This is the last of our major domains (aside from trivial issues with wmfusercontent.org) not in the STS-preload list. There are a few blockers to resolve first, though!
Description
Details
Status | Subtype | Assigned | Task | ||
---|---|---|---|---|---|
Resolved | BBlack | T104681 HTTPS Plans (tracking / high-level info) | |||
Resolved | BBlack | T104244 Preload HSTS | |||
Resolved | BBlack | T132685 Preload STS for wikimedia.org | |||
Resolved | BBlack | T34796 status.wikimedia.org has no (valid) HTTPS | |||
Resolved | BBlack | T132450 enable https for (ubuntu|apt|mirrors).wikimedia.org | |||
Resolved | BBlack | T132812 Sort out letsencrypt puppetization for simple public hosts |
Event Timeline
Note that T132450 is already resolved in practice. The ticket is just still open because we need to puppetize decent administration of the solution before the certs expire 90 days from now or the box's disks die, etc.
That leaves just the http://status.wikimedia.org/ issue in T34796 blocking wikimedia.org STS-preload AFAIK (everything else in wikimedia.org that matters at all should already at least have basic HTTPS working).
We're now basically in shape to do this. I'd like to wait a few days and see how https://status.wikimedia.org/ works out first. Then we can start running through and setting preload and includeSub on our HSTS headers (both for the standard clusters, and also whatever we can from the list in https://wikitech.wikimedia.org/wiki/HTTPS/domains ), and then submit for list inclusion.
Change 292928 had a related patch set uploaded (by BBlack):
Remove TLS bits from internal sites behind cache_misc
Change 292929 had a related patch set uploaded (by BBlack):
ssl_ciphersuite: standardize STS preload
Change 292930 had a related patch set uploaded (by BBlack):
Set includeSub/preload for wikimedia.org in VCL
Change 292928 merged by BBlack:
Remove TLS bits from internal sites behind cache_misc
This is submitted for preload now (which takes an agonizingly long and unpredictable time to reach the chrome list and then browsers...)