Skip to content
This repository was archived by the owner on Nov 6, 2023. It is now read-only.
This repository was archived by the owner on Nov 6, 2023. It is now read-only.

HTTPS no longer works on j.mp - disable the ruleset #5083

Description

@anonsubmitter

HTTPS no longer works on j.mp, so the ruleset should be disabled.
Sample: http://j.mp/12ZHdor

Activity

  1. mnordhoff commented on Jun 10, 2016

    @mnordhoff
    Contributor

    @jehiah What happened to https://j.mp/? Its certificate now only covers bit.ly and www.bit.ly. Is it an intentional change or a bug?

    (Also it's vulnerable to the OpenSSL padding oracle vulnerability CVE-2016-2107.)

    https://www.ssllabs.com/ssltest/analyze.html?d=j.mp

    The ruleset can easily be changed to rewrite j.mp to https://bit.ly/, but this has wider impact, on other people using https://j.mp/.

    ETA: I pushed a branch (mnordhoff/https-everywhere@65ab5d2) to rewrite j.mp to bit.ly, if that's the best course of action.

  2. added a commit that references this issue on Jun 10, 2016
    65ab5d2
  3. J0WI commented on Jun 10, 2016

    @J0WI
    Contributor

    @jehiah is this domain owned by Bitly?

  4. mnordhoff commented on Jun 12, 2016

    @mnordhoff
    Contributor

    At least one Bitly client domain, thesent.nl, also has a (www.)bit.ly certificate.

    https://www.ssllabs.com/ssltest/analyze.html?d=thesent.nl

    I checked about 20 other domains from the Bitly vanity ruleset without finding a third.

  5. jehiah commented on Jun 14, 2016

    @jehiah
    Contributor

    @J0WI @mnordhoff Yes, j.mp is owned by Bitly. We've resolved this SSL issue on our side, so we can close this issue now. (sorry for the delay in responding)

    Some background: At Bitly we are in the middle of migrating our platform to a new datacenter, and due to some capacity constraints needed to temporarily migrate j.mp to an independent system in a 3rd datacenter. We call this system which we keep on standby to serve redirects on links in case of failures in our normal link redirect system "plan-z". It's meant to keep Bitly links working even if we experience total loss of connectivity to our primary datacenter.

    By it's nature plan-z is both software and datastore diverse from our normal redirect process to better insulate it from human errors that might affect both systems. Unfortunately this plan-z system hasn't been setup to handle SSL termination for multiple domains until now (which is why it was returning the bit.ly certificate). We've now completed that work so when we need to leverage this backup system, it will handle SSL for all domains just like our normal backend does.

    As a side-note: the expected behavior is that a domain will appear to revert back to the bit.ly certificate when we don't have a better one available. Based on normal domain churn this will happen periodically and i'll be updating the full domain list from #4505 at the end of the month. That's the case for thesent.nl where we are no longer able to obtain a LetsEncrypt certificate for that domain.

  6. J0WI commented on Jun 14, 2016

    @J0WI
    Contributor

    Thanks a lot for your statement on this!

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions