
TLS on Unseen Servant?
- spanningtree
- Rider of Rohan
- Posts: 3666
- Joined: Sun Jul 22, 2012 9:35 pm
- Location: Las Vegas, NV
TLS on Unseen Servant?
I know the subject matter is not the most sensitive here on the board but is there any chance that Unseen Servant might move to TLS 1.2 in the future? I am connected to an airport free wifi right now and have some pangs that someone might sniff my creds. Just curious. 

Anall nathrack uthos bethos doss yell yenva. -Merlin
Re: TLS on Unseen Servant?
Drat. You weren't supposed to notice me or my packet sniffer.
But that's a good point.
But that's a good point.
Re: TLS on Unseen Servant?
How can I tell what version is currently running on this or any server?spanningtree wrote:I know the subject matter is not the most sensitive here on the board but is there any chance that Unseen Servant might move to TLS 1.2 in the future? I am connected to an airport free wifi right now and have some pangs that someone might sniff my creds. Just curious.
"Sir, our research shows that the bird is equal to or greater than the word."
The sab-cat has nine lives and no conscience
The sab-cat has nine lives and no conscience
Re: TLS on Unseen Servant?
Here's the message I get in Firefox when I try to connect with SSL:
The default login page is unencrypted, so once the SSL login page is working it'd be great if the login page would redirect to HTTPS, too.
It's been ages since I did any web admin, but it's probably either a web server configuration issue, a certificate issue, or both.An error occurred during a connection to http://www.unseenservant.us. SSL received a record that exceeded the maximum permissible length. Error code: SSL_ERROR_RX_RECORD_TOO_LONG
The page you are trying to view cannot be shown because the authenticity of the received data could not be verified.
Please contact the website owners to inform them of this problem.
The default login page is unencrypted, so once the SSL login page is working it'd be great if the login page would redirect to HTTPS, too.
Re: TLS on Unseen Servant?
Bumping this to mention that it would be great if the forums had a working SSL certificate / HTTPS login page.
Re: TLS on Unseen Servant?
This has come up a few times now so I'll look into it. IIRC it will add about $100 per year to the hosting costs.
"Sir, our research shows that the bird is equal to or greater than the word."
The sab-cat has nine lives and no conscience
The sab-cat has nine lives and no conscience
Re: TLS on Unseen Servant?
Is that the cost of the certificate, or the cost of your provider administering the certificate? Let's Encrypt is a free certificate authority, so getting the certificate itself shouldn't be costly. But I have no idea what your provider charges to put it on a server and keep it updated.
Re: TLS on Unseen Servant?
Any further thoughts on this? Most browsers are now marking all non-HTTPS sites as insecure.
Sniffing of Unseen Servant logins probably isn't at the top of anyone's agenda, but if there's anything I can do to help at least get the logins secured, let me know.
Sniffing of Unseen Servant logins probably isn't at the top of anyone's agenda, but if there's anything I can do to help at least get the logins secured, let me know.
Re: TLS on Unseen Servant?
Yes, given that browsers and flagging sites now, I was planning on doing it at least for these forums. But, at the moment we're having problems with the dice roller so I'm dealing with that. UGH!Zhym wrote:Any further thoughts on this? Most browsers are now marking all non-HTTPS sites as insecure.
Sniffing of Unseen Servant logins probably isn't at the top of anyone's agenda, but if there's anything I can do to help at least get the logins secured, let me know.
"Sir, our research shows that the bird is equal to or greater than the word."
The sab-cat has nine lives and no conscience
The sab-cat has nine lives and no conscience
Re: TLS on Unseen Servant?
Yeah. Obviously it's not the first priority at the moment. But, hey, while you've got your provider on the phone... 

Re: TLS on Unseen Servant?
SSL is now running on this server. Change the URL to https and it will work
"Sir, our research shows that the bird is equal to or greater than the word."
The sab-cat has nine lives and no conscience
The sab-cat has nine lives and no conscience
Re: TLS on Unseen Servant?
Sweet!
Do you think you could rig it so that the login page automatically redirects to HTTPS?
Do you think you could rig it so that the login page automatically redirects to HTTPS?
Re: TLS on Unseen Servant?
Yah I'm trying to figure out how to do that
"Sir, our research shows that the bird is equal to or greater than the word."
The sab-cat has nine lives and no conscience
The sab-cat has nine lives and no conscience
Re: TLS on Unseen Servant?
Ok, this should be working. Actually, all pages should be on httpsZhym wrote:Sweet!
Do you think you could rig it so that the login page automatically redirects to HTTPS?
"Sir, our research shows that the bird is equal to or greater than the word."
The sab-cat has nine lives and no conscience
The sab-cat has nine lives and no conscience
Re: TLS on Unseen Servant?
It's working for me. Thanks!
- AleBelly
- Rider of Rohan
- Posts: 9279
- Joined: Wed May 28, 2014 4:46 am
- Location: Research Triangle Park, NC
Re: TLS on Unseen Servant?
Me too. Three cheers!
Re: TLS on Unseen Servant?
Character sheets from the dice roller aren't showing up now. I suspect it might be because of the HTTPS change. The dice roller still shows up as insecure, so maybe my browsers, at least, are refusing to load remote HTTP content in an HTTPS connection?
Feel like re-doing everything you just did with the dice roller, too?
Feel like re-doing everything you just did with the dice roller, too?

Re: TLS on Unseen Servant?
FYI, I'm not positive, but I'm pretty sure the forums and the die roller are on two completely different hosts.Zhym wrote:Feel like re-doing everything you just did with the dice roller, too?
-- Games --
- DM: In Development
Re: TLS on Unseen Servant?
Oh, yeah. Looks like the dice roller is on GoDaddy, which may or may not support Let's Encrypt free server certs depending on the product.
https://www.godaddy.com/help/does-godad ... ducts-3983
Ouch.
https://www.godaddy.com/help/does-godad ... ducts-3983
Ouch.
Re: TLS on Unseen Servant?
Does it have to support the same type of SSL or just any SSL? Would it have to be the same exact cert?Zhym wrote:Oh, yeah. Looks like the dice roller is on GoDaddy, which may or may not support Let's Encrypt free server certs depending on the product.
https://www.godaddy.com/help/does-godad ... ducts-3983
Ouch.
I'll get SSL for the dice roller too if that'll solve the problem.
"Sir, our research shows that the bird is equal to or greater than the word."
The sab-cat has nine lives and no conscience
The sab-cat has nine lives and no conscience