Opened 3 months ago

Closed 5 weeks ago

#22806 closed defect (fixed)

http://blog.torproject.org/ should redirect to https

Reported by: arma Owned by: hiro
Priority: Medium Milestone:
Component: Webpages/Blog Version:
Severity: Normal Keywords:
Cc: Actual Points:
Parent ID: Points:
Reviewer: Sponsor:

Description

$ wget http://blog.torproject.org/
--2017-07-04 00:32:34--  http://blog.torproject.org/
Resolving blog.torproject.org (blog.torproject.org)... 23.185.0.2, 2620:12a:8001::2, 2620:12a:8000::2
Connecting to blog.torproject.org (blog.torproject.org)|23.185.0.2|:80... connected.
HTTP request sent, awaiting response... 200 OK
Length: unspecified [text/html]
Saving to: ‘index.html’

index.html              [ <=>                 ]  43.03K  --.-KB/s   in 0.03s  

2017-07-04 00:32:35 (1.54 MB/s) - ‘index.html’ saved [44067]

Shouldn't it instead be redirecting me to the https version of the site?

Child Tickets

Change History (5)

comment:1 Changed 3 months ago by mrphs

Also, FWIW ssllabs test indicates that HSTS is not enabled on blog:
https://www.ssllabs.com/ssltest/analyze.html?d=blog.torproject.org&s=23.185.0.2&latest

comment:2 Changed 3 months ago by hiro

Status: newaccepted

Opening an issue w/ pantheon regarding this. More soon.

comment:3 Changed 3 months ago by hiro

Resolution: fixed
Status: acceptedclosed

This is now fixed.

comment:4 Changed 6 weeks ago by arma

Resolution: fixed
Status: closedreopened

This has now become unfixed. http://blog.torproject.org/ is pleased to serve me our blog content, albeit with some sort of css breakage. (When you're testing it, be sure not to get tricked by your https-everywhere doing the redirect for you.)

comment:5 Changed 5 weeks ago by hiro

Resolution: fixed
Status: reopenedclosed

This got overwritten in the last update from pantheon :(. It is fixed again now.

Note: See TracTickets for help on using tickets.