Kodi Community Forum

Full Version: https for kodi.tv website
You're currently viewing a stripped down version of our content. View the full version with proper formatting.
Pages: 1 2
It's an ancient physical box with old slow disks and hardly any ram and cpu, an older OS and old versions of everything.
The problem is that there is little documentation, and some of the stuff running on it could not be migrated successfully last time we tried.

I feel confident that issue has been solved though, and that a second attempt to migrate would be more successful - now I need to find the time.
I did some security hardening and performance upgrades on the box - but this is as much as I can/will do until we move everything over to the new server.
SSL gets a solid B score at https://www.ssllabs.com/ssltest/analyze....Results=on now. It will be A once we move over.

edit: weirdly enough when accessing the link it sometimes says C, which is still cached from when i was setting up SSL.
Thanks for making https available on the main kodi website - given the old "rat" box, I think it's good enough solution to have https optionally available and link to those pages with https.

Any chance of getting the forum to use https? Here too the best solution would be to use https all the time, because there are "inline" login forms, but even just posting the password over https would be better than nothing, and a step above that would be using https for logged in users - it prevents passive/trivial attacks (http://en.wikipedia.org/wiki/Firesheep).

Also, it would be really nice to have the download hash information available over https (http://mirrors.xbmc.org/releases/win32/k...1.exe.sha1).

A more advanced alternative would be to use gpg, and have the signing key (or at least key fingerprint) available over https. Then either add a detached gpg signature to binaries, or just have hashes gpg signed, like many linux distros do.

(I guess having the windows installation binaries signed with authenticode is too much to ask...)
all in good time. We all have normal day jobs and a life Wink
A gentle reminder of a good time...
Not until we move the forum to a beter box. Think next year rather than next month.
Pages: 1 2