Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]
Groups > linux.debian.user > #179713 > unrolled thread
| Started by | Marc SCHAEFER <schaefer@alphanet.ch> |
|---|---|
| First post | 2017-04-02 19:10 +0200 |
| Last post | 2017-04-03 15:00 +0200 |
| Articles | 7 — 5 participants |
Back to article view | Back to linux.debian.user
Captive network account (w/ login redirect) and HSTS Marc SCHAEFER <schaefer@alphanet.ch> - 2017-04-02 19:10 +0200
Re: Captive network account (w/ login redirect) and HSTS Brian <ad44@cityscape.co.uk> - 2017-04-02 21:00 +0200
Re: Captive network account (w/ login redirect) and HSTS Marc SCHAEFER <schaefer@alphanet.ch> - 2017-04-02 21:30 +0200
Re: Captive network account (w/ login redirect) and HSTS David Wright <deblis@lionunicorn.co.uk> - 2017-04-02 22:30 +0200
Re: Captive network account (w/ login redirect) and HSTS Marc SCHAEFER <schaefer@alphanet.ch> - 2017-04-03 12:40 +0200
Re: Captive network account (w/ login redirect) and HSTS <tomas@tuxteam.de> - 2017-04-03 09:30 +0200
Re: Captive network account (w/ login redirect) and HSTS Darac Marjal <mailinglist@darac.org.uk> - 2017-04-03 15:00 +0200
| From | Marc SCHAEFER <schaefer@alphanet.ch> |
|---|---|
| Date | 2017-04-02 19:10 +0200 |
| Subject | Captive network account (w/ login redirect) and HSTS |
| Message-ID | <trRaO-3jk-13@gated-at.bofh.it> |
Hello,
with a basic Debian jessie install and a recent Firefox, I observe the
following:
[1] Debian has no specific support for detecting captive networks
(e.g. Android, iOS) and redirecting automatically the browser to
the captive login page
[2] launching Firefox on the default page doesn't work (doesn't get
redirected properly to the login page but fails with a HTTPS
certificate error), if there is a recent HSTS[*] security
configuration cache for the default domain page (e.g. google.com)
[1] is not really an issue: I wouldn't like myself that connecting to
a WiFi captive network starts a browser. Also, open captive networks are
messing up, dangerous, a WPA/RADIUS auth would be much better.
However, open captive networks are quite commons in hotels, airports,
parks, etc. So it cannot be dismissed.
[2] the only fix is to type an URL you know is HTTP, not HTTPS and does
not configure HSTS, and does not support DNSSEC. In my case I used
ptiturl.ch
Maybe this could be in the Debian User manual somehow?
Feel free to contact me if you want help in writing the documentation.
https://en.wikipedia.org/wiki/HTTP_Strict_Transport_Security
[toc] | [next] | [standalone]
| From | Brian <ad44@cityscape.co.uk> |
|---|---|
| Date | 2017-04-02 21:00 +0200 |
| Message-ID | <trSTf-4gk-3@gated-at.bofh.it> |
| In reply to | #179713 |
On Sun 02 Apr 2017 at 18:36:25 +0200, Marc SCHAEFER wrote: > with a basic Debian jessie install and a recent Firefox, I observe the > following: > > [1] Debian has no specific support for detecting captive networks > (e.g. Android, iOS) and redirecting automatically the browser to > the captive login page > > [2] launching Firefox on the default page doesn't work (doesn't get > redirected properly to the login page but fails with a HTTPS > certificate error), if there is a recent HSTS[*] security > configuration cache for the default domain page (e.g. google.com) > > [1] is not really an issue: I wouldn't like myself that connecting to > a WiFi captive network starts a browser. Also, open captive networks are > messing up, dangerous, a WPA/RADIUS auth would be much better. > > However, open captive networks are quite commons in hotels, airports, > parks, etc. So it cannot be dismissed. > > [2] the only fix is to type an URL you know is HTTP, not HTTPS and does > not configure HSTS, and does not support DNSSEC. In my case I used > ptiturl.ch > > Maybe this could be in the Debian User manual somehow? > > Feel free to contact me if you want help in writing the documentation. > > https://en.wikipedia.org/wiki/HTTP_Strict_Transport_Security Probably the best place for this is the wiki. Anyone can create a page on the topic of captive networks there. Maybe there one is in existence which can be added to. Feel free to add to such a page or start a new one. -- Brian.
[toc] | [prev] | [next] | [standalone]
| From | Marc SCHAEFER <schaefer@alphanet.ch> |
|---|---|
| Date | 2017-04-02 21:30 +0200 |
| Message-ID | <trTmh-4Gv-3@gated-at.bofh.it> |
| In reply to | #179715 |
On Sun, Apr 02, 2017 at 07:51:40PM +0100, Brian wrote: > Probably the best place for this is the wiki. Anyone can create a page > on the topic of captive networks there. Maybe there one is in existence > which can be added to. Feel free to add to such a page or start a new > one. I did not find any, so I created: https://wiki.debian.org/CaptivePortal Thank you for the suggestion.
[toc] | [prev] | [next] | [standalone]
| From | David Wright <deblis@lionunicorn.co.uk> |
|---|---|
| Date | 2017-04-02 22:30 +0200 |
| Message-ID | <trUil-5is-1@gated-at.bofh.it> |
| In reply to | #179716 |
On Sun 02 Apr 2017 at 21:20:30 (+0200), Marc SCHAEFER wrote: > On Sun, Apr 02, 2017 at 07:51:40PM +0100, Brian wrote: > > Probably the best place for this is the wiki. Anyone can create a page > > on the topic of captive networks there. Maybe there one is in existence > > which can be added to. Feel free to add to such a page or start a new > > one. > > I did not find any, so I created: > > https://wiki.debian.org/CaptivePortal That was quick! IIRC I have in the past typed ip route show and then pasted the IP of the default route into the browser. Am I remembering correctly, and would that IP address obey your conditions outlined earlier? Cheers, David.
[toc] | [prev] | [next] | [standalone]
| From | Marc SCHAEFER <schaefer@alphanet.ch> |
|---|---|
| Date | 2017-04-03 12:40 +0200 |
| Message-ID | <ts7yV-5Em-1@gated-at.bofh.it> |
| In reply to | #179717 |
On Sun, Apr 02, 2017 at 03:20:56PM -0500, David Wright wrote: > IIRC I have in the past typed ip route show > and then pasted the IP of the default route into the browser. > Am I remembering correctly, and would that IP address obey > your conditions outlined earlier? That would work too, even if default router is not the captive portal itself. Let's put that in the doc.
[toc] | [prev] | [next] | [standalone]
| From | <tomas@tuxteam.de> |
|---|---|
| Date | 2017-04-03 09:30 +0200 |
| Message-ID | <ts4B4-3Mv-17@gated-at.bofh.it> |
| In reply to | #179716 |
-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 On Sun, Apr 02, 2017 at 09:20:30PM +0200, Marc SCHAEFER wrote: [...] > I did not find any, so I created: > > https://wiki.debian.org/CaptivePortal \o/ Thanks! - -- t -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.12 (GNU/Linux) iEYEARECAAYFAljh+dcACgkQBcgs9XrR2kbBFACfan9XUNfJg4n0LM8rc9R6OuH/ +rIAnjb3Jw48xjIYvEGt1PwMevadTff+ =7WUV -----END PGP SIGNATURE-----
[toc] | [prev] | [next] | [standalone]
| From | Darac Marjal <mailinglist@darac.org.uk> |
|---|---|
| Date | 2017-04-03 15:00 +0200 |
| Message-ID | <ts9Kq-6Yw-5@gated-at.bofh.it> |
| In reply to | #179713 |
On Sun, Apr 02, 2017 at 06:36:25PM +0200, Marc SCHAEFER wrote: >Hello, > >with a basic Debian jessie install and a recent Firefox, I observe the >following: > > [1] Debian has no specific support for detecting captive networks > (e.g. Android, iOS) and redirecting automatically the browser to > the captive login page > > [2] launching Firefox on the default page doesn't work (doesn't get > redirected properly to the login page but fails with a HTTPS > certificate error), if there is a recent HSTS[*] security > configuration cache for the default domain page (e.g. google.com) > >[1] is not really an issue: I wouldn't like myself that connecting to >a WiFi captive network starts a browser. Also, open captive networks are >messing up, dangerous, a WPA/RADIUS auth would be much better. > >However, open captive networks are quite commons in hotels, airports, >parks, etc. So it cannot be dismissed. > >[2] the only fix is to type an URL you know is HTTP, not HTTPS and does >not configure HSTS, and does not support DNSSEC. In my case I used >ptiturl.ch > >Maybe this could be in the Debian User manual somehow? > >Feel free to contact me if you want help in writing the documentation. > >https://en.wikipedia.org/wiki/HTTP_Strict_Transport_Security > I believe the way Android works is, when the network interface changes, a request is fired off to a known page on Google. If that page returns a known HTTP code (200, I think), then everything is OK. But if it returns 301 (Moved Permanently), 302 (Found) or, preferably 511 (Network Authentication Required), then a one-shot browser is opened. I think this would be a great feature request for Network-Manager (which has the abiliity to monitor the network AND has a GUI AND is part of the default Debian). -- For more information, please reread.
[toc] | [prev] | [standalone]
Back to top | Article view | linux.debian.user
csiph-web