kepstin-laptop: sure, but this is a business that can afford to go a bit further
ianmcorvidae: all good info, thanks!
ianmcorvidae
duraconf is pretty hardcore about secure ciphers, so you may need to add more (IIRC it only allows PFS ciphers, for example)
ocharles
those configs are especially useful
ianmcorvidae
depending what you're looking at supporting, etc.
duraconf also turns on HSTS, which you may or may not need or care about
(if you want to support non-ssl, you definitely *don't* want it, anyway)
kepstin-laptop
heh, the ssllabs test is kind of fun; kepstin.ca gets an A+ right now.
ocharles
we may actualy want hsts
warp acks
we are very websocket heavy, and proxys tend to fuck them up pretty consistently
e.g., the entire site is unusable on EE's mobile network atm becaus they strip out the "Upgrade" header
thanks guys!
ianmcorvidae
yeah, obviously I don't know your needs :) so just trying to give general warnings
heh, good job
ocharles
yea, appreciated :)
warp
I have nothing to add, ianmcorvidae covered everything interesting and more.
ocharles
well, I feel like i'll only be leaving with more questions
but what else would I expect :)
ianmcorvidae
heh
warp
:D
ianmcorvidae
good ol' security/crypto
warp
ocharles: the ssllabs thing is good to check when it's all set up.
ianmcorvidae
and MB too, probably, we're bad about that I guess :P
oh, if you want HSTS, also note that you can fairly easily add yourself to browser lists of HSTS sites with pull requests (I believe at least chrome/FF have established processes for this), though I haven't researched it deeply
ZaphodBeeblebrox joined the channel
spinza joined the channel
voiceinsideyou joined the channel
spinza joined the channel
Nyanko-sensei joined the channel
voiceinsideyou joined the channel
spinza joined the channel
Mineo
wow, today I learned that one of the guys who started studying here in ilmenau with me is now winning one stage of the tour de france after another