7
Ticket #2171
Status: Closed
Opened by doubledogdare610
- Finished
Type:
Feature Request
Views:
990
Access:
Public
Opened:
8/20/16 5:20 pm 8/20/16 5:20 pm
Updated:
6/14/17 8:39 am 6/14/17 8:39 am

[Security Related] Request that planetminecraft.com get a HTTPS SSL security certificate..

It kind of bothers me that planetminecraft.com does not have a SSL security certificate.
It is highly critical for the saftey of PMC users.. I'd ask that administration implements one.

Here is a small list of well known and trusted Certificate Authorities in which a certificate can be obtained:

1. VeriSign (Lol, just found out that they no longer give out certificates without the purchase of other services.)
2. DigiCert
3. Symantec
4. GoDaddy
5. Comodo CA

Thank you for taking the time to read this ticket!
~doubledogdare610

EDIT: I have noticed that when I am using https://, I am not able to post replies to comments.. Looks like there is an even bigger problem..

Create an account or sign in to comment.

1
06/14/2017 8:39 am
Level 70 : Legendary Cyborg
Cyprezz
Cyprezz's Avatar
set status to Closed, set resolution to Finished.
All traffic is redirected to https.
1
03/23/2017 5:07 pm
Level 70 : Legendary Cyborg
Cyprezz
Cyprezz's Avatar
Chat now has https support.
All image tags in member content including submission descriptions, pms, comments, wall posts, etc retroactively support https & all future image tags going forward.
All internal links (www.planetminecraft.com) in member content will now maintain protocol choice.
Made several SSL fixes & changes to the current forums but they unfortunately won't maintain https while browsing until forced.
Closer to defaulting all traffic to https.
1
03/17/2017 4:51 pm
Level 70 : Legendary Cyborg
Cyprezz
Cyprezz's Avatar
set status to In Progress.
Site can be viewed via https. Still needs attention before closing this ticket. Some random images, advert tags and chat need attention before we can consider pushing all traffic to https but progress has been made.
1
03/17/2017 4:44 pm
Level 70 : Legendary Cyborg
Cyprezz
Cyprezz's Avatar
testing comments. Made significant progress on this today. Will continue testing and eliminating any non-secure assets. Feel free to test https now.
1
03/21/2017 12:16 am
Level 81 : Elite Blockhead
superalgae
superalgae's Avatar
Great news! Thanks Cyprezz! I just tried https, and everything is working so far. I'll comment here if I see any issues beyond the remaining work you listed.
1
03/16/2017 1:16 am
Level 81 : Elite Blockhead
superalgae
superalgae's Avatar
Supporting HTTPS might not be trivial, but such basic security should be higher priority than anything else on the site.
1
03/17/2017 10:02 am
Level 70 : Legendary Cyborg
Cyprezz
Cyprezz's Avatar
You're right. We're getting this taken care of as we speak and in the longer term, we will be supporting site wide https by default after the new forum launch.
1
03/12/2017 3:13 pm
Level 13 : Journeyman Network
Ralex
Ralex's Avatar
Chat is a perfect example of something that would break unless it also moved to SSL, because of how browsers work.

Websockets will force that the same method be used (so if you use HTTPS, the socket has to be secured) otherwise it will be refused. It's not a simple "enable it on the site" because there are parts that may not work correctly. That's why I said it's not simple. There's more than just a flag that's changed.

I believe we have the certificate already somewhere, but it's not a simple change to do.
1
03/12/2017 9:53 am
Level 22 : Expert Geek
SupremeMortal
SupremeMortal's Avatar
You can actually load HTTP data under a HTTPS connection however the browser will see the HTTP sources and mark the page as insecure.
1
03/11/2017 4:59 pm
Level 13 : Journeyman Network
Ralex
Ralex's Avatar
It's not "simple" to just go HTTP to HTTPS. Having done so myself, and seeing how MCF does it, it's not a simple "flip"

There is a huge amount of testing that has to go into it to make sure all services work correctly, because some pages will *refuse* to work if you load them in HTTPS but it still uses HTTP for stuff (like chat).
Planet Minecraft

Website

© 2010 - 2024
www.planetminecraft.com

Welcome