<?xml version="1.0" encoding="UTF-8" standalone="yes" ?>
<!DOCTYPE bugzilla SYSTEM "https://www.w3.org/Bugs/Public/page.cgi?id=bugzilla.dtd">

<bugzilla version="5.0.4"
          urlbase="https://www.w3.org/Bugs/Public/"
          
          maintainer="sysbot+bugzilla@w3.org"
>

    <bug>
          <bug_id>27390</bug_id>
          
          <creation_ts>2014-11-21 13:47:03 +0000</creation_ts>
          <short_desc>whatwg.org&apos;s TLS</short_desc>
          <delta_ts>2015-10-16 14:45:11 +0000</delta_ts>
          <reporter_accessible>1</reporter_accessible>
          <cclist_accessible>1</cclist_accessible>
          <classification_id>1</classification_id>
          <classification>Unclassified</classification>
          <product>WHATWG</product>
          <component>Unwelcome</component>
          <version>unspecified</version>
          <rep_platform>Other</rep_platform>
          <op_sys>other</op_sys>
          <bug_status>RESOLVED</bug_status>
          <resolution>WORKSFORME</resolution>
          
          
          <bug_file_loc></bug_file_loc>
          <status_whiteboard></status_whiteboard>
          <keywords></keywords>
          <priority>P3</priority>
          <bug_severity>normal</bug_severity>
          <target_milestone>Unsorted</target_milestone>
          
          
          <everconfirmed>1</everconfirmed>
          <reporter name="Anne">annevk</reporter>
          <assigned_to name="Anne">annevk</assigned_to>
          <cc>ian</cc>
    
    <cc>mike</cc>
          
          <qa_contact>sideshowbarker+unwelcome</qa_contact>

      

      

      

          <comment_sort_order>oldest_to_newest</comment_sort_order>  
          <long_desc isprivate="0" >
    <commentid>115285</commentid>
    <comment_count>0</comment_count>
    <who name="Anne">annevk</who>
    <bug_when>2014-11-21 13:47:03 +0000</bug_when>
    <thetext>If you don&apos;t like tracking this as a bug, feel free to resolve this as INVALID.

1) We need to ask DreamHost when they plan upgrading their VPS customers. All Shared customers have been upgraded, but VPS customers still have a pretty shitty setup: https://www.ssllabs.com/ssltest/analyze.html?d=whatwg.org https://www.ssllabs.com/ssltest/analyze.html?d=html.spec.whatwg.org

2) We should use StartSSL&apos;s intermediate certificate that uses SHA-2: https://www.startssl.com/certs/class2/sha2/pem/sub.class2.server.sha2.ca.pem</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>115332</commentid>
    <comment_count>1</comment_count>
    <who name="Ian &apos;Hixie&apos; Hickson">ian</who>
    <bug_when>2014-11-21 23:49:08 +0000</bug_when>
    <thetext>Assuming I didn&apos;t screw everything up, I just updated all 31 domains to use the same certs including that intermediate cert.

Feel free to contact them. :-)</thetext>
  </long_desc>
      
      

    </bug>

</bugzilla>