[clue-admin] Cert for TLS.

Jeff Cann president at cluedenver.org
Sat Jul 8 18:14:41 MDT 2006


Jed S. Baer wrote:
> On Fri, 07 Jul 2006 21:45:46 -0600
> David L. Anselmi wrote:
>
>   
>> I notice that we allow TLS to the web server but we don't have a 
>> meaningful certificate.  Anyone interested in correcting that?
>>     
>
> I've changed the httpd.conf file so that SSL is turned off. I don't know
> whether that impacts anything out there that I'm not aware of, and I
> assume it will disable TLS as well.

Jed,

Could you turn it back on?  Despite the invalid SSL cert, I use https to 
access GNU mailman administrative interface.  It normally sends 
passwords in clear text.  We got hacked at least once through mailman... 
not sure if it was due to clear text passwords or not.

I'm not sure if we need a valid cert,   It's funny to me that Dave 
suggested it because a few years ago, when I last suggested it, it was 
*Dave* who thought it wasn't necessary.  :)  Too bad we lost the 
archives as evidence.  Dang it!

Thanks
Jeff



More information about the clue-admin mailing list