> Vernon Mauery wrote, On 30/08/07 16:08:
>  > On 8/30/07, John Smith <[EMAIL PROTECTED]> wrote:
>  >>> John Smith wrote, On 30/08/07 03:13:
>  >>>
>  >>>  > Is there a way to configure Cherokee to only bind to one port for TLS
>  >>>  > mode? I don't need the classic 80 (http) and 443 (https)
>  >>>  > configuration, I'd rather only serve on 443 and nothing on 80.
>  >>>  > However, it seems "Port" must be defined, otherwise it still attempts
>  >>>  > to open port 80...
>  >
>  > This isn't necessarily  a bad thing...  Many people will automatically
>  > try http rather than https.  If you simply set up a handler that
>  > redirects all requests from http to https, then you will get the best
>  > of both worlds: fewer confused people wondering why they can't connect
>  > to http://yourdomain.dom/ and really only serve pages in the secure
>  > domain.
>
> Actually, if you use the "OnlySecure" property the server will take
> care of letting the client know that the resource is only available
> through https, and if the client supports it the protocol will be
> automatically upgraded using the same connection. Isn't it pretty
> cool?
>

Sounds like that could be an option... However, to put this in better
context, my main purpose for Cherokee was to use it for an
"appliance-based" (sorta embedded) system I'm setting up. Cherokee
intended to facilitate the webGUI to admin this system remotely. So I
wanted to offer SSL "or" non-SSL mode for the webGUI (not both at the
same time on two separate ports). The key concept is that the webGUI
should only be expected on a single port (much like a typical home
linksys router web interface).

Thanks for all the replies however, I either firewall the non-secure
port (not very clean) or look for another web server that can do all
php-cgi, ssl, htpasswd authen, small footprint, etc... not many
choices.

 ~JR

>  > --Vernon
>  >
>  >>>  > BTW, something funny, I did set "Port 0" & "PortTLS 443" and that
>  >>>  > seemed to work (I know 0 is not a true port). A quick 'netstat -an'
>  >>>  > reveals nothing binding to port 0 (haha), although Cherokee reports
>  >>>  > "Cherokee Web Server 0.5.6: Listening on ports 0 and 443" on startup.
>  >>>  > Another look and it appears Cherokee picked an arbitrary port. Seems
>  >>>  > every time it's started, it's a different port, randomly. Somehow not
>  >>>  > what I expected, but interesting behavior nonetheless.
>  >>>
>  >>> On 8/30/07, Alvaro Lopez Ortega <[EMAIL PROTECTED]> wrote:
>  >>>
>  >>> Right now, there is no way to do that.
>  >>>
>  >>> My first impression after I read your mail was that it wasn't anything
>  >>> more than a tiny patch, although when I was about to put my hands on
>  >>> the code I realized that Cherokee core structure doesn't allow that
>  >>> (at least in 0.6).
>  >>>
>  >>> I suppose this is one of those corner cases that Cherokee is not meant
>  >>> to support. Supporting this kind of functionality would raise the
>  >>> complexity of the core code, and therefore would make harder to add
>  >>> and support the feature that the bast majority of people do require.
>  >>>
>  >>> If someone comes up if a clean solution for this issue, I will be more
>  >>> than happy to apply it to trunk. Meanwhile I think that the best thing
>  >>> you can do is to set your firewall to drop the incoming connections to
>  >>> the http port (it isn't the perfect solution, I know).
>  >>>
>  >>> --
>  >>> Greetings, alo.
>  >>> http://www.alobbs.com
>  >>>
>  >> I fully understand about code design concept. Perhaps a future project
>  >> down the road... Thank you for clearing that up however.
>  >>
>  >> V/R,
>  >> JR
>  >> _______________________________________________
>  >> Cherokee mailing list
>  >> [email protected]
>  >> http://cherokee-project.com/cgi-bin/mailman/listinfo/cherokee
>  >>
>  > _______________________________________________
>  > Cherokee mailing list
>  > [email protected]
>  > http://cherokee-project.com/cgi-bin/mailman/listinfo/cherokee
>  >
>
>
> --
> Greetings, alo.
> http://www.alobbs.com
> _______________________________________________
> Cherokee mailing list
> [email protected]
> http://cherokee-project.com/cgi-bin/mailman/listinfo/cherokee
>
_______________________________________________
Cherokee mailing list
[email protected]
http://cherokee-project.com/cgi-bin/mailman/listinfo/cherokee

Reply via email to