Allow access through HTTPS...
Page 1 of 1
LeoNatan
☢ NFOHump Despot ☢



Posts: 73196
Location: Ramat Gan, Israel ๐Ÿ‡ฎ๐Ÿ‡ฑ
PostPosted: Sun, 19th Jun 2011 18:29    Post subject: Allow access through HTTPS...
Work has blocked NFOHump as a "sex" category... Rolling Eyes Laughing
So I use Opera Turbo as my "proxy" to visit, but its time is limited and I have to use Opera!

Please enable HTTPS access. There are some very cheap certificated at GoDaddy, or even better create nforce CA and users can add its root certificate to their trusted RCAs, if they want. This is very easy to do with OpenSSL or xca for more GUI approach.

Please spare me the headaches of trying to look for proxies.

Thank you,
Leo
Back to top
inz




Posts: 11914

PostPosted: Sun, 19th Jun 2011 18:32    Post subject:
Get a VPN?
Back to top
Neon
VIP Member



Posts: 18934
Location: Poland
PostPosted: Sun, 19th Jun 2011 18:35    Post subject:
Doubt he can install it in work.
Back to top
PumpAction
[Schmadmin]



Posts: 26759

PostPosted: Sun, 19th Jun 2011 18:46    Post subject:
Uhm NFOrce is already SSL secured (hehe, by comodo Laughing) and seems to be free too http://www.comodo.com/e-commerce/ssl-certificates/free-ssl-cert.php Laughing

Actually I'd like this too as I visit the hump when I'm at work too, but they don't block any shit over here Very Happy


=> NFOrce GIF plugin <= - Ryzen 3800X, 16GB DDR4-3200, Sapphire 5700XT Pulse
Back to top
LeoNatan
☢ NFOHump Despot ☢



Posts: 73196
Location: Ramat Gan, Israel ๐Ÿ‡ฎ๐Ÿ‡ฑ
PostPosted: Sun, 19th Jun 2011 19:45    Post subject:
inz wrote:
Get a VPN?

No. I have VPNs and they don't work.
Back to top
LeoNatan
☢ NFOHump Despot ☢



Posts: 73196
Location: Ramat Gan, Israel ๐Ÿ‡ฎ๐Ÿ‡ฑ
PostPosted: Sun, 19th Jun 2011 19:46    Post subject:
PumpAction wrote:
Uhm NFOrce is already SSL secured (hehe, by comodo Laughing) and seems to be free too http://www.comodo.com/e-commerce/ssl-certificates/free-ssl-cert.php Laughing

I doubt their Extended Validation Certificate is free (the green bar).

BTW,
 Spoiler:
 
Back to top
Werelds
Special Little Man



Posts: 15098
Location: 0100111001001100
PostPosted: Sun, 19th Jun 2011 20:14    Post subject:
Hell, I can generate the goddamn SSL certificate if needed Smile

Edit: anyone can for the record, it's a piece of cake. Mrt needs to fiddle with the config to set it up though, but that's still a piece of cake, whole process takes like 3 minutes
Back to top
LeoNatan
☢ NFOHump Despot ☢



Posts: 73196
Location: Ramat Gan, Israel ๐Ÿ‡ฎ๐Ÿ‡ฑ
PostPosted: Sun, 19th Jun 2011 20:17    Post subject:
I don't trust you with the RCA! Mad You still don't have access to the VIP pr0n FTP and I know you are on the hunt for user credentials......
Back to top
Werelds
Special Little Man



Posts: 15098
Location: 0100111001001100
PostPosted: Sun, 19th Jun 2011 20:30    Post subject:
I will soonโ„ข, I've got LulzSec going for it Cool Face
Back to top
Areius




Posts: 14850

PostPosted: Sun, 19th Jun 2011 22:54    Post subject:
Werelds wrote:
Hell, I can generate the goddamn SSL certificate if needed Smile

Edit: anyone can for the record, it's a piece of cake. Mrt needs to fiddle with the config to set it up though, but that's still a piece of cake, whole process takes like 3 minutes
But it probably won't be from a certified ssl provider, unless you are one of them Smile
Back to top
LeoNatan
☢ NFOHump Despot ☢



Posts: 73196
Location: Ramat Gan, Israel ๐Ÿ‡ฎ๐Ÿ‡ฑ
PostPosted: Sun, 19th Jun 2011 22:56    Post subject:
You can always add the root certificate, and it will be recognized throughout the operating system (beside Firefox Laughing). I don't see anything bad in this, just save money for the admins for certificates. Most people will use the regular port 80 clear version so it doesn't matter so much.
Back to top
LeoNatan
☢ NFOHump Despot ☢



Posts: 73196
Location: Ramat Gan, Israel ๐Ÿ‡ฎ๐Ÿ‡ฑ
PostPosted: Sun, 19th Jun 2011 23:09    Post subject:
Back to top
Werelds
Special Little Man



Posts: 15098
Location: 0100111001001100
PostPosted: Sun, 19th Jun 2011 23:21    Post subject:
Areius wrote:
But it probably won't be from a certified ssl provider, unless you are one of them Smile

No, but you can be your own root CA like Leo shows; and even in FF you can add the root certificate to your trusted ones (you used to at least? or did they remove that?). Only thing you gotta do is add the mime types to your server's config so it presents the public ones properly, and most browsers pick it up like they should. Result: a dialog whether you trust this CA, trust it permanently, job done Smile
Back to top
LeoNatan
☢ NFOHump Despot ☢



Posts: 73196
Location: Ramat Gan, Israel ๐Ÿ‡ฎ๐Ÿ‡ฑ
PostPosted: Sun, 19th Jun 2011 23:24    Post subject:
You still can in FF, but Mozilla being Mozilla, they have their own store Rolling Eyes, instead of using the native OSes' certificate stores. That's stupid in my opinion.
Back to top
Werelds
Special Little Man



Posts: 15098
Location: 0100111001001100
PostPosted: Sun, 19th Jun 2011 23:31    Post subject:
Yes it is. Still, just add the mimetype, provide a link to the public key and FF users can still accept it so Smile

Been a while since I last did it myself though, we've been using Digicert mostly, just have the clients pay extra. Considered going through the WebTrust process ourselves, but it's such a pain Razz
Back to top
LeoNatan
☢ NFOHump Despot ☢



Posts: 73196
Location: Ramat Gan, Israel ๐Ÿ‡ฎ๐Ÿ‡ฑ
PostPosted: Sun, 19th Jun 2011 23:40    Post subject:
The entire CAs and certification process is ridiculous. especially with the larger CAs, such as VeriSign. They charge insane amounts of cash for seemingly nothing. Sure, verification takes manpower and time, and should be charged for. But are you fucking kidding me? For the simpler certificates, only proof of domain ownership is needed and perhaps a scan of your ID card. Yes, that is obviously work 1000$ for a 2 year certificate for one domain or sub-domain name. Laughing And the wildcard certificates are even more hilariously priced (instead of "www.", the admin has to type "*." Shocked). Or how some charge more for larger keys, like they need to seat or something to generate the keys and sign. Laughing
Back to top
garus
VIP Member



Posts: 34200

PostPosted: Sun, 19th Jun 2011 23:45    Post subject:
snip


Last edited by garus on Tue, 27th Aug 2024 21:57; edited 1 time in total
Back to top
Werelds
Special Little Man



Posts: 15098
Location: 0100111001001100
PostPosted: Mon, 20th Jun 2011 00:17    Post subject:
The certificates are easy. A certificate is signed by a root authority though. Ever noticed the green address bar on sites like paypal? That's because those are signed by an authority that is "trusted" by browser manufacturers (amongst others). Now, I can give you hundreds of certificates, signed by me as their authority. Result? Popup whenever they are used, asking to allow it. That popup doesn't show for the trusted authorities. A trusted certificate still doesn't guarantee that a site is completely legit though.

That is in a nutshell why the whole business is so stupid.
Back to top
Dazz99




Posts: 7300

PostPosted: Mon, 20th Jun 2011 00:30    Post subject:
you browse nforce enough, you should focus on work at work and not your post count

your boss,
dazz


cockcockcockcockcockcockcockcockcockcockcockcock
Back to top
Werelds
Special Little Man



Posts: 15098
Location: 0100111001001100
PostPosted: Mon, 20th Jun 2011 01:33    Post subject:
You trying to tell us something with that sig there dazz? Cool Face
Back to top
[mrt]
[Admin] Code Monkey



Posts: 1342

PostPosted: Tue, 21st Jun 2011 01:13    Post subject:
What will happen if I accidentally click on,

https://www.nfohump.com

Oooo... Very Happy

Remember that this is on a sort of a trial run. If it works out without any major problems or issues it will stay. Also use the regular unsecured address to get to the hump whenever possible if you can and use the secured connection only when you have no other choice. Regular http is faster.


teey
Back to top
LeoNatan
☢ NFOHump Despot ☢



Posts: 73196
Location: Ramat Gan, Israel ๐Ÿ‡ฎ๐Ÿ‡ฑ
PostPosted: Tue, 21st Jun 2011 05:32    Post subject:
Very Happy Very Happy Very Happy

Can you share the NFOhump Ring certificate?
Back to top
PumpAction
[Schmadmin]



Posts: 26759

PostPosted: Tue, 21st Jun 2011 12:39    Post subject:
So I can log on from work now and them company can't log that stuff? Very Happy


=> NFOrce GIF plugin <= - Ryzen 3800X, 16GB DDR4-3200, Sapphire 5700XT Pulse
Back to top
LeoNatan
☢ NFOHump Despot ☢



Posts: 73196
Location: Ramat Gan, Israel ๐Ÿ‡ฎ๐Ÿ‡ฑ
PostPosted: Tue, 21st Jun 2011 19:11    Post subject:
PumpAction wrote:
So I can log on from work now and them company can't log that stuff? Very Happy

Unless your company has an SSL inspection system (like one from Check Point ) and pushes the root CA down with the GPO. Always check the certification path to make sure.

Here is one good reason to have the certificate stores separate from the OS ala Firefox.
Back to top
Yuri




Posts: 11000

PostPosted: Tue, 21st Jun 2011 21:15    Post subject:
Dazz99 wrote:
you browse nforce enough, you should focus on work at work and not your post count

your boss,
dazz





1 and 2 are still amazing.
Back to top
Page 1 of 1 All times are GMT + 1 Hour
NFOHump.com Forum Index - Site Feedback
Signature/Avatar nuking: none (can be changed in your profile)  


Display posts from previous:   

Jump to:  
You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum


Powered by phpBB 2.0.8 © 2001, 2002 phpBB Group