certificate posts

It was recently discovered that Cogneato websites' HTTPS certificates were cross-signed by an expired AddTrust certificate, and were showing security warnings in old versions of Safari. Continue reading post "#2949"


Self-signed certificate for testing

In playing with service workers, I set up a self-signed SSL certificate for my local development environment. I used instructions from debian.org. It was very simple, since I didn't need the security involved with a real operating site. Creating the certs took a single command:

openssl req -new -x509 -days 365 -nodes -out /path/to/server/config/certs/sitename.pem -keyout /path/to/server/config/certs/sitename.key

You then just need to set things up in the server configuration (Apache in my case). mod_ssl must be installed and enabled, which looks something like:

LoadModule ssl_module modules/mod_ssl.so
Continue reading post "Self-signed certificate for testing"

My sites now HTTPS with LetsEncrypt

My sites are now HTTPS-enabled with LetsEncrypt. It was easy to set up with Dreamhost's panel. It was just a few clicks and some waiting. This is the first time my own sites have been available over HTTPS. I've been wanting to do it for a while, but it was kind of costly until the free LetsEncrypt became available. This brings my sites in line with the "HTTPS Everywhere" movement. I've also been wanting to play with the new installable apps forming standard for making web apps installable almost like native apps.

I had written a post before about how I'm setting my security-related headers. I've now added an HTTPS related header in a similar manner: Upgrade-Insecure-Requests and HSTS.

Continue reading post "My sites now HTTPS with LetsEncrypt"

</toby>