Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

neverssl.com serves content on port 443 #2

Open
jamespic opened this issue Jun 28, 2018 · 3 comments
Open

neverssl.com serves content on port 443 #2

jamespic opened this issue Jun 28, 2018 · 3 comments

Comments

@jamespic
Copy link

neverssl.com is serving https traffic on port 443. The certificate on https://neverssl.com is not valid for that domain (it looks to be a wildcard for *.cloudfront.net), but otherwise the content is the same as http://neverssl.com

@njh
Copy link

njh commented Jul 26, 2018

Could it/should it redirect to port 80?
Or better if it refused the connection? (I don't think CloudFront allows disabling port 443).

Getting a valid certificate setup on CloudFront isn't too much effort - and Amazon Certificate Manger is free.

@unitof
Copy link

unitof commented Feb 9, 2020

This may be by design—if it gets a valid HTTPS certificate some more security-aggressive browsers might auto-upgrade the connection to HTTPS.

@danielrparks
Copy link

Firefox in HTTPS-only mode will automatically go to the HTTPS version of the site, even though the certificate is not valid. This makes it impossible to use without disabling HTTPS-only mode, which may not be allowed by the administrator of a work computer.

@github-staff github-staff deleted a comment from mehdi-dev97 May 27, 2024
@github-staff github-staff deleted a comment from mehdi-dev97 May 27, 2024
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

4 participants