<?xml version="1.0" encoding="utf-8" standalone="yes"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/">
  <channel>
    <title>https on {bjørn:johansen}</title>
    <link>https://bjornjohansen.com/category/https/</link>
    <description>Recent content in https on {bjørn:johansen}</description>
    <generator>Hugo -- 0.118.2</generator>
    <language>en-US</language>
    <lastBuildDate>Mon, 01 Aug 2016 16:38:47 +0000</lastBuildDate>
    <atom:link href="https://bjornjohansen.com/category/https/feed.xml" rel="self" type="application/rss+xml" />
    <item>
      <title>The future of Certificate Authorities</title>
      <link>https://bjornjohansen.com/the-future-of-certificate-authorities/</link>
      <pubDate>Mon, 01 Aug 2016 16:38:47 +0000</pubDate>
       <guid isPermaLink="false">urn:uuid:61636461-3766-5538-b865-616338333630</guid> 
      <description>With the advent of the fully automated and free of cost certificate authorities Let’s Encrypt and StartCom there is no doubt that the future of CAs are changing.</description>
    </item>
    <item>
      <title>Let’s Encrypt for Nginx</title>
      <link>https://bjornjohansen.com/letsencrypt-nginx/</link>
      <pubDate>Thu, 31 Mar 2016 20:48:31 +0000</pubDate>
       <guid isPermaLink="false">urn:uuid:38623063-3465-5338-b964-656234343537</guid> 
      <description>Let’s install an SSL-certificate from Let’s Encrypt for Nginx.</description>
    </item>
    <item>
      <title>Redirect all HTTP requests to HTTPS with Nginx</title>
      <link>https://bjornjohansen.com/redirect-to-https-with-nginx/</link>
      <pubDate>Thu, 15 Oct 2015 19:15:43 +0000</pubDate>
       <guid isPermaLink="false">urn:uuid:65646238-3538-5639-b735-303636353639</guid> 
      <description>All login credentials transferred over plain HTTP can easily be sniffed by an MITM attacker, but is is not enough to encrypt the login forms. If you are visiting plain HTTP pages while logged in, your session can be hijacked, and not even &lt;a href=&#34;https://www.bjornjohansen.com/two-factor-authentication-for-wordpress&#34;&gt;two-factor authentication&lt;/a&gt; will protect you. To protect all info sent between your visitors – which includes you – and your web server, we will redirect all requests that are coming over plain HTTP to the HTTPS equivalent.</description>
    </item>
    <item>
      <title>WordPress behind Big-IP</title>
      <link>https://bjornjohansen.com/wordpress-behind-big-ip/</link>
      <pubDate>Mon, 28 Sep 2015 17:09:42 +0000</pubDate>
       <guid isPermaLink="false">urn:uuid:61323430-6437-5137-a363-313964663739</guid> 
      <description>To be honest, I don’t exactly know too much about Big-IP, but I’ve come across someone who use it. They terminate HTTPS in Big-IP and WordPress runs on plain HTTP on port 80 on the backend nodes. By default, this makes WordPress confused, so you can’t login to the WordPress dashboard.</description>
    </item>
    <item>
      <title>HTTP Public Key Pinning (HPKP)</title>
      <link>https://bjornjohansen.com/public-key-pinning/</link>
      <pubDate>Thu, 16 Jul 2015 11:39:19 +0000</pubDate>
       <guid isPermaLink="false">urn:uuid:36656436-3236-5036-a238-646136336161</guid> 
      <description>&lt;a href=&#34;https://www.bjornjohansen.com/securing-nginx-ssl&#34;&gt;Using HTTPS&lt;/a&gt; helps preventing someone from snooping your username/password or hijacking your sessions. &lt;a href=&#34;https://www.bjornjohansen.com/optimizing-https-nginx&#34;&gt;Using HSTS&lt;/a&gt; makes sure the connection stays on HTTPS, even if a MITM tries to redirect you to the plain HTTP version of a web site. But it is easier than you might think for a MITM to use a rogue certificate, making you believe everything is fine. HTTP Public Key Pinning (HPKP) helps the browser check that everything actually is fine.</description>
    </item>
    <item>
      <title>Optimizing HTTPS on Nginx</title>
      <link>https://bjornjohansen.com/optimizing-https-nginx/</link>
      <pubDate>Sat, 18 Jan 2014 23:49:30 +0000</pubDate>
       <guid isPermaLink="false">urn:uuid:64373039-3439-5939-a565-376661666535</guid> 
      <description>Now that you have secured &lt;a href=&#34;https://www.bjornjohansen.com/securing-nginx-ssl&#34;&gt;Nginx with HTTPS&lt;/a&gt; and &lt;a href=&#34;https://www.bjornjohansen.com/enabling-spdy-nginx&#34;&gt;enabled SPDY&lt;/a&gt; &lt;a href=&#34;https://www.bjornjohansen.com/enable-http2-on-nginx&#34;&gt;enabled HTTP/2&lt;/a&gt;, it&amp;rsquo;s time to improve both the security and the performance of the server.</description>
    </item>
    <item>
      <title>Securing Nginx with HTTPS</title>
      <link>https://bjornjohansen.com/securing-nginx-ssl/</link>
      <pubDate>Thu, 22 Aug 2013 19:53:15 +0000</pubDate>
       <guid isPermaLink="false">urn:uuid:31313436-3262-5866-b731-393965366633</guid> 
      <description>&lt;img src=&#34;https://www.bjornjohansen.com/content/uploads/2013/08/origin_4146023669-150x150.jpg&#34; alt=&#34;SSL&#34;
     loading=&#34;lazy&#34; decoding=&#34;async&#34;&gt;
Adding a certificate and using the HTTPS protocol is a good improvement to the security in the communication between the browser and the server, and should be in place on all sites that have a user login. Contrary to what many (older) guides say, it doesn&amp;rsquo;t add much load on your server and is fairy easy and cheap to set up right.</description>
    </item>
  </channel>
</rss>
