Morning all.

I've taken a look and I think have resolved all the existing issues. We're now getting an A  on SSLLabs :) Charles can you check if the issue is resolved.

Just to be clear on an important change; I've disabled TLSV1.1 and below on the confidential server (board wiki and CiviCRM/Donate page). This is because I feel it needs a boost in security; what this DOES mean is that it now no longer supports Android versions below 4.4 and IE 10 and below.

If this poses a problem I can re-enable it, but standard practice is to move away from TLSV1.1 and below. 

I've left the website/wiki with the ealier TLS versions for wider support for now.

Sorry it took so long to get to this; my Gmail I don't check so often nowadays and I get a lot of junk that hides meaningful things; I've unsubscribed from lots of stuff and sorted some filters out to help with this. I'll also subscribe my work address to this list.

Cheers,
Tom


On Sun, 25 Jun 2017 at 10:35 Thomas Morton <morton.thomas@googlemail.com> wrote:
taking a look this morning. Stay tuned.

T

On Sun, 25 Jun 2017 at 10:21 Charles Matthews <charles.r.matthews@ntlworld.com> wrote:


On 25 June 2017 at 09:18 David Gerard <dgerard@gmail.com> wrote:


https://www.ssllabs.com/ssltest/analyze.html?d=donate.wikimedia.org.uk&latest
is as broken as ever and clearly shows the incomplete cert chain
issue.

I'm not going to mess around with yet another Bugzilla when what I'm
reporting on is that I'm trying to give WMUK money and the site's not
working properly. Y'know, WMUK can either care or not.

I believe they accept cheques.  Charles

_______________________________________________
Wikimedia UK mailing list
wikimediauk-l@wikimedia.org
https://lists.wikimedia.org/mailman/listinfo/wikimediauk-l
WMUK: https://wikimedia.org.uk