GNU bug report logs - #56468
www.gnu.org doesn't change http: to https:

Previous Next

Package: diffutils;

Reported by: Jerry Peek <jpeek <at> jpeek.com>

Date: Sat, 9 Jul 2022 17:05:02 UTC

Severity: normal

Done: Paul Eggert <eggert <at> cs.ucla.edu>

Bug is archived. No further changes may be made.

Full log


View this message in rfc822 format

From: "Andrew Engelbrecht via RT" <sysadmin <at> gnu.org>
Cc: eggert <at> cs.ucla.edu, 56468-done <at> debbugs.gnu.org
Subject: bug#56468: [gnu.org #1853606] Re: [bug-diffutils] bug#56468: www.gnu.org doesn't change http: to https:
Date: Thu, 28 Jul 2022 15:08:46 -0400
On Sat Jul 09 15:04:09 2022, eggert <at> CS.UCLA.EDU wrote:
> On 7/9/22 12:03, Jerry Peek wrote:
> > I just clicked on an old link to 
> > http://www.gnu.org/software/diffutils/manual/. Then the web browser 
> > showed the address http://www.gnu.org/software/diffutils/manual/ and 
> > marked it "insecure". So I tried 
> > https://www.gnu.org/software/diffutils/manual/ (with an s) and the 
> > browser showed that address.
> >
> > I'm writing to suggest that you might add a redirect from 
> > http://www.gnu.org/software/diffutils/manual/ to 
> > https://www.gnu.org/software/diffutils/manual/ so that no one will get 
> > the "insecure" page. 

Hi,

Sorry about the delayed reply. We want to support both HTTPS and HTTP, for those who are using old browsers with outdated ciphers, etc. The HSTS rule is there for people who do visit the HTTPS site, so they will automatically use it in the future.

I would personally lean towards more HTTPS, but so far, gnu.org is an exception to that. More discussion is welcome.

Thanks,
Andrew







This bug report was last modified 2 years and 296 days ago.

Previous Next


GNU bug tracking system
Copyright (C) 1999 Darren O. Benham, 1997,2003 nCipher Corporation Ltd, 1994-97 Ian Jackson.