On 8/30/07, John Smith <[EMAIL PROTECTED]> wrote: > > John Smith wrote, On 30/08/07 03:13: > > > > > Is there a way to configure Cherokee to only bind to one port for TLS > > > mode? I don't need the classic 80 (http) and 443 (https) > > > configuration, I'd rather only serve on 443 and nothing on 80. > > > However, it seems "Port" must be defined, otherwise it still attempts > > > to open port 80...
This isn't necessarily a bad thing... Many people will automatically try http rather than https. If you simply set up a handler that redirects all requests from http to https, then you will get the best of both worlds: fewer confused people wondering why they can't connect to http://yourdomain.dom/ and really only serve pages in the secure domain. --Vernon > > > BTW, something funny, I did set "Port 0" & "PortTLS 443" and that > > > seemed to work (I know 0 is not a true port). A quick 'netstat -an' > > > reveals nothing binding to port 0 (haha), although Cherokee reports > > > "Cherokee Web Server 0.5.6: Listening on ports 0 and 443" on startup. > > > Another look and it appears Cherokee picked an arbitrary port. Seems > > > every time it's started, it's a different port, randomly. Somehow not > > > what I expected, but interesting behavior nonetheless. > > > >On 8/30/07, Alvaro Lopez Ortega <[EMAIL PROTECTED]> wrote: > > > > Right now, there is no way to do that. > > > > My first impression after I read your mail was that it wasn't anything > > more than a tiny patch, although when I was about to put my hands on > > the code I realized that Cherokee core structure doesn't allow that > > (at least in 0.6). > > > > I suppose this is one of those corner cases that Cherokee is not meant > > to support. Supporting this kind of functionality would raise the > > complexity of the core code, and therefore would make harder to add > > and support the feature that the bast majority of people do require. > > > > If someone comes up if a clean solution for this issue, I will be more > > than happy to apply it to trunk. Meanwhile I think that the best thing > > you can do is to set your firewall to drop the incoming connections to > > the http port (it isn't the perfect solution, I know). > > > > -- > > Greetings, alo. > > http://www.alobbs.com > > > > I fully understand about code design concept. Perhaps a future project > down the road... Thank you for clearing that up however. > > V/R, > JR > _______________________________________________ > Cherokee mailing list > [email protected] > http://cherokee-project.com/cgi-bin/mailman/listinfo/cherokee > _______________________________________________ Cherokee mailing list [email protected] http://cherokee-project.com/cgi-bin/mailman/listinfo/cherokee
