> Vernon Mauery wrote, On 30/08/07 16:08: > > On 8/30/07, John Smith <[EMAIL PROTECTED]> wrote: > >>> John Smith wrote, On 30/08/07 03:13: > >>> > >>> > Is there a way to configure Cherokee to only bind to one port for TLS > >>> > mode? I don't need the classic 80 (http) and 443 (https) > >>> > configuration, I'd rather only serve on 443 and nothing on 80. > >>> > However, it seems "Port" must be defined, otherwise it still attempts > >>> > to open port 80... > > > > This isn't necessarily a bad thing... Many people will automatically > > try http rather than https. If you simply set up a handler that > > redirects all requests from http to https, then you will get the best > > of both worlds: fewer confused people wondering why they can't connect > > to http://yourdomain.dom/ and really only serve pages in the secure > > domain. > > Actually, if you use the "OnlySecure" property the server will take > care of letting the client know that the resource is only available > through https, and if the client supports it the protocol will be > automatically upgraded using the same connection. Isn't it pretty > cool? >
Sounds like that could be an option... However, to put this in better context, my main purpose for Cherokee was to use it for an "appliance-based" (sorta embedded) system I'm setting up. Cherokee intended to facilitate the webGUI to admin this system remotely. So I wanted to offer SSL "or" non-SSL mode for the webGUI (not both at the same time on two separate ports). The key concept is that the webGUI should only be expected on a single port (much like a typical home linksys router web interface). Thanks for all the replies however, I either firewall the non-secure port (not very clean) or look for another web server that can do all php-cgi, ssl, htpasswd authen, small footprint, etc... not many choices. ~JR > > --Vernon > > > >>> > BTW, something funny, I did set "Port 0" & "PortTLS 443" and that > >>> > seemed to work (I know 0 is not a true port). A quick 'netstat -an' > >>> > reveals nothing binding to port 0 (haha), although Cherokee reports > >>> > "Cherokee Web Server 0.5.6: Listening on ports 0 and 443" on startup. > >>> > Another look and it appears Cherokee picked an arbitrary port. Seems > >>> > every time it's started, it's a different port, randomly. Somehow not > >>> > what I expected, but interesting behavior nonetheless. > >>> > >>> On 8/30/07, Alvaro Lopez Ortega <[EMAIL PROTECTED]> wrote: > >>> > >>> Right now, there is no way to do that. > >>> > >>> My first impression after I read your mail was that it wasn't anything > >>> more than a tiny patch, although when I was about to put my hands on > >>> the code I realized that Cherokee core structure doesn't allow that > >>> (at least in 0.6). > >>> > >>> I suppose this is one of those corner cases that Cherokee is not meant > >>> to support. Supporting this kind of functionality would raise the > >>> complexity of the core code, and therefore would make harder to add > >>> and support the feature that the bast majority of people do require. > >>> > >>> If someone comes up if a clean solution for this issue, I will be more > >>> than happy to apply it to trunk. Meanwhile I think that the best thing > >>> you can do is to set your firewall to drop the incoming connections to > >>> the http port (it isn't the perfect solution, I know). > >>> > >>> -- > >>> Greetings, alo. > >>> http://www.alobbs.com > >>> > >> I fully understand about code design concept. Perhaps a future project > >> down the road... Thank you for clearing that up however. > >> > >> V/R, > >> JR > >> _______________________________________________ > >> Cherokee mailing list > >> [email protected] > >> http://cherokee-project.com/cgi-bin/mailman/listinfo/cherokee > >> > > _______________________________________________ > > Cherokee mailing list > > [email protected] > > http://cherokee-project.com/cgi-bin/mailman/listinfo/cherokee > > > > > -- > Greetings, alo. > http://www.alobbs.com > _______________________________________________ > Cherokee mailing list > [email protected] > http://cherokee-project.com/cgi-bin/mailman/listinfo/cherokee > _______________________________________________ Cherokee mailing list [email protected] http://cherokee-project.com/cgi-bin/mailman/listinfo/cherokee
