Changed TYPO3.org Rules - #9468
Conversation
Removing Neos and FLOW from List and removing some settings that are from the past.
Remove old flow host.
|
Please note Bastian is member of the TYPO3 server-team. So I'd trust him with his expertise here. |
| <target host="typo3.org"/> | ||
| <target host="association.typo3.org" /> | ||
| <target host="buzz.typo3.org" /> | ||
| <target host="certification.typo3.org" /> |
There was a problem hiding this comment.
The DNS records for association and certification are still alive, so please don't remove them.
|
|
||
| Other TYPO3 rulesets: | ||
|
|
||
| - T3Blog.com.xml |
There was a problem hiding this comment.
Why did you remove this reference?
| <target host="review.typo3.org" /> | ||
| <target host="shop.typo3.org" /> | ||
| <target host="wiki.typo3.org" /> | ||
| <target host="www.typo3.org" /> |
There was a problem hiding this comment.
award.typo3.org
campus.typo3.org
decisions.typo3.org
forger.typo3.org
notes.typo3.org
t3board\d\d.typo3.org
t3con\d\deu.typo3.org
t3dd\d\d.typo3.org
translation.typo3.org
|
|
||
| ⁴ Secured by us | ||
|
|
||
| - lists |
There was a problem hiding this comment.
api (404)
demo
government.v4.demo
flow (mismatch)
neos (mismatch)
styleguide
t3con0[7-9]
t3con10-frankfurt
t3con12de
Could you also document the reason why they are not working?
|
|
||
| - lists | ||
| --> | ||
| <ruleset name="TYPO3.org (partial)"> |
There was a problem hiding this comment.
I think we can remove the partial flag here.
|
Hey @J0WI , thanks for your comments, I am going to update this as soon as I got an answer. Is there a possibility to use a wildcard for everything.typo3.org expect lists.typo3.org? That way I do not have to update this for every vHost I update. Have a nice day, Bastian |
|
Yes, you can use a wildcard targets, regex in the rules and exclusions. Just have a look at our CONTRIBUTING.md for a full documentation. But please note that we want to get rid of wildcard targets. We only use them when a static list is impossible (e.g. user generated subdomains). In your case the t3con domains could be a good reason. Since you are part of the server team, you should have a look at https://hstspreload.org/. With preloaded HSTS we can get rid of this ruleset completely :) |
|
Just to keep this updated. I am going to move all "old" webpages from one of our servers to the new infrastructure in the next two weeks. Michael is going to get rid of lists.*.typo3.org and Steffen is going to secure monitoring.typo3.org in that time. When everything is finished we are going to enable HSTS with Preloading for TYPO3.org! Then I will come back, adjust this PR to remove TYPO3.org completely here and you could than easily merge this =). Here are more informations for everyone who is interested in such stuff. https://forge.typo3.org/projects/team-server-public/wiki/Meeting_2017-04-13 Greetings, Bastian |
|
These are great news! The removal can be done by https://github.com/EFForg/https-everywhere/tree/master/utils/hsts-prune |
|
@Avalarion can you share any news about the progress here? |
|
@Avalarion Are you still interested in working on this pull request? |
|
Sorry that I let this open for so long. All of our Systems should use HTTPS with HSTS within the next few weeks. We are currently working on the last systems so we can close this ticket without any more work. Shall I create a new one and drop all TYPO3 related stuff when we are finished? |
|
If the plan is that you're going to HSTS preload all of |
|
@Avalarion since typo3.org is still not preloaded it would be great if you could update this rule ;) |
|
Closing due to no revisions made. Can reopen if interest for revision is indicated. Also seems to be some conflicts now with other rule xml files. |
After a lot of time with a lot of changes this list needs to be updated =).
Greetings,
Bastian Bringenberg bastian.bringenberg@typo3.org