Page MenuHomePhabricator

Preload STS for wikimedia.org
Closed, ResolvedPublic

Description

This is the last of our major domains (aside from trivial issues with wmfusercontent.org) not in the STS-preload list. There are a few blockers to resolve first, though!

Details

Related Gerrit Patches:

Related Objects

Event Timeline

Note that T132450 is already resolved in practice. The ticket is just still open because we need to puppetize decent administration of the solution before the certs expire 90 days from now or the box's disks die, etc.

That leaves just the http://status.wikimedia.org/ issue in T34796 blocking wikimedia.org STS-preload AFAIK (everything else in wikimedia.org that matters at all should already at least have basic HTTPS working).

We're now basically in shape to do this. I'd like to wait a few days and see how https://status.wikimedia.org/ works out first. Then we can start running through and setting preload and includeSub on our HSTS headers (both for the standard clusters, and also whatever we can from the list in https://wikitech.wikimedia.org/wiki/HTTPS/domains ), and then submit for list inclusion.

Change 292928 had a related patch set uploaded (by BBlack):
Remove TLS bits from internal sites behind cache_misc

https://gerrit.wikimedia.org/r/292928

Change 292929 had a related patch set uploaded (by BBlack):
ssl_ciphersuite: standardize STS preload

https://gerrit.wikimedia.org/r/292929

Change 292930 had a related patch set uploaded (by BBlack):
Set includeSub/preload for wikimedia.org in VCL

https://gerrit.wikimedia.org/r/292930

Change 292928 merged by BBlack:
Remove TLS bits from internal sites behind cache_misc

https://gerrit.wikimedia.org/r/292928

Change 292929 merged by BBlack:
ssl_ciphersuite: standardize STS preload

https://gerrit.wikimedia.org/r/292929

Change 292930 merged by BBlack:
Set includeSub/preload for wikimedia.org in VCL

https://gerrit.wikimedia.org/r/292930

BBlack closed this task as Resolved.Jun 6 2016, 10:55 PM

This is submitted for preload now (which takes an agonizingly long and unpredictable time to reach the chrome list and then browsers...)