Re: Installing Current breaks RH7.3 SSL
"Alex K" <[email protected]> Sat, 1 Feb 2003 21:17:51 +0200
| Newsgroups | gmane.network.up2date.current.devel |
|---|---|
| Message-ID | <[email protected]> |
as one of the NRH guys that imply otherwise, i must disagree. the SSL is = not an absolute requirement, especially for testing, if we take into account = the amount of trouble people have with this issue. Farthermore, an administra= tor may decide, that since his deployment takes place inside his internal LAN= , he doesn't need to secure the information exchanged between the client an= d the server, to avoid dealing with all the SSL related issues.=0D =0D Of course, i must agree that since the login information can potentially contain confidential user data, an administrator should have the choice i= f to make some of the clients address the server using https, and he does - NRH has an entire paragraph in it's documentation devoted to explanation about configuring secure data transfer.=0D =0D Alex.=0D =0D -------Original Message-------=0D =0D From: [email protected]=0D Date: =F9=E1=FA 01 =F4=E1=F8=E5=E0=F8 2003 19:22:37=0D To: [email protected]=0D Subject: [Current-server] Installing Current breaks RH7.3 SSL=0D =0D On Sat, 2003-02-01 at 10:47, John Berninger wrote:=0D =0D > SSL is an absolute requirement, even for testing. The client=0D > has the ability to transfer package headers and packages via HTTP, but=0D > the login information is always transferred using HTTPS. This is=0D > because the login information can potentially contain confidential user= =0D > data, which should never be transmitted in the clear.=0D =0D This REALLY needs to be made clear in the instructions, because the=0D NRH-current guys imply otherwise.=0D =0D In fact, I initially set up my server URL as http: rather than https:,=0D and the initial configure *worked* and my initial attempt to update=0D *worked*. It was only on subsequent invocations of client side up2date=0D --configure that I got a traceback.=0D =0D At that point, I switched to https: and got a certificate validation=0D failure.=0D =0D So the point is that this is an obscure bug that occurs several steps=0D along the road, and should be documented up front.=0D =0D shap=0D =0D _______________________________________________=0D Current-server mailing list=0D [email protected]=0D http://lists.dulug.duke.edu/mailman/listinfo/current-server=0D =2E=20