<?xml version="1.0"?>
<rss xmlns:dc="http://purl.org/dc/elements/1.1/" version="2.0">
  <channel>
    <title>Transition Technology: Ticket #875: Free HTTPS certificates from Let's Encrypt</title>
    <link>http://localhost:8080/trac/ticket/875</link>
    <description>&lt;p&gt;
From mid November 2015 &lt;a class="ext-link" href="https://www.letsencrypt.org/"&gt;&lt;span class="icon"&gt;​&lt;/span&gt;Let's Encrypt&lt;/a&gt; should be live, providing free SSL/TLS certificates. Currently the TN pays for a Gandi wild card cert, costing £130.50 a year, in addition most the &lt;a class="wiki" href="http://localhost:8080/trac/wiki/WordPress"&gt;WordPress&lt;/a&gt; sites on &lt;a class="wiki" href="http://localhost:8080/trac/wiki/ParrotServer"&gt;ParrotServer&lt;/a&gt; don't have certs due to the cost, see &lt;a class="new ticket" href="http://localhost:8080/trac/ticket/540" title="maintenance: HTTPS for WordPress sites (new)"&gt;ticket:540&lt;/a&gt;.
&lt;/p&gt;
&lt;p&gt;
The &lt;a class="ext-link" href="https://github.com/letsencrypt/letsencrypt"&gt;&lt;span class="icon"&gt;​&lt;/span&gt;Let's Encrypt code&lt;/a&gt; is designed to be set up to run automatically -- certs are only valid for 90 days and the automatic renewal process runs when the cert is 60 days old.
&lt;/p&gt;
&lt;p&gt;
We should consider if we want to use &lt;a class="ext-link" href="https://www.letsencrypt.org/"&gt;&lt;span class="icon"&gt;​&lt;/span&gt;Let's Encrypt&lt;/a&gt; and what things would need to be put in place to use it, the wild card cert is due to expire on 22/01/16.
&lt;/p&gt;
&lt;ol&gt;&lt;li&gt;&lt;a class="wiki" href="http://localhost:8080/trac/wiki/PuffinServer"&gt;PuffinServer&lt;/a&gt; -- are we still going to be running &lt;a class="wiki" href="http://localhost:8080/trac/wiki/PuffinServer"&gt;PuffinServer&lt;/a&gt; in January 2016? Is there any chance that we might be able to consider the suggestions in &lt;a class="closed ticket" href="http://localhost:8080/trac/ticket/754#comment:61" title="maintenance: Can we upgrade from PHP 5.3? (closed: wontfix)"&gt;ticket:754#comment:61&lt;/a&gt;? I'm not sure if I want to spend time trying to get Let's Encrypt working with &lt;a class="closed ticket" href="http://localhost:8080/trac/ticket/872" title="defect: BOA 2.4.6 (closed: wontfix)"&gt;a old version of BOA&lt;/a&gt;, up to date versions of BOA might &lt;a class="ext-link" href="https://github.com/omega8cc/boa/issues/500"&gt;&lt;span class="icon"&gt;​&lt;/span&gt;support it out of the box&lt;/a&gt;.
&lt;/li&gt;&lt;li&gt;&lt;a class="wiki" href="http://localhost:8080/trac/wiki/PenguinServer"&gt;PenguinServer&lt;/a&gt; -- this site hosts a lot of sites, see &lt;a class="ext-link" href="https://penguin.transitionnetwork.org/"&gt;&lt;span class="icon"&gt;​&lt;/span&gt;the listing&lt;/a&gt;, automating Let's Encrypt would probably be a hour or two of work, it might makes sense to upgrade it to Debian Jessie at the same time.
&lt;/li&gt;&lt;li&gt;&lt;a class="wiki" href="http://localhost:8080/trac/wiki/ParrotServer"&gt;ParrotServer&lt;/a&gt; -- I suggest we rebuild this server from scratch, this would enable it to have the latest version of the &lt;a class="ext-link" href="https://docs.webarch.net/wiki/Webarch_Secure_Hosting"&gt;&lt;span class="icon"&gt;​&lt;/span&gt;Webarch Secure Hosting scripts&lt;/a&gt; and this include support for fail2ban for &lt;a class="wiki" href="http://localhost:8080/trac/wiki/WordPress"&gt;WordPress&lt;/a&gt; and phpMyAdmin, thus solving &lt;a class="new ticket" href="http://localhost:8080/trac/ticket/871" title="maintenance: Brute Force Attacks Against WordPress Sites (new)"&gt;ticket:871&lt;/a&gt; and includes automatic provisioning of Let's Encrypt certs for sites.
&lt;/li&gt;&lt;/ol&gt;&lt;p&gt;
What do people think?
&lt;/p&gt;
</description>
    <language>en-us</language>
    <image>
      <title>Transition Technology</title>
      <url>/trac/chrome/site/TransitionNetwork-Logo-Web-Small.jpg</url>
      <link>http://localhost:8080/trac/ticket/875</link>
    </image>
    <generator>Trac 0.12.5</generator>
    <item>
      
        <dc:creator>chris</dc:creator>

      <pubDate>Mon, 05 Oct 2015 10:48:11 GMT</pubDate>
      <title>hours, totalhours changed</title>
      <link>http://localhost:8080/trac/ticket/875#comment:1</link>
      <guid isPermaLink="false">http://localhost:8080/trac/ticket/875#comment:1</guid>
      <description>
          &lt;ul&gt;
            &lt;li&gt;&lt;strong&gt;hours&lt;/strong&gt;
                changed from &lt;em&gt;0.0&lt;/em&gt; to &lt;em&gt;0.4&lt;/em&gt;
            &lt;/li&gt;
            &lt;li&gt;&lt;strong&gt;totalhours&lt;/strong&gt;
                changed from &lt;em&gt;0.0&lt;/em&gt; to &lt;em&gt;0.4&lt;/em&gt;
            &lt;/li&gt;
          &lt;/ul&gt;
      </description>
      <category>Ticket</category>
    </item><item>
      
        <dc:creator>paul</dc:creator>

      <pubDate>Mon, 05 Oct 2015 17:25:05 GMT</pubDate>
      <title></title>
      <link>http://localhost:8080/trac/ticket/875#comment:2</link>
      <guid isPermaLink="false">http://localhost:8080/trac/ticket/875#comment:2</guid>
      <description>
        &lt;pre class="wiki"&gt;Sounds good :)
On Mon, Oct 5, 2015 at 11:48 AM, Transition Technology Trac &amp;lt;
trac@tech.transitionnetwork.org&amp;gt; wrote:
&amp;gt; #875: Free HTTPS certificates from Let's Encrypt
&amp;gt; -------------------------------------+-------------------------------------
&amp;gt;                  Reporter:  chris    |                Owner:  chris
&amp;gt;                      Type:           |               Status:  new
&amp;gt;   maintenance                        |            Milestone:  Maintenance
&amp;gt;                  Priority:  major    |             Keywords:
&amp;gt;                 Component:  Live     |  Add Hours to Ticket:  0.4
&amp;gt;   server                             |          Total Hours:  0
&amp;gt; Estimated Number of Hours:  0        |
&amp;gt;                 Billable?:  1        |
&amp;gt; -------------------------------------+-------------------------------------
&amp;gt;  From mid November 2015 [https://www.letsencrypt.org/ Let's Encrypt]
&amp;gt; should
&amp;gt;  be live, providing free SSL/TLS certificates. Currently the TN pays for a
&amp;gt;  Gandi wild card cert, costing £130.50 a year, in addition most the
&amp;gt;  WordPress sites on ParrotServer don't have certs due to the cost, see
&amp;gt;  ticket:540.
&amp;gt;
&amp;gt;  The [https://github.com/letsencrypt/letsencrypt Let's Encrypt code] is
&amp;gt;  designed to be set up to run automatically -- certs are only valid for 90
&amp;gt;  days and the automatic renewal process runs when the cert is 60 days old.
&amp;gt;
&amp;gt;  We should consider if we want to use [https://www.letsencrypt.org/ Let's
&amp;gt;  Encrypt] and what things would need to be put in place to use it, the wild
&amp;gt;  card cert is due to expire on 22/01/16.
&amp;gt;
&amp;gt;  1. PuffinServer -- are we still going to be running PuffinServer in
&amp;gt;  January 2016? Is there any chance that we might be able to consider the
&amp;gt;  suggestions in ticket:754#comment:61? I'm not sure if I want to spend time
&amp;gt;  trying to get Let's Encrypt working with [ticket:872 a old version of
&amp;gt;  BOA], up to date versions of BOA might
&amp;gt;  [https://github.com/omega8cc/boa/issues/500 support it out of the box].
&amp;gt;  2. PenguinServer -- this site hosts a lot of sites, see
&amp;gt;  [https://penguin.transitionnetwork.org/ the listing], automating Let's
&amp;gt;  Encrypt would probably be a hour or two of work, it might makes sense to
&amp;gt;  upgrade it to Debian Jessie at the same time.
&amp;gt;  3. ParrotServer -- I suggest we rebuild this server from scratch, this
&amp;gt;  would enable it to have the latest version of the
&amp;gt;  [https://docs.webarch.net/wiki/Webarch_Secure_Hosting Webarch Secure
&amp;gt;  Hosting scripts] and this include support for fail2ban for WordPress and
&amp;gt;  phpMyAdmin, thus solving ticket:871 and includes automatic provisioning of
&amp;gt;  Let's Encrypt certs for sites.
&amp;gt;
&amp;gt;  What do people think?
&amp;gt;
&amp;gt; --
&amp;gt; Ticket URL: &amp;lt;https://tech.transitionnetwork.org/trac/ticket/875&amp;gt;
&amp;gt; Transition Technology &amp;lt;https://tech.transitionnetwork.org/trac&amp;gt;
&amp;gt; Support and issues tracking for the Transition Network Web Project.
&amp;gt;
--
Paul Booker
Drupal Support for Websites and Linux Servers
Website: http://www.paulbooker.co.uk
Tel: +44 01922 861636
&lt;/pre&gt;
      </description>
      <category>Ticket</category>
    </item>
 </channel>
</rss>