Project

General

Profile

Actions

Bug #7235

closed

Can't access sites

Added by Raffi Khatchadourian about 8 years ago. Updated about 8 years ago.

Status:
Resolved
Priority name:
Normal
Assignee:
-
Category name:
-
Target version:
Start date:
2016-12-24
Due date:
% Done:

0%

Estimated time:
Deployment actions:

Description

I am getting an SSL error when trying to access any site on the commons, e.g., http://dev.commons.gc.cuny.edu. My browser says that the certificate is invalid. If I add a security exception and proceed, no matter from which site I am trying to access, the contents of the page seems to be something to the extent of "The Barry S. Brook Center For Music Research And Documentation."

Actions #1

Updated by Matt Gold about 8 years ago

Hi Raffi,

Sorry for the late response. This issue (a server configuration error) should be fixed now; please let us know whether the issue is solved for you.

Actions #2

Updated by Raffi Khatchadourian about 8 years ago

Matt Gold wrote:

Hi Raffi,

Sorry for the late response. This issue (a server configuration error) should be fixed now; please let us know whether the issue is solved for you.

No problem, Matt. But, why are these sites being served over HTTPS? What is the sensitive information that is being transferred? Of course, I understand that forms asking for passwords need to be posted via HTTPS but why the entire site in general?

Using HTTPS unnecessarily not only wastes computational resources on the server but also negatively affects SEO.

Actions #3

Updated by Matt Gold about 8 years ago

  • Status changed from New to Assigned

Hi Raffi. Central IT now requires that any CUNY website containing a login form be served over https. Since the sitewide header (the black band at the top of the CAC) includes a log-in mechanism, we are required to server over https.

Actions #4

Updated by Raffi Khatchadourian about 8 years ago

Matt Gold wrote:

Hi Raffi. Central IT now requires that any CUNY website containing a login form be served over https. Since the sitewide header (the black band at the top of the CAC) includes a log-in mechanism, we are required to server over https.

Thanka, Matt. But, shouldn't only the POST sent when the login form is submitted be over HTTPS? Why would the form itself (i.e., the text boxes) need to be secured?

Actions #5

Updated by Boone Gorges about 8 years ago

Using HTTPS unnecessarily not only wastes computational resources on the server but also negatively affects SEO.

Our eventual goal is to serve all content over SSL/TLS. Browsers will increasingly enforce this policy, by disabling various features and showing scary notices for non-secure pages. See https://https.cio.gov/everything/ for a helpful overview of why HTTPS everywhere is a good policy.

Actions #6

Updated by Raffi Khatchadourian about 8 years ago

Boone Gorges wrote:

Using HTTPS unnecessarily not only wastes computational resources on the server but also negatively affects SEO.

Our eventual goal is to serve all content over SSL/TLS. Browsers will increasingly enforce this policy, by disabling various features and showing scary notices for non-secure pages. See https://https.cio.gov/everything/ for a helpful overview of why HTTPS everywhere is a good policy.

Ah, okay. Thanks for the clarification, Boone.

Actions #7

Updated by Boone Gorges about 8 years ago

  • Status changed from Assigned to Resolved
  • Target version set to Not tracked
Actions

Also available in: Atom PDF