Page 1 of 1

Homepage: Link to the Forum isn't https:// (anymore) -SOLVED-

Posted: Sun Sep 23, 2018 9:19 am
by Dr. Octagon
Hello,

can someone tell me, why the Forum-Link on the homepage (https://linuxmint.com/links.php) does not refer to https://forum but to http://forum instead?
Additionally: If you get to the forum via this link... the forum login will be unencrypted, too.

Cu
Dr. Octagon

Re: Homepage: Link to the Forum isn't https:// (anymore)

Posted: Sun Sep 23, 2018 9:33 am
by gm10
Probably an oversight. The unencrypted login aside, which is a problem, the forums don't even work properly in http:// - at least Chromium blocks https:// sourced images on an http:// site so things like e.g. the Mint logo won't even show. Frankly http:// access should just be disabled completely.

I'll send the forum admin a PM about this.

Re: Homepage: Link to the Forum isn't https:// (anymore)

Posted: Mon Sep 24, 2018 12:33 am
by xenopeek
I can't reproduce this. Using the HTTP link to either will result in the server sending back a HTTP 301 response, redirecting the web browser to use HTTPS instead.

Possibly the issue is related to web browser cache. I'd like to know which web browser you were using and whether you can reproduce this somewhere that you have not visited those links prior. Like, create a new user account on your Linux Mint system and log in to that and try the links from there. (or completely delete your web browser cache but that's heavy handed) That way your web browser will have a clean cache and won't interfere.

I tested also with curl to cut out anything the web browser might be doing (output of commands cut for brevity):

Code: Select all

$ curl -v http://forums.linuxmint.com
< HTTP/1.1 301 Moved Permanently
< Location: https://forums.linuxmint.com/

$ curl -v http://blog.linuxmint.com
< HTTP/1.1 301 Moved Permanently
< Location: https://blog.linuxmint.com/

Re: Homepage: Link to the Forum isn't https:// (anymore)

Posted: Mon Sep 24, 2018 1:34 am
by catweazel
xenopeek wrote:
Mon Sep 24, 2018 12:33 am
I can't reproduce this.
I can. The link from https://linuxmint.com/links.php points to forums.linuxmint.com, without the protocol being specified, which causes the browser to not use https:// hence people clicking on the link from that page get an insecure connection.

Image

Note the lack of protocol being specified.

Re: Homepage: Link to the Forum isn't https:// (anymore)

Posted: Mon Sep 24, 2018 1:42 am
by administrollaattori
catweazel wrote:
Mon Sep 24, 2018 1:34 am
I can. The link from https://linuxmint.com/links.php points to forums.linuxmint.com,
I can also.
http-forums.jpg

Re: Homepage: Link to the Forum isn't https:// (anymore)

Posted: Mon Sep 24, 2018 3:02 am
by gm10
xenopeek wrote:
Mon Sep 24, 2018 12:33 am
I tested also with curl to cut out anything the web browser might be doing (output of commands cut for brevity):

Code: Select all

$ curl -v http://forums.linuxmint.com
< HTTP/1.1 301 Moved Permanently
< Location: https://forums.linuxmint.com/
Not what I'm getting:

Code: Select all

$ curl -v http://forums.linuxmint.com
* Connected to forums.linuxmint.com (192.124.249.8) port 80 (#0)
> User-Agent: curl/7.58.0
*< HTTP/1.1 200 OK
Also confirming the issue with Firefox 63 beta and all Chromium-based browsers.
xenopeek wrote:
Mon Sep 24, 2018 12:33 am

Code: Select all

$ curl -v http://blog.linuxmint.com
< HTTP/1.1 301 Moved Permanently
< Location: https://blog.linuxmint.com/
This one I can confirm, but we didn't flag that as a problem in the first place. On the other hand, the link to The Chat Room also won't redirect to https://. Suggest you just change all the links on that page to https:// out of principle.

Re: Homepage: Link to the Forum isn't https:// (anymore)

Posted: Mon Sep 24, 2018 5:52 am
by xenopeek
I have a suspicion. Can those with this issue run this command and share its output?
ping -c1 forums.linuxmint.com

Re: Homepage: Link to the Forum isn't https:// (anymore)

Posted: Mon Sep 24, 2018 5:57 am
by gm10
xenopeek wrote:
Mon Sep 24, 2018 5:52 am
I have a suspicion. Can those with this issue run this command and share its output?
ping -c1 forums.linuxmint.com
I have the same suspicion, that why I already included the IP in my curl output above. CDNs are fun. ;)

Re: Homepage: Link to the Forum isn't https:// (anymore)

Posted: Mon Sep 24, 2018 5:59 am
by catweazel
xenopeek wrote:
Mon Sep 24, 2018 5:52 am
I have a suspicion. Can those with this issue run this command and share its output?
ping -c1 forums.linuxmint.com

Code: Select all

~ $: ping -c1 forums.linuxmint.com
PING forums.linuxmint.com (192.124.249.8) 56(84) bytes of data.
64 bytes from cloudproxy10008.sucuri.net (192.124.249.8): icmp_seq=1 ttl=54 time=176 ms

--- forums.linuxmint.com ping statistics ---
1 packets transmitted, 1 received, 0% packet loss, time 0ms
rtt min/avg/max/mdev = 176.865/176.865/176.865/0.000 ms
I spy... cdn.

Re: Homepage: Link to the Forum isn't https:// (anymore)

Posted: Mon Sep 24, 2018 6:12 am
by xenopeek
gm10 wrote:
Mon Sep 24, 2018 3:02 am
Not what I'm getting:

Code: Select all

$ curl -v http://forums.linuxmint.com
* Connected to forums.linuxmint.com (192.124.249.8) port 80 (#0)
> User-Agent: curl/7.58.0
*< HTTP/1.1 200 OK
Even if I do curl -v forums.linuxmint.com it sends me the https redirect. I'm on the same Sucuri server as both of you so I'm stumped. I'll carry this up the chain to find an explanation. I mean, we'll update the website but that doesn't help people typing it manually. Sucuri should do a catchall redirect.

Re: Homepage: Link to the Forum isn't https:// (anymore)

Posted: Mon Sep 24, 2018 6:23 am
by gm10
xenopeek wrote:
Mon Sep 24, 2018 6:12 am
Sucuri should do a catchall redirect.
True but you could also force a redirect on the server instead or in addition, or at the very least force your login form to post to a https:// destination.

Re: Homepage: Link to the Forum isn't https:// (anymore)

Posted: Mon Sep 24, 2018 6:54 am
by Laurent85
A Sucuri issue, one of their proxy is outdated.

From my ISP, http accepted:

Code: Select all

curl -v http://forums.linuxmint.com
* Connected to forums.linuxmint.com (192.124.249.8) port 80 (#0)
> GET / HTTP/1.1
> Host: forums.linuxmint.com
> Accept: */*
> 
< HTTP/1.1 200 OK
< Server: Sucuri/Cloudproxy
< Date: Mon, 24 Sep 2018 10:33:25 GMT
< Content-Type: text/html; charset=UTF-8
< Transfer-Encoding: chunked
< Connection: keep-alive
< X-Sucuri-ID: 15008
From a different network using Tor, redirected to https:

Code: Select all

torify curl -v http://forums.linuxmint.com
Connected to forums.linuxmint.com (192.124.249.8) port 80 (#0)
> GET / HTTP/1.1
> Host: forums.linuxmint.com
> Accept: */*
> 
< HTTP/1.1 301 Moved Permanently
< Server: Sucuri/Cloudproxy
< Date: Mon, 24 Sep 2018 10:28:13 GMT
< Content-Type: text/html
< Content-Length: 178
< Connection: keep-alive
< Location: https://forums.linuxmint.com/
< X-XSS-Protection: 1; mode=block
< X-Frame-Options: SAMEORIGIN
< X-Content-Type-Options: nosniff
< X-Sucuri-ID: 13008

Re: Homepage: Link to the Forum isn't https:// (anymore)

Posted: Mon Sep 24, 2018 7:11 am
by gm10
Laurent85 wrote:
Mon Sep 24, 2018 6:54 am
A Sucuri issue, one of their proxy is outdated.
From a different network using Tor, redirected to https:
To narrow it down, using Opera's built-in VPN, the European endpoint receives http:// only, the Asian and American endpoints get redirected to https://

Re: Homepage: Link to the Forum isn't https:// (anymore)

Posted: Mon Sep 24, 2018 8:06 am
by xenopeek
And I'm in Europe not using any VPN... :lol:

Re: Homepage: Link to the Forum isn't https:// (anymore)

Posted: Mon Sep 24, 2018 8:14 am
by gm10
xenopeek wrote:
Mon Sep 24, 2018 8:06 am
And I'm in Europe not using any VPN... :lol:
Hah. Let me correct my previous post:
gm10 wrote:
Mon Sep 24, 2018 7:11 am
To narrow it down add to the confusion
:mrgreen:

Probably just load balancing in Europe though that masks this.

Re: Homepage: Link to the Forum isn't https:// (anymore)

Posted: Mon Sep 24, 2018 8:16 am
by karlchen
catweazel wrote:
Mon Sep 24, 2018 1:34 am
Image
Note the lack of protocol being specified.
This is merely caused by one of your Firefox settings. (browser.urlbar.trimURLs=true)
Mine tells me: http://forums.linuxmint.com/ (browser.urlbar.trimURLs=false)

Re: Homepage: Link to the Forum isn't https:// (anymore)

Posted: Mon Sep 24, 2018 8:25 am
by gm10
karlchen wrote:
Mon Sep 24, 2018 8:16 am
This is merely caused by one of your Firefox settings. (browser.urlbar.trimURLs=true)
For what it's worth, on chromium browsers: chrome://flags/#omnibox-ui-hide-steady-state-url-scheme-and-subdomains

Re: Homepage: Link to the Forum isn't https:// (anymore)

Posted: Mon Sep 24, 2018 10:40 am
by xenopeek
We've updated all the links on the https://linuxmint.com/links.php page, to add https where websites support it. Thanks for letting us know!

The redirect to https sometimes not happening is upstream to us and likely affects many more websites besides us. We'll have to wait a bit how that resolves. At least people coming here through links on the homepage will now be sent correctly to https.

Re: Homepage: Link to the Forum isn't https:// (anymore) -SOLVED-

Posted: Mon Sep 24, 2018 12:07 pm
by Dr. Octagon
Thanks!

Works fine now.

Cu
Dr. Octagon

Re: Homepage: Link to the Forum isn't https:// (anymore) -SOLVED-

Posted: Mon Oct 08, 2018 3:15 pm
by xenopeek
As a further update the issue with http not always redirecting to https looks to have been solved today. Manually typing the http link or opening the http link from a bookmark should automatically get redirected to https.