[LON-CAPA-admin] SSL Connections?

Guy Albertelli II guy at albertelli.com
Fri Sep 16 10:09:47 EDT 2005

Hi Todd,

> I seem to remember quite a while back that "Only Accept SSL Connections" for 
> inter-server communication was going to be implemented at least as MSU.  Has 
> that actually happened? 
\Unfortunately no.

We haven't had a chance to integrate the SSL request procedure with
the install process and thus haven't made it easy enough to do the SSL
certificate request procedure such that I can feel arrogant enough to
do this.

I desperately hope that 2.1 will have this integrated. So that I can
turn this on for good.

Meanwhile all of you who haven't done this:


I suggest doing this.

(It is a one time thing that you need to do and requires no restarting
of any services.)

> I'm curious because I don't recall having done 
> anything with our servers to make them use SSL, and as far as I know, I can 
> still access with no problems.  I'm curious in part because if it is this 
> transparent, I can enable that option on our servers, too, without fear of 
> breaking things for other users.

Well so far the response rate at following the directions in the above
email has been dismal.

(I think we have full compliance at 4 domains, and partial complaince
at 4 domains and partial compliance at 2)

Which has made me not do this yet.

(And I suspect it will remain dismal until UPDATE checks this and
forces the install of this.)

