Question on https for slimesalad + firefox

Talk about things that are not making games here. But you should also make games!

Moderators: Bob the Hamster, marionline, SDHawk

Post Reply
User avatar
marionline
Metal Slime
Posts: 673
Joined: Sat Feb 26, 2011 9:23 pm

Question on https for slimesalad + firefox

Post by marionline »

Hello!
I feel a bit stupid, but I am wondering what firefox's https-warning for slimesalad trying to tell me.
It says the website is not secure. :???: Did anyone else notice?
The reasons shown are the certificate is self-signed and not valid for slimesalad.com.

I'm not sure about the meaning of this. Is it that my web browser went paranoid after an update?
User avatar
Bob the Hamster
Lord of the Slimes
Posts: 7660
Joined: Tue Oct 16, 2007 2:34 pm
Location: Hamster Republic (Ontario Enclave)
Contact:

Post by Bob the Hamster »

I think it just means it is a self-signed certificate as opposed to a certificate signed by a trusted signer.

So it does protect against some level of eavesdropping, but does not verify site identity in any meaningful way.

(Untill today I had no idea that slimesalad even had any kind of https cert)
TMC
Metal King Slime
Posts: 4308
Joined: Sun Apr 10, 2011 9:19 am

Post by TMC »

The certificate is issued by DreamHost to itself. But even if you add a security exception, you'll find that you can't actually access SS over https -- you get a "Site not found" error. I'm guessing that that certificate is probably only used as a fallback by the hosting company to show error messages in case the website hasn't set up https. DreamHost might charge extra for https hosting, since it increases resource usage.
Last edited by TMC on Wed Feb 01, 2017 11:54 pm, edited 1 time in total.
User avatar
Bob the Hamster
Lord of the Slimes
Posts: 7660
Joined: Tue Oct 16, 2007 2:34 pm
Location: Hamster Republic (Ontario Enclave)
Contact:

Post by Bob the Hamster »

I use dreamhost too, and they provide completely free https using "Let's Encrypt" I have it working on all my domains.

I was assuming that Mogri had created his own SSL cert sometime before dreamhost added Let's Encrypt support-- but that was just a guess, I really don't know
User avatar
Mogri
Super Slime
Posts: 4669
Joined: Mon Oct 15, 2007 6:38 pm
Location: Austin, TX
Contact:

Post by Mogri »

Bob the Hamster wrote:I use dreamhost too, and they provide completely free https using "Let's Encrypt" I have it working on all my domains.

I was assuming that Mogri had created his own SSL cert sometime before dreamhost added Let's Encrypt support-- but that was just a guess, I really don't know
Hello hi. I've added a SSL cert. I had assumed that I would have to pay cash moneys for a cert, but I guess that's so last decade at this point. I should probably set up htaccess forwarding to https at this point, hmm?
User avatar
Taco Bot
Meat, Cheese, and Silicon
Posts: 484
Joined: Fri Jul 18, 2014 12:15 am
Location: Santa Cruz
Contact:

Post by Taco Bot »

Mogri wrote:Hello hi. I've added a SSL cert. I had assumed that I would have to pay cash moneys for a cert, but I guess that's so last decade at this point. I should probably set up htaccess forwarding to https at this point, hmm?
For sure. And thank you so much for setting up https. I was a little sketched out that ss was transmitting everything as plaintext. (I think? That's what I was led to believe?)
Sent from my iPhone
User avatar
Bob the Hamster
Lord of the Slimes
Posts: 7660
Joined: Tue Oct 16, 2007 2:34 pm
Location: Hamster Republic (Ontario Enclave)
Contact:

Post by Bob the Hamster »

Yay! The automatic https:// redirect works great :)
TMC
Metal King Slime
Posts: 4308
Joined: Sun Apr 10, 2011 9:19 am

Post by TMC »

Fantastic!

Let's Encrypt certs do have short expiry times though, have to watch out for that. It's apparently to encourage people to automate switching to new certificates regularly.
Last edited by TMC on Fri Mar 03, 2017 4:47 am, edited 1 time in total.
User avatar
Bob the Hamster
Lord of the Slimes
Posts: 7660
Joined: Tue Oct 16, 2007 2:34 pm
Location: Hamster Republic (Ontario Enclave)
Contact:

Post by Bob the Hamster »

Fortunately dreamhost already automated it
User avatar
FyreWulff
Slime Knight
Posts: 107
Joined: Wed Mar 13, 2013 9:16 pm
Location: The Internet
Contact:

Post by FyreWulff »

TMC wrote:Fantastic!

Let's Encrypt certs do have short expiry times though, have to watch out for that. It's apparently to encourage people to automate switching to new certificates regularly.
yeah, the point behind the constant expiry is that it's better than trying to maintain a growing giant blacklist of "bad" certs. Instead, certs just expire really fast, not lingering around and being a pain in the butt for future browsers.
Post Reply