Re: gnuplot.info unreachable (DNS failure)
Mojca Miklavec Groenhuis <[email protected]> Thu, 11 Sep 2025 02:18:12 +0200
| Newsgroups | gmane.comp.graphics.gnuplot.devel |
|---|---|
| Message-ID | <CALBOmsb=zsQ3empKzZm5KE1S-mOBDaFAeGjEcv8A6wDsHSD05A@mail.gmail.com> |
--===============0536311874847891500== Content-Type: multipart/alternative; boundary="000000000000c736ef063e7b7989" --000000000000c736ef063e7b7989 Content-Type: text/plain; charset="UTF-8" Content-Transfer-Encoding: quoted-printable On Thu, 11 Sept 2025, 00:45 Ethan A Merritt, <[email protected]> wrote: > > > On Wed, Sep 10, 2025 at 11:35=E2=80=AFAM Juh=C3=A1sz P=C3=A9ter <peter.ju= [email protected]> > wrote: > >> The error message means that the certificate required to serve the site >> over HTTPS is not valid for the domain name gnuplot.info (nor >> www.gnuplot.info >> <https://urldefense.com/v3/__http://www.gnuplot.info__;!!K-Hz7m0Vt54!hZA= tTCSEA3UZsTRDYd1Rlg-J8_Oq7DJZg-cJMaMoMBMcyZx3lwvCVqHE401p-ZikRUWZruc71FaDNh= ZkYYE3tw4$>). >> If you look at the certificate (offered by Firefox next to the error >> message), you can see that it was issued by Let's Encrypt to >> secureprojects.sourceforge.net, and it is valid for a large selection of >> other domain names, presumably all projects hosted by SF. >> > > Thank you for your insights. > > I think you are addressing a different issue - whether the connection > protocol is https or http. > Yes, this is not about DNS failure. I don't experience DNS failure, but see precisely the same errors/issues as Peter described. (Nowadays http should actually redirect to https. Modern browsers also refuse to show http pages.) It is not surprising that a certificate issued to SourceForge would not > mention gnuplot.info by name because that name is not connected to > SourceForge except in that (as I understand it) it currently redirects > queries to the actual gnuplot site gnuplot.sourceforge.net. > Except that it does matter for https. The hosting site needs to know that the certificate should also be for gnuplot.info and it needs to be explicit whether that is with or without www (or both). Either a separate certificate is needed for that, or the certificate used needs to be made aware that it needs to cover gnuplot.info. This really needs to be fixed on the hosting site, and usually the person in charge of the DNS is also needed in the process of making it work. Unless the administrators of gnuplot on SF have access to certificate settings (means you would also need to create and extend your own certificate), then SF support is really needed here to set it up. The current problem seems to be that the redirection itself fails in some > cases, or fails to pass through sufficient information > No. It's really a misconfigured site/certificate. > You still see the site, correct? Well ... yes and no, but the more correct answer is probably NO. By default you don't see the site because the web browser is protecting you from "the malicious site" until you approve an exception and security risk, but that is "an advanced use" (it is on purpose made difficult to do that). For completeness I should mention that the issue of connection via IPv6 as > opposed to IPv4 was raised earlier, and might be relevant, > It is possible that the site works correctly on IPv4 and fails with IPv6. My network right now doesn't support IPv6, so it's hard for me to check. It is unrelated to certificate issues, but it could hypothetically explain why DNS works for others and not for you if you have IPv6. (By correctly I mean resolving to the correct website. It still doesn't serve a compliant certificate.) Mojca > --000000000000c736ef063e7b7989 Content-Type: text/html; charset="UTF-8" Content-Transfer-Encoding: quoted-printable <div dir=3D"auto"><div><br><br><div class=3D"gmail_quote gmail_quote_contai= ner"><div dir=3D"ltr" class=3D"gmail_attr">On Thu, 11 Sept 2025, 00:45 Etha= n A Merritt, <<a href=3D"mailto:[email protected]">[email protected]</a>> w= rote:<br></div><blockquote class=3D"gmail_quote" style=3D"margin:0 0 0 .8ex= ;border-left:1px #ccc solid;padding-left:1ex"><div dir=3D"ltr"><div dir=3D"= ltr"><br></div><br><div class=3D"gmail_quote"><div dir=3D"ltr" class=3D"gma= il_attr">On Wed, Sep 10, 2025 at 11:35=E2=80=AFAM Juh=C3=A1sz P=C3=A9ter &l= t;<a href=3D"mailto:[email protected]" target=3D"_blank" rel=3D"nore= ferrer">[email protected]</a>> wrote:</div><blockquote class=3D"g= mail_quote" style=3D"margin:0px 0px 0px 0.8ex;border-left:1px solid rgb(204= ,204,204);padding-left:1ex"><div><div><div></div><div>The error message mea= ns that the certificate required to serve the site over HTTPS is not valid = for the domain name <a href=3D"http://gnuplot.info" target=3D"_blank" rel= =3D"noreferrer">gnuplot.info</a> (nor <a href=3D"https://urldefense.com/v3/= __http://www.gnuplot.info__;!!K-Hz7m0Vt54!hZAtTCSEA3UZsTRDYd1Rlg-J8_Oq7DJZg= -cJMaMoMBMcyZx3lwvCVqHE401p-ZikRUWZruc71FaDNhZkYYE3tw4$" target=3D"_blank" = rel=3D"noreferrer">www.gnuplot.info</a>). If you look at the certificate (o= ffered by Firefox next to the error message), you can see that it was issue= d by Let's Encrypt to <a href=3D"http://secureprojects.sourceforge.net"= target=3D"_blank" rel=3D"noreferrer">secureprojects.sourceforge.net</a>, a= nd it is valid for a large selection of other domain names, presumably all = projects hosted by SF. </div></div></div></blockquote><div><br></div><div>T= hank you for your insights.</div><div><br></div><div>I think you are addres= sing a different issue - whether the connection protocol is https or http.<= /div></div></div></blockquote></div></div><div dir=3D"auto"><br></div><div = dir=3D"auto">Yes, this is not about DNS failure. I don't experience DNS= failure, but see precisely the same errors/issues as Peter described.</div= ><div dir=3D"auto"><br></div><div dir=3D"auto">(Nowadays http should actual= ly redirect to https. Modern browsers also refuse to show http pages.)</div= ><div dir=3D"auto"><br></div><div dir=3D"auto"><div class=3D"gmail_quote gm= ail_quote_container"><blockquote class=3D"gmail_quote" style=3D"margin:0 0 = 0 .8ex;border-left:1px #ccc solid;padding-left:1ex"><div dir=3D"ltr"><div c= lass=3D"gmail_quote"><div> It is not surprising that a certificate issued t= o SourceForge would not mention <a href=3D"http://gnuplot.info" target=3D"_= blank" rel=3D"noreferrer">gnuplot.info</a> by name because that name is not= connected to SourceForge except in that (as I understand it) it currently = redirects queries to the actual gnuplot site <a href=3D"http://gnuplot.sour= ceforge.net" target=3D"_blank" rel=3D"noreferrer">gnuplot.sourceforge.net</= a>.</div></div></div></blockquote></div></div><div dir=3D"auto"><br></div><= div dir=3D"auto">Except that it does matter for https. The hosting site nee= ds to know that the certificate should also be for <a href=3D"http://gnuplo= t.info">gnuplot.info</a>=C2=A0 and it needs to be explicit whether that is = with or without www (or both).</div><div dir=3D"auto">Either a separate cer= tificate is needed for that, or the certificate used needs to be made aware= that it needs to cover <a href=3D"http://gnuplot.info">gnuplot.info</a>. T= his really needs to be fixed on the hosting site, and usually the person in= charge of the DNS is also needed in the process of making it work.</div><d= iv dir=3D"auto"><br></div><div dir=3D"auto">Unless the administrators of gn= uplot on SF have access to certificate settings (means you would also need = to create and extend your own certificate), then SF support is really neede= d here to set it up.=C2=A0</div><div dir=3D"auto"><br></div><div dir=3D"aut= o"><div class=3D"gmail_quote gmail_quote_container"><blockquote class=3D"gm= ail_quote" style=3D"margin:0 0 0 .8ex;border-left:1px #ccc solid;padding-le= ft:1ex"><div dir=3D"ltr"><div class=3D"gmail_quote"><div> The current probl= em seems to be that the redirection itself fails in some cases, or fails to= pass through sufficient information</div></div></div></blockquote></div></= div><div dir=3D"auto"><br></div><div dir=3D"auto">No. It's really a mis= configured site/certificate.</div><div dir=3D"auto"><br></div><div dir=3D"a= uto">> You still see the site, correct?</div><div dir=3D"auto"><br></div= ><div dir=3D"auto">Well ... yes and no, but the more correct answer is prob= ably NO. By default you don't see the site because the web browser is p= rotecting you from "the malicious site" until you approve an exce= ption and security risk, but that is "an advanced use" (it is on = purpose made difficult to do that).</div><div dir=3D"auto"><br></div><div d= ir=3D"auto"><div class=3D"gmail_quote gmail_quote_container"><blockquote cl= ass=3D"gmail_quote" style=3D"margin:0 0 0 .8ex;border-left:1px #ccc solid;p= adding-left:1ex"><div dir=3D"ltr"><div class=3D"gmail_quote"><div>For compl= eteness I should mention that the issue of connection via IPv6 as opposed t= o IPv4 was raised earlier, and might be relevant,</div></div></div></blockq= uote></div></div><div dir=3D"auto"><br></div><div dir=3D"auto">It is possib= le that the site works correctly on IPv4 and fails with IPv6. My network ri= ght now doesn't support IPv6, so it's hard for me to check. It is u= nrelated to certificate issues, but it could hypothetically explain why DNS= works for others and not for you if you have IPv6. (By correctly I mean re= solving to the correct website. It still doesn't serve a compliant cert= ificate.)</div><div dir=3D"auto"><br></div><div dir=3D"auto">Mojca</div><di= v dir=3D"auto"><div class=3D"gmail_quote gmail_quote_container"><blockquote= class=3D"gmail_quote" style=3D"margin:0 0 0 .8ex;border-left:1px #ccc soli= d;padding-left:1ex"> </blockquote></div></div></div> --000000000000c736ef063e7b7989-- --===============0536311874847891500== Content-Type: text/plain; charset="us-ascii" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit Content-Disposition: inline --===============0536311874847891500== Content-Type: text/plain; charset="us-ascii" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit Content-Disposition: inline _______________________________________________ gnuplot-beta mailing list [email protected] Membership management via: https://lists.sourceforge.net/lists/listinfo/gnuplot-beta --===============0536311874847891500==--