Project 511 Services Unit HTTPS Everything

A sub-project of 454 to migrate all Services Unit web services/sites to HTTPS from HTTP.

This specifically does not mean authenticating all web services, just that they should be served via HTTPS, as lots of browsers now warn when visiting HTTP sites.

Our plan will be to:

  1. not create any new web services that are HTTP - already doing this.
  2. identify all the web services that we run, and categorise them into 1 of the 4 types identified on Project454MoveToHTTPS#Types_of_sites_running_HTTP
  3. start working through that list, low hanging fruit first?

We've not actively done much on this yet. However any new sites are HTTPS only sites, and there are some RT tickets, eg where users are asking us specifically to do it.

List of machines

A combination of:

  • header-user live/services-unit.h
  • header-user dice/options/apacheconf.h
  • union of the above:cat A B | sort | uniq -d

gives us 57 hosts. However some will host multiple websites, and some are dev/test/play things. Project511ServicesUnitList

Some notes on Lets Encrypt


Dev meeting talks

Talk 1 - possibly 30/6/2020

Basically all that's happened since May is classified all 213 sites.

HTTP and HTTPS pub 37
HTTP only 78
HTTP pub HTTPS auth 10
HTTPS already 36
NA - DR, test, not us (anymore) 51

The first 2 categories, 115 should be relatively straightforward.

Of the 10 more tricky ones:

  • 4 are edweb sites (1 live, other others dev and DR)
  • The others are:
  • Old LFCS Plone site - will be gone soon
  • lists.inf
  • rbs.inf
  • dtest1.inf - test thing
  • mediasrv.inf/aiai
  • holler.inf - should be redirecting to ltg

Talk 3 2/3/2021

Of the 125 web sites originally identified as needing work to make them HTTPS only, 13 of them have now been done. That includes some of the trickier class of site which were HTTP public and HTTPS authenticated.

Type Total Done
HTTP and HTTPS pub 36 5
HTTP only 78 4
HTTP pub HTTPS auth 10 4
HTTPS already 36 0
NA 50 0

As you'll have seen, I hope to tick off another couple on Thursday.

1 site has deleted, and I've at least 2 more in my sights to delete.

I've marked my previous "start working through the list" milestone as done, and rather than add a milestone for every site, I've added one to try and do at least 4 sites a month (1 a week).

-- NeilBrown - 14 Jan 2020

Topic revision: r6 - 01 Mar 2021 - 16:02:11 - NeilBrown
This site is powered by the TWiki collaboration platformCopyright © by the contributing authors. All material on this collaboration platform is the property of the contributing authors.
Ideas, requests, problems regarding TWiki? Send feedback
This Wiki uses Cookies