Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

website does not allow https connection #11

Closed
R00dRallec opened this issue Jan 31, 2018 · 29 comments
Closed

website does not allow https connection #11

R00dRallec opened this issue Jan 31, 2018 · 29 comments

Comments

@R00dRallec
Copy link

strawberryperl.com can not be accessed via https. This enables man in the middle attacks which can manipulate the downloaded strawberry perl interpreter.
Even though the checksums are provided, they are also not available via https.

Last but not least, the executable installer is not signed which enables possible attacks.

Accessing the website via https://strawberryperl.com leads to a certificate error:
Certificate issued to: sni.dreamhost.com
Issued by: sni.dreamhost.com

@xenu
Copy link
Contributor

xenu commented Feb 10, 2018

AFAIK strawberryperl.com is hosted on dreamhost and it seems that its control panel has support for free letsencrypt certs: https://help.dreamhost.com/hc/en-us/articles/216539548-How-do-I-add-a-free-Let-s-Encrypt-certificate-

I guess it shouldn't be too much work to enable it.

@kmx
Copy link
Member

kmx commented Apr 7, 2018

@adamkennedy ping ^^

@kmx
Copy link
Member

kmx commented Jun 20, 2018

@adamkennedy ping

a letter from Google:

To owner of http://strawberryperl.com/,

In July 2018, Chrome (version 68) will start showing 
'NOT SECURE' warnings for all HTTP pages that it opens.

To prevent a 'Not Secure' warning from appearing when Chrome 
users visit your site, you must serve your site over HTTPS. 
Migrate your site to HTTPS to avoid triggering the new 
warning on your site and to help protect users' data.

@adamkennedy
Copy link
Contributor

adamkennedy commented Jul 18, 2018 via email

@kmx
Copy link
Member

kmx commented Jul 22, 2018

Pong

Hi Adam

could you please try to enable TLS via Let's Encrypt on strawberryperl.com hosting? It should be free and supported by Dreamhost - see https://help.dreamhost.com/hc/en-us/articles/216539548-How-do-I-add-a-free-Let-s-Encrypt-certificate-

@lucasmerlin
Copy link

lucasmerlin commented Jul 30, 2018

Soo uhh it seems like strawberryperl.com is completely down now?
Tested from my pc and from a google hosted vm:

$ ping strawberryperl.com
ping: strawberryperl.com: No address associated with hostname

@kmx
Copy link
Member

kmx commented Jul 30, 2018

@adamkennedy could you please have a look at this?

@redfast00
Copy link

@adamkennedy can you please enable HTTPS?

@kmx
Copy link
Member

kmx commented Nov 23, 2019

@adamkennedy is there a chance that you will find some spare time and set up the TLS on strawberryperl.com website?

@sjn
Copy link

sjn commented Jan 16, 2020

@adamkennedy or perhaps give someone else credentials to do this? (You can ping me if you need help finding someone :) )

@sisyphus
Copy link

As of about 2 months ago, I can't access webpages or download files from Strawberry Perl to my home network.
This issue of mine would not exist if Strawberry Perl provided https access.
(For some reason. my ISP has started denying me http access to many files on the internet.)

To be clear, I'm not saying it's Strawberry Perl's fault that I can't access the website - that would be an unreasonable assertion.
But that's the way it is for me at the moment.

See https://www.perlmonks.org/?node_id=11112755 for more details of my situation (and workaround).

Cheers,
Rob

@MartinMcGrath
Copy link

This will become a more of an issue shortly:

https://security.googleblog.com/2020/02/protecting-users-from-insecure_6.html

Today we’re announcing that Chrome will gradually ensure that secure (HTTPS) pages only download secure files. In a series of steps outlined below, we’ll start blocking "mixed content downloads" (non-HTTPS downloads started on secure pages).

As a first step, we are focusing on insecure downloads started on secure pages. These cases are especially concerning because Chrome currently gives no indication to the user that their privacy and security are at risk.

Starting in Chrome 82 (to be released April 2020), Chrome will gradually start warning on, and later blocking, these mixed content downloads.

@kmx
Copy link
Member

kmx commented Feb 17, 2020

ping @adamkennedy - we really, really need to set up the TLS on strawberryperl.com website

@sisyphus
Copy link

I don't know if this will help establish contact with @adamkennedy, but this is he :
https://www.linkedin.com/in/adamatalias

There's a contact link on that page to his personal website: http://ali.as/

I can't access that ali.as site to see what's there because that is (apparently) yet another page to which my http access is being denied.

@MartinMcGrath
Copy link

http://ali.as/contact.html returns a 'not found', going back several years on the waybackmachine hasn't provided a working page.

@rai-gaurav
Copy link

rai-gaurav commented Mar 23, 2020

@sisyphus I have asked the similar question on https://www.reddit.com/r/perl/comments/epihpr/httpstrawberryperlcom_on_https/. As mentioned in comment 'There is a mirror hosted at https://strawberry.perl.bot/'. You can use that for now. It is manged by https://www.reddit.com/user/simcop2387/

I also faced similar problem in past and right now using it.Only thing is - maybe it can take some time for the new version to appear. e.g. for now there is no Perl 5.30.2.1 on that link which was release couple of days back. But, it will get the work done for now.

@MartinMcGrath
Copy link

MartinMcGrath commented Mar 23, 2020

@sudo-batman

Can this also mirror http://strawberryperl.com/package/kmx/ ?

Apologies, you aren't the person I should be asking :) If you frequent reddit could you please pass that on to simcop2387?

I've emailed adamk at the cpan address some time ago, asking if this general issue can be addressed.

@simcop2387
Copy link

@MartinMcGrath Didn't get a message through reddit or anything but I happened to be checking this thread today. My home internet is broken at the moment (ISP tech coming in a few hours). Once that's fixed I'll get that added. I had no idea that was there. I'll do some digging to find any other packages in there too.

@MartinMcGrath
Copy link

@simcop2387 Fantastic, thanks for the help.

@simcop2387
Copy link

@MartinMcGrath After a harrowing 8.5 days of tethered cell phone internet, I am finally back in business with real internet. I'm grabbing those packages now and will have them uploaded asap. It's already looking much larger than I initially expected at first glance (up to 3 gigs and going)

@simcop2387
Copy link

And upload is done.

@MartinMcGrath
Copy link

@simcop2387 This is fantastic thanks

@adamkennedy Is there any chance strawberryperl.com can start using letsencrypt?

@pbcole
Copy link

pbcole commented Jul 13, 2020

Would be great it this can be done... I had been using strawberry.perl.bot as an alternative https location, but that's failing to work for me today - Chrome reporting ERR_SSL_VERSION_OR_CIPHER_MISMATCH.
Having strawberryperl.com behind https is definitely the way to go. is there anything I can do to help?

@ibrierley
Copy link

Who owns the domain, could it be pointed to the alternative site for the time ? (or is it tied in with the hosting).

@MartinMcGrath
Copy link

@ibrierley domains tend not to be tied to hosting in this manner, however the mirror mentioned above is no longer functional, and that doesn't address the real issue, all of the other existing links and documentation already pointing to strawberryperl.com.

@MartinMcGrath
Copy link

It seems that Mark Keating is currently working to resolve this issue.

@MartinMcGrath
Copy link

Looks like the issue can be closed: https://strawberryperl.com/

@ap
Copy link
Contributor

ap commented Dec 17, 2020

More to the point,

$ curl -I http://strawberryperl.com/
HTTP/1.1 301 Moved Permanently
Date: Thu, 17 Dec 2020 22:15:16 GMT
Server: Apache
Location: https://strawberryperl.com/
Content-Type: text/html; charset=iso-8859-1

(Emphasis mine.)

@kmx
Copy link
Member

kmx commented Feb 4, 2021

Solved

@kmx kmx closed this as completed Feb 4, 2021
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests