Re: [PATCH] uhttpd: Increase default certificate validate from 2 to 10 years

2020-09-02 Thread Hauke Mehrtens
On 9/2/20 12:05 PM, Yousong Zhou wrote: > On Wed, 2 Sep 2020 at 01:32, Hauke Mehrtens wrote: >> >> On 9/1/20 12:45 AM, Yousong Zhou wrote: >>> It's worth mentioning that recent versions of macos since 10.15 have a >>> restriction on certificate validity period, self-signed or not. It's >>> a stro

Re: [PATCH] uhttpd: Increase default certificate validate from 2 to 10 years

2020-09-02 Thread Yousong Zhou
On Wed, 2 Sep 2020 at 01:32, Hauke Mehrtens wrote: > > On 9/1/20 12:45 AM, Yousong Zhou wrote: > > It's worth mentioning that recent versions of macos since 10.15 have a > > restriction on certificate validity period, self-signed or not. It's > > a strong restriction that the browser ui will have

Re: [PATCH] uhttpd: Increase default certificate validate from 2 to 10 years

2020-09-02 Thread Karl Palsson
Hauke Mehrtens wrote: > > We will still over normal http, using https is only an > addition. So you will change <> back to 0 by default then? So it's actually optional? It's currently hardset to 1 here: https://git.openwrt.org/?p=openwrt/openwrt.git;a=blob;f=package/network/services/uhttpd/fil

Re: [PATCH] uhttpd: Increase default certificate validate from 2 to 10 years

2020-09-01 Thread Hauke Mehrtens
On 9/1/20 12:45 AM, Yousong Zhou wrote: > It's worth mentioning that recent versions of macos since 10.15 have a > restriction on certificate validity period, self-signed or not. It's > a strong restriction that the browser ui will have no buttons or knobs > to bypass the certificate validation, r

Re: [PATCH] uhttpd: Increase default certificate validate from 2 to 10 years

2020-09-01 Thread Rich Brown
Forgive me for chiming in now, for I have not been following the discussion closely. Is this change (specifically, using these certs for "ordinary operation" of OpenWrt) being considered for the 20.0x release? Would it delay the RC1 release in any way? If so, I believe we should move it off th

Re: [PATCH] uhttpd: Increase default certificate validate from 2 to 10 years

2020-09-01 Thread Karl Palsson
Yousong Zhou wrote: > It's worth mentioning that recent versions of macos since 10.15 > have a restriction on certificate validity period, self-signed > or not. It's a strong restriction that the browser ui will have > no buttons or knobs to bypass the certificate validation, > rendering such sit

Re: [PATCH] uhttpd: Increase default certificate validate from 2 to 10 years

2020-09-01 Thread Paul Oranje
> Op 1 sep. 2020, om 01:21 heeft Daniel Golle het > volgende geschreven: > > On Tue, Sep 01, 2020 at 06:45:02AM +0800, Yousong Zhou wrote: >> It's worth mentioning that recent versions of macos since 10.15 have a >> restriction on certificate validity period, self-signed or not. It's >> a st

Re: [PATCH] uhttpd: Increase default certificate validate from 2 to 10 years

2020-08-31 Thread Yousong Zhou
On Tue, 1 Sep 2020 at 06:45, Yousong Zhou wrote: > > It's worth mentioning that recent versions of macos since 10.15 have a > restriction on certificate validity period, self-signed or not. It's > a strong restriction that the browser ui will have no buttons or knobs > to bypass the certificate v

Re: [PATCH] uhttpd: Increase default certificate validate from 2 to 10 years

2020-08-31 Thread Daniel Golle
On Tue, Sep 01, 2020 at 06:45:02AM +0800, Yousong Zhou wrote: > It's worth mentioning that recent versions of macos since 10.15 have a > restriction on certificate validity period, self-signed or not. It's > a strong restriction that the browser ui will have no buttons or knobs > to bypass the cer

Re: [PATCH] uhttpd: Increase default certificate validate from 2 to 10 years

2020-08-31 Thread Yousong Zhou
It's worth mentioning that recent versions of macos since 10.15 have a restriction on certificate validity period, self-signed or not. It's a strong restriction that the browser ui will have no buttons or knobs to bypass the certificate validation, rendering such sites inaccessible. I remembered

Re: [PATCH] uhttpd: Increase default certificate validate from 2 to 10 years

2020-08-30 Thread Hauke Mehrtens
ts.openwrt.org >> Cc: Hauke Mehrtens >> Subject: [PATCH] uhttpd: Increase default certificate validate from 2 to 10 >> years >> >> The user has to accept this specific certificate manually in his browser, the >> browser does not trust it automatically, in this proc

RE: [PATCH] uhttpd: Increase default certificate validate from 2 to 10 years

2020-08-30 Thread Adrian Schmutzler
e default certificate validate from 2 to 10 > years > > The user has to accept this specific certificate manually in his browser, the > browser does not trust it automatically, in this process the user gets a scary > message to approve. I am not aware of a way to improve this initial

[PATCH] uhttpd: Increase default certificate validate from 2 to 10 years

2020-08-29 Thread Hauke Mehrtens
The user has to accept this specific certificate manually in his browser, the browser does not trust it automatically, in this process the user gets a scary message to approve. I am not aware of a way to improve this initial certificate approval. After the certificate expired the user gets a scary