Calgarypuck Forums - The Unofficial Calgary Flames Fan Community

Go Back   Calgarypuck Forums - The Unofficial Calgary Flames Fan Community > Main Forums > Fire on Ice: The Calgary Flames Forum
Register Forum Rules FAQ Community Calendar Today's Posts Search

Reply
 
Thread Tools Search this Thread
Old 08-19-2023, 09:52 AM   #1
Rejean31
Franchise Player
 
Rejean31's Avatar
 
Join Date: Sep 2002
Location: Central Alberta
Exp:
Default Anyone else having issues with site security?

I keep getting a message that this site is not secure.
__________________
Are the Oilers trying to set a record for most scumbags on the payroll??
Rejean31 is offline   Reply With Quote
The Following 13 Users Say Thank You to Rejean31 For This Useful Post:
Old 08-19-2023, 09:53 AM   #2
Dan02
Franchise Player
 
Dan02's Avatar
 
Join Date: Jun 2004
Location: Calgary
Exp:
Default

Yes
Dan02 is offline   Reply With Quote
The Following User Says Thank You to Dan02 For This Useful Post:
Old 08-19-2023, 09:55 AM   #3
cam_calderon
Powerplay Quarterback
 
cam_calderon's Avatar
 
Join Date: Oct 2022
Exp:
Default

Guessing there's some issue with the security provider.
__________________
Matthew Tkachuk apologist.
cam_calderon is offline   Reply With Quote
The Following User Says Thank You to cam_calderon For This Useful Post:
Old 08-19-2023, 09:56 AM   #4
Sainters7
Franchise Player
 
Sainters7's Avatar
 
Join Date: Dec 2005
Location: back in the 403
Exp:
Default

Yeah I'm having to use Tapatalk, as Chrome won't even let me visit the normal version of the site due to security concerns.
Sainters7 is offline   Reply With Quote
Old 08-19-2023, 09:57 AM   #5
The Original FFIV
First Line Centre
 
Join Date: Jan 2007
Exp:
Default

Me too. Says security certificate expired a day ago
The Original FFIV is offline   Reply With Quote
Old 08-19-2023, 10:04 AM   #6
taxbuster
#1 Goaltender
 
Join Date: Feb 2010
Exp:
Default

Yep- exactly. Cert expired. still loads as https though.
__________________
Hey...where'd my avatar go?
taxbuster is offline   Reply With Quote
Old 08-19-2023, 10:18 AM   #7
photon
The new goggles also do nothing.
 
photon's Avatar
 
Join Date: Oct 2001
Location: Calgary
Exp:
Default

Yeah the certificate just expired, I had the wrong day in my calendar.

The certs have been renewed so it should be ok now.
__________________
Uncertainty is an uncomfortable position.
But certainty is an absurd one.
photon is offline   Reply With Quote
Old 08-19-2023, 03:46 PM   #8
Buff
Franchise Player
 
Buff's Avatar
 
Join Date: Apr 2004
Location: I don't belong here
Exp:
Default

It looks like you're using Let's Encrypt. Don't they automatically renew? That's what my SA told me when he recommended we switched to them...

Anyway, thanks for keeping us up and running!
Buff is offline   Reply With Quote
Old 08-19-2023, 03:52 PM   #9
Blaster86
UnModerator
 
Blaster86's Avatar
 
Join Date: Dec 2004
Location: North Vancouver, British Columbia.
Exp:
Default

Quote:
Originally Posted by photon View Post
Yeah the certificate just expired, I had the wrong day in my calendar.

The certs have been renewed so it should be ok now.

####ing liar.


Photon just made a large purchase off Bad Dragon with my credit card.


This is my story and I am sticking to it.
__________________

THANK MR DEMKO
CPHL Ottawa Vancouver
Blaster86 is offline   Reply With Quote
The Following 2 Users Say Thank You to Blaster86 For This Useful Post:
Old 08-19-2023, 04:18 PM   #10
photon
The new goggles also do nothing.
 
photon's Avatar
 
Join Date: Oct 2001
Location: Calgary
Exp:
Default

Quote:
Originally Posted by Buff View Post
It looks like you're using Let's Encrypt. Don't they automatically renew? That's what my SA told me when he recommended we switched to them...

Anyway, thanks for keeping us up and running!
There's a tool you use to renew them, just a command from the command line. The command does a verification before doing the renewal just to make sure that things are as they should be (i.e. prove that you own the domain name), so usually it's easy to have it automated; just run the command automatically once a day or week or whatever.

Unfortunately I'm using what's called a wildcard cert and that verification method is more complicated, I have to update some DNS records with a couple of strings and there's no built in way to automate that.

I'll probably change things a bit at some point to make it easier to automate.
__________________
Uncertainty is an uncomfortable position.
But certainty is an absurd one.
photon is offline   Reply With Quote
Old 08-19-2023, 04:31 PM   #11
dustygoon
Franchise Player
 
dustygoon's Avatar
 
Join Date: Jul 2004
Location: Bay Area
Exp:
Default

Quote:
Originally Posted by Blaster86 View Post
####ing liar.


Photon just made a large purchase off Bad Dragon with my credit card.


This is my story and I am sticking to it.
<googles "Bad Dragon" since don't know what it is and can't help myself>

<and cops just showed up>
__________________
.
"Fun must be always!" - Tomas Hertl
dustygoon is offline   Reply With Quote
Old 08-19-2023, 05:51 PM   #12
gvitaly
Franchise Player
 
gvitaly's Avatar
 
Join Date: Jul 2010
Exp:
Default

Quote:
Originally Posted by photon View Post
There's a tool you use to renew them, just a command from the command line. The command does a verification before doing the renewal just to make sure that things are as they should be (i.e. prove that you own the domain name), so usually it's easy to have it automated; just run the command automatically once a day or week or whatever.

Unfortunately I'm using what's called a wildcard cert and that verification method is more complicated, I have to update some DNS records with a couple of strings and there's no built in way to automate that.

I'll probably change things a bit at some point to make it easier to automate.
That certainly makes your life harder. I usually just upload the new .crt files once a year using WinSCP/PuTTY, restart the server instance and I'm good to go.
gvitaly is offline   Reply With Quote
Old 08-19-2023, 08:00 PM   #13
Owen15
Scoring Winger
 
Join Date: May 2012
Exp:
Default

Quote:
Originally Posted by Rejean31 View Post
I keep getting a message that this site is not secure.
I think we can all agree this site is highly insecure.
Owen15 is offline   Reply With Quote
The Following 10 Users Say Thank You to Owen15 For This Useful Post:
Old 08-19-2023, 08:07 PM   #14
Blaster86
UnModerator
 
Blaster86's Avatar
 
Join Date: Dec 2004
Location: North Vancouver, British Columbia.
Exp:
Default

Quote:
Originally Posted by dustygoon View Post
<googles "Bad Dragon" since don't know what it is and can't help myself>

<and cops just showed up>

You ARE a dirty girl, aren't you
__________________

THANK MR DEMKO
CPHL Ottawa Vancouver
Blaster86 is offline   Reply With Quote
The Following User Says Thank You to Blaster86 For This Useful Post:
Old 08-19-2023, 08:34 PM   #15
photon
The new goggles also do nothing.
 
photon's Avatar
 
Join Date: Oct 2001
Location: Calgary
Exp:
Default

Quote:
Originally Posted by gvitaly View Post
That certainly makes your life harder. I usually just upload the new .crt files once a year using WinSCP/PuTTY, restart the server instance and I'm good to go.
Let's Encrypt certs are only good for 3 months at a time.. but it's not that bad, the command puts the new certs in the right place so really I'm just replacing a WinSCP copy with a copy/paste into some DNS records, then do the same reload the web server and it's done.
__________________
Uncertainty is an uncomfortable position.
But certainty is an absurd one.
photon is offline   Reply With Quote
The Following User Says Thank You to photon For This Useful Post:
Old 08-20-2023, 05:42 PM   #16
Buff
Franchise Player
 
Buff's Avatar
 
Join Date: Apr 2004
Location: I don't belong here
Exp:
Default

Our previous web host wouldn't let us use Let's Encrypt telling us "we don't want to learn something new". So we sucked it up for a few years until it was time to refresh our sites and switch hosts. The new developer asked us to consider switching to Let's Encrypt. We were happy. I guess we don't have to worry about renewing them as the developers take care of that as part of our ongoing support and maintenance.... That frees up our time so we can be more efficient in asking our users "Have you tried turning it off and on again".
Buff is offline   Reply With Quote
The Following User Says Thank You to Buff For This Useful Post:
Old 08-21-2023, 01:12 PM   #17
FanIn80
GOAT!
 
FanIn80's Avatar
 
Join Date: Jun 2006
Exp:
Default

Today I learned about Bad Dragon, and I'm not so sure I needed that information.
FanIn80 is offline   Reply With Quote
The Following 2 Users Say Thank You to FanIn80 For This Useful Post:
Old 08-21-2023, 01:15 PM   #18
Blaster86
UnModerator
 
Blaster86's Avatar
 
Join Date: Dec 2004
Location: North Vancouver, British Columbia.
Exp:
Default

Quote:
Originally Posted by FanIn80 View Post
Today I learned about Bad Dragon, and I'm not so sure I needed that information.

Knowledge is power. Use it wisely.
__________________

THANK MR DEMKO
CPHL Ottawa Vancouver
Blaster86 is offline   Reply With Quote
Old 09-05-2023, 07:08 PM   #19
FlamesAddiction
Franchise Player
 
FlamesAddiction's Avatar
 
Join Date: Oct 2001
Location: Vancouver
Exp:
Default

Hey, just wondering if this is an issue for anyone again? I clicked on a CP link and my firewall gave me the notice saying that someone from debunk or debunker might be trying to hack through this website. On the address bar on my browser, it says "Dangerous" in red next to the CP url. None of the other websites I have tried are showing this.

Edit: I closed my browser and reopened CP, and the "Dangerous" tag is gone, so maybe nothing. Still kind of weird though.
__________________
"A pessimist thinks things can't get any worse. An optimist knows they can."

Last edited by FlamesAddiction; 09-05-2023 at 07:15 PM.
FlamesAddiction is online now   Reply With Quote
Old 09-05-2023, 07:22 PM   #20
gvitaly
Franchise Player
 
gvitaly's Avatar
 
Join Date: Jul 2010
Exp:
Default

Quote:
Originally Posted by FlamesAddiction View Post
Hey, just wondering if this is an issue for anyone again? I clicked on a CP link and my firewall gave me the notice saying that someone from debunk or debunker might be trying to hack through this website. On the address bar on my browser, it says "Dangerous" in red next to the CP url. None of the other websites I have tried are showing this.

Edit: I closed my browser and reopened CP, and the "Dangerous" tag is gone, so maybe nothing. Still kind of weird though.
I have been getting a passive mixed content warning on my FireFox. Essentially it means that the site is secure using HTTPS, but there are linked elements such as images from other sites that might not be secure.

From my perspective that's not really an issue. Passive mixed content can't really be used to steal personal data. I think it's more of a security risk in term of phishing/misleading.

EDIT: for example on this page it's Blaster's signature picture. Which comes from http://i.imgur.com/KshaBLB.gif , and that's why it's not secure. I don't get that warning on the main forum page.

Last edited by gvitaly; 09-05-2023 at 07:32 PM.
gvitaly is offline   Reply With Quote
The Following User Says Thank You to gvitaly For This Useful Post:
Reply


Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off

Forum Jump


All times are GMT -6. The time now is 08:00 PM.

Calgary Flames
2024-25




Powered by vBulletin® Version 3.8.4
Copyright ©2000 - 2025, Jelsoft Enterprises Ltd.
Copyright Calgarypuck 2021 | See Our Privacy Policy