xapian websites available via https

James Aylett james-xapian at tartarus.org
Sun Jan 31 13:51:21 GMT 2016


On 24 Jan 2016, at 13:48, James Aylett <james-xapian at tartarus.org> wrote:

> Xapian’s websites (xapian.org, trac.xapian.org and lists.xapian.org) are now available via https: https://xapian.org, https://trac.xapian.org and https://lists.xapian.org/mailman/listinfo. (Currently https://lists.xapian.org/ redirects to non-https, because of limitations in mailman.)

Update: lists.xapian.org and trac.xapian.org will now *default* to https. If you access them via http, they’ll issue a redirect to the https version. If anyone has any issues at all with logging in or working with these sites, please let me know as soon as possible!

I’ll leave this for a month or so and then add HSTS headers and turn them into permanent redirects, so that browsers know not to bother trying the http version at all.

Some links within Mailman (particularly archives) will still go to http, because it doesn’t seem to have any configuration options for getting this right. As far as I can tell, neither Mailman nor Trac supports issuing secure-only cookies (which is why moving to HSTS is important).

I won’t be doing this (at least for the time being) for other Xapian sites.

J

-- 
 James Aylett, occasional trouble-maker
 xapian.org




More information about the Xapian-discuss mailing list