Package: www.debian.org

Currently, www.debian.org is served both via HTTP and HTTPS. Since HTTP must die [1], I propose to redirect *all* HTTP requests to HTTPS.

gentoo.org, archlinux.org, getfedora.org, opensuse.org and redhat.com already do this.

That should be a relatively straightforward rule in apache.conf, along the lines of the existing:

Redirect permanent / https://www.debian.org/

in "<VirtualHost <%= vhost_listen_443 %> >",
just added to "<VirtualHost <%= vhost_listen %> >".
https://anonscm.debian.org/cgit/mirror/dsa-puppet.git/plain/modules/roles/templates/apache-www.debian.org.erb

Thanks, and keep up the good work!

1. https://www.youtube.com/watch?v=Mg-pfkK97gY

--
ilf

Über 80 Millionen Deutsche benutzen keine Konsole. Klick dich nicht weg!
                -- Eine Initiative des Bundesamtes für Tastaturbenutzung

Attachment: signature.asc
Description: PGP signature

Reply via email to