HTTPS at lists.ovirt.org

Hi, following a report in twitter I found that we support only HTTP and not HTTPS access to the lists.ovirt.org (www.ovirt.org supports https). The question is if we wish to allow https which is becoming mandatory these days? another related question, is if we wish to support HSTS which is the next step and Google starts enforcing it in its domain[2]. Thanks, Doron [1] https://en.wikipedia.org/wiki/HTTP_Strict_Transport_Security [2] http://www.zdnet.com/article/googles-hsts-rollout-forced-https-for-google-co...

I believe Evgheni & Duck are working on it as part of [1] moving all oVirt services to HTTPs. Evgheni/Duck - any update on adding it to lists.ovirt.org soon? [1] https://ovirt-jira.atlassian.net/browse/OVIRT-749 On Sun, Mar 5, 2017 at 12:20 PM, Doron Fediuck <dfediuck@redhat.com> wrote:
Hi, following a report in twitter I found that we support only HTTP and not HTTPS access to the lists.ovirt.org (www.ovirt.org supports https).
The question is if we wish to allow https which is becoming mandatory these days?
another related question, is if we wish to support HSTS which is the next step and Google starts enforcing it in its domain[2].
Thanks, Doron
[1] https://en.wikipedia.org/wiki/HTTP_Strict_Transport_Security [2] http://www.zdnet.com/article/googles-hsts-rollout- forced-https-for-google-com-aims-to-help-block-attacks/
_______________________________________________ Infra mailing list Infra@ovirt.org http://lists.ovirt.org/mailman/listinfo/infra
-- Eyal Edri Associate Manager RHV DevOps EMEA ENG Virtualization R&D Red Hat Israel phone: +972-9-7692018 irc: eedri (on #tlv #rhev-dev #rhev-integ)

For some reason lists.ovirt.org is excluded? On 5 March 2017 at 15:19, Eyal Edri <eedri@redhat.com> wrote:
I believe Evgheni & Duck are working on it as part of [1] moving all oVirt services to HTTPs.
Evgheni/Duck - any update on adding it to lists.ovirt.org soon?
[1] https://ovirt-jira.atlassian.net/browse/OVIRT-749
On Sun, Mar 5, 2017 at 12:20 PM, Doron Fediuck <dfediuck@redhat.com> wrote:
Hi, following a report in twitter I found that we support only HTTP and not HTTPS access to the lists.ovirt.org (www.ovirt.org supports https).
The question is if we wish to allow https which is becoming mandatory these days?
another related question, is if we wish to support HSTS which is the next step and Google starts enforcing it in its domain[2].
Thanks, Doron
[1] https://en.wikipedia.org/wiki/HTTP_Strict_Transport_Security [2] http://www.zdnet.com/article/googles-hsts-rollout-forced -https-for-google-com-aims-to-help-block-attacks/
_______________________________________________ Infra mailing list Infra@ovirt.org http://lists.ovirt.org/mailman/listinfo/infra
-- Eyal Edri Associate Manager RHV DevOps EMEA ENG Virtualization R&D Red Hat Israel
phone: +972-9-7692018 <+972%209-769-2018> irc: eedri (on #tlv #rhev-dev #rhev-integ)

Excluded from what? Its part of the list of servers that should get HTTPs support from what I understood, in progress as i mentioned. But lets wait for Evgheni & Duck to reply tomorrow to get more info. e. On Sun, Mar 5, 2017 at 3:41 PM, Doron Fediuck <dfediuck@redhat.com> wrote:
For some reason lists.ovirt.org is excluded?
On 5 March 2017 at 15:19, Eyal Edri <eedri@redhat.com> wrote:
I believe Evgheni & Duck are working on it as part of [1] moving all oVirt services to HTTPs.
Evgheni/Duck - any update on adding it to lists.ovirt.org soon?
[1] https://ovirt-jira.atlassian.net/browse/OVIRT-749
On Sun, Mar 5, 2017 at 12:20 PM, Doron Fediuck <dfediuck@redhat.com> wrote:
Hi, following a report in twitter I found that we support only HTTP and not HTTPS access to the lists.ovirt.org (www.ovirt.org supports https).
The question is if we wish to allow https which is becoming mandatory these days?
another related question, is if we wish to support HSTS which is the next step and Google starts enforcing it in its domain[2].
Thanks, Doron
[1] https://en.wikipedia.org/wiki/HTTP_Strict_Transport_Security [2] http://www.zdnet.com/article/googles-hsts-rollout-forced -https-for-google-com-aims-to-help-block-attacks/
_______________________________________________ Infra mailing list Infra@ovirt.org http://lists.ovirt.org/mailman/listinfo/infra
-- Eyal Edri Associate Manager RHV DevOps EMEA ENG Virtualization R&D Red Hat Israel
phone: +972-9-7692018 <+972%209-769-2018> irc: eedri (on #tlv #rhev-dev #rhev-integ)
-- Eyal Edri Associate Manager RHV DevOps EMEA ENG Virtualization R&D Red Hat Israel phone: +972-9-7692018 irc: eedri (on #tlv #rhev-dev #rhev-integ)

On 5 March 2017 at 15:54, Eyal Edri <eedri@redhat.com> wrote:
Excluded from what? Its part of the list of servers that should get HTTPs support from what I understood, in progress as i mentioned.
The ticket status is done. Is there another one?
But lets wait for Evgheni & Duck to reply tomorrow to get more info.
e.
On Sun, Mar 5, 2017 at 3:41 PM, Doron Fediuck <dfediuck@redhat.com> wrote:
For some reason lists.ovirt.org is excluded?
On 5 March 2017 at 15:19, Eyal Edri <eedri@redhat.com> wrote:
I believe Evgheni & Duck are working on it as part of [1] moving all oVirt services to HTTPs.
Evgheni/Duck - any update on adding it to lists.ovirt.org soon?
[1] https://ovirt-jira.atlassian.net/browse/OVIRT-749
On Sun, Mar 5, 2017 at 12:20 PM, Doron Fediuck <dfediuck@redhat.com> wrote:
Hi, following a report in twitter I found that we support only HTTP and not HTTPS access to the lists.ovirt.org (www.ovirt.org supports https).
The question is if we wish to allow https which is becoming mandatory these days?
another related question, is if we wish to support HSTS which is the next step and Google starts enforcing it in its domain[2].
Thanks, Doron
[1] https://en.wikipedia.org/wiki/HTTP_Strict_Transport_Security [2] http://www.zdnet.com/article/googles-hsts-rollout-forced -https-for-google-com-aims-to-help-block-attacks/
_______________________________________________ Infra mailing list Infra@ovirt.org http://lists.ovirt.org/mailman/listinfo/infra
-- Eyal Edri Associate Manager RHV DevOps EMEA ENG Virtualization R&D Red Hat Israel
phone: +972-9-7692018 <+972%209-769-2018> irc: eedri (on #tlv #rhev-dev #rhev-integ)
-- Eyal Edri Associate Manager RHV DevOps EMEA ENG Virtualization R&D Red Hat Israel
phone: +972-9-7692018 <+972%209-769-2018> irc: eedri (on #tlv #rhev-dev #rhev-integ)

On Sun, Mar 5, 2017 at 3:55 PM, Doron Fediuck <dfediuck@redhat.com> wrote:
On 5 March 2017 at 15:54, Eyal Edri <eedri@redhat.com> wrote:
Excluded from what? Its part of the list of servers that should get HTTPs support from what I understood, in progress as i mentioned.
The ticket status is done.
Missed that, thanks for letting me know, I re-opened it.
Is there another one?
But lets wait for Evgheni & Duck to reply tomorrow to get more info.
e.
On Sun, Mar 5, 2017 at 3:41 PM, Doron Fediuck <dfediuck@redhat.com> wrote:
For some reason lists.ovirt.org is excluded?
On 5 March 2017 at 15:19, Eyal Edri <eedri@redhat.com> wrote:
I believe Evgheni & Duck are working on it as part of [1] moving all oVirt services to HTTPs.
Evgheni/Duck - any update on adding it to lists.ovirt.org soon?
[1] https://ovirt-jira.atlassian.net/browse/OVIRT-749
On Sun, Mar 5, 2017 at 12:20 PM, Doron Fediuck <dfediuck@redhat.com> wrote:
Hi, following a report in twitter I found that we support only HTTP and not HTTPS access to the lists.ovirt.org (www.ovirt.org supports https).
The question is if we wish to allow https which is becoming mandatory these days?
another related question, is if we wish to support HSTS which is the next step and Google starts enforcing it in its domain[2].
Thanks, Doron
[1] https://en.wikipedia.org/wiki/HTTP_Strict_Transport_Security [2] http://www.zdnet.com/article/googles-hsts-rollout-forced -https-for-google-com-aims-to-help-block-attacks/
_______________________________________________ Infra mailing list Infra@ovirt.org http://lists.ovirt.org/mailman/listinfo/infra
-- Eyal Edri Associate Manager RHV DevOps EMEA ENG Virtualization R&D Red Hat Israel
phone: +972-9-7692018 <+972%209-769-2018> irc: eedri (on #tlv #rhev-dev #rhev-integ)
-- Eyal Edri Associate Manager RHV DevOps EMEA ENG Virtualization R&D Red Hat Israel
phone: +972-9-7692018 <+972%209-769-2018> irc: eedri (on #tlv #rhev-dev #rhev-integ)
-- Eyal Edri Associate Manager RHV DevOps EMEA ENG Virtualization R&D Red Hat Israel phone: +972-9-7692018 irc: eedri (on #tlv #rhev-dev #rhev-integ)
participants (2)
-
Doron Fediuck
-
Eyal Edri