On 8/30/07, John Smith <[EMAIL PROTECTED]> wrote:
> > John Smith wrote, On 30/08/07 03:13:
> >
> >  > Is there a way to configure Cherokee to only bind to one port for TLS
> >  > mode? I don't need the classic 80 (http) and 443 (https)
> >  > configuration, I'd rather only serve on 443 and nothing on 80.
> >  > However, it seems "Port" must be defined, otherwise it still attempts
> >  > to open port 80...

This isn't necessarily  a bad thing...  Many people will automatically
try http rather than https.  If you simply set up a handler that
redirects all requests from http to https, then you will get the best
of both worlds: fewer confused people wondering why they can't connect
to http://yourdomain.dom/ and really only serve pages in the secure
domain.

--Vernon

> >  > BTW, something funny, I did set "Port 0" & "PortTLS 443" and that
> >  > seemed to work (I know 0 is not a true port). A quick 'netstat -an'
> >  > reveals nothing binding to port 0 (haha), although Cherokee reports
> >  > "Cherokee Web Server 0.5.6: Listening on ports 0 and 443" on startup.
> >  > Another look and it appears Cherokee picked an arbitrary port. Seems
> >  > every time it's started, it's a different port, randomly. Somehow not
> >  > what I expected, but interesting behavior nonetheless.
> >
> >On 8/30/07, Alvaro Lopez Ortega <[EMAIL PROTECTED]> wrote:
> >
> > Right now, there is no way to do that.
> >
> > My first impression after I read your mail was that it wasn't anything
> > more than a tiny patch, although when I was about to put my hands on
> > the code I realized that Cherokee core structure doesn't allow that
> > (at least in 0.6).
> >
> > I suppose this is one of those corner cases that Cherokee is not meant
> > to support. Supporting this kind of functionality would raise the
> > complexity of the core code, and therefore would make harder to add
> > and support the feature that the bast majority of people do require.
> >
> > If someone comes up if a clean solution for this issue, I will be more
> > than happy to apply it to trunk. Meanwhile I think that the best thing
> > you can do is to set your firewall to drop the incoming connections to
> > the http port (it isn't the perfect solution, I know).
> >
> > --
> > Greetings, alo.
> > http://www.alobbs.com
> >
>
> I fully understand about code design concept. Perhaps a future project
> down the road... Thank you for clearing that up however.
>
> V/R,
> JR
> _______________________________________________
> Cherokee mailing list
> [email protected]
> http://cherokee-project.com/cgi-bin/mailman/listinfo/cherokee
>
_______________________________________________
Cherokee mailing list
[email protected]
http://cherokee-project.com/cgi-bin/mailman/listinfo/cherokee

Reply via email to