Page MenuHomePhabricator

noc.wikimedia.org should support HTTPS
Closed, ResolvedPublic

Description

Please allow https connect to noc.wikimedia.org. Thanks.


Version: unspecified
Severity: enhancement

Details

Reference
bz23004

Event Timeline

bzimport raised the priority of this task from to Medium.Nov 21 2014, 11:05 PM
bzimport set Reference to bz23004.
bzimport added a subscriber: Unknown Object (MLST).

Why not?
There are many user, who use the secure server, why there should not view the config of the Wikimedia Projects with https, when it is possible to view all other of the Wikimedia Projects.

Sysadmins: Please make this as INVALID, when there is no need for a secure server for noc.wikimedia.org. Thanks.

Invalid, there is NO reason to do this. It's public data, and no logins.

bug 17517 might have some relevance

But this is still invalid

Secure connections are intended to prevent loss of sensitive information
transitioned from user to server and vice versa. Noc is a read-only site,
readable by everyone - no need to protect the data sent to the user. And data
in requests from user to server is also free from sensitive data - because SUL
cookies aren't set blindly for *.wikimedia.org, your Wikipedia session cookies
cannot be sniffed from your noc.wikimedia.org traffic.

  • Bug 32066 has been marked as a duplicate of this bug. ***

Re-opening per Ryan's comment (copied below from bug 32066 comment 8):

I don't think it's necessary to have this argument every time a bug is
submitted for services that don't have https, so... For every service we have,
if it is feasible to do https, we should do https.

Works now, but some links should be changed to protocol relative links and the image should load over a protocol relative link.

Thanks.

changed to relative pathes / protocol agnostic:

"Server configuration"
"MediaWiki profiling information"
"Core dbs"

changed to always use https://:

"Bugzilla"
"Blog"
"Wikimedia Subversion Repository"

unchanged due to existing issues: (have tickets)

"Ganglia"
"ServerAdminLog"

won't fix:

"Wikimedia Downloads" (dumps)

status.wikimedia.org is one that gives a warning for the certificate

stats.wikimedia.org in https asks for web login

@Billinghurst: ACK, just that those are not really related to noc.wm and have their own tickets.

status.wikimedia.org is an alias for status.watchmouse.com., so not directly under our control but we still have an open ticket to proxy it (RT 1849).

stats.wikimedia is in BZ 32143

Created attachment 9970
Updated

Fixed in attachment

I really need to get my git setup working...

Attached:

  • Bug 35739 has been marked as a duplicate of this bug. ***

(In reply to comment #15)

Created attachment 9970 [details]
Updated

Fixed in attachment

I really need to get my git setup working...

Committed in https://gerrit.wikimedia.org/r/#change,4367

Attached:

Thehelpfulonewiki wrote:

Seems to have been fixed.