<?xml version="1.0"?>
<rss xmlns:dc="http://purl.org/dc/elements/1.1/" version="2.0">
  <channel>
    <title>Transition Technology: Ticket #920: SSL weirdness?</title>
    <link>http://localhost:8080/trac/ticket/920</link>
    <description>&lt;p&gt;
Hi Chris
&lt;/p&gt;
&lt;p&gt;
So Paul put the site into maintenance mode, took a database dump and then tried to re-enable live mode using the drush command.
&lt;/p&gt;
&lt;p&gt;
It seems it came out of maintenance mode OK, but we're now getting this certificate error.
&lt;/p&gt;
&lt;p&gt;
I have changed the Zone file on Gandi in the meantime, but this doesn't seem to be propagating.
&lt;/p&gt;
&lt;p&gt;
Any ideas?
&lt;/p&gt;
&lt;p&gt;
Thanks
&lt;/p&gt;
&lt;p&gt;
Sam
&lt;/p&gt;
</description>
    <language>en-us</language>
    <image>
      <title>Transition Technology</title>
      <url>/trac/chrome/site/TransitionNetwork-Logo-Web-Small.jpg</url>
      <link>http://localhost:8080/trac/ticket/920</link>
    </image>
    <generator>Trac 0.12.5</generator>
    <item>
      
        <dc:creator>sam</dc:creator>

      <pubDate>Thu, 14 Jul 2016 20:22:10 GMT</pubDate>
      <title>attachment set</title>
      <link>http://localhost:8080/trac/ticket/920</link>
      <guid isPermaLink="false">http://localhost:8080/trac/ticket/920</guid>
      <description>
          &lt;ul&gt;
            &lt;li&gt;&lt;strong&gt;attachment&lt;/strong&gt;
                set to &lt;em&gt;Screen Shot 2016-07-14 at 20.08.05.png&lt;/em&gt;
            &lt;/li&gt;
          &lt;/ul&gt;
      </description>
      <category>Ticket</category>
    </item><item>
      
        <dc:creator>sam</dc:creator>

      <pubDate>Thu, 14 Jul 2016 23:10:13 GMT</pubDate>
      <title>status changed; resolution set</title>
      <link>http://localhost:8080/trac/ticket/920#comment:1</link>
      <guid isPermaLink="false">http://localhost:8080/trac/ticket/920#comment:1</guid>
      <description>
          &lt;ul&gt;
            &lt;li&gt;&lt;strong&gt;status&lt;/strong&gt;
                changed from &lt;em&gt;new&lt;/em&gt; to &lt;em&gt;closed&lt;/em&gt;
            &lt;/li&gt;
            &lt;li&gt;&lt;strong&gt;resolution&lt;/strong&gt;
                set to &lt;em&gt;fixed&lt;/em&gt;
            &lt;/li&gt;
          &lt;/ul&gt;
      </description>
      <category>Ticket</category>
    </item><item>
      
        <dc:creator>chris</dc:creator>

      <pubDate>Fri, 15 Jul 2016 09:38:11 GMT</pubDate>
      <title>hours, totalhours changed</title>
      <link>http://localhost:8080/trac/ticket/920#comment:2</link>
      <guid isPermaLink="false">http://localhost:8080/trac/ticket/920#comment:2</guid>
      <description>
          &lt;ul&gt;
            &lt;li&gt;&lt;strong&gt;hours&lt;/strong&gt;
                changed from &lt;em&gt;0.0&lt;/em&gt; to &lt;em&gt;0.25&lt;/em&gt;
            &lt;/li&gt;
            &lt;li&gt;&lt;strong&gt;totalhours&lt;/strong&gt;
                changed from &lt;em&gt;0.0&lt;/em&gt; to &lt;em&gt;0.25&lt;/em&gt;
            &lt;/li&gt;
          &lt;/ul&gt;
        &lt;p&gt;
Sorry I wasn't able to look at this last night, there are 3 things that, I would suggest, should be addressed:
&lt;/p&gt;
&lt;ol&gt;&lt;li&gt;For people who didn't visit the site when it had a HSTS header can now login using an unencrypted connection, thus sending their password in the clear, this is the first time that has been allowed since the Drupal site was set up. There should be a &lt;tt&gt;Redirect&lt;/tt&gt; in place here: &lt;a class="ext-link" href="http://transitionnetwork.org/user/login"&gt;&lt;span class="icon"&gt;​&lt;/span&gt;http://transitionnetwork.org/user/login&lt;/a&gt; (if you follow this link and get the HTTPS page it is because HSTS is causing your client to only request the encrypted version of the page, try with a new web browser and you can login using a unencrypted connection.)
&lt;/li&gt;&lt;/ol&gt;&lt;ol start="2"&gt;&lt;li&gt;The intermediate certs are not sent by the server, see &lt;a class="ext-link" href="https://www.ssllabs.com/ssltest/analyze.html?d=transitionnetwork.org"&gt;&lt;span class="icon"&gt;​&lt;/span&gt;https://www.ssllabs.com/ssltest/analyze.html?d=transitionnetwork.org&lt;/a&gt; and &lt;a class="ext-link" href="https://wiki.gandi.net/en/ssl/intermediate"&gt;&lt;span class="icon"&gt;​&lt;/span&gt;https://wiki.gandi.net/en/ssl/intermediate&lt;/a&gt;
&lt;/li&gt;&lt;/ol&gt;&lt;ol start="3"&gt;&lt;li&gt;The HTTPS version of the site is no longer sending a HSTS header, the &lt;tt&gt;Header&lt;/tt&gt; directive needed is documented here &lt;a class="ext-link" href="https://docs.webarch.net/wiki/HTAccess#Enforcing_HTTPS"&gt;&lt;span class="icon"&gt;​&lt;/span&gt;https://docs.webarch.net/wiki/HTAccess#Enforcing_HTTPS&lt;/a&gt;
&lt;/li&gt;&lt;/ol&gt;
      </description>
      <category>Ticket</category>
    </item><item>
      
        <dc:creator>chris</dc:creator>

      <pubDate>Fri, 15 Jul 2016 09:57:20 GMT</pubDate>
      <title>attachment set</title>
      <link>http://localhost:8080/trac/ticket/920</link>
      <guid isPermaLink="false">http://localhost:8080/trac/ticket/920</guid>
      <description>
          &lt;ul&gt;
            &lt;li&gt;&lt;strong&gt;attachment&lt;/strong&gt;
                set to &lt;em&gt;mixed-content.png&lt;/em&gt;
            &lt;/li&gt;
          &lt;/ul&gt;
      </description>
      <category>Ticket</category>
    </item><item>
      
        <dc:creator>chris</dc:creator>

      <pubDate>Fri, 15 Jul 2016 09:58:29 GMT</pubDate>
      <title>hours, totalhours changed</title>
      <link>http://localhost:8080/trac/ticket/920#comment:3</link>
      <guid isPermaLink="false">http://localhost:8080/trac/ticket/920#comment:3</guid>
      <description>
          &lt;ul&gt;
            &lt;li&gt;&lt;strong&gt;hours&lt;/strong&gt;
                changed from &lt;em&gt;0.0&lt;/em&gt; to &lt;em&gt;0.1&lt;/em&gt;
            &lt;/li&gt;
            &lt;li&gt;&lt;strong&gt;totalhours&lt;/strong&gt;
                changed from &lt;em&gt;0.25&lt;/em&gt; to &lt;em&gt;0.35&lt;/em&gt;
            &lt;/li&gt;
          &lt;/ul&gt;
        &lt;ol start="4"&gt;&lt;li&gt;People are going to be getting even more mixed content warnings than before, when the site was on &lt;a class="wiki" href="http://localhost:8080/trac/wiki/PuffinServer"&gt;PuffinServer&lt;/a&gt; there was an issue, which was never resolved with the slide show on the front page, see &lt;a class="closed ticket" href="http://localhost:8080/trac/ticket/680" title="defect: Mixed content: HTTP content on HTTPS version of site (closed: wontfix)"&gt;ticket:680&lt;/a&gt;, but now are additional images embedded in the HTTPS front page via HTTP, eg &lt;a class="ext-link" href="http://www.transitionnetwork.org/sites/default/files/imagecache/featured_image_thumb/sites/www.transitionnetwork.org/files/romaniafood.jpg"&gt;&lt;span class="icon"&gt;​&lt;/span&gt;http://www.transitionnetwork.org/sites/default/files/imagecache/featured_image_thumb/sites/www.transitionnetwork.org/files/romaniafood.jpg&lt;/a&gt; &lt;a style="padding:0; border:none" href="http://localhost:8080/trac/attachment/ticket/920/mixed-content.png"&gt;&lt;img src="http://localhost:8080/trac/raw-attachment/ticket/920/mixed-content.png" /&gt;&lt;/a&gt;
&lt;/li&gt;&lt;/ol&gt;&lt;ol start="5"&gt;&lt;li&gt;Content loaded from the dev site, on the live front page, is not available via HTTPS, eg this image &lt;a class="ext-link" href="http://dev.transitionnetwork.org/sites/default/files/imagecache/slideshow_660/sites/www.transitionnetwork.org/files/images/slides/iraq8.jpg"&gt;&lt;span class="icon"&gt;​&lt;/span&gt;http://dev.transitionnetwork.org/sites/default/files/imagecache/slideshow_660/sites/www.transitionnetwork.org/files/images/slides/iraq8.jpg&lt;/a&gt; can't be accessed at &lt;a class="ext-link" href="https://dev.transitionnetwork.org/sites/default/files/imagecache/slideshow_660/sites/www.transitionnetwork.org/files/images/slides/iraq8.jpg"&gt;&lt;span class="icon"&gt;​&lt;/span&gt;https://dev.transitionnetwork.org/sites/default/files/imagecache/slideshow_660/sites/www.transitionnetwork.org/files/images/slides/iraq8.jpg&lt;/a&gt;
&lt;/li&gt;&lt;/ol&gt;
      </description>
      <category>Ticket</category>
    </item><item>
      
        <dc:creator>paul</dc:creator>

      <pubDate>Fri, 15 Jul 2016 11:10:08 GMT</pubDate>
      <title></title>
      <link>http://localhost:8080/trac/ticket/920#comment:4</link>
      <guid isPermaLink="false">http://localhost:8080/trac/ticket/920#comment:4</guid>
      <description>
        &lt;p&gt;
Thanks for the feedback Chris. I'll go through these now.
&lt;/p&gt;
&lt;ol&gt;&lt;li&gt;Fixed.
&lt;/li&gt;&lt;/ol&gt;
      </description>
      <category>Ticket</category>
    </item><item>
      
        <dc:creator>paul</dc:creator>

      <pubDate>Fri, 15 Jul 2016 11:40:04 GMT</pubDate>
      <title></title>
      <link>http://localhost:8080/trac/ticket/920#comment:5</link>
      <guid isPermaLink="false">http://localhost:8080/trac/ticket/920#comment:5</guid>
      <description>
        &lt;p&gt;
@Sam
&lt;/p&gt;
&lt;p&gt;
1 The website now has the canonical URL &lt;a class="ext-link" href="https://transitionnetwork.org"&gt;&lt;span class="icon"&gt;​&lt;/span&gt;https://transitionnetwork.org&lt;/a&gt;
&lt;/p&gt;
&lt;p&gt;
2 and 3.  Would you like me to explore 2 and 3?  This looks to be something that would be better managed by Chris?
&lt;/p&gt;
&lt;p&gt;
4  This looks to be a problem with the slideshow module. The image is requested over HTTPS but is delivered over HTTPS. Let me know if this needs to be investigated further.
&lt;/p&gt;
&lt;p&gt;
&lt;a class="ext-link" href="https://transitionnetwork.org/admin/content/node-type/slide/fields/field_slide_destination_link"&gt;&lt;span class="icon"&gt;​&lt;/span&gt;https://transitionnetwork.org/admin/content/node-type/slide/fields/field_slide_destination_link&lt;/a&gt;
&lt;a class="ext-link" href="https://transitionnetwork.org/node/46457/edit"&gt;&lt;span class="icon"&gt;​&lt;/span&gt;https://transitionnetwork.org/node/46457/edit&lt;/a&gt;
&lt;/p&gt;
&lt;p&gt;
5 &lt;a class="ext-link" href="http://www.transitionnetwork.org/sites/default/files/imagecache/slideshow_660/sites/www.transitionnetwork.org/files/images/slides/iraq8.jpg"&gt;&lt;span class="icon"&gt;​&lt;/span&gt;http://www.transitionnetwork.org/sites/default/files/imagecache/slideshow_660/sites/www.transitionnetwork.org/files/images/slides/iraq8.jpg&lt;/a&gt; is now redirecting to &lt;a class="ext-link" href="https://transitionnetwork.org/sites/default/files/imagecache/slideshow_660/sites/www.transitionnetwork.org/files/images/slides/iraq8.jpg"&gt;&lt;span class="icon"&gt;​&lt;/span&gt;https://transitionnetwork.org/sites/default/files/imagecache/slideshow_660/sites/www.transitionnetwork.org/files/images/slides/iraq8.jpg&lt;/a&gt;.
&lt;/p&gt;
      </description>
      <category>Ticket</category>
    </item>
 </channel>
</rss>