Join GitHub today
GitHub is home to over 31 million developers working together to host and review code, manage projects, and build software together.
Sign upserve the rust-lang.org domain over https #13180
Comments
thestinger
added
the
A-infrastructure
label
Mar 28, 2014
thestinger
changed the title
serve the entire rust-lang.org domain over https
serve the rust-lang.org domain over https
Apr 1, 2014
This comment has been minimized.
This comment has been minimized.
|
This should apply to all subdomains ( @brson, what’s needed for this to happen? |
This comment has been minimized.
This comment has been minimized.
huonw
closed this
Aug 4, 2014
This comment has been minimized.
This comment has been minimized.
|
I hadn’t realized that #16123 was only about static.rust-lang.org and links to it. www.rust-lang.org and doc.rust-lang.org should of course be HTTPS as well. Could this be re-opened? |
cmr
reopened this
Dec 7, 2014
This comment has been minimized.
This comment has been minimized.
DomT4
commented
Dec 7, 2014
|
Presuming the If you went with self-signed certs sitting behind the Cloudflare protection, you'd actually spend less per year than it'd cost purchasing a wildcard cert to cover everything. Cloudflare allows you to stick self-signed certs on the server without it raising an enormous browser red-flag. Reasonably easy to setup, as well. |
This comment has been minimized.
This comment has been minimized.
|
It might also make sense to use whatever setup we already use for static.rust-lang.org. CC @brson |
This comment has been minimized.
This comment has been minimized.
|
The rust website is hosted on GitHub pages. It would need to be hosted somewhere else to serve it over https. |
This comment has been minimized.
This comment has been minimized.
|
It looks really bad when I see a big project like this that still hasn't gotten HTTPS on their website. What exactly is blocking this? It shouldn't be hard to do. If the current hosting can't provide it, it should be changed. |
XrXr
referenced this issue
Jan 30, 2015
Closed
Running the code on www.rust-lang.org doesn't work #21781
frewsxcv
referenced this issue
Feb 23, 2015
Closed
Use TLS / HSTS for the site, discourse, etc. #17914
This comment has been minimized.
This comment has been minimized.
This comment has been minimized.
This comment has been minimized.
DomT4
commented
Feb 23, 2015
This comment has been minimized.
This comment has been minimized.
|
Yes, thanks :) |
This comment has been minimized.
This comment has been minimized.
|
To do this we need to frob the nginx config to redirect www.rust-lang.org to GitHub pages, then update the DNS to point to the nginx server. |
This comment has been minimized.
This comment has been minimized.
sigmavirus24
commented
Jun 16, 2015
|
It'd also be pretty great if Rust became the third language in the "Good" category on https://httpswatch.com/programming#programming-languages |
This comment has been minimized.
This comment has been minimized.
|
I don't want this to come off as aggressive, but I'm genuinely wondering why this is taking so long? This shouldn't take more than 20 minutes to set up. Setting up a MITM attack to change the download links to malicious links is trivial, not to mention not having HTTPS is just plain unprofessional. |
This comment has been minimized.
This comment has been minimized.
edunham
referenced this issue
Jun 18, 2015
Closed
Infra RFC: Move rust-lang.org from github pages to S3/Cloudfront for SSL support #148
This comment has been minimized.
This comment has been minimized.
|
Status: https://www.rust-lang.org/ fixes the original issue of this ticket. http://rust-lang.org redirects to https://www.rust-lang.org. rust-lang/prev.rust-lang.org#165 will handle the issues raised in the ensuing discussion. At least we're up to "mediocre" on https://httpswatch.com/programming#programming-languages |
This comment has been minimized.
This comment has been minimized.
|
Yay! Nice work! (This issue should probably be closed now.) |
edunham
closed this
Aug 5, 2015
This comment has been minimized.
This comment has been minimized.
tanriol
commented
Mar 20, 2016
|
The github's certificate is still in use for https://blog.rust-lang.org (rust-lang/blog.rust-lang.org#81). |
thestinger commentedMar 28, 2014
I don't think there's really any need to have http for the site at all. Any non-TLS location is a chance for an attacker to send users to a malicious download.