Date: Thu, 13 Aug 2020 16:39:43 -0400 From: Jon Radel <jon@radel.com> To: freebsd-questions@freebsd.org Subject: Re: OT: Dealing with a hosting company with it's head up it's rear end Message-ID: <451a71db-d3aa-ed2b-3d3e-362081a9acea@radel.com> In-Reply-To: <CAGBxaX=9asO=X32RucVyNz5kppPhbZc9Ayx-pyiXMBi85BeJ6w@mail.gmail.com> References: <CAGBxaXmg0DGSEYtWBZcbmQbqc2vZFtpHrmW68txBck0nKJak=w@mail.gmail.com> <CAGBxaX=XbbFLyZm5-BO=6jCCrU%2BV%2BjubxAkTMYKnZZZq=XK50A@mail.gmail.com> <CALeGphwfr7j-xgSwMdiXeVxUPOP-Wb8WFs95tT_%2Ba8jig_Skxw@mail.gmail.com> <CAGBxaX=CXbZq-k6=udNaXTj2m%2BgnpDCB%2Bui4wgvtrzyHhjGeSw@mail.gmail.com> <40xvq0.qf0q3x.1hge1ap-qmf@smtp.boon.family> <CAGBxaX=9asO=X32RucVyNz5kppPhbZc9Ayx-pyiXMBi85BeJ6w@mail.gmail.com>
index | next in thread | previous in thread | raw e-mail
[-- Attachment #1 --]
On 8/13/20 16:12, Aryeh Friedman wrote:
> On Thu, Aug 13, 2020 at 3:59 PM André Boon <freebsd@andreboon.nl> wrote:
>
>>
>> On Thursday, August 13, 2020, Aryeh Friedman wrote:
>>> On Thu, Aug 13, 2020 at 3:04 PM Jack L. <xxjack12xx@gmail.com> wrote:
>>>
>>>> Just change the ssh/rdp ports?
>>>>
>>>>
>>> All ports except 80 and 25 are firewalled
>>>
>> Are you sure port 443 isn't open as well? I would expect so if port 80 is
>> available. That would allow port 80 to be used for SSH if you're OK with
>> only providing HTTPS.
>>
> They have a whacko firewall config that will eat 443/decrypt it/forward it
> on as plain http via a proxy on the firewall
>
>
Well, the availability of TLS off-load is arguably a feature, but to
require the use of it... Apparently they acquired a security consultant
with a rather limited, and limiting, view of how the world works. Or
even worse, they don't have a security expert involved and are making it
up as they go.
Much as it pains me to say this, it's probably time to involve the
lawyers and figure out whether the contract has been explicitly or
implicitly breached and see if you can shed the vendor without too big
an expense. This probably comes down to the extent this project was
discussed as part of the sales process and what representations about
suitability the provider might have made.
And then move to an IaaS provider that gives you direct control over
most of these matters and leave this wacky little PaaS provider to the
market they appear to be aiming for--presumably WordPress sites and the
like.
--
--Jon Radel
jon@radel.com
[-- Attachment #2 --]
0 *H
010
`He 0 *H
00Πj8;+kٸRV0
*H
010 UGB10UGreater Manchester10USalford10U
COMODO CA Limited1+0)U"COMODO RSA Certification Authority0
130110000000Z
280109235959Z010 UGB10UGreater Manchester10USalford10U
COMODO CA Limited1=0;U4COMODO RSA Client Authentication and Secure Email CA0"0
*H
0
W(vu@8v!P%yL}:X>1.4vلj=4HK hyt4z|e`'"2@rF5P3*UT+%4D5+
ZSu+=7F_Zte
>)
94Fro8pNhFF#Ne6/M{UWֱmAYT"o)CI m84$.zW4 r^M9,R$
<080U#0~=<8220Ula|=+qH^ċ0U0U0 0U
00U 0LUE0C0A?=;http://crl.comodoca.com/COMODORSACertificationAuthority.crl0q+e0c0;+0/http://crt.comodoca.com/COMODORSAAddTrustCA.crt0$+0http://ocsp.comodoca.com0
*H
x\(4O<_VΟV쏢kI/5@qB!fk&kn{hJd| q[Lǿᓬ?"@fCOݐrXurJH5;#68jle) )Y4Nezyq{: kx%iچ:w#f6HLP~jo9KXnM#:!!69i\}^M;TSX7 ̯3]Tc6O$voX*5!4.aKE8HIĹ7?Ar}r# R/h<סnuy<1 3mɔv#~&pvg' skMH#/ƨ$/uXqTu(|^-vM҆NKX7fA\X5sh2qP\YǟENRarpGtZp_"k7DdJVGz00Ԡt$a,w0
*H
010 UGB10UGreater Manchester10USalford10U
COMODO CA Limited1=0;U4COMODO RSA Client Authentication and Secure Email CA0
180304000000Z
210303235959Z010 UUS10U2215010 UVA10USpringfield10U 6917 Ridgeway Dr.10U
Jon T. Radel1200U)Issued through Jon T. Radel E-PKI Manager10UCorporate Secure Email10U Jon Radel10 *H
jon@radel.com0"0
*H
0
LNuOpS#OfK!UdYo
/Ǡ8,K +3ڄdI̓h3f8\/9N6(6/FY~˩I¯.~1$#DT]~8҄YO7+8b°$aEr]bW8ECIGJZ
tTK 5ڈhӎڀ6Pc
3=dEH 00U#0la|=+qH^ċ0UtZI&Ҝ0U0U0 0U%0++0FU ?0=0;+10+0)+https://secure.comodo.net/CPS0ZUS0Q0OMKIhttp://crl.comodoca.com/COMODORSAClientAuthenticationandSecureEmailCA.crl0+0}0U+0Ihttp://crt.comodoca.com/COMODORSAClientAuthenticationandSecureEmailCA.crt0$+0http://ocsp.comodoca.com0U0
jon@radel.com0
*H
T4iYDP#3oN]k|QϵH2q-®%WK0P3c[7Г<w'A\|MkY&~X;#`+;ok&Isݕ?CfpHwg2
5A~=f|M~^=ArZSYQ-4A;֎n9hEkhl^}Ky2B|(T]:15010010 UGB10UGreater Manchester10USalford10U
COMODO CA Limited1=0;U4COMODO RSA Client Authentication and Secure Email CAt$a,w0
`He Y0 *H
1 *H
0 *H
1
200813203943Z0/ *H
1" {g}0`4^_B5P2.LG"0l *H
1_0]0 `He*0 `He0
*H
0*H
0
*H
@0+0
*H
(0 +710010 UGB10UGreater Manchester10USalford10U
COMODO CA Limited1=0;U4COMODO RSA Client Authentication and Secure Email CAt$a,w0*H
1010 UGB10UGreater Manchester10USalford10U
COMODO CA Limited1=0;U4COMODO RSA Client Authentication and Secure Email CAt$a,w0
*H
Fg}<>AV0f&1{ޞRVOK$My2C(P`ʻc"г9UQ,F`aq^q{
3`Iv
jSU2ćMe0.w<F.Iq<H}H ([=E=H@Z}ޜ
-QZpu18dPո?KEeܞ('/e]Q:X[wtBHE9H.Skz}T_
help
Want to link to this message? Use this
URL: <https://mail-archive.FreeBSD.org/cgi/mid.cgi?451a71db-d3aa-ed2b-3d3e-362081a9acea>
