waltligon / orangefs

Official repository for PVFS/OrangeFS
Other
62 stars 7 forks source link

Read Me / Main Page Contains Insecure Links #103

Open anon314159 opened 9 months ago

anon314159 commented 9 months ago

Hello,

The main page and read me documentation contains insecure links. The lack of SSL/TLS could lead to MITM / Session Hijacking or other types of attacks. Apache/Nginx should be configured to either redirect clients to tcp port 443 or disallow clients on port 80 entirely.

Thank you.

waltligon commented 8 months ago

I appreciate the info - but I don’t follow you. I’m not sure which “main page” you mean, or which links you are referring to. If you can get me more specific info maybe I can see to it getting fixed.

Walt

On Jan 15, 2024, at 2:17 PM, anon314159 @.***> wrote:

Hello,

The main page and read me documentation contains insecure links. The lack of SSL/TLS could lead to MITM / Session Hijacking or other types of attacks. Apache/Nginx should be configured to either redirect clients to tcp port 443 or disallow clients on port 80 entirely.

Thank you.

— Reply to this email directly, view it on GitHub https://nam12.safelinks.protection.outlook.com/?url=https%3A%2F%2Fgithub.com%2Fwaltligon%2Forangefs%2Fissues%2F103&data=05%7C02%7Cwalt%40clemson.edu%7C275e23204f6c4ffdfcc008dc15fe9758%7C0c9bf8f6ccad4b87818d49026938aa97%7C0%7C0%7C638409430404635618%7CUnknown%7CTWFpbGZsb3d8eyJWIjoiMC4wLjAwMDAiLCJQIjoiV2luMzIiLCJBTiI6Ik1haWwiLCJXVCI6Mn0%3D%7C3000%7C%7C%7C&sdata=v5NHH2AbkD9UDVVM1cnP2qLoMze6ABOJ8cTExpDgneg%3D&reserved=0, or unsubscribe https://nam12.safelinks.protection.outlook.com/?url=https%3A%2F%2Fgithub.com%2Fnotifications%2Funsubscribe-auth%2FABURJULWJRQSKMNNZBYVK5LYOV6D3AVCNFSM6AAAAAB!%20B3W6G3OVHI2DSMVQWIX3LMV43ASLTON2WKOZSGA4DENJWGY3TGNA&data=05%7C02%7Cwalt%40clemson.edu%7C275e23204f6c4ffdfcc008dc15fe9758%7C0c9bf8f6ccad4b87818d49026938aa97%7C0%7C0%7C638409430404635618%7CUnknown%7CTWFpbGZsb3d8eyJWIjoiMC4wLjAwMDAiLCJQIjoiV2luMzIiLCJBTiI6Ik1haWwiLCJXVCI6Mn0%3D%7C3000%7C%7C%7C&sdata=7cBQjP6J9zwu0sCdkurKGdDr9dBRCdNUDzU2Xwf2v4o%3D&reserved=0. You are receiving this because you are subscribed to this thread.