Re: [E-devel] phab now broken.

2013-04-03 Thread Bertrand Jacquin
On 2013-04-03 04:33, Carsten Haitzler wrote:
 On Tue, 2 Apr 2013 20:57:34 +0200 Steven Le Roux ste...@le-roux.info 
 said:
 
 We could go with CACert ... not a big deal if a last century browser 
 alerts
 with an unknown CA... at least chrome has it built-in already.
 
 we are with cacert. problem is several current browsers dont support 
 cacert.
 it's the ssl cert kabal. that's life.

Easily be added in every browser :

* Firefox

http://wiki.cacert.org/FAQ/BrowserClients#Importing_the_CAcert_Root_Certificate

* Chrome / Chromium

http://wiki.cacert.org/FAQ/BrowserClients#Google_Chrome

And more generally http://wiki.cacert.org/FAQ/BrowserClients

--
Minimize network downtime and maximize team effectiveness.
Reduce network management and security costs.Learn how to hire 
the most talented Cisco Certified professionals. Visit the 
Employer Resources Portal
http://www.cisco.com/web/learning/employer_resources/index.html
___
enlightenment-devel mailing list
enlightenment-devel@lists.sourceforge.net
https://lists.sourceforge.net/lists/listinfo/enlightenment-devel


Re: [E-devel] phab now broken.

2013-04-03 Thread The Rasterman
On Wed, 03 Apr 2013 11:05:16 +0200 Bertrand Jacquin be...@meleeweb.net said:

 On 2013-04-03 04:33, Carsten Haitzler wrote:
  On Tue, 2 Apr 2013 20:57:34 +0200 Steven Le Roux ste...@le-roux.info 
  said:
  
  We could go with CACert ... not a big deal if a last century browser 
  alerts
  with an unknown CA... at least chrome has it built-in already.
  
  we are with cacert. problem is several current browsers dont support 
  cacert.
  it's the ssl cert kabal. that's life.
 
 Easily be added in every browser :
 
 * Firefox
 
 http://wiki.cacert.org/FAQ/BrowserClients#Importing_the_CAcert_Root_Certificate
 
 * Chrome / Chromium
 
 http://wiki.cacert.org/FAQ/BrowserClients#Google_Chrome
 
 And more generally http://wiki.cacert.org/FAQ/BrowserClients

doesn't matter - people just bitch that we dont have proper certs. they dont
bother doing this. i had to deal with a stream of such complaints when i put up
the first blog on phab. they just dont care. users wont accept having to fix
their browser or os by answering nay dialogs for exceptions or doing the
above. :(


-- 
- Codito, ergo sum - I code, therefore I am --
The Rasterman (Carsten Haitzler)ras...@rasterman.com


--
Minimize network downtime and maximize team effectiveness.
Reduce network management and security costs.Learn how to hire 
the most talented Cisco Certified professionals. Visit the 
Employer Resources Portal
http://www.cisco.com/web/learning/employer_resources/index.html
___
enlightenment-devel mailing list
enlightenment-devel@lists.sourceforge.net
https://lists.sourceforge.net/lists/listinfo/enlightenment-devel


Re: [E-devel] phab now broken.

2013-04-03 Thread Bertrand Jacquin
Le mercredi 03 avril 2013 à 12h25, « Carsten Haitzler » a écrit :
 On Wed, 03 Apr 2013 11:05:16 +0200 Bertrand Jacquin be...@meleeweb.net said:
 
  On 2013-04-03 04:33, Carsten Haitzler wrote:
   On Tue, 2 Apr 2013 20:57:34 +0200 Steven Le Roux ste...@le-roux.info 
   said:
   
   We could go with CACert ... not a big deal if a last century browser 
   alerts
   with an unknown CA... at least chrome has it built-in already.
   
   we are with cacert. problem is several current browsers dont support 
   cacert.
   it's the ssl cert kabal. that's life.
  
  Easily be added in every browser :
  
  * Firefox
  
  http://wiki.cacert.org/FAQ/BrowserClients#Importing_the_CAcert_Root_Certificate
  
  * Chrome / Chromium
  
  http://wiki.cacert.org/FAQ/BrowserClients#Google_Chrome
  
  And more generally http://wiki.cacert.org/FAQ/BrowserClients
 
 doesn't matter - people just bitch that we dont have proper certs. they dont
 bother doing this. i had to deal with a stream of such complaints when i put 
 up
 the first blog on phab. they just dont care. users wont accept having to fix
 their browser or os by answering nay dialogs for exceptions or doing the
 above. :(

The fact is that those who want to can avoid this warning. This is
mainly destinated for those who do regular access to e https ressources
and want to bypass the certificate warning.

Users won't accept, that dev have the choice to spend 5 minutes fixing
it once for good.

-- 
Bertrand Jacquin, EXOSEC (http://www.exosec.fr/)
ZAC des Metz - 3 Rue du petit robinson - 78350 JOUY EN JOSAS
Tel: +33 1 30 67 60 65  -  Fax: +33 1 75 43 40 70
GSM: +33 6 71 01 70 30  -  mailto:bjacq...@exosec.fr


pgpkT5OLShnpb.pgp
Description: PGP signature
--
Minimize network downtime and maximize team effectiveness.
Reduce network management and security costs.Learn how to hire 
the most talented Cisco Certified professionals. Visit the 
Employer Resources Portal
http://www.cisco.com/web/learning/employer_resources/index.html___
enlightenment-devel mailing list
enlightenment-devel@lists.sourceforge.net
https://lists.sourceforge.net/lists/listinfo/enlightenment-devel


Re: [E-devel] phab now broken.

2013-04-03 Thread The Rasterman
On Wed, 3 Apr 2013 13:44:37 +0200 Bertrand Jacquin be...@meleeweb.net said:

 Le mercredi 03 avril 2013 à 12h25, « Carsten Haitzler » a écrit :
  On Wed, 03 Apr 2013 11:05:16 +0200 Bertrand Jacquin be...@meleeweb.net
  said:
  
   On 2013-04-03 04:33, Carsten Haitzler wrote:
On Tue, 2 Apr 2013 20:57:34 +0200 Steven Le Roux ste...@le-roux.info 
said:

We could go with CACert ... not a big deal if a last century browser 
alerts
with an unknown CA... at least chrome has it built-in already.

we are with cacert. problem is several current browsers dont support 
cacert.
it's the ssl cert kabal. that's life.
   
   Easily be added in every browser :
   
   * Firefox
   
   http://wiki.cacert.org/FAQ/BrowserClients#Importing_the_CAcert_Root_Certificate
   
   * Chrome / Chromium
   
   http://wiki.cacert.org/FAQ/BrowserClients#Google_Chrome
   
   And more generally http://wiki.cacert.org/FAQ/BrowserClients
  
  doesn't matter - people just bitch that we dont have proper certs. they dont
  bother doing this. i had to deal with a stream of such complaints when i
  put up the first blog on phab. they just dont care. users wont accept
  having to fix their browser or os by answering nay dialogs for exceptions
  or doing the above. :(
 
 The fact is that those who want to can avoid this warning. This is
 mainly destinated for those who do regular access to e https ressources
 and want to bypass the certificate warning.

but the don't want to. thats the problem. not magically and instantly working
perfectly out of the box in their browser == fail in their eyes.

 Users won't accept, that dev have the choice to spend 5 minutes fixing
 it once for good.

but they don't. :( reality is that we need to have a good document explaining
why we use cacert, and not starttls and why we dont pay the certificate tax.

-- 
- Codito, ergo sum - I code, therefore I am --
The Rasterman (Carsten Haitzler)ras...@rasterman.com


--
Minimize network downtime and maximize team effectiveness.
Reduce network management and security costs.Learn how to hire 
the most talented Cisco Certified professionals. Visit the 
Employer Resources Portal
http://www.cisco.com/web/learning/employer_resources/index.html
___
enlightenment-devel mailing list
enlightenment-devel@lists.sourceforge.net
https://lists.sourceforge.net/lists/listinfo/enlightenment-devel


Re: [E-devel] phab now broken.

2013-04-03 Thread Bertrand Jacquin
 but the don't want to. thats the problem. not magically and instantly working
 perfectly out of the box in their browser == fail in their eyes.

Too lazy guys. And this not what I saw on other foss projets. Developers are not
end users, not the same investment the both of them. Often, FOSS
developers know about CAcert and trust it.

  Users won't accept, that dev have the choice to spend 5 minutes fixing
  it once for good
 
 but they don't. :( reality is that we need to have a good document explaining
 why we use cacert, and not starttls and why we dont pay the certificate tax.

This is on my todo, was too lazy to do it yet :)

-- 
Bertrand Jacquin, EXOSEC (http://www.exosec.fr/)
ZAC des Metz - 3 Rue du petit robinson - 78350 JOUY EN JOSAS
Tel: +33 1 30 67 60 65  -  Fax: +33 1 75 43 40 70
GSM: +33 6 71 01 70 30  -  mailto:bjacq...@exosec.fr


pgpndJNAaJrn3.pgp
Description: PGP signature
--
Minimize network downtime and maximize team effectiveness.
Reduce network management and security costs.Learn how to hire 
the most talented Cisco Certified professionals. Visit the 
Employer Resources Portal
http://www.cisco.com/web/learning/employer_resources/index.html___
enlightenment-devel mailing list
enlightenment-devel@lists.sourceforge.net
https://lists.sourceforge.net/lists/listinfo/enlightenment-devel


Re: [E-devel] phab now broken.

2013-04-03 Thread Bertrand Jacquin
Le mercredi 03 avril 2013 à 14h42, « Carsten Haitzler » a écrit :
 On Wed, 3 Apr 2013 14:23:38 +0200 Bertrand Jacquin be...@meleeweb.net said:
 
   but the don't want to. thats the problem. not magically and instantly
   working perfectly out of the box in their browser == fail in their eyes.
  
  Too lazy guys. And this not what I saw on other foss projets. Developers are
  not end users, not the same investment the both of them. Often, FOSS
  developers know about CAcert and trust it.
 
 this was end users trying to access blog stuff via https... :/

I know. I was showing the cacert link for developers, not users that in
any case we can't force to do anything in any case. Not the trick here
(for me).

-- 
Bertrand Jacquin, EXOSEC (http://www.exosec.fr/)
ZAC des Metz - 3 Rue du petit robinson - 78350 JOUY EN JOSAS
Tel: +33 1 30 67 60 65  -  Fax: +33 1 75 43 40 70
GSM: +33 6 71 01 70 30  -  mailto:bjacq...@exosec.fr


pgpodt3GXkByf.pgp
Description: PGP signature
--
Minimize network downtime and maximize team effectiveness.
Reduce network management and security costs.Learn how to hire 
the most talented Cisco Certified professionals. Visit the 
Employer Resources Portal
http://www.cisco.com/web/learning/employer_resources/index.html___
enlightenment-devel mailing list
enlightenment-devel@lists.sourceforge.net
https://lists.sourceforge.net/lists/listinfo/enlightenment-devel


Re: [E-devel] phab now broken.

2013-04-03 Thread Tom Hacohen
On 03/04/13 13:42, Carsten Haitzler (The Rasterman) wrote:
 On Wed, 3 Apr 2013 14:23:38 +0200 Bertrand Jacquin be...@meleeweb.net said:

 but the don't want to. thats the problem. not magically and instantly
 working perfectly out of the box in their browser == fail in their eyes.

 Too lazy guys. And this not what I saw on other foss projets. Developers are
 not end users, not the same investment the both of them. Often, FOSS
 developers know about CAcert and trust it.

 this was end users trying to access blog stuff via https... :/

1. Everyone should use https all the time.
2. As Carsten has said, https doesn't really work for most people 
(because of CACert).

We need to fix it. Either by getting free starttls certs for phab, 
build, www, and git, if possible, or figuring out another solution.

--
Tom.


--
Minimize network downtime and maximize team effectiveness.
Reduce network management and security costs.Learn how to hire 
the most talented Cisco Certified professionals. Visit the 
Employer Resources Portal
http://www.cisco.com/web/learning/employer_resources/index.html
___
enlightenment-devel mailing list
enlightenment-devel@lists.sourceforge.net
https://lists.sourceforge.net/lists/listinfo/enlightenment-devel


Re: [E-devel] phab now broken.

2013-04-03 Thread Bertrand Jacquin
Le mercredi 03 avril 2013 à 14h52, « Tom Hacohen » a écrit :
 On 03/04/13 13:42, Carsten Haitzler (The Rasterman) wrote:
  On Wed, 3 Apr 2013 14:23:38 +0200 Bertrand Jacquin be...@meleeweb.net 
  said:
 
  but the don't want to. thats the problem. not magically and instantly
  working perfectly out of the box in their browser == fail in their eyes.
 
  Too lazy guys. And this not what I saw on other foss projets. Developers 
  are
  not end users, not the same investment the both of them. Often, FOSS
  developers know about CAcert and trust it.
 
  this was end users trying to access blog stuff via https... :/
 
 1. Everyone should use https all the time.

For things that need authentification. Not public ressources.

Phabricator is br0ken, it put scheme + vhost in every href, js
inclusion, css etc, it's really not the way to make a viable website. It
should only propose absolute path to / and not the full URL.

 2. As Carsten has said, https doesn't really work for most people 
 (because of CACert).

Nothing we can do about CAcert, but it's better than a own self
generated cert.

 We need to fix it. Either by getting free starttls certs for phab, 
 build, www, and git, if possible, or figuring out another solution.

A wildcard is necessary overwise we need one certificate per IP, and so
one vhost, one public IP. This is not a longterm solution, not really
feasble.

A proper wildcard cert can fix the issue. But it's not something cheap.

-- 
Bertrand Jacquin, EXOSEC (http://www.exosec.fr/)
ZAC des Metz - 3 Rue du petit robinson - 78350 JOUY EN JOSAS
Tel: +33 1 30 67 60 65  -  Fax: +33 1 75 43 40 70
GSM: +33 6 71 01 70 30  -  mailto:bjacq...@exosec.fr


pgpN8KnEJKU4o.pgp
Description: PGP signature
--
Minimize network downtime and maximize team effectiveness.
Reduce network management and security costs.Learn how to hire 
the most talented Cisco Certified professionals. Visit the 
Employer Resources Portal
http://www.cisco.com/web/learning/employer_resources/index.html___
enlightenment-devel mailing list
enlightenment-devel@lists.sourceforge.net
https://lists.sourceforge.net/lists/listinfo/enlightenment-devel


Re: [E-devel] phab now broken.

2013-04-03 Thread Steven Le Roux
Or we could use TLS/SNI on the RP to match the good vhost with one IP.


On Wed, Apr 3, 2013 at 2:57 PM, Bertrand Jacquin be...@meleeweb.net wrote:

 Le mercredi 03 avril 2013 à 14h52, « Tom Hacohen » a écrit :
  On 03/04/13 13:42, Carsten Haitzler (The Rasterman) wrote:
   On Wed, 3 Apr 2013 14:23:38 +0200 Bertrand Jacquin be...@meleeweb.net
 said:
  
   but the don't want to. thats the problem. not magically and instantly
   working perfectly out of the box in their browser == fail in their
 eyes.
  
   Too lazy guys. And this not what I saw on other foss projets.
 Developers are
   not end users, not the same investment the both of them. Often, FOSS
   developers know about CAcert and trust it.
  
   this was end users trying to access blog stuff via https... :/
 
  1. Everyone should use https all the time.

 For things that need authentification. Not public ressources.

 Phabricator is br0ken, it put scheme + vhost in every href, js
 inclusion, css etc, it's really not the way to make a viable website. It
 should only propose absolute path to / and not the full URL.

  2. As Carsten has said, https doesn't really work for most people
  (because of CACert).

 Nothing we can do about CAcert, but it's better than a own self
 generated cert.

  We need to fix it. Either by getting free starttls certs for phab,
  build, www, and git, if possible, or figuring out another solution.

 A wildcard is necessary overwise we need one certificate per IP, and so
 one vhost, one public IP. This is not a longterm solution, not really
 feasble.

 A proper wildcard cert can fix the issue. But it's not something cheap.

 --
 Bertrand Jacquin, EXOSEC (http://www.exosec.fr/)
 ZAC des Metz - 3 Rue du petit robinson - 78350 JOUY EN JOSAS
 Tel: +33 1 30 67 60 65  -  Fax: +33 1 75 43 40 70
 GSM: +33 6 71 01 70 30  -  mailto:bjacq...@exosec.fr


 --
 Minimize network downtime and maximize team effectiveness.
 Reduce network management and security costs.Learn how to hire
 the most talented Cisco Certified professionals. Visit the
 Employer Resources Portal
 http://www.cisco.com/web/learning/employer_resources/index.html
 ___
 enlightenment-devel mailing list
 enlightenment-devel@lists.sourceforge.net
 https://lists.sourceforge.net/lists/listinfo/enlightenment-devel




-- 
Steven Le Roux
Jabber-ID : ste...@jabber.fr
0x39494CCB ste...@le-roux.info
2FF7 226B 552E 4709 03F0  6281 72D7 A010 3949 4CCB
--
Minimize network downtime and maximize team effectiveness.
Reduce network management and security costs.Learn how to hire 
the most talented Cisco Certified professionals. Visit the 
Employer Resources Portal
http://www.cisco.com/web/learning/employer_resources/index.html
___
enlightenment-devel mailing list
enlightenment-devel@lists.sourceforge.net
https://lists.sourceforge.net/lists/listinfo/enlightenment-devel


Re: [E-devel] phab now broken.

2013-04-03 Thread Tom Hacohen
On 03/04/13 13:57, Bertrand Jacquin wrote:
 Le mercredi 03 avril 2013 à 14h52, « Tom Hacohen » a écrit :
 On 03/04/13 13:42, Carsten Haitzler (The Rasterman) wrote:
 On Wed, 3 Apr 2013 14:23:38 +0200 Bertrand Jacquin be...@meleeweb.net 
 said:

 but the don't want to. thats the problem. not magically and instantly
 working perfectly out of the box in their browser == fail in their eyes.

 Too lazy guys. And this not what I saw on other foss projets. Developers 
 are
 not end users, not the same investment the both of them. Often, FOSS
 developers know about CAcert and trust it.

 this was end users trying to access blog stuff via https... :/

 1. Everyone should use https all the time.

 For things that need authentification. Not public ressources.

 Phabricator is br0ken, it put scheme + vhost in every href, js
 inclusion, css etc, it's really not the way to make a viable website. It
 should only propose absolute path to / and not the full URL.

I'm not a web developer, but I also found it weird that they do that, 
and only allow http/s, and don't allow using both.

There must be a reason for that though.

--
Tom.



--
Minimize network downtime and maximize team effectiveness.
Reduce network management and security costs.Learn how to hire 
the most talented Cisco Certified professionals. Visit the 
Employer Resources Portal
http://www.cisco.com/web/learning/employer_resources/index.html
___
enlightenment-devel mailing list
enlightenment-devel@lists.sourceforge.net
https://lists.sourceforge.net/lists/listinfo/enlightenment-devel


Re: [E-devel] phab now broken.

2013-04-03 Thread Steven Le Roux
#define work ?

Even if you get a warning and a striked lock in your url bar, it's
working...

SSL certs in browser is just a trust network... and you can just buy this
trust with costly webtrust audit...

In case you missed it, China had eaten 18% of the internet trafic during
15minutes...  not an error... they are in the ROOT CA granted in browser
(CNN) so they basicaly did a giant MITM.




On Wed, Apr 3, 2013 at 2:52 PM, Tom Hacohen tom.haco...@samsung.com wrote:

 On 03/04/13 13:42, Carsten Haitzler (The Rasterman) wrote:
  On Wed, 3 Apr 2013 14:23:38 +0200 Bertrand Jacquin be...@meleeweb.net
 said:
 
  but the don't want to. thats the problem. not magically and instantly
  working perfectly out of the box in their browser == fail in their
 eyes.
 
  Too lazy guys. And this not what I saw on other foss projets.
 Developers are
  not end users, not the same investment the both of them. Often, FOSS
  developers know about CAcert and trust it.
 
  this was end users trying to access blog stuff via https... :/

 1. Everyone should use https all the time.
 2. As Carsten has said, https doesn't really work for most people
 (because of CACert).

 We need to fix it. Either by getting free starttls certs for phab,
 build, www, and git, if possible, or figuring out another solution.

 --
 Tom.



 --
 Minimize network downtime and maximize team effectiveness.
 Reduce network management and security costs.Learn how to hire
 the most talented Cisco Certified professionals. Visit the
 Employer Resources Portal
 http://www.cisco.com/web/learning/employer_resources/index.html
 ___
 enlightenment-devel mailing list
 enlightenment-devel@lists.sourceforge.net
 https://lists.sourceforge.net/lists/listinfo/enlightenment-devel




-- 
Steven Le Roux
Jabber-ID : ste...@jabber.fr
0x39494CCB ste...@le-roux.info
2FF7 226B 552E 4709 03F0  6281 72D7 A010 3949 4CCB
--
Minimize network downtime and maximize team effectiveness.
Reduce network management and security costs.Learn how to hire 
the most talented Cisco Certified professionals. Visit the 
Employer Resources Portal
http://www.cisco.com/web/learning/employer_resources/index.html
___
enlightenment-devel mailing list
enlightenment-devel@lists.sourceforge.net
https://lists.sourceforge.net/lists/listinfo/enlightenment-devel


Re: [E-devel] phab now broken.

2013-04-03 Thread David Seikel
On Wed, 3 Apr 2013 15:02:28 +0200 Steven Le Roux ste...@le-roux.info
wrote:

 #define work ?
 
 Even if you get a warning and a striked lock in your url bar, it's
 working...
 
 SSL certs in browser is just a trust network... and you can just buy
 this trust with costly webtrust audit...
 
 In case you missed it, China had eaten 18% of the internet trafic
 during 15minutes...  not an error... they are in the ROOT CA granted
 in browser (CNN) so they basicaly did a giant MITM.

I did miss that, got links for it?

-- 
A big old stinking pile of genius that no one wants
coz there are too many silver coated monkeys in the world.


signature.asc
Description: PGP signature
--
Minimize network downtime and maximize team effectiveness.
Reduce network management and security costs.Learn how to hire 
the most talented Cisco Certified professionals. Visit the 
Employer Resources Portal
http://www.cisco.com/web/learning/employer_resources/index.html___
enlightenment-devel mailing list
enlightenment-devel@lists.sourceforge.net
https://lists.sourceforge.net/lists/listinfo/enlightenment-devel


Re: [E-devel] phab now broken.

2013-04-03 Thread Bertrand Jacquin
On 2013-04-03 16:23, David Seikel wrote:
 On Wed, 3 Apr 2013 15:02:28 +0200 Steven Le Roux ste...@le-roux.info
 wrote:
 
 #define work ?
 
 Even if you get a warning and a striked lock in your url bar, it's
 working...
 
 SSL certs in browser is just a trust network... and you can just buy
 this trust with costly webtrust audit...
 
 In case you missed it, China had eaten 18% of the internet trafic
 during 15minutes...  not an error... they are in the ROOT CA granted
 in browser (CNN) so they basicaly did a giant MITM.
 
 I did miss that, got links for it?

http://www.netresec.com/?page=Blogmonth=2013-02post=Forensics-of-Chinese-MITM-on-GitHub
http://appliance.cloudshark.org/news/cloudshark-in-the-wild/mitm-attack-capture-shared-through-cloudshark/

It append in the past also

--
Minimize network downtime and maximize team effectiveness.
Reduce network management and security costs.Learn how to hire 
the most talented Cisco Certified professionals. Visit the 
Employer Resources Portal
http://www.cisco.com/web/learning/employer_resources/index.html
___
enlightenment-devel mailing list
enlightenment-devel@lists.sourceforge.net
https://lists.sourceforge.net/lists/listinfo/enlightenment-devel


Re: [E-devel] phab now broken.

2013-04-03 Thread Bertrand Jacquin
On 2013-04-03 15:05, Steven Le Roux wrote:
 Or we could use TLS/SNI on the RP to match the good vhost with one IP.

Even more incompatibility on client side.

--
Minimize network downtime and maximize team effectiveness.
Reduce network management and security costs.Learn how to hire 
the most talented Cisco Certified professionals. Visit the 
Employer Resources Portal
http://www.cisco.com/web/learning/employer_resources/index.html
___
enlightenment-devel mailing list
enlightenment-devel@lists.sourceforge.net
https://lists.sourceforge.net/lists/listinfo/enlightenment-devel


Re: [E-devel] phab now broken.

2013-04-03 Thread Steven Le Roux
me (if you can read frog :) ) :
http://steven.le-roux.info/comment-la-chine-a-detourner-15-du-trafic-int

Or :
http://www.nationaldefensemagazine.org/blog/Lists/Posts/Post.aspx?ID=249#

I reversed some numbers :)

It was : 15% of Internet BGP routes, during 18%.

The thing is... if in those 15% you have Google, Youtube and YouPr0n, you
basically have 90% of the overall traffic...




On Wed, Apr 3, 2013 at 4:23 PM, David Seikel onef...@gmail.com wrote:

 On Wed, 3 Apr 2013 15:02:28 +0200 Steven Le Roux ste...@le-roux.info
 wrote:

  #define work ?
 
  Even if you get a warning and a striked lock in your url bar, it's
  working...
 
  SSL certs in browser is just a trust network... and you can just buy
  this trust with costly webtrust audit...
 
  In case you missed it, China had eaten 18% of the internet trafic
  during 15minutes...  not an error... they are in the ROOT CA granted
  in browser (CNN) so they basicaly did a giant MITM.

 I did miss that, got links for it?

 --
 A big old stinking pile of genius that no one wants
 coz there are too many silver coated monkeys in the world.


 --
 Minimize network downtime and maximize team effectiveness.
 Reduce network management and security costs.Learn how to hire
 the most talented Cisco Certified professionals. Visit the
 Employer Resources Portal
 http://www.cisco.com/web/learning/employer_resources/index.html
 ___
 enlightenment-devel mailing list
 enlightenment-devel@lists.sourceforge.net
 https://lists.sourceforge.net/lists/listinfo/enlightenment-devel




-- 
Steven Le Roux
Jabber-ID : ste...@jabber.fr
0x39494CCB ste...@le-roux.info
2FF7 226B 552E 4709 03F0  6281 72D7 A010 3949 4CCB
--
Minimize network downtime and maximize team effectiveness.
Reduce network management and security costs.Learn how to hire 
the most talented Cisco Certified professionals. Visit the 
Employer Resources Portal
http://www.cisco.com/web/learning/employer_resources/index.html
___
enlightenment-devel mailing list
enlightenment-devel@lists.sourceforge.net
https://lists.sourceforge.net/lists/listinfo/enlightenment-devel


Re: [E-devel] phab now broken.

2013-04-02 Thread Raoul Hecky
Le 31.03.2013 22:49, Bertrand Jacquin a écrit :
 On 2013-03-28 09:21, Carsten Haitzler wrote:
 http://www.enlightenment.org/ss/e-5153fd6e428484.46501811.png

 http and https both... :/ :(

 OK. To made a report on this.

 Some people was wanting phab in HTTP for the gsoc page as the cert is
 not an official trusted one, so we moved to HTTP, what break thing 
 for
 some other people, so they revert to HTTPS, we do this 2/3 times 
 cause
 of no sync betwee, people.

Why not using StartSSL to get a free trusted certificate:
https://www.startssl.com/

 Now it's HTTPS for everyone, and DH issue are now fixed (thanks KainX
 and antognolli).

 Beber

 
 --
 Own the Future-Intel(R) Level Up Game Demo Contest 2013
 Rise to greatness in Intel's independent game demo contest. Compete
 for recognition, cash, and the chance to get your game on Steam.
 $5K grand prize plus 10 genre and skill prizes. Submit your demo
 by 6/6/13. http://altfarm.mediaplex.com/ad/ck/12124-176961-30367-2
 ___
 enlightenment-devel mailing list
 enlightenment-devel@lists.sourceforge.net
 https://lists.sourceforge.net/lists/listinfo/enlightenment-devel

-- 
Raoul Hecky

--
Own the Future-Intel(R) Level Up Game Demo Contest 2013
Rise to greatness in Intel's independent game demo contest. Compete 
for recognition, cash, and the chance to get your game on Steam. 
$5K grand prize plus 10 genre and skill prizes. Submit your demo 
by 6/6/13. http://altfarm.mediaplex.com/ad/ck/12124-176961-30367-2
___
enlightenment-devel mailing list
enlightenment-devel@lists.sourceforge.net
https://lists.sourceforge.net/lists/listinfo/enlightenment-devel


Re: [E-devel] phab now broken.

2013-04-02 Thread Bertrand Jacquin
On 2013-04-02 13:35, Raoul Hecky wrote:
 Le 31.03.2013 22:49, Bertrand Jacquin a écrit :
 On 2013-03-28 09:21, Carsten Haitzler wrote:
 http://www.enlightenment.org/ss/e-5153fd6e428484.46501811.png
 
 http and https both... :/ :(
 
 OK. To made a report on this.
 
 Some people was wanting phab in HTTP for the gsoc page as the cert is
 not an official trusted one, so we moved to HTTP, what break thing
 for
 some other people, so they revert to HTTPS, we do this 2/3 times
 cause
 of no sync betwee, people.
 
 Why not using StartSSL to get a free trusted certificate:
 https://www.startssl.com/

Cause we need a wildcard one and they don't provide free wildcard 
certs.

--
Own the Future-Intel(R) Level Up Game Demo Contest 2013
Rise to greatness in Intel's independent game demo contest. Compete 
for recognition, cash, and the chance to get your game on Steam. 
$5K grand prize plus 10 genre and skill prizes. Submit your demo 
by 6/6/13. http://altfarm.mediaplex.com/ad/ck/12124-176961-30367-2
___
enlightenment-devel mailing list
enlightenment-devel@lists.sourceforge.net
https://lists.sourceforge.net/lists/listinfo/enlightenment-devel


Re: [E-devel] phab now broken.

2013-04-02 Thread Raoul Hecky
Le 02.04.2013 14:58, Bertrand Jacquin a écrit :
 On 2013-04-02 13:35, Raoul Hecky wrote:
 Le 31.03.2013 22:49, Bertrand Jacquin a écrit :
 On 2013-03-28 09:21, Carsten Haitzler wrote:
 http://www.enlightenment.org/ss/e-5153fd6e428484.46501811.png

 http and https both... :/ :(

 OK. To made a report on this.

 Some people was wanting phab in HTTP for the gsoc page as the cert 
 is
 not an official trusted one, so we moved to HTTP, what break thing
 for
 some other people, so they revert to HTTPS, we do this 2/3 times
 cause
 of no sync betwee, people.

 Why not using StartSSL to get a free trusted certificate:
 https://www.startssl.com/

 Cause we need a wildcard one and they don't provide free wildcard
 certs.

Ah you're right :)

 
 --
 Own the Future-Intel(R) Level Up Game Demo Contest 2013
 Rise to greatness in Intel's independent game demo contest. Compete
 for recognition, cash, and the chance to get your game on Steam.
 $5K grand prize plus 10 genre and skill prizes. Submit your demo
 by 6/6/13. http://altfarm.mediaplex.com/ad/ck/12124-176961-30367-2
 ___
 enlightenment-devel mailing list
 enlightenment-devel@lists.sourceforge.net
 https://lists.sourceforge.net/lists/listinfo/enlightenment-devel

-- 
Raoul Hecky

--
Own the Future-Intel(R) Level Up Game Demo Contest 2013
Rise to greatness in Intel's independent game demo contest. Compete 
for recognition, cash, and the chance to get your game on Steam. 
$5K grand prize plus 10 genre and skill prizes. Submit your demo 
by 6/6/13. http://altfarm.mediaplex.com/ad/ck/12124-176961-30367-2
___
enlightenment-devel mailing list
enlightenment-devel@lists.sourceforge.net
https://lists.sourceforge.net/lists/listinfo/enlightenment-devel


Re: [E-devel] phab now broken.

2013-04-02 Thread Steven Le Roux
We could go with CACert ... not a big deal if a last century browser alerts
with an unknown CA... at least chrome has it built-in already.


On Tue, Apr 2, 2013 at 3:07 PM, Raoul Hecky raoul.he...@gmail.com wrote:

 Le 02.04.2013 14:58, Bertrand Jacquin a écrit :
  On 2013-04-02 13:35, Raoul Hecky wrote:
  Le 31.03.2013 22:49, Bertrand Jacquin a écrit :
  On 2013-03-28 09:21, Carsten Haitzler wrote:
  http://www.enlightenment.org/ss/e-5153fd6e428484.46501811.png
 
  http and https both... :/ :(
 
  OK. To made a report on this.
 
  Some people was wanting phab in HTTP for the gsoc page as the cert
  is
  not an official trusted one, so we moved to HTTP, what break thing
  for
  some other people, so they revert to HTTPS, we do this 2/3 times
  cause
  of no sync betwee, people.
 
  Why not using StartSSL to get a free trusted certificate:
  https://www.startssl.com/
 
  Cause we need a wildcard one and they don't provide free wildcard
  certs.

 Ah you're right :)

 
 
 --
  Own the Future-Intel(R) Level Up Game Demo Contest 2013
  Rise to greatness in Intel's independent game demo contest. Compete
  for recognition, cash, and the chance to get your game on Steam.
  $5K grand prize plus 10 genre and skill prizes. Submit your demo
  by 6/6/13. http://altfarm.mediaplex.com/ad/ck/12124-176961-30367-2
  ___
  enlightenment-devel mailing list
  enlightenment-devel@lists.sourceforge.net
  https://lists.sourceforge.net/lists/listinfo/enlightenment-devel

 --
 Raoul Hecky


 --
 Own the Future-Intel(R) Level Up Game Demo Contest 2013
 Rise to greatness in Intel's independent game demo contest. Compete
 for recognition, cash, and the chance to get your game on Steam.
 $5K grand prize plus 10 genre and skill prizes. Submit your demo
 by 6/6/13. http://altfarm.mediaplex.com/ad/ck/12124-176961-30367-2
 ___
 enlightenment-devel mailing list
 enlightenment-devel@lists.sourceforge.net
 https://lists.sourceforge.net/lists/listinfo/enlightenment-devel




-- 
Steven Le Roux
Jabber-ID : ste...@jabber.fr
0x39494CCB ste...@le-roux.info
2FF7 226B 552E 4709 03F0  6281 72D7 A010 3949 4CCB
--
Minimize network downtime and maximize team effectiveness.
Reduce network management and security costs.Learn how to hire 
the most talented Cisco Certified professionals. Visit the 
Employer Resources Portal
http://www.cisco.com/web/learning/employer_resources/index.html
___
enlightenment-devel mailing list
enlightenment-devel@lists.sourceforge.net
https://lists.sourceforge.net/lists/listinfo/enlightenment-devel


Re: [E-devel] phab now broken.

2013-04-02 Thread The Rasterman
On Tue, 2 Apr 2013 20:57:34 +0200 Steven Le Roux ste...@le-roux.info said:

 We could go with CACert ... not a big deal if a last century browser alerts
 with an unknown CA... at least chrome has it built-in already.

we are with cacert. problem is several current browsers dont support cacert.
it's the ssl cert kabal. that's life.

 On Tue, Apr 2, 2013 at 3:07 PM, Raoul Hecky raoul.he...@gmail.com wrote:
 
  Le 02.04.2013 14:58, Bertrand Jacquin a écrit :
   On 2013-04-02 13:35, Raoul Hecky wrote:
   Le 31.03.2013 22:49, Bertrand Jacquin a écrit :
   On 2013-03-28 09:21, Carsten Haitzler wrote:
   http://www.enlightenment.org/ss/e-5153fd6e428484.46501811.png
  
   http and https both... :/ :(
  
   OK. To made a report on this.
  
   Some people was wanting phab in HTTP for the gsoc page as the cert
   is
   not an official trusted one, so we moved to HTTP, what break thing
   for
   some other people, so they revert to HTTPS, we do this 2/3 times
   cause
   of no sync betwee, people.
  
   Why not using StartSSL to get a free trusted certificate:
   https://www.startssl.com/
  
   Cause we need a wildcard one and they don't provide free wildcard
   certs.
 
  Ah you're right :)
 
  
  
  --
   Own the Future-Intel(R) Level Up Game Demo Contest 2013
   Rise to greatness in Intel's independent game demo contest. Compete
   for recognition, cash, and the chance to get your game on Steam.
   $5K grand prize plus 10 genre and skill prizes. Submit your demo
   by 6/6/13. http://altfarm.mediaplex.com/ad/ck/12124-176961-30367-2
   ___
   enlightenment-devel mailing list
   enlightenment-devel@lists.sourceforge.net
   https://lists.sourceforge.net/lists/listinfo/enlightenment-devel
 
  --
  Raoul Hecky
 
 
  --
  Own the Future-Intel(R) Level Up Game Demo Contest 2013
  Rise to greatness in Intel's independent game demo contest. Compete
  for recognition, cash, and the chance to get your game on Steam.
  $5K grand prize plus 10 genre and skill prizes. Submit your demo
  by 6/6/13. http://altfarm.mediaplex.com/ad/ck/12124-176961-30367-2
  ___
  enlightenment-devel mailing list
  enlightenment-devel@lists.sourceforge.net
  https://lists.sourceforge.net/lists/listinfo/enlightenment-devel
 
 
 
 
 -- 
 Steven Le Roux
 Jabber-ID : ste...@jabber.fr
 0x39494CCB ste...@le-roux.info
 2FF7 226B 552E 4709 03F0  6281 72D7 A010 3949 4CCB
 --
 Minimize network downtime and maximize team effectiveness.
 Reduce network management and security costs.Learn how to hire 
 the most talented Cisco Certified professionals. Visit the 
 Employer Resources Portal
 http://www.cisco.com/web/learning/employer_resources/index.html
 ___
 enlightenment-devel mailing list
 enlightenment-devel@lists.sourceforge.net
 https://lists.sourceforge.net/lists/listinfo/enlightenment-devel


-- 
- Codito, ergo sum - I code, therefore I am --
The Rasterman (Carsten Haitzler)ras...@rasterman.com


--
Minimize network downtime and maximize team effectiveness.
Reduce network management and security costs.Learn how to hire 
the most talented Cisco Certified professionals. Visit the 
Employer Resources Portal
http://www.cisco.com/web/learning/employer_resources/index.html
___
enlightenment-devel mailing list
enlightenment-devel@lists.sourceforge.net
https://lists.sourceforge.net/lists/listinfo/enlightenment-devel


Re: [E-devel] phab now broken.

2013-03-31 Thread Bertrand Jacquin
On 2013-03-28 09:21, Carsten Haitzler wrote:
 http://www.enlightenment.org/ss/e-5153fd6e428484.46501811.png
 
 http and https both... :/ :(

OK. To made a report on this.

Some people was wanting phab in HTTP for the gsoc page as the cert is 
not an official trusted one, so we moved to HTTP, what break thing for 
some other people, so they revert to HTTPS, we do this 2/3 times cause 
of no sync betwee, people.

Now it's HTTPS for everyone, and DH issue are now fixed (thanks KainX 
and antognolli).

Beber

--
Own the Future-Intel(R) Level Up Game Demo Contest 2013
Rise to greatness in Intel's independent game demo contest. Compete 
for recognition, cash, and the chance to get your game on Steam. 
$5K grand prize plus 10 genre and skill prizes. Submit your demo 
by 6/6/13. http://altfarm.mediaplex.com/ad/ck/12124-176961-30367-2
___
enlightenment-devel mailing list
enlightenment-devel@lists.sourceforge.net
https://lists.sourceforge.net/lists/listinfo/enlightenment-devel