kepstin-laptop: sure, but this is a business that can afford to go a bit further
2014-07-08 18939, 2014
ocharles
ianmcorvidae: all good info, thanks!
2014-07-08 18914, 2014
ianmcorvidae
duraconf is pretty hardcore about secure ciphers, so you may need to add more (IIRC it only allows PFS ciphers, for example)
2014-07-08 18914, 2014
ocharles
those configs are especially useful
2014-07-08 18930, 2014
ianmcorvidae
depending what you're looking at supporting, etc.
2014-07-08 18958, 2014
ianmcorvidae
duraconf also turns on HSTS, which you may or may not need or care about
2014-07-08 18913, 2014
ianmcorvidae
(if you want to support non-ssl, you definitely *don't* want it, anyway)
2014-07-08 18915, 2014
kepstin-laptop
heh, the ssllabs test is kind of fun; kepstin.ca gets an A+ right now.
2014-07-08 18926, 2014
ocharles
we may actualy want hsts
2014-07-08 18931, 2014
warp acks
2014-07-08 18937, 2014
ocharles
we are very websocket heavy, and proxys tend to fuck them up pretty consistently
2014-07-08 18951, 2014
ocharles
e.g., the entire site is unusable on EE's mobile network atm becaus they strip out the "Upgrade" header
2014-07-08 18953, 2014
ocharles
thanks guys!
2014-07-08 18954, 2014
ianmcorvidae
yeah, obviously I don't know your needs :) so just trying to give general warnings
2014-07-08 18957, 2014
ianmcorvidae
heh, good job
2014-07-08 18903, 2014
ocharles
yea, appreciated :)
2014-07-08 18952, 2014
warp
I have nothing to add, ianmcorvidae covered everything interesting and more.
2014-07-08 18924, 2014
ocharles
well, I feel like i'll only be leaving with more questions
2014-07-08 18930, 2014
ocharles
but what else would I expect :)
2014-07-08 18934, 2014
ianmcorvidae
heh
2014-07-08 18934, 2014
warp
:D
2014-07-08 18943, 2014
ianmcorvidae
good ol' security/crypto
2014-07-08 18950, 2014
warp
ocharles: the ssllabs thing is good to check when it's all set up.
2014-07-08 18951, 2014
ianmcorvidae
and MB too, probably, we're bad about that I guess :P
2014-07-08 18945, 2014
ianmcorvidae
oh, if you want HSTS, also note that you can fairly easily add yourself to browser lists of HSTS sites with pull requests (I believe at least chrome/FF have established processes for this), though I haven't researched it deeply
2014-07-08 18952, 2014
ZaphodBeeblebrox joined the channel
2014-07-08 18917, 2014
spinza joined the channel
2014-07-08 18913, 2014
voiceinsideyou joined the channel
2014-07-08 18900, 2014
spinza joined the channel
2014-07-08 18908, 2014
Nyanko-sensei joined the channel
2014-07-08 18913, 2014
voiceinsideyou joined the channel
2014-07-08 18951, 2014
spinza joined the channel
2014-07-08 18955, 2014
Mineo
wow, today I learned that one of the guys who started studying here in ilmenau with me is now winning one stage of the tour de france after another