secondlife / jira-archive

2 stars 0 forks source link

[BUG-41678] SSL use - don't get blamed - but and do it right #13162

Open sl-service-account opened 7 years ago

sl-service-account commented 7 years ago

Steps to Reproduce

Surfing to http://status.secondlifegrid.net to see whats up.

Actual Behavior

today is grid-MainD(MAINtance-Day) So we all run to http://status.secondlifegrid.net when seeing anything. But newer Browsers report correctly that something is wrong. Here firefox(nightly flavor in this case) warn if pages do not use SSL and warn if pages use SSL wrong.

Here the page should use SSL and already have the most it needs for. Only the certificate is wrong.

Expected Behavior

the nice SL-status-page telling us briefly whats up.

The page is somewhat secure and that is shown without a warning

Other information

Please keep in mind, that most visitors(of SLs status-page) are maybe already in a bad mood. So its generally seen as good idea to give them not further downers to their mood. And briefly tell whats up and will be nice soon.

Its no problem to outsource such. But pleeeaaase do it right!

Attachments

Original Jira Fields | Field | Value | | ------------- | ------------- | | Issue | BUG-41678 | | Summary | SSL use - don't get blamed - but and do it right | | Type | Bug | | Priority | Unset | | Status | Accepted | | Resolution | Accepted | | Reporter | Dil Spitz (dil.spitz) | | Created at | 2017-04-04T16:16:55Z | | Updated at | 2017-04-05T21:48:46Z | ``` { 'Business Unit': ['Platform'], 'Date of First Response': '2017-04-04T11:26:27.786-0500', "Is there anything you'd like to add?": 'Please keep in mind, that most visitors(of SLs status-page) are maybe already in a bad mood.\r\nSo its generally seen as good idea to give them not further downers to their mood. And briefly tell whats up and will be nice soon.\r\n\r\nIts no problem to outsource such. _But_ ??pleeeaaase?? do it right!', 'ReOpened Count': 0.0, 'Severity': 'Unset', 'System': 'Website', 'Target Viewer Version': 'viewer-development', 'What just happened?': 'today is grid-MainD(MAINtance-Day)\r\nSo we all run to http://status.secondlifegrid.net when seeing anything.\r\nBut newer Browsers report correctly that something is wrong.\r\nHere firefox(nightly flavor in this case) warn if pages do not use SSL and warn if pages use SSL wrong.\r\n\r\nHere the page should use SSL and already have the most it needs for. Only the certificate is wrong.', 'What were you doing when it happened?': 'Surfing to [http://status.secondlifegrid.net] to see whats up.', 'What were you expecting to happen instead?': 'the nice SL-status-page telling us briefly whats up.\r\n\r\nThe page is somewhat ??secure?? and that is shown without a ??warning??', } ```
sl-service-account commented 7 years ago

Chaser Zaks commented at 2017-04-04T16:26:28Z

This I would like to see. HTTPS on the status page would be nice especially since there are SMS/Phone/Email subscription options for updates on the page.

sl-service-account commented 7 years ago

Grumpity Linden commented at 2017-04-05T21:10:17Z

boom!

sl-service-account commented 7 years ago

Dil Spitz commented at 2017-04-05T21:48:46Z

\o/ the new certificate has its 'Subject Alt Name' now (DNS Name: status.secondlifegrid.net) and all looks bright :)