Dear develppers of the site,
Having registered on the fairmarket website, I noticed the following :
1) The browser protests against the website's certs "https is untrust"
giving it an exception , I encountered with the following flaws :
2) Time-zone difference notice which cannot be corrected as the website proposes BTW.
3) Clicking on any menu link (incl. the portal) gives "Odoo client error" message or "loading"
word without doing anything further.
So I am really embarassed is it my browser's fault or the website's developpers' ?
<p>The certificate error is because the market.fair.coop web server is sending an incomplete SSL certificate chain: it is not sending the Let's Encrypt intermediate SSL certificate. Firefox and Chromium on my computer do not detect this as an error because they bundle the certificate, but other browsers I have tried (surf, Epiphany, Dillo) as well as command line tools curl and wget do detect the error, because the intermediate certificate is not in the operating system's CA store. The missing certificate is Let’s Encrypt Authority X1, which is explained at https://letsencrypt.org/certificates/</p> <p>For reference, see SSL Lab's report https://www.ssllabs.com/ssltest/analyze.html?d=market.fair.coop and compare with https://www.ssllabs.com/ssltest/analyze.html?viaform=on&d=helloworld.letsencrypt.org</p> <p>I recommend the server administrators of FairMarket update the web server config to use the full chain. This means if you are using nginx that the file referenced by ssl_certificate should be the domain's certificate concatenated with the intermediate certificate letsencryptauthorityx1.pem</p>
<p>1) FairMarket uses letsencrypt to manage the SSL certificates and i am not experiencing issues in this aspect in several machines. So for this point, i think if your browser is too old and can not has the Letsencrypt CA certificate installed and raises the security error. You can try to install the certificates manually from https://letsencrypt.org/certificates/ not only for the FairMarket, also for all the sites using letsencrypt.</p> <p>2)</p> <p>a. After signup from website --> Click Top Right "Your Username" / My Account. This should bring you to the "Portal" web page.</p> <p>b. Click Top Right "Your Username" / Preferences. This open your user's preferences web page.</p> <p>c. Change the Timezone field, review other fields and save. Now the warning should have dissapeared.</p> <p>3) Extrange, looking in the logs right now.</p> <p> </p>
<p>Hi Madgy. </p> <p>As far as I know, point 1 may be your browser's fault. Depending on what browser u are using, it may be an old version, so you should update it, for the new versions of browsers should now recognize the brand new Let'sEncrypt Certificate. https://letsencrypt.org/</p> <p>Besides, I'd like you to focus on the point that all of the work being made for this market and all the FairCoop's ecosystem has been developed by a community, with much love and belief in a true change, so I'd like to ask you, please, to be kind, patient and thankful: We are in beta, we are in transition, no capitalist entity around to blame. Its us, the commons, building our tools.</p> <p>Greetings</p>
Please try to give a substantial answer. If you wanted to comment on the question or answer, just use the commenting tool. Please remember that you can always revise your answers - no need to answer the same question twice. Also, please don't forget to vote - it really helps to select the best questions and answers!
Keep me informed
About This Forum
This forum is for new features proposals in FairMarket and to speak about the future of the tool and cooperations with external platforms.Read Guidelines
|Asked: 23/2/16 - 7:56 π.μ.|
|Seen: 2616 times|
|Τελευταία Ενημέρωση: 14/11/17 - 11:30 π.μ.|