Opened 6 years ago

Closed 6 years ago

#4753 closed defect (fixed)

redirect looses ssl

Reported by: skyper Owned by: Grant Slater
Priority: minor Milestone:
Component: wiki Version:
Keywords: ssl redirect Cc:

Description

The redirect from https://wiki.osm.org/ is leading to http and not https.

Please, keep the protocol. Thanks

Change History (6)

comment:1 Changed 6 years ago by Tom Hughes

Resolution: wontfix
Status: newclosed

This is deliberate - as SSL is (relatively) expensive we only offer it for the login process on the wiki and everything else is directed back to normal http.

comment:2 in reply to:  1 Changed 6 years ago by skyper

Resolution: wontfix
Status: closedreopened

Replying to TomH:

This is deliberate - as SSL is (relatively) expensive we only offer it for the login process on the wiki and everything else is directed back to normal http.

That is not true. https is working for wiki and trac but many do not know. (comment:5:ticket:3914)

Only the redirect does not work for the wiki.

I already wrote 18 month ago, that there are methods to use proxies / caching on a machine using http and loopbacks and then only encrypt connections to other machine. An example would be http://linksunten.indymedia.org. I could get more info about the setup if needed.

comment:3 Changed 6 years ago by Tom Hughes

Thank you, but lessons in sucking eggs are not required. We are in fact already running a proxy in front of the wiki to help with the load.

Yes, you are right that trac is now globally enabled, because it gets a lot less use.

The wiki machine is fairly well loaded however, and the wiki gets a lot of use, hence why https is discouraged there. It may be possible to access it in that way but the intention is that only login traffic is passed over https which is why logins direct to https and then back to http afterwards.

Certainly accessing osm.org over https is not something we would recommend as we have no certificate for that name.

comment:4 in reply to:  3 Changed 6 years ago by skyper

Replying to TomH:

Certainly accessing osm.org over https is not something we would recommend as we have no certificate for that name.

Ok, I can live with typing the complete name and just was irritated by the "broken" redirection.

comment:5 Changed 6 years ago by skyper

It got even worse. Right now I am send to plain http on many redirects like https://wiki.openstreetmap.org.

This is definitely a bug.

comment:6 Changed 6 years ago by Grant Slater

Resolution: fixed
Status: reopenedclosed

SSL now fully enabled. Lets see how the hardware handles.

Note: See TracTickets for help on using tickets.