
| Message-ID | <tCNnb-3yM-5@gated-at.bofh.it> |
| In reply to | #180617 |
On Tue, May 02, 2017 at 04:42:04PM -0400, Gene Heskett wrote: > Humm, is this sounding like I should open up a fwd to port 443 on this > machine in dd-wrt? As it is, I am only NATing port 6309 to it via the > NAT menu. You will need to open another port up for HTTPS, yes, and 443 is the default. If you open up 443, then https://<your URI> will work for browsers, otherwise you'd need an explicit port e.g. https://<your URI>:1234, exactly the same as you have for your current site over HTTP, not using port 80. So long as you intend for attempts to connect to your non-SSL HTTP site to be redirected to the HTTPS one, you will need two ports, as the HTTP site is still listening and serving requests, even if they are all redirects. (It might actually be technically possible to run HTTP and HTTPS on the same port using some kind of clever detection scheme to see which the client was using on connection, in the same way it is possible to multiplex HTTPS and SSH on the same port; but it's a sufficiently niché trick that I don't recommend trying it) -- Jonathan Dowland
[toc] | [prev] | [next] | [standalone]
| From | Gene Heskett <gheskett@shentel.net> |
|---|---|
| Date | 2017-05-02 23:50 +0200 |
| Message-ID | <tCNQd-3I8-7@gated-at.bofh.it> |
| In reply to | #180618 |
On Tuesday 02 May 2017 17:18:13 Jonathan Dowland wrote: > On Tue, May 02, 2017 at 04:42:04PM -0400, Gene Heskett wrote: > > Humm, is this sounding like I should open up a fwd to port 443 on > > this machine in dd-wrt? As it is, I am only NATing port 6309 to it > > via the NAT menu. > > You will need to open another port up for HTTPS, yes, and 443 is the > default. If you open up 443, then https://<your URI> will work for > browsers, otherwise you'd need an explicit port e.g. https://<your > URI>:1234, exactly the same as you have for your current site over > HTTP, not using port 80. > Thanks for that, and I have the ideal number in mind, the 6309 is a clone of the 6809, until you flip a couple bits in an un-acknowledged control register. Then it pipelines the instruction fetch, saveing a cycle, and grows a few more registers and instructions, some of which support 32 bit data. Net result being that the os, rewritten to take advantage, Nitros9, which used to be os9, is nearly 2x faster, at the same old clock speed. > So long as you intend for attempts to connect to your non-SSL HTTP > site to be redirected to the HTTPS one, you will need two ports, as > the HTTP site is still listening and serving requests, even if they > are all redirects. > > (It might actually be technically possible to run HTTP and HTTPS on > the same port using some kind of clever detection scheme to see which > the client was using on connection, in the same way it is possible to > multiplex HTTPS and SSH on the same port; but it's a sufficiently > niché trick that I don't recommend trying it) I've enough examples of Murphy around here already. :( Thanks for clarifying that, Jonathan. Cheers, Gene Heskett -- "There are four boxes to be used in defense of liberty: soap, ballot, jury, and ammo. Please use in that order." -Ed Howdershelt (Author) Genes Web page <http://geneslinuxbox.net:6309/gene>
[toc] | [prev] | [standalone]
Page 2 of 2 — ← Prev page 1 [2]
Back to top | Article view | linux.debian.user
csiph-web