[almighty] deploying SSL certs

Karanbir Singh kbsingh at redhat.com
Fri Sep 9 08:22:46 UTC 2016


-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

hi,

Some considerations on getting to SSL in the demo infra.

1) the hostname for the API services are fixed at buildtime, with a
https service up, I'd like to potentially move this to https. ref:
https://github.com/almighty/almighty-ui/blob/master/cico_build_deploy.sh
#L13

2) if we can do (1) then I'd like to make all http:// traffic redirect
to https://

3) We need certs for demo.almighy.io as well as demo.api.almighty.io -
while we wait on external requirements, what is the risk in doing a
trial deployment with self signed certs ? The frontend service does
not itself make any calls, they are all done at the browser end, so
the user/dev accepting the certs once would be all thats needed ( till
we get the proper certs in place ).

Regards,

- -- 
Karanbir Singh, Project Lead, The CentOS Project, London, UK
Red Hat Ext. 8274455 | DID: 0044 207 009 4455
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v2.0.22 (GNU/Linux)

iQEcBAEBAgAGBQJX0nFWAAoJEI3Oi2Mx7xbtRIUIANKWf3dqUCgGn6t+/7739yrS
VH88CpahQ6EY60W7Pg1n4twnUgZlhraPGW5YuYFebLgvoc7Vb0m8d7M5tpiXqRsL
759C0K6Ogd28LWMrgupQ5obz6xxKMoQOj0ptpY2ODgn53xD6sZkIBIahX/BHCwzo
nU3qeckknKh/7jllRgDpeVZKr7WGAd2nWFZZVBRJykrljkxOGxYSy6JRbGDvaPWS
soskAtWxoAjBO8mU/DdWa/xkuYhjlj8DhoHH70P4hR1oQl1OQ0vbr6xjCRThY+h/
oaXczjva2R4VbHRhoSlXRXGuzMx/OPCGm39+oPRu5KiEEq+d1Em8wmPp+K5bKeA=
=1HOS
-----END PGP SIGNATURE-----




More information about the almighty-public mailing list