et’s Encrypt is a new open source certificate authority that promises to provide free SSL certificates in a standardized, API accessible and non-commercial way. If you’ve installed SSL certificates in the past, you’re probably familiar with the process of signing up for a certificate with some paid for provider and then going through the manual process of swapping certificate requests and completed requests.
There are several features that are not available from the Settings menu, which you can only access using the chrome:// commands. Some of the features are available under both Menu and chrome:// commands. One of the most useful, underutilized and hidden features in Chrome is the network internals tools that you access by manually entering chrome://net-internals into your address bar. All chrome:// addresses need to be input by the user as links don’t work. It will immediately begin to start capturing network data, which you can stop by going to Capture at the top and clicking stop. You are able to see just about every aspect of Chrome’s internals from this area.
Among the various properties you are able to extract and analyze are:
Proxy, Events, Timeline, DNS, Sockets, Alt-Svc, HTTP/2, QUIC, SDCH, Cache, Modules, HSTS, Bandwidth, Prerender
surprisingly this hasn’t been covered more thoroughly considering how many people are running nginx as a reverse proxy for their back end cms such as wordpress. this article will show you how to configure nginx with ssl and redirect to non-www. if your wordpress installation is sitting behind a reverse proxy like nginx, wordpress won’t be able to see the proper ip address of the client computer for your accurate statistics and reporting. instead wordpress will show your reverse proxy instead of the correct client ip addresses. if you’re using cloudflare then there are various plugins to fix that, for nginx there is not. to […]
let’s encrypt is a free, automated, and open certificate authority (ca), run for the public’s benefit. let’s encrypt is a service provided by the internet security research group (isrg). this is the biggest thing i’ve seen hit the internet in the last 5 years, and yet they opened to the public silently back in december 2015 as far as i know. you can go read more about them on their website. i will show you how i got my certificate for this website without using their automated agent software (since i’m running amazon linux, which certbot does not support yet). […]
How To Create Temporary and Permanent Redirects with Apache and Nginx
the below strong ciphers are copy/pastable for your apache, nginx, lighttpd, haproxy, postfix, exim, proftpd, dovecot, hitch tls proxy, zarafa, mysql, directadmin, postgresql, openssh server/client, golang server and unifi controller config mirrored directly from https://cipherli.st. they provide strong ssl security for all modern browsers, and you’ll obtain an a+ on the ssl labs test. in short, they: set a strong forward secrecy enabled cipher suite disable sslv2 and sslv3 add http strict transport security and x-frame-deny headers enable ocsp stapling (except on lighttpd, feature not supported yet) these examples are meant for sysadmins who have done this before (and sysadmins are […]