10 posts, 4 contributors
Search the DAFNE Online Forums
alistairmcmi...
DAFNE Graduate
NHS Greater Glasgow and Clyde 5 posts |
Given that Chrome and Firefox both now flag any site that takes usernames and passwords over HTTP as insecure (in the address bar and in a popover respectively), are there plans to move the site to HTTPS? |
marke
Site Administrator
South East Kent PCT 681 posts |
Hi, |
alistairmcmi...
DAFNE Graduate
NHS Greater Glasgow and Clyde 5 posts |
Why not a free certificate from https://letsencrypt.org/? Linode do support them. |
marke
Site Administrator
South East Kent PCT 681 posts |
Hi, Sorry I have already explained why we cannot get a certificate. A free certificate is not an option because free certificate providers are not in the trusted root certificates store in windows and have to be manually added. Sorry if this seems to be a bit blunt but I do work in IT and have involvement in security. I know how certificates and security work and get audited on these things every 6 months. If someone produces the cash I will be more than happy to do it. We did try to get financial help from Diabetes UK but they were not interested and the NHS don't have the ability to give us money unless we are a limited company which also means a load of financial costs. We run the site in our spare time with no money, This is not a sob story, we are happy to do it, we just have no financial resources. |
alistairmcmi...
DAFNE Graduate
NHS Greater Glasgow and Clyde 5 posts |
That's the good thing about Let's Encrypt certificates. They are signed by a root certificate that is already installed on everyone's devices. So no manual work necessary on anyone's devices. |
marke
Site Administrator
South East Kent PCT 681 posts |
Hi, thanks it does look as though this would work. I will try to set something up to test it on our site, I just need to ensure that all devices can connect without an issue or we might have to change the site to use https on supported devices. This looks to be a new operation and is unlike the free one we currently use ( for email) that is not in the trusted root authority store. It too needs to be updated regularly but we can live with that since its worth it if its free. I will update this thread once I have tested it and ensured it works as expected on most devices. |
michaelj
DAFNE Graduate
South East Kent PCT 45 posts |
I too have had problems with the new version of Firefox telling me the DAFNE site is unsecured. Have now stopped using this to log in, but find the Google Chrome still functions with no problems and lets me in without fuss |
marke
Site Administrator
South East Kent PCT 681 posts |
So, After a few headaches and some downtime we now support https. Thanks go to Alistair for pointing me in the direction of lets encrypt. We are still supporting both http and https so you can use either at the moment. Eventually I will try to re-direct http requests to the http site but I need a rest now ;-) Upgrading websites is really not as easy as it should be when you do it in your own time ( that's both Simon and me, not just me !). I will add a news item to the site to let everyone know they can now use https and get rid of the browser warnings about security. |
alistairmcmi...
DAFNE Graduate
NHS Greater Glasgow and Clyde 5 posts |
That's great news. Thanks Mark and Simon for taking the time to do this. Sorry for giving your guys a headache. I feel bad for not offering to help out now. |
Simon
Site Administrator
Sheffield Teaching Hospitals 578 posts |
Hi Alistair, |