Skip site navigation (1)Skip section navigation (2)
Date:      Thu, 13 Aug 2020 16:39:43 -0400
From:      Jon Radel <jon@radel.com>
To:        freebsd-questions@freebsd.org
Subject:   Re: OT: Dealing with a hosting company with it's head up it's rear end
Message-ID:  <451a71db-d3aa-ed2b-3d3e-362081a9acea@radel.com>
In-Reply-To: <CAGBxaX=9asO=X32RucVyNz5kppPhbZc9Ayx-pyiXMBi85BeJ6w@mail.gmail.com>
References:  <CAGBxaXmg0DGSEYtWBZcbmQbqc2vZFtpHrmW68txBck0nKJak=w@mail.gmail.com> <CAGBxaX=XbbFLyZm5-BO=6jCCrU%2BV%2BjubxAkTMYKnZZZq=XK50A@mail.gmail.com> <CALeGphwfr7j-xgSwMdiXeVxUPOP-Wb8WFs95tT_%2Ba8jig_Skxw@mail.gmail.com> <CAGBxaX=CXbZq-k6=udNaXTj2m%2BgnpDCB%2Bui4wgvtrzyHhjGeSw@mail.gmail.com> <40xvq0.qf0q3x.1hge1ap-qmf@smtp.boon.family> <CAGBxaX=9asO=X32RucVyNz5kppPhbZc9Ayx-pyiXMBi85BeJ6w@mail.gmail.com>

index | next in thread | previous in thread | raw e-mail

[-- Attachment #1 --]
On 8/13/20 16:12, Aryeh Friedman wrote:
> On Thu, Aug 13, 2020 at 3:59 PM André Boon <freebsd@andreboon.nl> wrote:
>
>>
>> On Thursday, August 13, 2020, Aryeh Friedman wrote:
>>> On Thu, Aug 13, 2020 at 3:04 PM Jack L. <xxjack12xx@gmail.com> wrote:
>>>
>>>> Just change the ssh/rdp ports?
>>>>
>>>>
>>> All ports except 80 and 25 are firewalled
>>>
>> Are you sure port 443 isn't open as well? I would expect so if port 80 is
>> available. That would allow port 80 to be used for SSH if you're OK with
>> only providing HTTPS.
>>
> They have a whacko firewall config that will eat 443/decrypt it/forward it
> on as plain http via a proxy on the firewall
>
>
Well, the availability of TLS off-load is arguably a feature, but to
require the use of it...  Apparently they acquired a security consultant
with a rather limited, and limiting, view of how the world works.  Or
even worse, they don't have a security expert involved and are making it
up as they go.

Much as it pains me to say this, it's probably time to involve the
lawyers and figure out whether the contract has been explicitly or
implicitly breached and see if you can shed the vendor without too big
an expense.   This probably comes down to the extent this project was
discussed as part of the sales process and what representations about
suitability the provider might have made.

And then move to an IaaS provider that gives you direct control over
most of these matters and leave this wacky little PaaS provider to the
market they appear to be aiming for--presumably WordPress sites and the
like.

-- 
--Jon Radel
jon@radel.com



[-- Attachment #2 --]
0	*H
010
	`He0	*H
00Πj8;+kٸRV0
	*H
010	UGB10UGreater Manchester10USalford10U
COMODO CA Limited1+0)U"COMODO RSA Certification Authority0
130110000000Z
280109235959Z010	UGB10UGreater Manchester10USalford10U
COMODO CA Limited1=0;U4COMODO RSA Client Authentication and Secure Email CA0"0
	*H
0
W(vu@8v!P%yL}:X>1.4vلj=4HK hyt4z|e`'"2@rF5P3*UT+%4D5+
ZSu+­=7F_Zte
>)
94Fro8pNhFF#Ne6/M{UWֱmAYT"o)CI	m84$.zW4 r^M9,R$
<080U#0~=<8220Ula|=+qH^ċ0U0U00U 
00U 0LUE0C0A?=;http://crl.comodoca.com/COMODORSACertificationAuthority.crl0q+e0c0;+0/http://crt.comodoca.com/COMODORSAAddTrustCA.crt0$+0http://ocsp.comodoca.com0
	*H
x\(4O<_VΟV쏢kI/5@qB!fk&kn{hJd| q[Lǿᓬ?"@fCOݐrXurJH5;#68jle) )Y4’Nezyq{:kx%iچ:w#f6HLP~jo9KXnM#:!!69i\}^M;TSX7	̯3]Tc6O$voX*5!4.aKE8HIĹ7?Ar}r# R/h<סnuy<1	3mɔv#~&pvg' skMH#/ƨ$/uXqTu(|^-vM҆NKX7fA\X5sh2qP\YǟENRarpGtZp_"k7DdJVGz00Ԡt$a,w0
	*H
010	UGB10UGreater Manchester10USalford10U
COMODO CA Limited1=0;U4COMODO RSA Client Authentication and Secure Email CA0
180304000000Z
210303235959Z010	UUS10U2215010	UVA10USpringfield10U	6917 Ridgeway Dr.10U
Jon T. Radel1200U)Issued through Jon T. Radel E-PKI Manager10UCorporate Secure Email10U	Jon Radel10	*H
	
jon@radel.com0"0
	*H
0
LNuOpS#OfK!UdYo
/Ǡ8,K +3ڄdI̓h3f8\/9N6(6/FY~˩I¯.~1$#DT]~8҄YO7+8b°$aEr]bW8ECIGJZ
tTK5ڈhӎڀ6Pc
3=dEH00U#0la|=+qH^ċ0UtZI&Ҝ0U0U00U%0++0FU ?0=0;+10+0)+https://secure.comodo.net/CPS0ZUS0Q0OMKIhttp://crl.comodoca.com/COMODORSAClientAuthenticationandSecureEmailCA.crl0+0}0U+0Ihttp://crt.comodoca.com/COMODORSAClientAuthenticationandSecureEmailCA.crt0$+0http://ocsp.comodoca.com0U0
jon@radel.com0
	*H
T4iYDP#3oN]k|QϵH2q-®%WK0P3c[7Г<w'A\|MkY&~X;#`+;ok&Isݕ?CfpHwg2
5A~=f|M~^=ArZSYQ-4A;֎n9hEkhl^}Ky2B|(T]:15010010	UGB10UGreater Manchester10USalford10U
COMODO CA Limited1=0;U4COMODO RSA Client Authentication and Secure Email CAt$a,w0
	`HeY0	*H
	1	*H
0	*H
	1
200813203943Z0/	*H
	1" {g}0`4^_B5P2.LG"0l	*H
	1_0]0	`He*0	`He0
*H
0*H
0
*H
@0+0
*H
(0	+710010	UGB10UGreater Manchester10USalford10U
COMODO CA Limited1=0;U4COMODO RSA Client Authentication and Secure Email CAt$a,w0*H
	1010	UGB10UGreater Manchester10USalford10U
COMODO CA Limited1=0;U4COMODO RSA Client Authentication and Secure Email CAt$a,w0
	*H
Fg}<>AV0f&1{ޞRVOK$My2C(P`ʻc"г9UQ,F`aq^q{
3`Iv
jSU2ćMe0.w<F.Iq<H}H	([=E=H@Z}ޜ
-QZpu18dPո?KEeܞ('/e]Q:X[wtBHE9H.Skz}T_
help

Want to link to this message? Use this
URL: <https://mail-archive.FreeBSD.org/cgi/mid.cgi?451a71db-d3aa-ed2b-3d3e-362081a9acea>