Web Access https

Post new topic   Reply to topic    DD-WRT Forum Index -> Atheros WiSOC based Hardware
Goto page Previous  1, 2
Author Message
johnnyNobody999
DD-WRT Guru


Joined: 10 Jan 2014
Posts: 504

PostPosted: Wed Nov 23, 2016 16:47    Post subject: Reply with quote
Mile-Lile wrote:
or we could all donate 1 euro and buy certificate...


Or, when I get the time, figure out how to use letsencrypt certs.
Sponsor
<Kong>
DD-WRT Guru


Joined: 15 Dec 2010
Posts: 4339
Location: Germany

PostPosted: Wed Nov 23, 2016 19:23    Post subject: Reply with quote
johnnyNobody999 wrote:
<Kong> wrote:
johnnyNobody999 wrote:
I tried Chrome, Opera, and Firefox. None of them will connect.


Are you sure you have no security software on the pc that intercepts https connections, such as kaspersky.


Nope. But I am using the HTTPS EVERYWHERE extension. I don't have problems connecting to any other site with https.


Well t is a big difference if you connect to a server that has a self signed cert or a regular server on the net that has a regular cert.

You are not telling us, that your only problem was, that you could not find the override option that the browser showed you?

THere are two types of problems:

1. Browser won't allow overriding, e.g. if the cipher is too weak, and it is possible that some beta browser version enforce new restrictions

2. Browser will allow override if you accept the cert. If this was the case, then you really wasted our time.

_________________
KONG PB's: http://www.desipro.de/ddwrt/
KONG Info: http://tips.desipro.de/
Mile-Lile
DD-WRT Guru


Joined: 24 Feb 2013
Posts: 1634
Location: Belgrade

PostPosted: Wed Nov 23, 2016 20:02    Post subject: Reply with quote
johnnyNobody999 wrote:
Mile-Lile wrote:
or we could all donate 1 euro and buy certificate...


Or, when I get the time, figure out how to use letsencrypt certs.


Maybe you are smarter than ddwrt team http://svn.dd-wrt.com/ticket/4993 but then again this https web access wouldn't be a big deal to you...

and I wasn't joking about donation...
johnnyNobody999
DD-WRT Guru


Joined: 10 Jan 2014
Posts: 504

PostPosted: Mon Nov 28, 2016 1:29    Post subject: Reply with quote
Mile-Lile wrote:
johnnyNobody999 wrote:
Mile-Lile wrote:
or we could all donate 1 euro and buy certificate...


Or, when I get the time, figure out how to use letsencrypt certs.


Maybe you are smarter than ddwrt team http://svn.dd-wrt.com/ticket/4993 but then again this https web access wouldn't be a big deal to you...

and I wasn't joking about donation...


Apparently the cert replacement is non-trivial. From what I read you have to repackage the firmware with the necessary cert files. https://www.dd-wrt.com/phpBB2/viewtopic.php?t=27979
johnnyNobody999
DD-WRT Guru


Joined: 10 Jan 2014
Posts: 504

PostPosted: Fri Dec 02, 2016 17:31    Post subject: Reply with quote
<Kong> wrote:


THere are two types of problems:

1. Browser won't allow overriding, e.g. if the cipher is too weak, and it is possible that some beta browser version enforce new restrictions

2. Browser will allow override if you accept the cert. If this was the case, then you really wasted our time.


I was able to get past the certificate warning but this is just another security issue. This is just another security issue that needs to be fixed. Sorry to have wasted your time but it seems to me that if HTTPS is going to be a feature it should be made easy to replace the default certificate. I'm not criticizing the developers, I'm just giving feedback.
Coolidge
DD-WRT Novice


Joined: 07 Oct 2017
Posts: 33

PostPosted: Wed Apr 18, 2018 19:39    Post subject: Reply with quote
<Kong> wrote:
https://www.dd-wrt.com/phpBB2/viewtopic.php?p=1055247#1055247

HTTPS (...) might be a problem on older units that do not have enough flash to include openssl, which is necessary nowadays, since browsers do not allow the use of old ciphers anymore.

(...)

HTTPS is not supported anymore on this router, it only has 4MB flash and therefore comes with an old ssl lib. There is not enough flash to upgrade the ssl lib on these models.


This is most interesting what Kong is saying, it should be sticked somewhere because many users (including me) wondered why simple "https" checkbox enabling crashed their devices making them unresponsive. It was due to security limitations of modern browsers denying access to too weak SSL. Now it makes perfect sense: 4MB flash memory devices cannot handle https connection meaning you need an 8MB+ OpenVPN capable router to establish a https connection with.
Goto page Previous  1, 2 Display posts from previous:    Page 2 of 2
Post new topic   Reply to topic    DD-WRT Forum Index -> Atheros WiSOC based Hardware All times are GMT

Navigation

 
Jump to:  
You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum
You cannot attach files in this forum
You cannot download files in this forum