08-19-2023, 09:52 AM
|
#1
|
Franchise Player
Join Date: Sep 2002
Location: Central Alberta
|
Anyone else having issues with site security?
I keep getting a message that this site is not secure.
__________________
Are the Oilers trying to set a record for most scumbags on the payroll??
|
|
|
The Following 13 Users Say Thank You to Rejean31 For This Useful Post:
|
14,
1qqaaz,
Badgers Nose,
CF84,
Cheese,
D as in David,
Flames_F.T.W,
Gaudreau is a Ninja,
nfotiu,
Pickle Juice,
Scroopy Noopers,
Southside403,
Wormius
|
08-19-2023, 09:53 AM
|
#2
|
Franchise Player
Join Date: Jun 2004
Location: Calgary
|
Yes
|
|
|
The Following User Says Thank You to Dan02 For This Useful Post:
|
|
08-19-2023, 09:55 AM
|
#3
|
Powerplay Quarterback
|
Guessing there's some issue with the security provider.
__________________
Matthew Tkachuk apologist.
|
|
|
The Following User Says Thank You to cam_calderon For This Useful Post:
|
|
08-19-2023, 09:56 AM
|
#4
|
Franchise Player
Join Date: Dec 2005
Location: back in the 403
|
Yeah I'm having to use Tapatalk, as Chrome won't even let me visit the normal version of the site due to security concerns.
|
|
|
08-19-2023, 09:57 AM
|
#5
|
First Line Centre
|
Me too. Says security certificate expired a day ago
|
|
|
08-19-2023, 10:04 AM
|
#6
|
#1 Goaltender
|
Yep- exactly. Cert expired. still loads as https though.
__________________
Hey...where'd my avatar go?
|
|
|
08-19-2023, 10:18 AM
|
#7
|
The new goggles also do nothing.
Join Date: Oct 2001
Location: Calgary
|
Yeah the certificate just expired, I had the wrong day in my calendar.
The certs have been renewed so it should be ok now.
__________________
Uncertainty is an uncomfortable position.
But certainty is an absurd one.
|
|
|
The Following 26 Users Say Thank You to photon For This Useful Post:
|
All In Good Time,
Barnet Flame,
Boblobla,
Buff,
CF84,
Cheese,
Draug,
dustygoon,
Fire,
flambers,
Flames1217,
GreenHardHat,
Groot,
klikitiklik,
Macho0978,
Mass_nerder,
midniteowl,
MrMike,
Reggie Dunlop,
Rejean31,
rogermexico,
Sainters7,
Scroopy Noopers,
terryclancy,
The Original FFIV,
Wormius
|
08-19-2023, 03:46 PM
|
#8
|
Franchise Player
Join Date: Apr 2004
Location: I don't belong here
|
It looks like you're using Let's Encrypt. Don't they automatically renew? That's what my SA told me when he recommended we switched to them...
Anyway, thanks for keeping us up and running!
|
|
|
08-19-2023, 03:52 PM
|
#9
|
UnModerator
Join Date: Dec 2004
Location: North Vancouver, British Columbia.
|
Quote:
Originally Posted by photon
Yeah the certificate just expired, I had the wrong day in my calendar.
The certs have been renewed so it should be ok now.
|
####ing liar.
Photon just made a large purchase off Bad Dragon with my credit card.
This is my story and I am sticking to it.
__________________

THANK MR DEMKOCPHL Ottawa Vancouver
|
|
|
The Following 2 Users Say Thank You to Blaster86 For This Useful Post:
|
|
08-19-2023, 04:18 PM
|
#10
|
The new goggles also do nothing.
Join Date: Oct 2001
Location: Calgary
|
Quote:
Originally Posted by Buff
It looks like you're using Let's Encrypt. Don't they automatically renew? That's what my SA told me when he recommended we switched to them...
Anyway, thanks for keeping us up and running!
|
There's a tool you use to renew them, just a command from the command line. The command does a verification before doing the renewal just to make sure that things are as they should be (i.e. prove that you own the domain name), so usually it's easy to have it automated; just run the command automatically once a day or week or whatever.
Unfortunately I'm using what's called a wildcard cert and that verification method is more complicated, I have to update some DNS records with a couple of strings and there's no built in way to automate that.
I'll probably change things a bit at some point to make it easier to automate.
__________________
Uncertainty is an uncomfortable position.
But certainty is an absurd one.
|
|
|
08-19-2023, 04:31 PM
|
#11
|
Franchise Player
Join Date: Jul 2004
Location: Bay Area
|
Quote:
Originally Posted by Blaster86
####ing liar.
Photon just made a large purchase off Bad Dragon with my credit card.
This is my story and I am sticking to it.
|
<googles "Bad Dragon" since don't know what it is and can't help myself>
<and cops just showed up>
__________________
.
"Fun must be always!" - Tomas Hertl
|
|
|
08-19-2023, 05:51 PM
|
#12
|
Franchise Player
|
Quote:
Originally Posted by photon
There's a tool you use to renew them, just a command from the command line. The command does a verification before doing the renewal just to make sure that things are as they should be (i.e. prove that you own the domain name), so usually it's easy to have it automated; just run the command automatically once a day or week or whatever.
Unfortunately I'm using what's called a wildcard cert and that verification method is more complicated, I have to update some DNS records with a couple of strings and there's no built in way to automate that.
I'll probably change things a bit at some point to make it easier to automate.
|
That certainly makes your life harder. I usually just upload the new .crt files once a year using WinSCP/PuTTY, restart the server instance and I'm good to go.
|
|
|
08-19-2023, 08:00 PM
|
#13
|
Scoring Winger
|
Quote:
Originally Posted by Rejean31
I keep getting a message that this site is not secure.
|
I think we can all agree this site is highly insecure.
|
|
|
The Following 10 Users Say Thank You to Owen15 For This Useful Post:
|
|
08-19-2023, 08:07 PM
|
#14
|
UnModerator
Join Date: Dec 2004
Location: North Vancouver, British Columbia.
|
Quote:
Originally Posted by dustygoon
<googles "Bad Dragon" since don't know what it is and can't help myself>
<and cops just showed up>
|
You ARE a dirty girl, aren't you
__________________

THANK MR DEMKOCPHL Ottawa Vancouver
|
|
|
The Following User Says Thank You to Blaster86 For This Useful Post:
|
|
08-19-2023, 08:34 PM
|
#15
|
The new goggles also do nothing.
Join Date: Oct 2001
Location: Calgary
|
Quote:
Originally Posted by gvitaly
That certainly makes your life harder. I usually just upload the new .crt files once a year using WinSCP/PuTTY, restart the server instance and I'm good to go.
|
Let's Encrypt certs are only good for 3 months at a time.. but it's not that bad, the command puts the new certs in the right place so really I'm just replacing a WinSCP copy with a copy/paste into some DNS records, then do the same reload the web server and it's done.
__________________
Uncertainty is an uncomfortable position.
But certainty is an absurd one.
|
|
|
The Following User Says Thank You to photon For This Useful Post:
|
|
08-20-2023, 05:42 PM
|
#16
|
Franchise Player
Join Date: Apr 2004
Location: I don't belong here
|
Our previous web host wouldn't let us use Let's Encrypt telling us "we don't want to learn something new". So we sucked it up for a few years until it was time to refresh our sites and switch hosts. The new developer asked us to consider switching to Let's Encrypt. We were happy. I guess we don't have to worry about renewing them as the developers take care of that as part of our ongoing support and maintenance.... That frees up our time so we can be more efficient in asking our users "Have you tried turning it off and on again".
|
|
|
The Following User Says Thank You to Buff For This Useful Post:
|
|
08-21-2023, 01:12 PM
|
#17
|
GOAT!
|
Today I learned about Bad Dragon, and I'm not so sure I needed that information.
|
|
|
The Following 2 Users Say Thank You to FanIn80 For This Useful Post:
|
|
08-21-2023, 01:15 PM
|
#18
|
UnModerator
Join Date: Dec 2004
Location: North Vancouver, British Columbia.
|
Quote:
Originally Posted by FanIn80
Today I learned about Bad Dragon, and I'm not so sure I needed that information.
|
Knowledge is power. Use it wisely.
__________________

THANK MR DEMKOCPHL Ottawa Vancouver
|
|
|
09-05-2023, 07:08 PM
|
#19
|
Franchise Player
Join Date: Oct 2001
Location: Vancouver
|
Hey, just wondering if this is an issue for anyone again? I clicked on a CP link and my firewall gave me the notice saying that someone from debunk or debunker might be trying to hack through this website. On the address bar on my browser, it says "Dangerous" in red next to the CP url. None of the other websites I have tried are showing this.
Edit: I closed my browser and reopened CP, and the "Dangerous" tag is gone, so maybe nothing. Still kind of weird though.
__________________
"A pessimist thinks things can't get any worse. An optimist knows they can."
Last edited by FlamesAddiction; 09-05-2023 at 07:15 PM.
|
|
|
09-05-2023, 07:22 PM
|
#20
|
Franchise Player
|
Quote:
Originally Posted by FlamesAddiction
Hey, just wondering if this is an issue for anyone again? I clicked on a CP link and my firewall gave me the notice saying that someone from debunk or debunker might be trying to hack through this website. On the address bar on my browser, it says "Dangerous" in red next to the CP url. None of the other websites I have tried are showing this.
Edit: I closed my browser and reopened CP, and the "Dangerous" tag is gone, so maybe nothing. Still kind of weird though.
|
I have been getting a passive mixed content warning on my FireFox. Essentially it means that the site is secure using HTTPS, but there are linked elements such as images from other sites that might not be secure.
From my perspective that's not really an issue. Passive mixed content can't really be used to steal personal data. I think it's more of a security risk in term of phishing/misleading.
EDIT: for example on this page it's Blaster's signature picture. Which comes from http://i.imgur.com/KshaBLB.gif , and that's why it's not secure. I don't get that warning on the main forum page.
Last edited by gvitaly; 09-05-2023 at 07:32 PM.
|
|
|
The Following User Says Thank You to gvitaly For This Useful Post:
|
|
Posting Rules
|
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts
HTML code is Off
|
|
|
All times are GMT -6. The time now is 10:01 AM.
|
|