Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]


Groups > linux.debian.user > #180540 > unrolled thread

converting my local site to be https only access

Started byGene Heskett <gheskett@shentel.net>
First post2017-04-29 05:40 +0200
Last post2017-05-02 23:50 +0200
Articles 20 on this page of 31 — 12 participants

Back to article view | Back to linux.debian.user


Contents

  converting my local site to be https only access Gene Heskett <gheskett@shentel.net> - 2017-04-29 05:40 +0200
    Re: converting my local site to be https only access Felix Dietrich <felix.dietrich@sperrhaken.name> - 2017-04-29 10:30 +0200
      Re: converting my local site to be https only access Gene Heskett <gheskett@shentel.net> - 2017-04-29 15:10 +0200
        Re: converting my local site to be https only access Jochen Spieker <ml@well-adjusted.de> - 2017-04-29 20:30 +0200
          Re: converting my local site to be https only access Gene Heskett <gheskett@shentel.net> - 2017-04-29 20:50 +0200
            Re: converting my local site to be https only access Gene Heskett <gheskett@shentel.net> - 2017-04-30 23:10 +0200
              Re: converting my local site to be https only access Dejan Jocic <jodejka@gmail.com> - 2017-04-30 23:50 +0200
              Re: converting my local site to be https only access Eike Lantzsch <zp6cge@gmx.net> - 2017-05-01 00:00 +0200
              Re: converting my local site to be https only access davidson@freevolt.org - 2017-05-01 02:20 +0200
                Re: converting my local site to be https only access Lisi Reisz <lisi.reisz@gmail.com> - 2017-05-01 03:00 +0200
                  Re: converting my local site to be https only access Gene Heskett <gheskett@shentel.net> - 2017-05-01 03:40 +0200
                  Re: converting my local site to be https only access davidson@freevolt.org - 2017-05-01 21:50 +0200
                Re: converting my local site to be https only access Gene Heskett <gheskett@shentel.net> - 2017-05-01 03:40 +0200
                  Re: converting my local site to be https only access Greg Wooledge <wooledg@eeg.ccf.org> - 2017-05-01 15:30 +0200
                    Re: converting my local site to be https only access Gene Heskett <gheskett@shentel.net> - 2017-05-01 16:10 +0200
                  Re: converting my local site to be https only access rhkramer@gmail.com - 2017-05-01 17:20 +0200
                    Re: converting my local site to be https only access Gene Heskett <gheskett@shentel.net> - 2017-05-01 19:00 +0200
                      Re: converting my local site to be https only access rhkramer@gmail.com - 2017-05-01 21:00 +0200
                        Re: converting my local site to be https only access rhkramer@gmail.com - 2017-05-01 21:00 +0200
                  Re: converting my local site to be https only access davidson@freevolt.org - 2017-05-02 01:40 +0200
                  Re: converting my local site to be https only access Ric Moore <wayward4now@gmail.com> - 2017-05-03 18:40 +0200
    Re: converting my local site to be https only access Jonathan Dowland <jmtd@debian.org> - 2017-05-02 12:40 +0200
      Re: converting my local site to be https only access <tomas@tuxteam.de> - 2017-05-02 13:30 +0200
        Re: converting my local site to be https only access Jonathan Dowland <jmtd@debian.org> - 2017-05-02 23:20 +0200
          Re: converting my local site to be https only access Gene Heskett <gheskett@shentel.net> - 2017-05-02 23:40 +0200
            Re: converting my local site to be https only access <tomas@tuxteam.de> - 2017-05-03 11:30 +0200
              Re: converting my local site to be https only access Gene Heskett <gheskett@shentel.net> - 2017-05-03 14:40 +0200
                Re: converting my local site to be https only access <tomas@tuxteam.de> - 2017-05-03 15:30 +0200
      Re: converting my local site to be https only access Gene Heskett <gheskett@shentel.net> - 2017-05-02 22:50 +0200
        Re: converting my local site to be https only access Jonathan Dowland <jmtd@debian.org> - 2017-05-02 23:20 +0200
          Re: converting my local site to be https only access Gene Heskett <gheskett@shentel.net> - 2017-05-02 23:50 +0200

Page 1 of 2  [1] 2  Next page →


#180540 — converting my local site to be https only access

FromGene Heskett <gheskett@shentel.net>
Date2017-04-29 05:40 +0200
Subjectconverting my local site to be https only access
Message-ID<tBroJ-AM-1@gated-at.bofh.it>
Greetings all;

My web site (see the sig) is local, on this machine, in a pretty tight 
sandbox, but not running https.

Where can I find a tut that is a complete instruction set to have it do 
an auto-redirect to itself, but using the "s" stuff regardless of the 
accessing client as long as the client can handle the https stuff this 
conversion will return to the client?

I tried putting those 3 lines quoted numerous times at the bottom of the 
httpd/conf/httpd.conf, but that killed local access so I assume it also 
killed external access too.  And its failure did not generate an 
error.log entry.

Something was said about the AllowRedirect settings in httpd.conf, but it 
did not specify what to change it to. Currently several such entries 
are "none"

I want to have it applied to the whole site. URL to the best tut please.

Thank you. 

Cheers, Gene Heskett
-- 
"There are four boxes to be used in defense of liberty:
 soap, ballot, jury, and ammo. Please use in that order."
-Ed Howdershelt (Author)
Genes Web page <http://geneslinuxbox.net:6309/gene>

[toc] | [next] | [standalone]


#180541

FromFelix Dietrich <felix.dietrich@sperrhaken.name>
Date2017-04-29 10:30 +0200
Message-ID<tBvVo-3Tv-9@gated-at.bofh.it>
In reply to#180540
Gene Heskett <gheskett@shentel.net> writes:

> Where can I find a tut that is a complete instruction set to have it do 
> an auto-redirect to itself, but using the "s" stuff regardless of the 
> accessing client as long as the client can handle the https stuff this 
> conversion will return to the client?

For the apache webserver, which I am assuming you are using, I found

    https://wiki.apache.org/httpd/RedirectSSL

which describes how to permanently redirect clients to an encrypted
connection.  Clients without the capability to use SSL encryption will
not be able to see the contents of your site.

> I tried putting those 3 lines quoted numerous times at the bottom of the 
> httpd/conf/httpd.conf, but that killed local access so I assume it also 
> killed external access too.  And its failure did not generate an 
> error.log entry.

Which 3 lines are you referring to?  I cannot see any lines that look
like they represent configuration file syntax in your message.

> Something was said about the AllowRedirect settings in httpd.conf, but it 
> did not specify what to change it to.

Where was something said about AllowRedirect?  What was stated exactly?

> URL to the best tut please.

As much as I enjoy a bit of social interaction: are you abusing us to do
your internet searches for you?  Searching for "SSL redirect apache"
yields plenty of results.  Part of the "joy" of the computer hobby is to
wheat out obsolete information, identify the wrong, and copy and paste
the slightly less wrong.  I also won't judge anything to be "the best" –
unless it is my own of course. :-p

--
Felix Dietrich

[toc] | [prev] | [next] | [standalone]


#180546

FromGene Heskett <gheskett@shentel.net>
Date2017-04-29 15:10 +0200
Message-ID<tBAil-6Em-3@gated-at.bofh.it>
In reply to#180541
On Saturday 29 April 2017 04:05:01 Felix Dietrich wrote:

> Gene Heskett <gheskett@shentel.net> writes:
> > Where can I find a tut that is a complete instruction set to have it
> > do an auto-redirect to itself, but using the "s" stuff regardless of
> > the accessing client as long as the client can handle the https
> > stuff this conversion will return to the client?
>
> For the apache webserver, which I am assuming you are using, I found
>
>     https://wiki.apache.org/httpd/RedirectSSL
>
> which describes how to permanently redirect clients to an encrypted
> connection.  Clients without the capability to use SSL encryption will
> not be able to see the contents of your site.
>
> > I tried putting those 3 lines quoted numerous times at the bottom of
> > the httpd/conf/httpd.conf, but that killed local access so I assume
> > it also killed external access too.  And its failure did not
> > generate an error.log entry.
>
> Which 3 lines are you referring to?  I cannot see any lines that look
> like they represent configuration file syntax in your message.
>
> > Something was said about the AllowRedirect settings in httpd.conf,
> > but it did not specify what to change it to.
>
> Where was something said about AllowRedirect?  What was stated
> exactly?
>
> > URL to the best tut please.
>
> As much as I enjoy a bit of social interaction: are you abusing us to
> do your internet searches for you?  Searching for "SSL redirect
> apache" yields plenty of results.  Part of the "joy" of the computer
> hobby is to wheat out obsolete information, identify the wrong, and
> copy and paste the slightly less wrong.  I also won't judge anything
> to be "the best" – unless it is my own of course. :-p
>
Chuckle, point taken, used your search string and got smarter hits for 
apache2.  Since my domain registrar is namecheap, I'm reading this link:
<https://www.namecheap.com/support/knowledgebase/article.aspx/9821/38/redirect-to-https-on-apache>

The recommended commands, and responses:

sudo a2enmod rewrite
[sudo] password for gene: 
Enabling module rewrite.
To activate the new configuration, you need to run:
  service apache2 restart

gene@coyote:/etc/httpd/conf$ sudo a2enmod ssl
Enabling module ssl.
See /usr/share/doc/apache2.2-common/README.Debian.gz on how to configure 
SSL and create self-signed certificates.
To activate the new configuration, you need to run:
  service apache2 restart


On restarting apache2, I get this error report on screen but the 
error.log is not showing the attempted restart.
Error shown:

Syntax error on line 71 of /etc/apache2/mods-enabled/ssl.conf:
Invalid command 'Header', perhaps misspelled or defined by a module not 
included in the server configuration
Action 'start' failed.

That files line 71: region
68:SSLCipherSuite AES128+EECDH:AES128+EDH
69:SSLHonorCipherOrder on # enable only secure protocols: SSLv3 and 
TLSv1, but not SSLv2
70:SSLProtocol -all +TLSv1
71:Header always set Strict-Transport-Security "max-age=63072000; include 
SubDomains"
72:Header alway set X-Frame-Options DENY

Being big dummy, whats this tell me?  So I read the file it recommends, 
which contains 2 more commands:
	a2ensite default-ssl
	a2enmod ssl
which appear to have worked, but it still will not restart.

The next recommended command is:

If you install the ssl-cert package, a self-signed certificate will be
automatically created using the hostname currently configured on your 
computer.
You can recreate that certificate (e.g. after you have changed /etc/hosts 
or
DNS to give the correct hostname) as user root with:

make-ssl-cert generate-default-snakeoil --force-overwrite

But this brings up a question:
The hostname of this computer doesn't match the name in the sig, my whole 
home networks domain name is coyote.den, and this machine is 
coyote.coyote.den.  Since its all behind a dd-wrt install, and its not 
even running on a normal port number, this to bypass the ususal port 80 
blocking the ISP's do in order to force you to use their servers at X$ a 
month, and to honor one of the cpu industries most enforced secrets 
ever, which is the Hitachi HD63C09, a clone of the Moto 6809, but which 
we have discovered is many times smarter. Hence the port:6309 in the 
sig, and the only port forwarded to this machine.

So in internal name and the one in the sig don't match?
So which name will it use if I run the above cert generator command?

 Ah, reading further, thats addressed by:

To create more certificates with different host names, you can use

	make-ssl-cert /usr/share/ssl-cert/ssleay.cnf /path/to/cert-file.crt

This will ask you for the hostname and place both SSL key and certificate 
in
the file /path/to/cert-file.crt . Use this file with the 
SSLCertificateFile
directive in the Apache config (you don't need the SSLCertificateKeyFile 
in
this case as it also contains the key). The file /path/to/cert-file.crt 
should
only be readable by root. A good directory to use for the additional
certificates/keys is /etc/ssl/private.

So I run it this way:
root@coyote:~# 
make-ssl-cert /usr/share/ssl-cert/ssleay.cnf /etc/ssl/private/
debconf: DbDriver "config": /var/cache/debconf/config.dat is locked by 
another process: Resource temporarily unavailable.

synaptic was running in another workspace, waiting on input, and it wants 
to restart the gui among other things, canceled it.

Now a 2nd attempt:
Could not create certificate. Openssl output was:
Error Loading extension section v3_req
4147165448:error:2207507C:X509 V3 routines:v2i_GENERAL_NAME_ex:missing 
value:v3_alt.c:531:
4147165448:error:22098080:X509 V3 routines:X509V3_EXT_nconf:error in 
extension:v3_conf.c:95:name=subjectAltName, 
value=coyote.coyote.den,IP:192,168.71.3

Aha! a comma in the wrong place.

3rd pass:
root@coyote:~# 
make-ssl-cert /usr/share/ssl-cert/ssleay.cnf /etc/ssl/private
Could not create certificate. Openssl output was:
Error Loading extension section v3_req
4147910920:error:2207507C:X509 V3 routines:v2i_GENERAL_NAME_ex:missing 
value:v3_alt.c:531:
4147910920:error:22098080:X509 V3 routines:X509V3_EXT_nconf:error in 
extension:v3_conf.c:95:name=subjectAltName, 
value=coyote.coyote.den,IP:192.168.71.3

WTH is v3_req?  Apparently refers to man 5 x509_config,
and that is way above my pay grade.

4th pass, different arguments for the extras.Failed, same report.

Looks like it did work when I used the snake-oil version:
root@coyote:~# ls -l /etc/ssl/private/
total 4
-rw-r----- 1 root ssl-cert 1704 Apr 29 08:46 ssl-cert-snakeoil.key

And the 2nd version about 6" up then appeared to fail as before.

however, no httpd start
And still no entry's from the restarts in /var/log/apache2/error.log.

My site is offline.  And I need to reboot after the last update.

Thanks Felix.
> --
> Felix Dietrich


Cheers, Gene Heskett
-- 
"There are four boxes to be used in defense of liberty:
 soap, ballot, jury, and ammo. Please use in that order."
-Ed Howdershelt (Author)
Genes Web page <http://geneslinuxbox.net:6309/gene>

[toc] | [prev] | [next] | [standalone]


#180550

FromJochen Spieker <ml@well-adjusted.de>
Date2017-04-29 20:30 +0200
Message-ID<tBFi2-1bq-5@gated-at.bofh.it>
In reply to#180546

[Multipart message — attachments visible in raw view] — view raw

Gene Heskett:
> On Saturday 29 April 2017 04:05:01 Felix Dietrich wrote:
>> Gene Heskett <gheskett@shentel.net> writes:
>> 
>>> Where can I find a tut that is a complete instruction set to have it
>>> do an auto-redirect to itself, but using the "s" stuff regardless of
>>> the accessing client as long as the client can handle the https
>>> stuff this conversion will return to the client?

What you want to do requires that you understand the basics of Apache's
configuration mechanism. You should really start with that.

http://httpd.apache.org/docs/2.4/en/getting-started.html
http://httpd.apache.org/docs/2.4/en/bind.html
http://httpd.apache.org/docs/2.4/en/configuring.html 
http://httpd.apache.org/docs/2.4/en/urlmapping.html
http://httpd.apache.org/docs/2.4/en/vhosts/

That's really just the basics so you know where to put random things you
find on the internet. For your use case, these should also be helpful:

http://httpd.apache.org/docs/2.4/en/ssl/
http://httpd.apache.org/docs/2.4/en/rewrite/

What the upstream Apache documentation does not mention (or care about)
is that Debian has its own way of splitting up Apache configuration
files. If a random (not Debian- or Ubuntu-specific) tutorial tells you
to change your httpd.conf then this is most certainly not the way to do
it in Debian.

>>> I tried putting those 3 lines quoted numerous times at the bottom of
>>> the httpd/conf/httpd.conf, but that killed local access so I assume
>>> it also killed external access too.  And its failure did not
>>> generate an error.log entry.

The bottom of your httpd.conf might be the wrong place to put it. It
really depends on your local configuration which we do not know. Do you
have a plain Debian installation that you did yourself or do you use an
image from a hoster or any other company? What changes have you done to
your configuration?

What Debian expects most admins to do is drop their own virtual host
definitions into /etc/apache2/sites-available/ and use a2ensite to
enable them. Global configuration directives can be placed in
conf-available/ (use a2enconf).

>>> Something was said about the AllowRedirect settings in httpd.conf,
>>> but it did not specify what to change it to.

Don't touch httpd.conf, it will probably not do what you want to
achieve. Instead, edit the virtual host you are using.

> Chuckle, point taken, used your search string and got smarter hits for 
> apache2.  Since my domain registrar is namecheap, I'm reading this link:
> <https://www.namecheap.com/support/knowledgebase/article.aspx/9821/38/redirect-to-https-on-apache>

Your domain registrar is irrelevant here. Look for
Debian/Ubuntu-specific tutorials after reading up on the basics.

> Syntax error on line 71 of /etc/apache2/mods-enabled/ssl.conf:
> Invalid command 'Header', perhaps misspelled or defined by a module not 
> included in the server configuration
> Action 'start' failed.

Apparently the header module is not enabled in your configuration. You
can do so by running "a2enmod headers".

> If you install the ssl-cert package, a self-signed certificate will be
> automatically created using the hostname currently configured on your 
> computer.

If your machine is publicly available, there is really no reason anymore
to use self-signed certificates -- except for testing, probably. If your
configuration works with your self-signed certificate, you should
consider using Let's Encrypt.

> So in internal name and the one in the sig don't match?
> So which name will it use if I run the above cert generator command?

Nowadays you can run more than one VirtualHosts even with only one IP
address. You just set up regular virtual hosts which use their own
certificates.

I cannot comment on the other errors you are getting, but (just in case
I didn't stress it enough :)) I think your life will become a lot easier
once you master the basics of Apache. The creation of SSL certificates
actually becomes a lot easier with Let's Encrypt.

J.
-- 
In this bunker there are women and children. There are no weapons.
[Agree]   [Disagree]
                 <http://archive.slowlydownward.com/NODATA/data_enter2.html>

[toc] | [prev] | [next] | [standalone]


#180551

FromGene Heskett <gheskett@shentel.net>
Date2017-04-29 20:50 +0200
Message-ID<tBFBo-1jR-5@gated-at.bofh.it>
In reply to#180550
On Saturday 29 April 2017 14:21:27 Jochen Spieker wrote:

> Gene Heskett:
> > On Saturday 29 April 2017 04:05:01 Felix Dietrich wrote:
> >> Gene Heskett <gheskett@shentel.net> writes:
> >>> Where can I find a tut that is a complete instruction set to have
> >>> it do an auto-redirect to itself, but using the "s" stuff
> >>> regardless of the accessing client as long as the client can
> >>> handle the https stuff this conversion will return to the client?
>
> What you want to do requires that you understand the basics of
> Apache's configuration mechanism. You should really start with that.
>
> http://httpd.apache.org/docs/2.4/en/getting-started.html
> http://httpd.apache.org/docs/2.4/en/bind.html
> http://httpd.apache.org/docs/2.4/en/configuring.html
> http://httpd.apache.org/docs/2.4/en/urlmapping.html
> http://httpd.apache.org/docs/2.4/en/vhosts/
>
> That's really just the basics so you know where to put random things
> you find on the internet. For your use case, these should also be
> helpful:
>
> http://httpd.apache.org/docs/2.4/en/ssl/
> http://httpd.apache.org/docs/2.4/en/rewrite/
>
> What the upstream Apache documentation does not mention (or care
> about) is that Debian has its own way of splitting up Apache
> configuration files. If a random (not Debian- or Ubuntu-specific)
> tutorial tells you to change your httpd.conf then this is most
> certainly not the way to do it in Debian.
>
> >>> I tried putting those 3 lines quoted numerous times at the bottom
> >>> of the httpd/conf/httpd.conf, but that killed local access so I
> >>> assume it also killed external access too.  And its failure did
> >>> not generate an error.log entry.
>
> The bottom of your httpd.conf might be the wrong place to put it. It
> really depends on your local configuration which we do not know. Do
> you have a plain Debian installation that you did yourself or do you
> use an image from a hoster or any other company? What changes have you
> done to your configuration?
>
> What Debian expects most admins to do is drop their own virtual host
> definitions into /etc/apache2/sites-available/ and use a2ensite to
> enable them. Global configuration directives can be placed in
> conf-available/ (use a2enconf).
>
> >>> Something was said about the AllowRedirect settings in httpd.conf,
> >>> but it did not specify what to change it to.
>
> Don't touch httpd.conf, it will probably not do what you want to
> achieve. Instead, edit the virtual host you are using.
>
> > Chuckle, point taken, used your search string and got smarter hits
> > for apache2.  Since my domain registrar is namecheap, I'm reading
> > this link:
> > <https://www.namecheap.com/support/knowledgebase/article.aspx/9821/3
> >8/redirect-to-https-on-apache>
>
> Your domain registrar is irrelevant here. Look for
> Debian/Ubuntu-specific tutorials after reading up on the basics.
>
> > Syntax error on line 71 of /etc/apache2/mods-enabled/ssl.conf:
> > Invalid command 'Header', perhaps misspelled or defined by a module
> > not included in the server configuration
> > Action 'start' failed.
>
> Apparently the header module is not enabled in your configuration. You
> can do so by running "a2enmod headers".
>
Not being fam with this a2enmod thing, I just used mc to make a softlink.  
That moved the error and changed it a wee bit, to line 72, which had the 
keyword always spelled alway. Fixed, start right up. I can only see it 
at localhost, so I've no clue if the link in my sig works or not.

If it redirects to https and the front page pix loads, I'm good to go I 
think.

> > If you install the ssl-cert package, a self-signed certificate will
> > be automatically created using the hostname currently configured on
> > your computer.

Which is not the same as the dns servers returns.
>
> If your machine is publicly available, there is really no reason
> anymore to use self-signed certificates -- except for testing,
> probably. If your configuration works with your self-signed
> certificate, you should consider using Let's Encrypt.
>
> > So in internal name and the one in the sig don't match?
> > So which name will it use if I run the above cert generator command?
>
> Nowadays you can run more than one VirtualHosts even with only one IP
> address. You just set up regular virtual hosts which use their own
> certificates.
>
> I cannot comment on the other errors you are getting, but (just in
> case I didn't stress it enough :)) I think your life will become a lot
> easier once you master the basics of Apache. The creation of SSL
> certificates actually becomes a lot easier with Let's Encrypt.

Those are done I believe:
root@coyote:/etc/httpd/conf# ls -l /etc/ssl/private/
total 8
lrwxrwxrwx 1 root root       18 Apr 29 10:27 fba0a812 -> 
ssl-cert-genes.key
-rw------- 1 root root     2798 Apr 29 10:27 ssl-cert-genes.key
-rw-r----- 1 root ssl-cert 1704 Apr 29 08:46 ssl-cert-snakeoil.key

Unless thats not enough.
>
> J.

Thanks, Jochen Spieker.

Cheers, Gene Heskett
-- 
"There are four boxes to be used in defense of liberty:
 soap, ballot, jury, and ammo. Please use in that order."
-Ed Howdershelt (Author)
Genes Web page <http://geneslinuxbox.net:6309/gene>

[toc] | [prev] | [next] | [standalone]


#180557

FromGene Heskett <gheskett@shentel.net>
Date2017-04-30 23:10 +0200
Message-ID<tC4gq-8jL-11@gated-at.bofh.it>
In reply to#180551
On Saturday 29 April 2017 14:49:04 Gene Heskett wrote:

> On Saturday 29 April 2017 14:21:27 Jochen Spieker wrote:
> > Gene Heskett:
> > > On Saturday 29 April 2017 04:05:01 Felix Dietrich wrote:
> > >> Gene Heskett <gheskett@shentel.net> writes:
> > >>> Where can I find a tut that is a complete instruction set to
> > >>> have it do an auto-redirect to itself, but using the "s" stuff
> > >>> regardless of the accessing client as long as the client can
> > >>> handle the https stuff this conversion will return to the
> > >>> client?
> >
> > What you want to do requires that you understand the basics of
> > Apache's configuration mechanism. You should really start with that.
> >
> > http://httpd.apache.org/docs/2.4/en/getting-started.html
> > http://httpd.apache.org/docs/2.4/en/bind.html
> > http://httpd.apache.org/docs/2.4/en/configuring.html
> > http://httpd.apache.org/docs/2.4/en/urlmapping.html
> > http://httpd.apache.org/docs/2.4/en/vhosts/
> >
I don't have 2.4, 2.2 here on wheezy.

Looking in the docs/2.2/envvars reference and trying some of the commands 
I find I apparently must specify the port # somehow. apache2ctl cannot 
connect on port 80.  It apparently uses /etc/alternatives/www-browser, 
which is a softlink to /usrt/bin/lynx, and guess what?

lynx support at lynx.isc.org has been deleted. And it won't work without 
talking to isc.org first.  Even after being re-installed.

So A: file a bug against lynx, best to remove it as its apparently been 
EOL'd by isc.org

And B: what can I change that softlink in /etc/alternatives to so 
apache2ctl will work against localhost:6309 ?

And C: If I have to learn a new httpd server, is nginx any better than 
apache2?
> > That's really just the basics so you know where to put random things
> > you find on the internet. For your use case, these should also be
> > helpful:
> >
> > http://httpd.apache.org/docs/2.4/en/ssl/
> > http://httpd.apache.org/docs/2.4/en/rewrite/
> >
> > What the upstream Apache documentation does not mention (or care
> > about) is that Debian has its own way of splitting up Apache
> > configuration files. If a random (not Debian- or Ubuntu-specific)
> > tutorial tells you to change your httpd.conf then this is most
> > certainly not the way to do it in Debian.
> >
> > >>> I tried putting those 3 lines quoted numerous times at the
> > >>> bottom of the httpd/conf/httpd.conf, but that killed local
> > >>> access so I assume it also killed external access too.  And its
> > >>> failure did not generate an error.log entry.
> >
> > The bottom of your httpd.conf might be the wrong place to put it. It
> > really depends on your local configuration which we do not know. Do
> > you have a plain Debian installation that you did yourself or do you
> > use an image from a hoster or any other company? What changes have
> > you done to your configuration?
> >
> > What Debian expects most admins to do is drop their own virtual host
> > definitions into /etc/apache2/sites-available/ and use a2ensite to
> > enable them. Global configuration directives can be placed in
> > conf-available/ (use a2enconf).
> >
> > >>> Something was said about the AllowRedirect settings in
> > >>> httpd.conf, but it did not specify what to change it to.
> >
> > Don't touch httpd.conf, it will probably not do what you want to
> > achieve. Instead, edit the virtual host you are using.
> >
> > > Chuckle, point taken, used your search string and got smarter hits
> > > for apache2.  Since my domain registrar is namecheap, I'm reading
> > > this link:
> > > <https://www.namecheap.com/support/knowledgebase/article.aspx/9821
> > >/3 8/redirect-to-https-on-apache>
> >
> > Your domain registrar is irrelevant here. Look for
> > Debian/Ubuntu-specific tutorials after reading up on the basics.
> >
> > > Syntax error on line 71 of /etc/apache2/mods-enabled/ssl.conf:
> > > Invalid command 'Header', perhaps misspelled or defined by a
> > > module not included in the server configuration
> > > Action 'start' failed.
> >
> > Apparently the header module is not enabled in your configuration.
> > You can do so by running "a2enmod headers".
>
> Not being fam with this a2enmod thing, I just used mc to make a
> softlink. That moved the error and changed it a wee bit, to line 72,
> which had the keyword always spelled alway. Fixed, start right up. I
> can only see it at localhost, so I've no clue if the link in my sig
> works or not.
>
> If it redirects to https and the front page pix loads, I'm good to go
> I think.
>
> > > If you install the ssl-cert package, a self-signed certificate
> > > will be automatically created using the hostname currently
> > > configured on your computer.
>
> Which is not the same as the dns servers returns.
>
> > If your machine is publicly available, there is really no reason
> > anymore to use self-signed certificates -- except for testing,
> > probably. If your configuration works with your self-signed
> > certificate, you should consider using Let's Encrypt.
> >
> > > So in internal name and the one in the sig don't match?
> > > So which name will it use if I run the above cert generator
> > > command?
> >
> > Nowadays you can run more than one VirtualHosts even with only one
> > IP address. You just set up regular virtual hosts which use their
> > own certificates.
> >
> > I cannot comment on the other errors you are getting, but (just in
> > case I didn't stress it enough :)) I think your life will become a
> > lot easier once you master the basics of Apache. The creation of SSL
> > certificates actually becomes a lot easier with Let's Encrypt.
>
> Those are done I believe:
> root@coyote:/etc/httpd/conf# ls -l /etc/ssl/private/
> total 8
> lrwxrwxrwx 1 root root       18 Apr 29 10:27 fba0a812 ->
> ssl-cert-genes.key
> -rw------- 1 root root     2798 Apr 29 10:27 ssl-cert-genes.key
> -rw-r----- 1 root ssl-cert 1704 Apr 29 08:46 ssl-cert-snakeoil.key
>
> Unless thats not enough.
>
> > J.
>
> Thanks, Jochen Spieker.
>
> Cheers, Gene Heskett


Cheers, Gene Heskett
-- 
"There are four boxes to be used in defense of liberty:
 soap, ballot, jury, and ammo. Please use in that order."
-Ed Howdershelt (Author)
Genes Web page <http://geneslinuxbox.net:6309/gene>

[toc] | [prev] | [next] | [standalone]


#180558

FromDejan Jocic <jodejka@gmail.com>
Date2017-04-30 23:50 +0200
Message-ID<tC4T7-5F-1@gated-at.bofh.it>
In reply to#180557
On 30-04-17, Gene Heskett wrote:
> On Saturday 29 April 2017 14:49:04 Gene Heskett wrote:
> 
> > On Saturday 29 April 2017 14:21:27 Jochen Spieker wrote:
> > > Gene Heskett:
> > > > On Saturday 29 April 2017 04:05:01 Felix Dietrich wrote:
> > > >> Gene Heskett <gheskett@shentel.net> writes:
> > > >>> Where can I find a tut that is a complete instruction set to
> > > >>> have it do an auto-redirect to itself, but using the "s" stuff
> > > >>> regardless of the accessing client as long as the client can
> > > >>> handle the https stuff this conversion will return to the
> > > >>> client?
> > >
> > > What you want to do requires that you understand the basics of
> > > Apache's configuration mechanism. You should really start with that.
> > >
> > > http://httpd.apache.org/docs/2.4/en/getting-started.html
> > > http://httpd.apache.org/docs/2.4/en/bind.html
> > > http://httpd.apache.org/docs/2.4/en/configuring.html
> > > http://httpd.apache.org/docs/2.4/en/urlmapping.html
> > > http://httpd.apache.org/docs/2.4/en/vhosts/
> > >
> I don't have 2.4, 2.2 here on wheezy.
> 
> Looking in the docs/2.2/envvars reference and trying some of the commands 
> I find I apparently must specify the port # somehow. apache2ctl cannot 
> connect on port 80.  It apparently uses /etc/alternatives/www-browser, 
> which is a softlink to /usrt/bin/lynx, and guess what?
> 
> lynx support at lynx.isc.org has been deleted. And it won't work without 
> talking to isc.org first.  Even after being re-installed.
> 
> So A: file a bug against lynx, best to remove it as its apparently been 
> EOL'd by isc.org
> 
> And B: what can I change that softlink in /etc/alternatives to so 
> apache2ctl will work against localhost:6309 ?

For changing those softlinks in /etc/alternatives best would be to use
update-alternatives. As root, or with sudo, whatever you prefer. As to
what would be best in your case, I do not know. Other terminal browsers
you could use are Links and w3m.

[toc] | [prev] | [next] | [standalone]


#180559

FromEike Lantzsch <zp6cge@gmx.net>
Date2017-05-01 00:00 +0200
Message-ID<tC52N-9c-1@gated-at.bofh.it>
In reply to#180557
On Sunday, 30 April 2017 17:07:47 -04 Gene Heskett wrote:
[snip]
> 
> I don't have 2.4, 2.2 here on wheezy.
> 
> Looking in the docs/2.2/envvars reference and trying some of the commands
> I find I apparently must specify the port # somehow. apache2ctl cannot
> connect on port 80.  It apparently uses /etc/alternatives/www-browser,
> which is a softlink to /usrt/bin/lynx, and guess what?
> 
> lynx support at lynx.isc.org has been deleted. And it won't work without
> talking to isc.org first.  Even after being re-installed.
> 
> So A: file a bug against lynx, best to remove it as its apparently been
> EOL'd by isc.org

[snip]

Gene,
You might like to replace lynx with links.
There is also links2 and elinks, but according to openbsd.org elinks is full 
of security holes and those guys I do believe.

Sorry, can't comment on your main problem.

Cheers
Eike

[toc] | [prev] | [next] | [standalone]


#180561

Fromdavidson@freevolt.org
Date2017-05-01 02:20 +0200
Message-ID<tC7eh-1FK-3@gated-at.bofh.it>
In reply to#180557
On Sun, 30 Apr 2017, Gene Heskett wrote:

> On Saturday 29 April 2017 14:49:04 Gene Heskett wrote:
>
>> On Saturday 29 April 2017 14:21:27 Jochen Spieker wrote:
>>> Gene Heskett:
>>>> On Saturday 29 April 2017 04:05:01 Felix Dietrich wrote:
>>>>> Gene Heskett <gheskett@shentel.net> writes:
>>>>>> Where can I find a tut that is a complete instruction set to
>>>>>> have it do an auto-redirect to itself, but using the "s" stuff
>>>>>> regardless of the accessing client as long as the client can
>>>>>> handle the https stuff this conversion will return to the
>>>>>> client?
>>>
>>> What you want to do requires that you understand the basics of
>>> Apache's configuration mechanism. You should really start with that.
>>>
>>> http://httpd.apache.org/docs/2.4/en/getting-started.html
>>> http://httpd.apache.org/docs/2.4/en/bind.html
>>> http://httpd.apache.org/docs/2.4/en/configuring.html
>>> http://httpd.apache.org/docs/2.4/en/urlmapping.html
>>> http://httpd.apache.org/docs/2.4/en/vhosts/
>>>
> I don't have 2.4, 2.2 here on wheezy.
>
> Looking in the docs/2.2/envvars reference and trying some of the commands
> I find I apparently must specify the port # somehow. apache2ctl cannot
> connect on port 80.  It apparently uses /etc/alternatives/www-browser,
> which is a softlink to /usrt/bin/lynx, and guess what?
>
> lynx support at lynx.isc.org has been deleted. And it won't work without
> talking to isc.org first.  Even after being re-installed.

Lynx works just fine. I expect your configuration file simply has some
references to obsolete remote locations.

Does this work?

  $ WWW_HOME="https://en.wikipedia.org/wiki/PEBKAC" lynx

or this?

  $ WWW_HOME="file://localhost/REPLACE-ME-WITH-A-PATH-TO-SOME-LOCAL-HTML-DOC.html" lynx

And does this...

  $ grep '^STARTFILE:' /etc/lynx-cur/lynx.cfg

...confirm that you have something obsolete like

  STARTFILE:http://lynx.isc.org/

in your lynx.cfg ?

Then fix that broken reference. Edit /etc/lynx-cur/lynx.cfg, replacing
that STARTFILE url with whatever you like.

FWIW, I think

  STARTFILE:file://localhost/~/

makes a sensible default.

Or, if for some incomprehensible reason you think a remote website is
an appropriate default startfile, you could use

   STARTFILE:http://lynx.invisible-island.net/

instead.

While you're at it, you might want to cast your eye over any other
lines returned by this...

  $ grep '^[A-Z_]*:[[:blank:]]*https\?://' /etc/lynx-cur/lynx.cfg

...and see if you wouldn't rather change them to something more
up-to-date, more reliable, or more appropriate for your installation.

> So A: file a bug against lynx, best to remove it as its apparently been
> EOL'd by isc.org

Huh? You would remove a program simply because isc.org removes a
couple web pages?

Development of lynx continues unabated:

  http://invisible-island.net/lynx/lynx-develop.html

Good luck with your project.

[toc] | [prev] | [next] | [standalone]


#180564

FromLisi Reisz <lisi.reisz@gmail.com>
Date2017-05-01 03:00 +0200
Message-ID<tC7R0-1Tz-5@gated-at.bofh.it>
In reply to#180561
On Monday 01 May 2017 01:19:21 davidson@freevolt.org wrote:
> Development of lynx continues unabated:
>
>   http://invisible-island.net/lynx/lynx-develop.html

The most recent reference seems to be to 2015:
"Finally (as of 2015)....  "

Lisi

[toc] | [prev] | [next] | [standalone]


#180565

FromGene Heskett <gheskett@shentel.net>
Date2017-05-01 03:40 +0200
Message-ID<tC8tH-2oO-1@gated-at.bofh.it>
In reply to#180564
On Sunday 30 April 2017 20:51:54 Lisi Reisz wrote:

> On Monday 01 May 2017 01:19:21 davidson@freevolt.org wrote:
> > Development of lynx continues unabated:
> >
> >   http://invisible-island.net/lynx/lynx-develop.html
>
> The most recent reference seems to be to 2015:
> "Finally (as of 2015)....  "
>
> Lisi

Thanks Lisi, I hadn't had time to look yet.

Cheers, Gene Heskett
-- 
"There are four boxes to be used in defense of liberty:
 soap, ballot, jury, and ammo. Please use in that order."
-Ed Howdershelt (Author)
Genes Web page <http://geneslinuxbox.net:6309/gene>

[toc] | [prev] | [next] | [standalone]


#180590

Fromdavidson@freevolt.org
Date2017-05-01 21:50 +0200
Message-ID<tCpux-4NU-13@gated-at.bofh.it>
In reply to#180564
On Mon, 1 May 2017, Lisi Reisz wrote:

> On Monday 01 May 2017 01:19:21 davidson@freevolt.org wrote:
>> Development of lynx continues unabated:
>>
>>   http://invisible-island.net/lynx/lynx-develop.html
>
> The most recent reference seems to be to 2015:
> "Finally (as of 2015)....  "

I linked to that page because it contained discussion of the website's
move away from isc.org to invisible-island.net .

Lynx current development:

  http://lynx.invisible-island.net/current/index.html

More generally:

  http://lynx.invisible-island.net/

[toc] | [prev] | [next] | [standalone]


#180567

FromGene Heskett <gheskett@shentel.net>
Date2017-05-01 03:40 +0200
Message-ID<tC8tH-2oO-5@gated-at.bofh.it>
In reply to#180561
On Sunday 30 April 2017 20:19:21 davidson@freevolt.org wrote:

> On Sun, 30 Apr 2017, Gene Heskett wrote:
> > On Saturday 29 April 2017 14:49:04 Gene Heskett wrote:
> >> On Saturday 29 April 2017 14:21:27 Jochen Spieker wrote:
> >>> Gene Heskett:
> >>>> On Saturday 29 April 2017 04:05:01 Felix Dietrich wrote:
> >>>>> Gene Heskett <gheskett@shentel.net> writes:
> >>>>>> Where can I find a tut that is a complete instruction set to
> >>>>>> have it do an auto-redirect to itself, but using the "s" stuff
> >>>>>> regardless of the accessing client as long as the client can
> >>>>>> handle the https stuff this conversion will return to the
> >>>>>> client?
> >>>
> >>> What you want to do requires that you understand the basics of
> >>> Apache's configuration mechanism. You should really start with
> >>> that.
> >>>
> >>> http://httpd.apache.org/docs/2.4/en/getting-started.html
> >>> http://httpd.apache.org/docs/2.4/en/bind.html
> >>> http://httpd.apache.org/docs/2.4/en/configuring.html
> >>> http://httpd.apache.org/docs/2.4/en/urlmapping.html
> >>> http://httpd.apache.org/docs/2.4/en/vhosts/
> >
> > I don't have 2.4, 2.2 here on wheezy.
> >
> > Looking in the docs/2.2/envvars reference and trying some of the
> > commands I find I apparently must specify the port # somehow.
> > apache2ctl cannot connect on port 80.  It apparently uses
> > /etc/alternatives/www-browser, which is a softlink to
> > /usrt/bin/lynx, and guess what?
> >
> > lynx support at lynx.isc.org has been deleted. And it won't work
> > without talking to isc.org first.  Even after being re-installed.
>
> Lynx works just fine. I expect your configuration file simply has some
> references to obsolete remote locations.
>
> Does this work?
>
>   $ WWW_HOME="https://en.wikipedia.org/wiki/PEBKAC" lynx
>
> or this?
>
>   $
> WWW_HOME="file://localhost/REPLACE-ME-WITH-A-PATH-TO-SOME-LOCAL-HTML-D
>OC.html" lynx
>
> And does this...
>
>   $ grep '^STARTFILE:' /etc/lynx-cur/lynx.cfg
>
> ...confirm that you have something obsolete like
>
>   STARTFILE:http://lynx.isc.org/
>
> in your lynx.cfg ?
>
it was.

> Then fix that broken reference. Edit /etc/lynx-cur/lynx.cfg, replacing
> that STARTFILE url with whatever you like.
>
> FWIW, I think
>
>   STARTFILE:file://localhost/~/
>
> makes a sensible default.

except I am then trapped in my home dir.
>
> Or, if for some incomprehensible reason you think a remote website is
> an appropriate default startfile, you could use
>
>    STARTFILE:http://lynx.invisible-island.net/
>
> instead.
>
> While you're at it, you might want to cast your eye over any other
> lines returned by this...
>
>   $ grep '^[A-Z_]*:[[:blank:]]*https\?://' /etc/lynx-cur/lynx.cfg

Which was a wisc.edu url.
>
> ...and see if you wouldn't rather change them to something more
> up-to-date, more reliable, or more appropriate for your installation.
>
> > So A: file a bug against lynx, best to remove it as its apparently
> > been EOL'd by isc.org
>
> Huh? You would remove a program simply because isc.org removes a
> couple web pages?
>
> Development of lynx continues unabated:
>
>   http://invisible-island.net/lynx/lynx-develop.html

Sorta seems to me that ought to be kept uptodate in re that by the debian 
folks.
> Good luck with your project. 

I have atm, the darnest collection of Murphy's work I've ever seen. So I 
am inclined to fire up amrecover, back it up a week, and recover 
the /etc/apache2, /etc/httpd, and /var/www/html trees.  That sould put 
me back to a working, non ssl, web server.  All this got started because 
the next firefox says it will not look at a plain http site, and I was 
trying to make robots.txt kick googlebot in the gonads and out of my 
site, its eating more #$%& bandwidth than my site traffic is.  So once 
I've restored normal http operations, I'll come back and see if I can 
find some help converting it to https.

Thank you davidson@freevolt.org.

Cheers, Gene Heskett
-- 
"There are four boxes to be used in defense of liberty:
 soap, ballot, jury, and ammo. Please use in that order."
-Ed Howdershelt (Author)
Genes Web page <http://geneslinuxbox.net:6309/gene>

[toc] | [prev] | [next] | [standalone]


#180573

FromGreg Wooledge <wooledg@eeg.ccf.org>
Date2017-05-01 15:30 +0200
Message-ID<tCjyO-1f8-13@gated-at.bofh.it>
In reply to#180567
On Sun, Apr 30, 2017 at 09:32:33PM -0400, Gene Heskett wrote:
> >   STARTFILE:file://localhost/~/
> >
> > makes a sensible default.
> 
> except I am then trapped in my home dir.

*boggle*

You can press 'g' and then paste (or type) whatever URL you want into
the terminal.  You are not "trapped" anywhere.

Of course, the fact that you are in lynx means half the Web will not
WORK, especially your new-fangled "Let's Encrypt" https site using a
virtual domain, which is presumably what you are actually trying to use
lynx to test.

elinks has the same problem.  It can't talk to sites like
https://paste.debian.net/

I have been told that w3m might not have this problem, but I haven't
had a chance to try it yet.

[toc] | [prev] | [next] | [standalone]


#180574

FromGene Heskett <gheskett@shentel.net>
Date2017-05-01 16:10 +0200
Message-ID<tCkbw-1IO-23@gated-at.bofh.it>
In reply to#180573
On Monday 01 May 2017 09:28:10 Greg Wooledge wrote:

> On Sun, Apr 30, 2017 at 09:32:33PM -0400, Gene Heskett wrote:
> > >   STARTFILE:file://localhost/~/
> > >
> > > makes a sensible default.
> >
> > except I am then trapped in my home dir.
>
> *boggle*
>
> You can press 'g' and then paste (or type) whatever URL you want into
> the terminal.  You are not "trapped" anywhere.

I was referring to the usual visitor who likely doesn't know that.

> Of course, the fact that you are in lynx means half the Web will not
> WORK, especially your new-fangled "Let's Encrypt" https site using a
> virtual domain, which is presumably what you are actually trying to
> use lynx to test.
>
> elinks has the same problem.  It can't talk to sites like
> https://paste.debian.net/
>
> I have been told that w3m might not have this problem, but I haven't
> had a chance to try it yet.

Neither have I. I think I have it, but  don't recall that it worked the 
last time.  But does ok now.

Thanks, its back among the living. but not for https.

Cheers, Gene Heskett
-- 
"There are four boxes to be used in defense of liberty:
 soap, ballot, jury, and ammo. Please use in that order."
-Ed Howdershelt (Author)
Genes Web page <http://geneslinuxbox.net:6309/gene>

[toc] | [prev] | [next] | [standalone]


#180576

Fromrhkramer@gmail.com
Date2017-05-01 17:20 +0200
Message-ID<tClhf-2mc-5@gated-at.bofh.it>
In reply to#180567
On Sunday, April 30, 2017 09:32:33 PM Gene Heskett wrote:
> All this got started because
> the next firefox says it will not look at a plain http site, and I was

I hadn't heard anything about this, so I tried Googling.  The only thing I've 
found so far is reference to an optional add-on / plugin ("HTTPS Everywhere", 
iiuc) that would allow the browser to look only at ssl (https) pages.  Am I 
missing something?

(Well, I didn't read what I found carefully or completely, I did see some 
snippet of text that said that, in some respects, it would work (or use some 
methodologies) of NoScript, which *might* mean that there might be a way to 
override the plugin manually to view non-SSL pages.)

(Not to say that SSL everywhere wouldn't be a good idea, but, until "legacy" 
websites are converted, we may be missing a lot of the web.)

[toc] | [prev] | [next] | [standalone]


#180581

FromGene Heskett <gheskett@shentel.net>
Date2017-05-01 19:00 +0200
Message-ID<tCmQ1-39r-5@gated-at.bofh.it>
In reply to#180576
On Monday 01 May 2017 11:18:21 rhkramer@gmail.com wrote:

> On Sunday, April 30, 2017 09:32:33 PM Gene Heskett wrote:
> > All this got started because
> > the next firefox says it will not look at a plain http site, and I
> > was
>
> I hadn't heard anything about this, so I tried Googling.  The only
> thing I've found so far is reference to an optional add-on / plugin
> ("HTTPS Everywhere", iiuc) that would allow the browser to look only
> at ssl (https) pages.  Am I missing something?
>
That refers to ones browser, zip to do with a web server.

> (Well, I didn't read what I found carefully or completely, I did see
> some snippet of text that said that, in some respects, it would work
> (or use some methodologies) of NoScript, which *might* mean that there
> might be a way to override the plugin manually to view non-SSL pages.)
>
> (Not to say that SSL everywhere wouldn't be a good idea, but, until
> "legacy" websites are converted, we may be missing a lot of the web.)

Its converting my legacy web site that I am attempting to do.

Cheers, Gene Heskett
-- 
"There are four boxes to be used in defense of liberty:
 soap, ballot, jury, and ammo. Please use in that order."
-Ed Howdershelt (Author)
Genes Web page <http://geneslinuxbox.net:6309/gene>

[toc] | [prev] | [next] | [standalone]


#180586

Fromrhkramer@gmail.com
Date2017-05-01 21:00 +0200
Message-ID<tCoI9-4h9-5@gated-at.bofh.it>
In reply to#180581
On Monday, May 01, 2017 12:57:58 PM Gene Heskett wrote:
> On Monday 01 May 2017 11:18:21 rhkramer@gmail.com wrote:
> > I hadn't heard anything about this, so I tried Googling.  The only
> > thing I've found so far is reference to an optional add-on / plugin
> > ("HTTPS Everywhere", iiuc) that would allow the browser to look only
> > at ssl (https) pages.  Am I missing something?
> 
> That refers to ones browser, zip to do with a web server.

Well, Firefox is a browser, I thought that was what was being talked about?

> Its converting my legacy web site that I am attempting to do.

Understood

[toc] | [prev] | [next] | [standalone]


#180587

Fromrhkramer@gmail.com
Date2017-05-01 21:00 +0200
Message-ID<tCoI9-4h9-13@gated-at.bofh.it>
In reply to#180586
On Monday, May 01, 2017 02:54:05 PM rhkramer@gmail.com wrote:
> On Monday, May 01, 2017 12:57:58 PM Gene Heskett wrote:
> > On Monday 01 May 2017 11:18:21 rhkramer@gmail.com wrote:
> > > I hadn't heard anything about this, so I tried Googling.  The only
> > > thing I've found so far is reference to an optional add-on / plugin
> > > ("HTTPS Everywhere", iiuc) that would allow the browser to look only
> > > at ssl (https) pages.  Am I missing something?
> > 
> > That refers to ones browser, zip to do with a web server.
> 
> Well, Firefox is a browser, I thought that was what was being talked about?

Oh, maybe to be clearer, that plugin is for Firefox.

[toc] | [prev] | [next] | [standalone]


#180591

Fromdavidson@freevolt.org
Date2017-05-02 01:40 +0200
Message-ID<tCt57-70S-1@gated-at.bofh.it>
In reply to#180567
On Sun, 30 Apr 2017, Gene Heskett wrote:

> On Sunday 30 April 2017 20:19:21 davidson@freevolt.org wrote:
>
>> On Sun, 30 Apr 2017, Gene Heskett wrote:
[trimmed]
>>> lynx support at lynx.isc.org has been deleted. And it won't work
>>> without talking to isc.org first.  Even after being re-installed.
>>
>> Lynx works just fine. I expect your configuration file simply has some
>> references to obsolete remote locations.
>>
>> Does this work?
>>
>>   $ WWW_HOME="https://en.wikipedia.org/wiki/PEBKAC" lynx
>>
>> or this?
>>
>>   $
>> WWW_HOME="file://localhost/REPLACE-ME-WITH-A-PATH-TO-SOME-LOCAL-HTML-D
>> OC.html" lynx
>>
>> And does this...
>>
>>   $ grep '^STARTFILE:' /etc/lynx-cur/lynx.cfg
>>
>> ...confirm that you have something obsolete like
>>
>>   STARTFILE:http://lynx.isc.org/
>>
>> in your lynx.cfg ?
>>
> it was.
>
>> Then fix that broken reference. Edit /etc/lynx-cur/lynx.cfg, replacing
>> that STARTFILE url with whatever you like.
>>
>> FWIW, I think
>>
>>   STARTFILE:file://localhost/~/
>>
>> makes a sensible default.
>
> except I am then trapped in my home dir.

Well, as Greg W. pointed out, you aren't really restricted to whatever
links happen to be present in the startfile/"Main screen".

When running in "Novice" mode, the shortcut key for loading an
arbitrary url (G) is helpfully listed at the bottom of every screen:

   Arrow keys: Up and Down to move.  Right to follow a link; Left to go back.
   H)elp O)ptions P)rint G)o M)ain screen Q)uit /=search [delete]=history list

But if you would like the default "Main screen" to be something more
web-access-centric, the choice is yours. Maybe

  STARTFILE:https://duckduckgo.com/lite/

or

  STARTFILE:https://www.google.com/

would fit the bill. Or something else entirely. Obviously you will
know better than I do what your users will find helpful.

Somebody upstream of us apparently thought that a site about lynx
would be a good initial default. Not a bad choice, if you ask me. Too
bad the site had to move.

>> Or, if for some incomprehensible reason you think a remote website is
>> an appropriate default startfile, you could use
>>
>>    STARTFILE:http://lynx.invisible-island.net/
>>
>> instead.
>>
>> While you're at it, you might want to cast your eye over any other
>> lines returned by this...
>>
>>   $ grep '^[A-Z_]*:[[:blank:]]*https\?://' /etc/lynx-cur/lynx.cfg
>
> Which was a wisc.edu url.

Thought so: http://scout.wisc.edu/

Which was presumably the value of DEFAULT_INDEX_FILE .

Whatever scout.wisc.edu may have had there in the past, the content
currently shown on that page is pretty much worthless as a general web
index.

So you'll probably change it to something better.

>> ...and see if you wouldn't rather change them to something more
>> up-to-date, more reliable, or more appropriate for your installation.
>>
>>> So A: file a bug against lynx, best to remove it as its apparently
>>> been EOL'd by isc.org
>>
>> Huh? You would remove a program simply because isc.org removes a
>> couple web pages?
>>
>> Development of lynx continues unabated:
>>
>>   http://invisible-island.net/lynx/lynx-develop.html
>
> Sorta seems to me that ought to be kept uptodate in re that by the
> debian folks.

Sounds reasonable to me.

On the other hand, it is the site administrator, rather than Thomas
Dickey or the debian maintainer for lynx-cur, who is in the better
position to determine helpful values for both STARTFILE and
DEFAULT_INDEX_FILE in a given lynx install. I imagine (or hope) they
are frequently customised.

Anyways, maintenance of Wheezy is now in the hands of the Debian LTS
team:

  https://wiki.debian.org/LTS/FAQ#Where_can_bugs_be_reported.3F

   Where can bugs be reported?

    Please report bugs that you found in the packages to the
    debian-lts[1] mailing list. The bar for severity will be raised
    (minor issues will no longer be fixed).

    1. https://wiki.debian.org/LTS/Contact#debian-lts

>> Good luck with your project.
>
> I have atm, the darnest collection of Murphy's work I've ever seen. So I
> am inclined to fire up amrecover, back it up a week, and recover
> the /etc/apache2, /etc/httpd, and /var/www/html trees.  That sould put
> me back to a working, non ssl, web server.  All this got started because
> the next firefox says it will not look at a plain http site, and I was
> trying to make robots.txt kick googlebot in the gonads and out of my
> site, its eating more #$%& bandwidth than my site traffic is.  So once
> I've restored normal http operations, I'll come back and see if I can
> find some help converting it to https.

It'll be interesting to follow along.

[toc] | [prev] | [next] | [standalone]


Page 1 of 2  [1] 2  Next page →

Back to top | Article view | linux.debian.user


csiph-web