Skip to content
GitLab
    • Explore Projects Groups Topics Snippets
Projects Groups Topics Snippets
  • /
  • Help
    • Help
    • Support
    • Community forum
    • Submit feedback
    • Contribute to GitLab
  • Sign in
  • fusiondirectory fusiondirectory
  • Project information
    • Project information
    • Activity
    • Labels
    • Members
  • Repository
    • Repository
    • Files
    • Commits
    • Branches
    • Tags
    • Contributor statistics
    • Graph
    • Compare revisions
  • Issues 39
    • Issues 39
    • List
    • Boards
    • Service Desk
    • Milestones
  • Packages and registries
    • Packages and registries
    • Package Registry
    • Container Registry
    • Terraform modules
  • Activity
  • Graph
  • Create a new issue
  • Commits
  • Issue Boards
Collapse sidebar
  • fusiondirectoryfusiondirectory
  • fusiondirectoryfusiondirectory
  • Issues
  • #2669
Closed
Open
Issue created 11 years ago by bmortier@bmortierMaintainer
  • New related issue

  • New related issue

forceSSL in fusiondirectory.conf doesn't work

Closed

forceSSL in fusiondirectory.conf doesn't work

During FD setup, I checked the "Enforce encrypted connections" option. Now I have forceSSL="True" in /etc/fusiondirectory/fusiondirectory.conf But when going to the configuration tab in FD, the option "Enforce encrypted connections" is unchecked. And I can use either http and https to browser FD.

(from redmine: issue id 2669, created on 2013-08-23, closed on 2013-09-11)

  • Changesets:
    • Revision 7fffb19e by Côme Chilliet on 2013-08-23T18:14:43.000Z:
Fixes: #2669 forceSSL doesn't work
  • Revision 99730237 by Côme Chilliet on 2013-08-23T18:15:13.000Z:
Fixes: #2669 forceSSL doesn't work
  • Revision f43807f8 by Côme Chilliet on 2013-09-04T12:21:47.000Z:
Fixes: #2669 SSL check in password recovery was in the wrong place
  • Revision 2324652a by Côme Chilliet on 2013-09-04T12:22:06.000Z:
Fixes: #2669 SSL check in password recovery was in the wrong place
  • Custom Fields:
    • Bug in version: 1.0.6
  • Uploads:
    • 0001-Fixes-2669-forceSSL-doesn-t-work.patch
    • 0002-Fixes-2669-SSL-check-in-password-recovery-was-in-the.patch

    Tasks

    ...

    Linked items
    0

    Link issues together to show that they're related. Learn more.

    Activity


    • bmortier
      bmortier @bmortier · 11 years ago
      Author Maintainer

      After further testings, it seems that the enforcing works only on the login page. Once logged, I can switch between http and https anytime.

      (from redmine: written on 2013-08-23)

      By jlgrall on 2017-09-02T15:03:44 (imported from GitLab)

    • bmortier
      bmortier @bmortier · 11 years ago
      Author Maintainer

      With this the check should be done on each page. I also put the forceSSL value into the LDAP config in the setup. But I've let it in the fusiondirectory.conf, because I feel like it should still be global if a user checks it in the setup and then have several LDAP configured… But maybe I'm wrong and it will be too confusing have two values that can differ :-/ I'm not sure about this.

      Anyway the patch needs to be heavily tested.

      (from redmine: written on 2013-08-23)

      By Côme Chilliet on 2017-09-02T15:03:45 (imported from GitLab)

    • bmortier
      bmortier @bmortier · 11 years ago
      Author Maintainer

      Ok, tested the patch, enforcing SSL now works on other pages than the login page.

      But I still have the "Enforce encrypted connections" unchecked in my Configuration tab. Not sure if it was intended.

      (from redmine: written on 2013-08-23)

      By jlgrall on 2017-09-02T15:03:45 (imported from GitLab)

    • bmortier closed 7 years ago

      closed

      By Administrator on 2017-09-02T15:03:45 (imported from GitLab)

    • bmortier added Fixed fusiondirectory-core and removed Bugs labels 6 years ago

      added Fixed fusiondirectory-core and removed Bugs labels

      By bmortier on 2019-01-11T16:43:49 (imported from GitLab)

    Please register or sign in to reply
    Assignee
    bmortier's avatar
    bmortier
    Assign to
    Labels
    0
    None
    0
    None
      Assign labels
    • Manage project labels

    Milestone
    No milestone
    None
    Due date
    None
    None
    None
    Time tracking
    Confidentiality
    Not confidential

    You are going to turn on confidentiality. Only project members with at least the Reporter role, the author, and assignees can view or be notified about this issue.

    Lock issue
    Unlocked
    Participants
    Reference:

    Menu

    Explore Projects Groups Topics Snippets