Skip to content
This repository was archived by the owner on Nov 6, 2023. It is now read-only.

Changed TYPO3.org Rules - #9468

Closed
Avalarion wants to merge 2 commits into
EFForg:masterfrom
Avalarion:master
Closed

Changed TYPO3.org Rules#9468
Avalarion wants to merge 2 commits into
EFForg:masterfrom
Avalarion:master

Conversation

@Avalarion

Copy link
Copy Markdown

After a lot of time with a lot of changes this list needs to be updated =).

Greetings,

Bastian Bringenberg bastian.bringenberg@typo3.org

Removing Neos and FLOW from List and removing some settings that are from the past.
Remove old flow host.
@neufeind

neufeind commented Apr 9, 2017

Copy link
Copy Markdown

Please note Bastian is member of the TYPO3 server-team. So I'd trust him with his expertise here.

<target host="typo3.org"/>
<target host="association.typo3.org" />
<target host="buzz.typo3.org" />
<target host="certification.typo3.org" />

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

The DNS records for association and certification are still alive, so please don't remove them.


Other TYPO3 rulesets:

- T3Blog.com.xml

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Why did you remove this reference?

<target host="review.typo3.org" />
<target host="shop.typo3.org" />
<target host="wiki.typo3.org" />
<target host="www.typo3.org" />

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

award.typo3.org
campus.typo3.org
decisions.typo3.org
forger.typo3.org
notes.typo3.org
t3board\d\d.typo3.org
t3con\d\deu.typo3.org
t3dd\d\d.typo3.org
translation.typo3.org


⁴ Secured by us

- lists

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

api (404)
demo
government.v4.demo
flow (mismatch)
neos (mismatch)
styleguide
t3con0[7-9]
t3con10-frankfurt
t3con12de

Could you also document the reason why they are not working?


- lists
-->
<ruleset name="TYPO3.org (partial)">

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I think we can remove the partial flag here.

@Avalarion

Copy link
Copy Markdown
Author

Hey @J0WI ,

thanks for your comments, I am going to update this as soon as I got an answer. Is there a possibility to use a wildcard for everything.typo3.org expect lists.typo3.org? That way I do not have to update this for every vHost I update.

Have a nice day,

Bastian

@J0WI

J0WI commented Apr 9, 2017

Copy link
Copy Markdown
Contributor

Yes, you can use a wildcard targets, regex in the rules and exclusions. Just have a look at our CONTRIBUTING.md for a full documentation.

But please note that we want to get rid of wildcard targets. We only use them when a static list is impossible (e.g. user generated subdomains). In your case the t3con domains could be a good reason.

Since you are part of the server team, you should have a look at https://hstspreload.org/. With preloaded HSTS we can get rid of this ruleset completely :)

@Avalarion

Copy link
Copy Markdown
Author

Just to keep this updated. I am going to move all "old" webpages from one of our servers to the new infrastructure in the next two weeks.

Michael is going to get rid of lists.*.typo3.org and Steffen is going to secure monitoring.typo3.org in that time. When everything is finished we are going to enable HSTS with Preloading for TYPO3.org!

Then I will come back, adjust this PR to remove TYPO3.org completely here and you could than easily merge this =).

Here are more informations for everyone who is interested in such stuff.

https://forge.typo3.org/projects/team-server-public/wiki/Meeting_2017-04-13

Greetings,

Bastian

@J0WI

J0WI commented Apr 13, 2017

Copy link
Copy Markdown
Contributor

These are great news!

The removal can be done by https://github.com/EFForg/https-everywhere/tree/master/utils/hsts-prune
This script checks the preloded list of all browsers that are supported by us. The preload list of Firefox ESR and Tor is not updated that frequently, so we still need this rule for a while.

@J0WI

J0WI commented Jul 6, 2017

Copy link
Copy Markdown
Contributor

@Avalarion can you share any news about the progress here?

@jeremyn

jeremyn commented Dec 5, 2017

Copy link
Copy Markdown
Contributor

@Avalarion Are you still interested in working on this pull request?

@Avalarion

Copy link
Copy Markdown
Author

Sorry that I let this open for so long. All of our Systems should use HTTPS with HSTS within the next few weeks. We are currently working on the last systems so we can close this ticket without any more work. Shall I create a new one and drop all TYPO3 related stuff when we are finished?

@jeremyn

jeremyn commented Dec 5, 2017

Copy link
Copy Markdown
Contributor

If the plan is that you're going to HSTS preload all of typo3.org and its subdomains, then you can close this PR now and then open a new one in the future to delete all the typo3.org coverage, once the HSTS preloading has made its way out into the major browsers.

@J0WI

J0WI commented Sep 21, 2018

Copy link
Copy Markdown
Contributor

@Avalarion since typo3.org is still not preloaded it would be great if you could update this rule ;)

@zoracon

zoracon commented Feb 13, 2019

Copy link
Copy Markdown
Contributor

Closing due to no revisions made. Can reopen if interest for revision is indicated. Also seems to be some conflicts now with other rule xml files.

@zoracon zoracon closed this Feb 13, 2019
Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

6 participants