MTBNJ.COM Security!

Patrick

Overthinking the draft from the basement already
Staff member
computer geek time.....you need to change the settings on the web server to only allow HTTPS connections.

Done just now. Well sort of -

Geekin'
I used the rewrite rules in .htaccess as a redirect - if i did it correctly, there is no way to bypass them.
(basically, if the server port is 80 go https) - along with redirecting mtbnj.org->mtbnj.com

So Forumers (forumizens?)- let me know if i broke it! or if you can break it.
 

jdgang

Well-Known Member
seems to be working. Went to a different browser and typed in mtbnj and it went directly to https. also it did it on my phone.
 

Patrick

Overthinking the draft from the basement already
Staff member

the signed certificate only applies to the www and base domain names (mtbnj.com)
so the error happens before the web page is fetched. (cause security)

on some browsers, it is only the base name (this seems like a config error on server side, as there should
be two certificates) clicking on the padlock on desktop version of chome, it clearly shows the certificate
pertains to the server mtbnj.com

on the iphone (which uses the apple webkit underneath) it shows that it isn't secure for www.mtbnj.com -
which is how i rewrite the URL - i could just rewrite it to mtbnj.com instead - but it will still throw the error
on first contact.

Seems it was working yesterday tho!
 

soundz

The Hat
Team MTBNJ Halter's
the signed certificate only applies to the www and base domain names (mtbnj.com)
so the error happens before the web page is fetched. (cause security)

on some browsers, it is only the base name (this seems like a config error on server side, as there should
be two certificates) clicking on the padlock on desktop version of chome, it clearly shows the certificate
pertains to the server mtbnj.com

on the iphone (which uses the apple webkit underneath) it shows that it isn't secure for www.mtbnj.com -
which is how i rewrite the URL - i could just rewrite it to mtbnj.com instead - but it will still throw the error
on first contact.

Seems it was working yesterday tho!

I guess we can live with that. I think we should get rid of the catchall since those domains may get indexed and also count against SEO for duplicate content.
 

Patrick

Overthinking the draft from the basement already
Staff member
I guess we can live with that. I think we should get rid of the catchall since those domains may get indexed and also count against SEO for duplicate content.

gone. i think the ttl for the zone file is 12 hours, so may take a bit....
 

Patrick

Overthinking the draft from the basement already
Staff member
I guess we can live with that. I think we should get rid of the catchall since those domains may get indexed and also count against SEO for duplicate content.

fixed some of the smilies, they were fully qualified with http: - need to get the remote ones on-server - cause they aren't secured.
that is causing most of the warnings/issues at the moment.
 

Kaleidopete

Well-Known Member
Ever since I switched over to the https/ version my photos that I post don't come in as full sized, they display as little boxes.
But when I go to edit them they display as the full photos I posted. Now I can't tell if it is just me and my computer of if others
are seeing the same weird event with my posted photos. It seems older posts I've made DO show full photos, but my newer posts
don't , sometimes. weird. I think I'll try another one right now.

xterrawayoveryonder_518_2019_0281-X2.jpg
 

Patrick

Overthinking the draft from the basement already
Staff member
Ever since I switched over to the https/ version my photos that I post don't come in as full sized, they display as little boxes.
But when I go to edit them they display as the full photos I posted. Now I can't tell if it is just me and my computer of if others
are seeing the same weird event with my posted photos. It seems older posts I've made DO show full photos, but my newer posts
don't , sometimes. weird. I think I'll try another one right now.

View attachment 95934

i just had something strange happen where it was small.
i've shut off the requirement for https right now - and it is better.

looking into it.
 

Patrick

Overthinking the draft from the basement already
Staff member
Ever since I switched over to the https/ version my photos that I post don't come in as full sized, they display as little boxes.
But when I go to edit them they display as the full photos I posted. Now I can't tell if it is just me and my computer of if others
are seeing the same weird event with my posted photos. It seems older posts I've made DO show full photos, but my newer posts
don't , sometimes. weird. I think I'll try another one right now.

View attachment 95934

i see the picture full size now.

might have to clear browser data and cookies.
then restart. it seems to have cleared the issue -

there may be some weirdness with logging in if you don't.

http://www.mtbnj.com/

login, then switch to https, and see what happens
 

qclabrat

Well-Known Member
on my Pixel, not able to get past the default page with all the sections
Clicking New Posts brings me no where
 

Patrick

Overthinking the draft from the basement already
Staff member
on my Pixel, not able to get past the default page with all the sections
Clicking New Posts brings me no where

weird - clear all the browsing data and cookies?
are you logged in?

can you follow specific forum links?

this is a weird one.
 

qclabrat

Well-Known Member
Ever since I switched over to the https/ version my photos that I post don't come in as full sized, they display as little boxes.
But when I go to edit them they display as the full photos I posted. Now I can't tell if it is just me and my computer of if others
are seeing the same weird event with my posted photos. It seems older posts I've made DO show full photos, but my newer posts
don't , sometimes. weird. I think I'll try another one right now.

View attachment 95934
that's an awesome pic, Brian looks jacked up.
 
Top Bottom