Re: [arch-dev-public] [RFC] Add archlinux.org domain to HSTS Preload list

2017-03-06 Thread Giancarlo Razzolini
Em janeiro 26, 2017 17:58 Giancarlo Razzolini escreveu: As one week was passed, and no objections were made, the archlinux.org was just added to the preload list [0][1]. [0] https://git.archlinux.org/infrastructure.git/commit/?id=9beccb72d1e6e26593484ddb2c7bf642ea9446d2 [1]

Re: [arch-dev-public] [RFC] Add archlinux.org domain to HSTS Preload list

2017-01-26 Thread Giancarlo Razzolini
Em janeiro 19, 2017 23:05 Giancarlo Razzolini escreveu: I plan to wait another week before moving on to adding archlinux.org domain to the preload list. Hi all, As one week was passed, and no objections were made, the archlinux.org was just added to the preload list [0][1]. It takes some

Re: [arch-dev-public] [RFC] Add archlinux.org domain to HSTS Preload list

2017-01-19 Thread Giancarlo Razzolini
Em janeiro 5, 2017 18:45 Giancarlo Razzolini escreveu: As it was reminded to me off list, preload is an all or nothing approach, due to the restrictions on the size of the preload list. Can I submit archlinux.org to the preload list? Two weeks have passed and there were no objections.

Re: [arch-dev-public] [RFC] Add archlinux.org domain to HSTS Preload list

2017-01-05 Thread Giancarlo Razzolini
Em janeiro 5, 2017 15:27 Giancarlo Razzolini escreveu: One option though is to not include subdomains and only make archlinux.org and www to the preload list now, and make the entire domain, after we are sure. As it was reminded to me off list, preload is an all or nothing approach,

Re: [arch-dev-public] [RFC] Add archlinux.org domain to HSTS Preload list

2017-01-05 Thread Giancarlo Razzolini
Em janeiro 5, 2017 14:26 Pierre Schmitz escreveu: In general a great idea. Our Torrent tracker does not support https as it seems: http://tracker.archlinux.org:6969/stat I haven't looked into it yet though. Port 443 redirects to bbs which is strange... I only tested port 443 on those

Re: [arch-dev-public] [RFC] Add archlinux.org domain to HSTS Preload list

2017-01-05 Thread Pierre Schmitz
On 04.01.2017 20:43, Giancarlo Razzolini wrote: Hi All, With some improvements we have been doing to the infrastructure, we've reached a point were practically everything on archlinux.org is hosted using TLS/SSL. I have run a sslyze test on every of our DNS entries and the ones

[arch-dev-public] [RFC] Add archlinux.org domain to HSTS Preload list

2017-01-04 Thread Giancarlo Razzolini
Hi All, With some improvements we have been doing to the infrastructure, we've reached a point were practically everything on archlinux.org is hosted using TLS/SSL. I have run a sslyze test on every of our DNS entries and the ones that did not answered are supposed to. In case you