Re: Installing Current breaks RH7.3 SSL

"Alex K" <[email protected]> Sat, 1 Feb 2003 21:17:51 +0200
Newsgroups gmane.network.up2date.current.devel
Message-ID <[email protected]>
as one of the NRH guys that imply otherwise, i must disagree. the SSL is =
not
an absolute requirement, especially for testing, if we take into account =
the
amount of trouble people have with this issue. Farthermore, an administra=
tor
may decide, that since his deployment takes place inside his internal LAN=
,
he doesn't need to secure the information exchanged between the client an=
d
the server, to avoid dealing with all the SSL related issues.=0D
=0D
Of course, i must agree that since the login information can potentially
contain confidential user data, an administrator should have the choice i=
f
to make some of the clients address the server using https, and he does -
NRH has an entire paragraph in it's documentation devoted to explanation
about configuring secure data transfer.=0D
=0D
Alex.=0D
 =0D
-------Original Message-------=0D
 =0D
From: [email protected]=0D
Date: =F9=E1=FA 01 =F4=E1=F8=E5=E0=F8 2003 19:22:37=0D
To: [email protected]=0D
Subject: [Current-server] Installing Current breaks RH7.3 SSL=0D
 =0D
On Sat, 2003-02-01 at 10:47, John Berninger wrote:=0D
 =0D
> SSL is an absolute requirement, even for testing. The client=0D
> has the ability to transfer package headers and packages via HTTP, but=0D
> the login information is always transferred using HTTPS. This is=0D
> because the login information can potentially contain confidential user=
=0D
> data, which should never be transmitted in the clear.=0D
 =0D
This REALLY needs to be made clear in the instructions, because the=0D
NRH-current guys imply otherwise.=0D
 =0D
In fact, I initially set up my server URL as http: rather than https:,=0D
and the initial configure *worked* and my initial attempt to update=0D
*worked*. It was only on subsequent invocations of client side up2date=0D
--configure that I got a traceback.=0D
 =0D
At that point, I switched to https: and got a certificate validation=0D
failure.=0D
 =0D
So the point is that this is an obscure bug that occurs several steps=0D
along the road, and should be documented up front.=0D
 =0D
shap=0D
 =0D
_______________________________________________=0D
Current-server mailing list=0D
[email protected]=0D
http://lists.dulug.duke.edu/mailman/listinfo/current-server=0D
=2E=20