Author Topic: https://geekhack.org -- limited SSL support deployed  (Read 12360 times)

0 Members and 1 Guest are viewing this topic.

Offline mkawa

  •  No Marketplace Access
  • Thread Starter
  • Posts: 6562
  • (ツ)@@@. crankypants
https://geekhack.org -- limited SSL support deployed
« on: Fri, 14 November 2014, 19:12:22 »
folks,

we've rolled out limited support for ssl on geekhack. https://geekhack.org will bring you to the TLS enabled version of the site, that encrypts and authenticates your password between our servers and your machine. in particular, you will need to tell your browser that it is ok to load _mixed content_ on geekhack.org

Quote
in google chrome:

on the right side of the location text field, there will be a shield icon. click the shield icon and then "load insecure content"

i will add instructions as people report issues.

to all the brilliant friends who have left us, and all the students who climb on their shoulders.

Offline byker

  • Literally Canada
  • ** Moderator Emeritus
  • Posts: 3136
  • Location: Gone fishin
Re: https://geekhack.org -- limited SSL support deployed
« Reply #1 on: Fri, 14 November 2014, 19:29:16 »
I have done that, but it automatically switches back to regular http after I load a different page on gh, for example when I click to write a reply.

Offline Coreda

  • Posts: 776
Re: https://geekhack.org -- limited SSL support deployed
« Reply #2 on: Fri, 14 November 2014, 19:48:04 »
Good stuff! Problem is allowing the mixed content only works per-page or seems to be a temporary setting (at least in Firefox), and otherwise the GH stylesheet breaks completely :/

Also found that currently adding 'www' returns a 403 error page.

I have done that, but it automatically switches back to regular http after I load a different page on gh, for example when I click to write a reply.

This too.

Offline mkawa

  •  No Marketplace Access
  • Thread Starter
  • Posts: 6562
  • (ツ)@@@. crankypants
Re: https://geekhack.org -- limited SSL support deployed
« Reply #3 on: Fri, 14 November 2014, 20:14:40 »
this may be fixed.

to all the brilliant friends who have left us, and all the students who climb on their shoulders.

Offline iMav

  • geekhack creator/founder
  • Location: Valley City, ND
  • "Τα εργαλεία σας είναι σημαντικά."
Re: https://geekhack.org -- limited SSL support deployed
« Reply #4 on: Fri, 14 November 2014, 20:22:19 »
I think it works pretty darned good now.  :)

Offline inanis

  • Truly Literally The Cloud
  • * Destiny Supporter
  • Posts: 790
  • Location: Dark Places
    • SEALWoodworking
Re: https://geekhack.org -- limited SSL support deployed
« Reply #5 on: Fri, 14 November 2014, 20:23:09 »
Yah for HTTPS!

Maybe it is just me, but your root cert doesn't appear to be trusted by all browsers. I see it just fine in IE and Chrome, but Firefox and Chrome on my phone both say the cert is untrusted and shows no chain.
Some hearts are gallows, I'm not here for hangin' around

Offline iMav

  • geekhack creator/founder
  • Location: Valley City, ND
  • "Τα εργαλεία σας είναι σημαντικά."
Re: https://geekhack.org -- limited SSL support deployed
« Reply #6 on: Fri, 14 November 2014, 20:39:25 »
Chrome and Safari on OS X seem happy with the cert.  IE and Chrome on Windows don't complain.  iPhone trusts the cert as well.

The SSL cert was donated...so I didn't choose the certificate authority.  :)

Offline mkawa

  •  No Marketplace Access
  • Thread Starter
  • Posts: 6562
  • (ツ)@@@. crankypants
Re: https://geekhack.org -- limited SSL support deployed
« Reply #7 on: Fri, 14 November 2014, 20:44:42 »
CAs on phone distributions are always a PITA. your phone's android distribution could be > a year old depending on your carrier, manufacturer, etc. etc. etc.

just push on through

to all the brilliant friends who have left us, and all the students who climb on their shoulders.

Offline Coreda

  • Posts: 776
Re: https://geekhack.org -- limited SSL support deployed
« Reply #8 on: Fri, 14 November 2014, 21:12:01 »
It works now - nice fix, mk.

Offline mkawa

  •  No Marketplace Access
  • Thread Starter
  • Posts: 6562
  • (ツ)@@@. crankypants
Re: https://geekhack.org -- limited SSL support deployed
« Reply #9 on: Fri, 14 November 2014, 21:14:57 »
all imav

to all the brilliant friends who have left us, and all the students who climb on their shoulders.

Offline inanis

  • Truly Literally The Cloud
  • * Destiny Supporter
  • Posts: 790
  • Location: Dark Places
    • SEALWoodworking
Re: https://geekhack.org -- limited SSL support deployed
« Reply #10 on: Fri, 14 November 2014, 21:18:03 »
Totally understand - free is good!

If it helps at all, I think the issue I was seeing isn't the root, but part of the chain. Specifically the COMODO RSA Domain Validation Secure Server CA certificate. Sometimes this can happen if the full chain isn't installed, or, and perhaps more likely, it could just be that my browser isn't having it. Either way, I appreciate the HTTPS so I'm not going to complain.

Thanks!
Some hearts are gallows, I'm not here for hangin' around

Offline strict

  • TKL Zealot
  • Posts: 1921
  • Location: PA
Re: https://geekhack.org -- limited SSL support deployed
« Reply #11 on: Fri, 14 November 2014, 21:46:06 »
Appreciate the effort to move us to SSL/TLS!

I did notice that ever since the upgrade my tapatalk hasn't been working. I thought maybe I needed to log out and back in but I haven't been able to sign back in after logging out.

Edit - Looks like we're also missing the intermediate certs - https://www.sslshopper.com/ssl-checker.html#hostname=https://geekhack.org
« Last Edit: Fri, 14 November 2014, 22:00:13 by strict »

Realforce EK45 (Silenced)  |  Realforce 87UW (45g)  |  Realforce 87UWS (Variable)
Filco MJ2 TKL (Cherry Clears)  |  Phantom 87 (78g Gateron Clears)  |  Phantom 86 (67g Zealios)


Offline byker

  • Literally Canada
  • ** Moderator Emeritus
  • Posts: 3136
  • Location: Gone fishin
Re: https://geekhack.org -- limited SSL support deployed
« Reply #12 on: Fri, 14 November 2014, 22:23:24 »
Working now imav!

Offline CommonCurt

  • One of the cool kids
  • * Esteemed Elder
  • Posts: 4643
  • Location: WPB, FL
  • 🍒 Beige or Bust
    • My Flickr Page
Re: https://geekhack.org -- limited SSL support deployed
« Reply #13 on: Fri, 14 November 2014, 22:58:25 »
Edit - Looks like we're also missing the intermediate certs - https://www.sslshopper.com/ssl-checker.html#hostname=https://geekhack.org

Yep, my mobile browser is giving me **** about the certs.
Some of Ye ole  Keyboards -->
More
OTD Koala:  62g Old MX-Blacks   |   LZ-GH V2:  MX-?62g   |   KMAC2:   62g Tactile MX-Greys   |   LZ CLS s:   62g Vintage MX-Blacks   |   X60:   62g Vintage MX-Blacks   |   GON NerD 60:  62g Old MX-Clears   |   Filco MJ2 (Beige) TKL's:  62g MX-Clears  &   62g Vintage MX-Blacks   |   IBM '91 SSK
                                
       
WTB/WTS/WTT ---->
More

Offline jdcarpe

  • * Curator
  • Posts: 8852
  • Location: Odessa, TX
  • Live long, and prosper.
Re: https://geekhack.org -- limited SSL support deployed
« Reply #14 on: Fri, 14 November 2014, 23:00:47 »
Firefox on Xubuntu complains about the certs.
KMAC :: LZ-GH :: WASD CODE :: WASD v2 :: GH60 :: Alps64 :: JD45 :: IBM Model M :: IBM 4704 "Pingmaster"

http://jd40.info :: http://jd45.info


in memoriam

"When I was a kid, I used to take things apart and never put them back together."

Offline user 18

  • * Senior Moderator
  • Posts: 2231
  • Location: Deutschland
Re: https://geekhack.org -- limited SSL support deployed
« Reply #15 on: Sat, 15 November 2014, 00:09:45 »
Chrome on Linux Mint and on Crunchbang Linux accepts the certificate. Tapatalk isn't working for me either on stock Android 4.4.4 anymore, and chrome for android also doesn't like the cert here.
Please PM me if you are waiting on classifieds approval or have a question about the classifieds rules. | geekhack Terms of Service

Max Nighthawk x8 (MX Brown) | CM QFR (MX Blue) | CM QFR (MX Clear) | RK-9000 (MX Red) | Model M 1391401 | Model M SSK 1370475 | CM Novatouch | G80-8113 (MX Clear) | 60% (85g MX Blue) | Whitefox Aria (MX Clear) | CL-LX (MX Clear) | Mira SE (MX Clear)
Avatar by ashdenej

Offline iMav

  • geekhack creator/founder
  • Location: Valley City, ND
  • "Τα εργαλεία σας είναι σημαντικά."
Re: https://geekhack.org -- limited SSL support deployed
« Reply #16 on: Sat, 15 November 2014, 01:10:03 »
How does it look now?

Offline CPTBadAss

  • Woke up like this
  • Posts: 14365
    • Tactile Zine
Re: https://geekhack.org -- limited SSL support deployed
« Reply #17 on: Sat, 15 November 2014, 01:18:45 »
Tapatalk isn't working.

Offline user 18

  • * Senior Moderator
  • Posts: 2231
  • Location: Deutschland
Re: https://geekhack.org -- limited SSL support deployed
« Reply #18 on: Sat, 15 November 2014, 01:20:01 »
Chrome on android is happy now, it seems
Please PM me if you are waiting on classifieds approval or have a question about the classifieds rules. | geekhack Terms of Service

Max Nighthawk x8 (MX Brown) | CM QFR (MX Blue) | CM QFR (MX Clear) | RK-9000 (MX Red) | Model M 1391401 | Model M SSK 1370475 | CM Novatouch | G80-8113 (MX Clear) | 60% (85g MX Blue) | Whitefox Aria (MX Clear) | CL-LX (MX Clear) | Mira SE (MX Clear)
Avatar by ashdenej

Offline iMav

  • geekhack creator/founder
  • Location: Valley City, ND
  • "Τα εργαλεία σας είναι σημαντικά."
Re: https://geekhack.org -- limited SSL support deployed
« Reply #19 on: Sat, 15 November 2014, 01:21:55 »
Chrome on android is happy now, it seems

Ok, cool.  Looking into Tapatalk right now.

Offline iMav

  • geekhack creator/founder
  • Location: Valley City, ND
  • "Τα εργαλεία σας είναι σημαντικά."
Re: https://geekhack.org -- limited SSL support deployed
« Reply #20 on: Sat, 15 November 2014, 01:27:45 »
Tapatalk works fine.  Just need to delete and re-add the forum.

(Posting this from Tapatalk)

Offline CPTBadAss

  • Woke up like this
  • Posts: 14365
    • Tactile Zine
Re: https://geekhack.org -- limited SSL support deployed
« Reply #21 on: Sat, 15 November 2014, 08:32:31 »
Got it working now after deleting and re-adding the forum. Thanks imav!

Offline strict

  • TKL Zealot
  • Posts: 1921
  • Location: PA
Re: https://geekhack.org -- limited SSL support deployed
« Reply #22 on: Sat, 15 November 2014, 09:01:29 »
How does it look now?

Everything looks good here (intermediate cert and tapatalk). Thanks for your work!  :thumb:

Realforce EK45 (Silenced)  |  Realforce 87UW (45g)  |  Realforce 87UWS (Variable)
Filco MJ2 TKL (Cherry Clears)  |  Phantom 87 (78g Gateron Clears)  |  Phantom 86 (67g Zealios)


Offline Tiramisuu

  • Posts: 329
Re: https://geekhack.org -- limited SSL support deployed
« Reply #23 on: Sat, 15 November 2014, 10:51:25 »
  :thumb:   kudos.
Keyboard error F1 to continue.

Poker 2, Gherkin, Lets Split, Planck, Filco

Offline user 18

  • * Senior Moderator
  • Posts: 2231
  • Location: Deutschland
Re: https://geekhack.org -- limited SSL support deployed
« Reply #24 on: Sat, 15 November 2014, 12:18:55 »
Working now, thanks :)
Please PM me if you are waiting on classifieds approval or have a question about the classifieds rules. | geekhack Terms of Service

Max Nighthawk x8 (MX Brown) | CM QFR (MX Blue) | CM QFR (MX Clear) | RK-9000 (MX Red) | Model M 1391401 | Model M SSK 1370475 | CM Novatouch | G80-8113 (MX Clear) | 60% (85g MX Blue) | Whitefox Aria (MX Clear) | CL-LX (MX Clear) | Mira SE (MX Clear)
Avatar by ashdenej

Offline SpAmRaY

  • NOT a Moderator
  • * Certified Spammer
  • Posts: 14667
  • Location: ¯\(°_o)/¯
  • because reasons.......
Re: https://geekhack.org -- limited SSL support deployed
« Reply #25 on: Sat, 15 November 2014, 14:19:41 »
Tapatalk isn't working for me.

Offline mkawa

  •  No Marketplace Access
  • Thread Starter
  • Posts: 6562
  • (ツ)@@@. crankypants
Re: https://geekhack.org -- limited SSL support deployed
« Reply #26 on: Sat, 15 November 2014, 14:25:47 »
have you tried deleting the forum and adding it again?

also, what version of tapatalk?

to all the brilliant friends who have left us, and all the students who climb on their shoulders.

Offline SpAmRaY

  • NOT a Moderator
  • * Certified Spammer
  • Posts: 14667
  • Location: ¯\(°_o)/¯
  • because reasons.......
Re: https://geekhack.org -- limited SSL support deployed
« Reply #27 on: Sat, 15 November 2014, 14:57:35 »
have you tried deleting the forum and adding it again?

also, what version of tapatalk?

That worked. 4.9.5

Offline geniekid

  • Posts: 763
  • Location: Chicago, IL
Re: https://geekhack.org -- limited SSL support deployed
« Reply #28 on: Sat, 15 November 2014, 15:44:13 »
Yay!  This is probably one of the most important things to happen to this site that almost none of the users will care about :P

Offline swill

  • * Elevated Elder
  • Posts: 3365
  • Location: Canada eh
  • builder & enabler
    • swillkb.com
Re: https://geekhack.org -- limited SSL support deployed
« Reply #29 on: Sat, 15 November 2014, 23:13:42 »
Tapatalk isn't working for me.

Tapatalk is no longer working for me either.  I suspect it has something to do with the SSL roll out, but I do not know that for sure.

Offline swill

  • * Elevated Elder
  • Posts: 3365
  • Location: Canada eh
  • builder & enabler
    • swillkb.com
Re: https://geekhack.org -- limited SSL support deployed
« Reply #30 on: Sat, 15 November 2014, 23:16:34 »
have you tried deleting the forum and adding it again?

also, what version of tapatalk?

That worked. 4.9.5

Woops, I should have read this before I posted...  I just removed and re-added Geekhack and it is working again.  Thanks...  :)

Offline Coreda

  • Posts: 776
Re: https://geekhack.org -- limited SSL support deployed
« Reply #31 on: Mon, 17 November 2014, 01:21:32 »
So, I'm not sure if it's the move to SSL or just something on my end, but I've been noticing that after signing in via the top-left fields while viewing a thread it redirects me to a different thread, rather than the one I was on. In one case it opened a thread I had in another tab. Weird.
« Last Edit: Mon, 17 November 2014, 01:24:39 by Coreda »

Offline mkawa

  •  No Marketplace Access
  • Thread Starter
  • Posts: 6562
  • (ツ)@@@. crankypants
Re: https://geekhack.org -- limited SSL support deployed
« Reply #32 on: Mon, 17 November 2014, 19:41:40 »
i suspect i know what's going on with that, but if it's benign, i think we're better of leaving that one alone.

to all the brilliant friends who have left us, and all the students who climb on their shoulders.

Offline rowdy

  • HHKB Hapster
  • * Erudite Elder
  • Posts: 21175
  • Location: melbourne.vic.au
  • Missed another sale.
Re: https://geekhack.org -- limited SSL support deployed
« Reply #33 on: Mon, 17 November 2014, 21:34:21 »
I'm not sure if it is related to SSL, but I only started noticing this at home and work since SSL has been in place.

When I load a thread with unread topics, the text on the page seems to load fairly quickly, but then there is a long pause before the "unread" icon appears next to the unread threads.  This is a bit distracting as I click those icons to visit the first new post in each of the relevant threads.
"Because keyboards are accessories to PC makers, they focus on minimizing the manufacturing costs. But that’s incorrect. It’s in HHKB’s slogan, but when America’s cowboys were in the middle of a trip and their horse died, they would leave the horse there. But even if they were in the middle of a desert, they would take their saddle with them. The horse was a consumable good, but the saddle was an interface that their bodies had gotten used to. In the same vein, PCs are consumable goods, while keyboards are important interfaces." - Eiiti Wada

NEC APC-H4100E | Ducky DK9008 Shine MX blue LED red | Ducky DK9008 Shine MX blue LED green | Link 900243-08 | CM QFR MX black | KeyCool 87 white MX reds | HHKB 2 Pro | Model M 02-Mar-1993 | Model M 29-Nov-1995 | CM Trigger (broken) | CM QFS MX green | Ducky DK9087 Shine 3 TKL Yellow Edition MX black | Lexmark SSK 21-Apr-1994 | IBM SSK 13-Oct-1987 | CODE TKL MX clear | Model M 122 01-Jun-1988

Ị̸͚̯̲́ͤ̃͑̇̑ͯ̊̂͟ͅs̞͚̩͉̝̪̲͗͊ͪ̽̚̚ ̭̦͖͕̑́͌ͬͩ͟t̷̻͔̙̑͟h̹̠̼͋ͤ͋i̤̜̣̦̱̫͈͔̞ͭ͑ͥ̌̔s̬͔͎̍̈ͥͫ̐̾ͣ̔̇͘ͅ ̩̘̼͆̐̕e̞̰͓̲̺̎͐̏ͬ̓̅̾͠͝ͅv̶̰͕̱̞̥̍ͣ̄̕e͕͙͖̬̜͓͎̤̊ͭ͐͝ṇ̰͎̱̤̟̭ͫ͌̌͢͠ͅ ̳̥̦ͮ̐ͤ̎̊ͣ͡͡n̤̜̙̺̪̒͜e̶̻̦̿ͮ̂̀c̝̘̝͖̠̖͐ͨͪ̈̐͌ͩ̀e̷̥͇̋ͦs̢̡̤ͤͤͯ͜s͈̠̉̑͘a̱͕̗͖̳̥̺ͬͦͧ͆̌̑͡r̶̟̖̈͘ỷ̮̦̩͙͔ͫ̾ͬ̔ͬͮ̌?̵̘͇͔͙ͥͪ͞ͅ