Re: [Tails-dev] Tails HSTS website error - was: Tails control port filter proxy in Whonix?

2016-10-18 Thread intrigeri
anonym:
> Patrick Schleizer:
>>> https://git.tails.boum.org/tails/tree/config/chroot_local-includes/usr/local/lib/tor-controlport-filter?h=feature/7870-include_onionshare
>> 
>> When I visit that link, I cannot proceed.

[...]

We try to never advertise links to https://git.t.b.o for
this very reason. The correct link is:

https://git-tails.immerda.ch/tails/tree/config/chroot_local-includes/usr/local/lib/tor-controlport-filter?h=feature/7870-include_onionshare

> IIRC there's some experimentation with Let's Encrypt.

Not that I know of. Maybe you're confused by me deploying Let's
Encrypt on our infra, while our Git is hosted by immerda (so mostly
out of our control).

___
Tails-dev mailing list
Tails-dev@boum.org
https://mailman.boum.org/listinfo/tails-dev
To unsubscribe from this list, send an empty email to 
tails-dev-unsubscr...@boum.org.

Re: [Tails-dev] Tails HSTS website error - was: Tails control port filter proxy in Whonix?

2016-10-17 Thread anonym
Patrick Schleizer:
>> https://git.tails.boum.org/tails/tree/config/chroot_local-includes/usr/local/lib/tor-controlport-filter?h=feature/7870-include_onionshare
> 
> When I visit that link, I cannot proceed.
> 
>> Your connection is not secure
>>
>> The owner of git.tails.boum.org has configured their website improperly. To 
>> protect your information from being stolen, Firefox has not connected to 
>> this website.
>>
>> This site uses HTTP Strict Transport Security (HSTS) to specify that Firefox 
>> only connect to it securely. As a result, it is not possible to add an 
>> exception for this certificate.

IIRC there's some experimentation with Let's Encrypt. You can of course
instead pull Tails Git, check out the feature/7870-include_onionshare
branch, and look at:

* config/chroot_local-includes/usr/local/lib/tor-controlport-filter
* config/chroot_local-includes/etc/tor-controlport-filter.d/

> Thanks anonym, for all your work on tails control port filter and
> replies. Very exciting developments! I am preparing responses and will
> test it soonish.

Yay! Perhaps you can add deskt...@secure-os.org to Cc as intrigeri
suggested?

Cheers!

___
Tails-dev mailing list
Tails-dev@boum.org
https://mailman.boum.org/listinfo/tails-dev
To unsubscribe from this list, send an empty email to 
tails-dev-unsubscr...@boum.org.

[Tails-dev] Tails HSTS website error - was: Tails control port filter proxy in Whonix?

2016-10-17 Thread Patrick Schleizer
> https://git.tails.boum.org/tails/tree/config/chroot_local-includes/usr/local/lib/tor-controlport-filter?h=feature/7870-include_onionshare

When I visit that link, I cannot proceed.

> Your connection is not secure
> 
> The owner of git.tails.boum.org has configured their website improperly. To 
> protect your information from being stolen, Firefox has not connected to this 
> website.
> 
> This site uses HTTP Strict Transport Security (HSTS) to specify that Firefox 
> only connect to it securely. As a result, it is not possible to add an 
> exception for this certificate.

Thanks anonym, for all your work on tails control port filter and
replies. Very exciting developments! I am preparing responses and will
test it soonish.

Cheers,
Patrick

___
Tails-dev mailing list
Tails-dev@boum.org
https://mailman.boum.org/listinfo/tails-dev
To unsubscribe from this list, send an empty email to 
tails-dev-unsubscr...@boum.org.