Vernon Mauery wrote, On 30/08/07 16:08:
 > On 8/30/07, John Smith <[EMAIL PROTECTED]> wrote:
 >>> John Smith wrote, On 30/08/07 03:13:
 >>>
 >>>  > Is there a way to configure Cherokee to only bind to one port for TLS
 >>>  > mode? I don't need the classic 80 (http) and 443 (https)
 >>>  > configuration, I'd rather only serve on 443 and nothing on 80.
 >>>  > However, it seems "Port" must be defined, otherwise it still attempts
 >>>  > to open port 80...
 >
 > This isn't necessarily  a bad thing...  Many people will automatically
 > try http rather than https.  If you simply set up a handler that
 > redirects all requests from http to https, then you will get the best
 > of both worlds: fewer confused people wondering why they can't connect
 > to http://yourdomain.dom/ and really only serve pages in the secure
 > domain.

Actually, if you use the "OnlySecure" property the server will take
care of letting the client know that the resource is only available
through https, and if the client supports it the protocol will be
automatically upgraded using the same connection. Isn't it pretty
cool?

 > --Vernon
 >
 >>>  > BTW, something funny, I did set "Port 0" & "PortTLS 443" and that
 >>>  > seemed to work (I know 0 is not a true port). A quick 'netstat -an'
 >>>  > reveals nothing binding to port 0 (haha), although Cherokee reports
 >>>  > "Cherokee Web Server 0.5.6: Listening on ports 0 and 443" on startup.
 >>>  > Another look and it appears Cherokee picked an arbitrary port. Seems
 >>>  > every time it's started, it's a different port, randomly. Somehow not
 >>>  > what I expected, but interesting behavior nonetheless.
 >>>
 >>> On 8/30/07, Alvaro Lopez Ortega <[EMAIL PROTECTED]> wrote:
 >>>
 >>> Right now, there is no way to do that.
 >>>
 >>> My first impression after I read your mail was that it wasn't anything
 >>> more than a tiny patch, although when I was about to put my hands on
 >>> the code I realized that Cherokee core structure doesn't allow that
 >>> (at least in 0.6).
 >>>
 >>> I suppose this is one of those corner cases that Cherokee is not meant
 >>> to support. Supporting this kind of functionality would raise the
 >>> complexity of the core code, and therefore would make harder to add
 >>> and support the feature that the bast majority of people do require.
 >>>
 >>> If someone comes up if a clean solution for this issue, I will be more
 >>> than happy to apply it to trunk. Meanwhile I think that the best thing
 >>> you can do is to set your firewall to drop the incoming connections to
 >>> the http port (it isn't the perfect solution, I know).
 >>>
 >>> --
 >>> Greetings, alo.
 >>> http://www.alobbs.com
 >>>
 >> I fully understand about code design concept. Perhaps a future project
 >> down the road... Thank you for clearing that up however.
 >>
 >> V/R,
 >> JR
 >> _______________________________________________
 >> Cherokee mailing list
 >> [email protected]
 >> http://cherokee-project.com/cgi-bin/mailman/listinfo/cherokee
 >>
 > _______________________________________________
 > Cherokee mailing list
 > [email protected]
 > http://cherokee-project.com/cgi-bin/mailman/listinfo/cherokee
 >


-- 
Greetings, alo.
http://www.alobbs.com
_______________________________________________
Cherokee mailing list
[email protected]
http://cherokee-project.com/cgi-bin/mailman/listinfo/cherokee

Reply via email to