it seems that CPDL does not support HTTPS, even for the contributor wiki. An Apache webserver is listening on cpdl.org:443, but it just serves an error page. So contributors send their passwords over HTTP, like in 2005. It pains me to see this .
It should be pretty easy to get a free TLS certificate from letsencrypt.org and use it on cpdl.org, even if only for the contributor wiki. This should not take the administrator more than 20 minutes, and I'd volunteer to assist in the process (I have configured nginx to do this a number of times, it is straightforward).
We don't have to redirect people from HTTP to HTTPS at first, for fear of increased server load; the HTTPS option will just be there for the few security-sensitive contributors . Later, if the server load is acceptable, the login links can be changed to let everyone be more secure.
Forum for all users to discuss the implementation and operation of the ChoralWiki at CPDL
2 posts • Page 1 of 1
Who is online
Users browsing this forum: No registered users and 1 guest