Ticket #409 (closed defect: fixed)
HTTPS Security Issues
Reported by: | chris | Owned by: | chris |
---|---|---|---|
Priority: | minor | Milestone: | |
Component: | Live server | Keywords: | |
Cc: | laura, jim | Estimated Number of Hours: | 1.0 |
Add Hours to Ticket: | 0 | Billable?: | yes |
Total Hours: | 1.0 |
Description
There are some issues that are highlighted here:
Overall Rating: F Zero
Chain issues Incorrect order
This server is vulnerable to the BEAST attack (more info https://community.qualys.com/blogs/securitylabs/2011/10/17/mitigating-the-beast-attack-on-tls )
https://www.ssllabs.com/ssltest/analyze.html?d=transitionnetwork.org
That should be fixed on both servers and the documentation should be updated to match:
Change History
Note: See
TracTickets for help on using
tickets.
On quince this apache config:
Was changed to the following for all virtual servers:
And the gandi intermediate cert was recreated:
And the docs updated, wiki:NewLiveServer#HTTPS
For kiwi, this nginx configuration:
Was updated to:
The nginx chained cert was recreated:
And now kiwi also scores a A: https://www.ssllabs.com/ssltest/analyze.html?d=kiwi%2etransitionnetwork%2eorg&s=81%2e95%2e52%2e78
And the notes here have been updated wiki:SecurityInfo