Re: [Pharo-users] Insecure issue tracker registration

2018-06-15 Thread Marcus Denker
Hi, I have found a simple workaround (not yet the final solution): Please check: https://tracker.pharo.org/issues-register-service > On 15 Jun 2018, at 13:56, Tim Mackinnon wrote: > > I think Let’s Encrypt can be your friend (that seems to be the instructions > all of the providers

Re: [Pharo-users] Insecure issue tracker registration

2018-06-15 Thread Tim Mackinnon
I think Let’s Encrypt can be your friend (that seems to be the instructions all of the providers give - e.g. https://www.digitalocean.com/community/tutorials/how-to-secure-nginx-with-let-s-encrypt-on-ubuntu-16-04

Re: [Pharo-users] Insecure issue tracker registration

2018-06-15 Thread Marcus Denker
Hello, yes, we really need to setup SSL for that server. I will have a look next week. > On 13 Jun 2018, at 10:25, Manuel Leuenberger wrote: > > Hi, > > I announced my concerns on Discord already, but got no reaction, so I post it > here as well to have it properly archived. > > "A

Re: [Pharo-users] Insecure issue tracker registration

2018-06-13 Thread Ben Coman
On 13 June 2018 at 16:25, Manuel Leuenberger wrote: > Hi, > > I announced my concerns on Discord already, but got no reaction, so I post > it here as well to have it properly archived. > > "A colleague just noticed that the registration for the issue tracker is > HTTP-only. This is not an

[Pharo-users] Insecure issue tracker registration

2018-06-13 Thread Manuel Leuenberger
Hi, I announced my concerns on Discord already, but got no reaction, so I post it here as well to have it properly archived. "A colleague just noticed that the registration for the issue tracker is HTTP-only. This is not an appropriate choice for sensitive data like a password. Any