8 ms·
HTTPS for GitHub Pages
- jsprogrammer 10y agoSweet. Was just lamenting its absence.
- r3bl 10y agoAbout damn time! I "cheated" the system by having a script that will redirect you to the HTTPS version if you click on anything from the HTTP protocol, which kind of accomplishes forcing the HTTPS encryption, but not really. Then I've decided to switch to my own domain and just use CloudFlare (+ whitelisting Tor). Now I'm kind of thinking about switching to GitLab Pages since they pretty much kick the hell out of GitHub Pages in every single way when you compare their features (like, you can use any static site generator and you can roll your own Lets Encrypt SSL certificate on them).
- sbruchmann 10y agoI’m not familiar with GitLab Pages but you can already use any static site generator with GitHub Pages as well.
- r3bl 10y agoHuh, turns out you're right. Not sure if that was the case when I started moving to GitHub (~15 months ago) or not, but looks like it's a thing now. But still, you can do other things like selecting a different code highlighter (which GitHub deprecated recently).
- mawburn 10y agoIt's always been the case. Github Pages has always been just a static file host.
- chillacy 10y agoTo clarify, you mean you can if you add the output to your git repo right? Currently I have gh pages set to automatically build my site with jekyll, but I believe they limit plugins to only safe ones.
- grep4master 10y agoAre you sure that's not a Gitlab EE-only feature?
- r3bl 10y agoYes, I am: https://pages.gitlab.io/ https://pages.gitlab.io/ It's a feature they introduced pretty recently (~ a month ago IIRC), but it always kind of worked with CI + some tinkering (I know this because my organization used our own instance of GitLab as our publishing platform before this feature became a thing).
- Snappy 10y agoYes, it's a GitLab EE-only feature, but it's also available for free on GitLab.com, which is running GitLab EE.
- bluetidepro 10y agoNice work GitHub! That's huge! I think that means you could now use GitHub pages for Slack services that required HTTPS? If so, that's really awesome!
- tvanantwerp 10y agoDoesn't appear to work with custom domains.
- davis_m 10y agoI would hope not. If Github could generate valid SSL certs for random domains, something would be very broken.
- nileshtrivedi 10y agoIt would just request LetsEncrypt to generate those certs and then prove the "ownership" (more like "control") of those domains by whatever method LetsEncrypt wants (.well-known perhaps?).
- Nullabillity 10y agoYup, .well-known should be pretty simple for them to implement.
- atonse 10y agoProbably in the works? SNI should make this pretty easy now, right? Maybe GH doesn't want the responsibility of hosting everyone's private keys.
- minimaxir 10y agoFrom the documentation: > HTTPS is not supported for GitHub Pages using custom domains. Not unsurprising, but unfortunate.
- travjones 10y agoCloudflare's free plan includes one-click SSL for custom domains. That's what I use for my github pages sites.
- kevincox 10y agoAlthough it doesn't validate the backend certificate.
- ddbennett 10y agoFor those on Bitbucket, <username>.bitbucket.io is the HTTPS equivalent of <username>.bitbucket.org.
- jgowans 10y agoICYI, you can also get free, self-renewing, wildcard SSL certs for custom domains on Bitbucket by using the Aerobatic add-on for Bitbucket. [https://www.aerobatic.com https://www.aerobatic.com] disclaimer: co-founder of Aerobatic
- JBiserkov 10y agoGreat service! For those wondering what are the limitations of the otherwise very generous free plan: 2 sites, 1 domain, 5 deployments in a 24 hour period something something Amazon US East
- fibo 10y agoThank you GitHub for this gift, static web sites and now forced https
- bnb 10y agoForced? You can enable and disable it in every repo's settings.
- kramerc 10y agoNot for "GitHub Pages sites created after June 15, 2016 and using a github.io domain."[1] [1] https://help.github.com/articles/securing-your-github-pages-site-with-https/ https://help.github.com/articles/securing-your-github-pages-...
- theandrewbailey 10y agoI just noticed it this morning when trying to put up a demo file for a project. I was confused by the docs saying 'don't do anything sensitive because no HTTPS', but clearly seeing the https:// https:// URLs.
- Wonnk13 10y agoWhat's the best way to get HTTPS for custom domains? Letsencrypt or Cloudflare? I don't think those are encrypted end to end, no?
- donut2d 10y agoLet's Encrypt is a certificate authority and provides certificates and so it would be end-to-end. However, CloudFlare is not end-to-end unless the server already supports HTTPS.
- nothrabannosir 10y ago> CloudFlare is not end-to-end unless the server already supports HTTPS. That's literally what this article is about.
- BHSPitMonkey 10y agoHTTPS isn't supported if you're using GH Pages with a custom domain.
- pfg 10y agoI wouldn't call CloudFlare end-to-end encrypted. They see the plaintext, independent of whether communication with the backend is encrypted or not.
- developer2 10y agoCloudFlare has a detailed explanation of the various options[1]. [1] https://support.cloudflare.com/hc/en-us/articles/200170416-What-do-the-SSL-options-mean- https://support.cloudflare.com/hc/en-us/articles/200170416-W...
- nothrabannosir 10y agoCloudflare wouldn't be e2e in the sense that the SSL would terminate at Cloudflare, which would then open a new SSL connection to GitHub. Everything would be properly encrypted, but Cloudflare would indeed have access to the plaintext (i.e. it isn't e2e).
- pfista 10y agoDoes anyone know if github is planning to support https for custom domains?
- max_ 10y agoCurrently, they don't have plans. just use cloudflare.
- mlissner 10y agoThat doesn't actually create a properly encrypted connection. It only encrypts between the user and the site (at CloudFlare), not between the site and Github. Without that last hop being encrypted, you have to weigh whether this is an improvement or not.
- JeremyBanks 10y agoIt significantly decreases the attack surface, since most of the connection will be encrypted inside CloudFare's network or over HTTPs. Should be a clear win for most cases.
- manigandham 10y agoYes it does - this is all a setting you can choose and since Github does support HTTPS (and has for a while) you can always set it on "strict" and ensure a continuous encrypted connection on both sides of CloudFlare.
- MichaelGG 10y agoBut what certificate will Github present for your custom domain? I don't think you can tell CF to accept Github pages's cert for your own domain. They either use their own CA or don't do auth, right? At least on non-enterprise plans.
- manigandham 10y agoCloudFlare is what serves your custom domain. On the backend you point CloudFlare to https://username.github.io https://username.github.io and CF will receive the wildcard certificate for *.github.io
- calebm 10y agoIf I understand it correctly, the same HTTPS certificate is used for all GitHub pages websites. So hypothetically, I could do a MITM attack and redirect a user from an HTTPS protected GitHub pages site to my malicious GitHub Pages site right? (although the url would be different... but could be similar)
- jsingleton 10y agoI've been running the HTTPS Everywhere add-on and hadn't realised that this wasn't already a thing. As the post says, they have supported HTTPS for a while and this is just adding a redirection option so you don't need to resort to JS hacks. It doesn't say if they are using 301 redirects or HSTS headers, I'm guessing the former.
- Jeaye 10y agoYou can enable HTTPS for custom domains using this approach: https://blog.jeaye.com/2016/03/01/github-pages-https/ https://blog.jeaye.com/2016/03/01/github-pages-https/ Just be sure to delete your CNAME file, based on a recent Github behavior change.
- franciscop 10y agoSo now github "sorta sorta" [1] supports https: - You CAN force HTTPS for your *.github.io site. - You CAN use an https://yourname.github.io https://yourname.github.io URL. - You CANNOT use a custom domain name with a fully secured HTTPS connection. [1] https://konklone.com/post/github-pages-now-sorta-supports-https-so-use-it https://konklone.com/post/github-pages-now-sorta-supports-ht...
- aorth 10y agoFrom the announcement (because I was confused): You have been able to request Pages sites over HTTPS for some time, but we refrained from officially supporting it because the traffic from our CDN to our servers wasn't encrypted until now.